|
Plagegeister aller Art und deren Bekämpfung: Virus erwischt oder nicht?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.12.2014, 23:07 | #1 |
| Virus erwischt oder nicht? hallo, ich poste hier für meinen Kollegen weil er nicht auf den Browser kann ADWCleanerLog Code:
ATTFilter # AdwCleaner v4.106 - Report created 22/12/2014 at 22:47:28 # Updated 21/12/2014 by Xplode # Database : 2014-12-21.4 [Live] # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits) # Username : Jacko - JACKO-PC # Running from : C:\Users\Jacko\Desktop\adwcleaner_4.106.exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Found : C:\Program Files (x86)\predm Folder Found : C:\ProgramData\TVWizard Folder Found : C:\Users\Jacko\AppData\Local\Temp\CloudGuard Folder Found : C:\Users\Jacko\AppData\Local\TVWizard ***** [ Scheduled Tasks ] ***** ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\AppDataLow\Software\DynConIE Key Found : HKCU\Software\InetStat Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKCU\Software\OCS Key Found : HKCU\Software\TutoTag Key Found : HKCU\Software\Wnkey Key Found : [x64] HKCU\Software\InetStat Key Found : [x64] HKCU\Software\OCS Key Found : [x64] HKCU\Software\TutoTag Key Found : [x64] HKCU\Software\Wnkey Key Found : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6} Key Found : HKLM\SOFTWARE\GAMESDESKTOP Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKLM\SOFTWARE\mystartsearchSoftware Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17496 Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.mystartsearch.com/?type=hp&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.mystartsearch.com/?type=hp&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} -\\ Mozilla Firefox v -\\ Google Chrome v39.0.2171.95 ************************* AdwCleaner[R0].txt - [4047 octets] - [22/12/2014 22:44:37] AdwCleaner[R1].txt - [3917 octets] - [22/12/2014 22:47:28] ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [3977 octets] ########## |
23.12.2014, 00:22 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virus erwischt oder nicht? Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
23.12.2014, 00:25 | #3 |
| Virus erwischt oder nicht? FRST. txt datei muss in 3 gesplittet werden lol ka was er da gemacht hat is ziemlich viel
__________________Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-12-2014 01 Ran by Jacko (administrator) on JACKO-PC on 22-12-2014 23:01:36 Running from C:\Users\Jacko\Downloads Loaded Profile: Jacko (Available profiles: Jacko) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\avp.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Spotify Ltd) C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\avpui.exe () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe (Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe (Razer, Inc.) C:\Users\Jacko\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe (Valve Corporation) C:\Games\Steam\Steam.exe (Valve Corporation) C:\Games\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) C:\Games\Steam\bin\steamwebhelper.exe (Microsoft Corporation) C:\Windows\System32\SndVol.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe (Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.5383\Battle.net.exe () C:\Users\Jacko\Desktop\adwcleaner_4.106.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1796056 2014-08-19] (NVIDIA Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2014-11-03] (Razer Inc.) HKLM-x32\...\Run: [gmsd_de_12] => [X] HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-12-03] (Adobe Systems Incorporated) HKLM-x32\...\RunOnce: [DXTempFolder] => rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Jacko\AppData\Local\Temp\DXFE1E.tmp\" HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [Steam] => C:\Games\Steam\steam.exe [1940160 2014-11-18] (Valve Corporation) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [Spotify Web Helper] => C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-13] (Spotify Ltd) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30876768 2014-12-03] (Skype Technologies S.A.) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [Spotify] => C:\Users\Jacko\AppData\Roaming\Spotify\spotify.exe [6737976 2014-12-13] (Spotify Ltd) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\RunOnce: [Adobe Speed Launcher] => 1419278647 HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\MountPoints2: {6cc90581-7cba-11e4-9649-806e6f6e6963} - D:\setup.exe HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\MountPoints2: {dd6bad4c-7cba-11e4-8f19-9d3bf42e9911} - F:\setup.exe BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: [S-1-5-21-1241592699-1578615748-785451789-1000] => localhost:8080 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} HKU\S-1-5-21-1241592699-1578615748-785451789-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mystartsearch.com/?type=hp&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE HKU\S-1-5-21-1241592699-1578615748-785451789-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp HKU\S-1-5-21-1241592699-1578615748-785451789-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} BHO: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) BHO: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{F77548F7-36AA-4552-845A-9A58B59FAE10}: [NameServer] 31.168.224.106,5.135.12.52 FireFox: ======== FF ProfilePath: C:\Users\Jacko\AppData\Roaming\Mozilla\Firefox\Profiles\0JhA7EB1.default FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @kaspersky.com/content_blocker_6418E0D362104DADA084DC312DFA8ABC -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\content_blocker@kaspersky.com () FF Plugin-x32: @kaspersky.com/virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\virtual_keyboard@kaspersky.com () FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Avira Browser Safety - C:\Users\Jacko\AppData\Roaming\Mozilla\Firefox\Profiles\0JhA7EB1.default\Extensions\abs@avira.com [2014-12-05] FF HKLM-x32\...\Firefox\Extensions: [content_blocker_6418E0D362104DADA084DC312DFA8ABC@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\content_blocker@kaspersky.com FF Extension: Модуль блокування небезпечних веб-сайтів - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\content_blocker@kaspersky.com [2014-12-18] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\virtual_keyboard@kaspersky.com FF Extension: Віртуальна клавіатура - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2014-12-18] Chrome: ======= CHR Profile: C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-22] CHR Extension: (Google Docs) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-22] CHR Extension: (Google Drive) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-22] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-22] CHR Extension: (YouTube) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-22] CHR Extension: (Adblock Plus) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-22] CHR Extension: (Google-Suche) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-22] CHR Extension: (Kaspersky Protection) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2014-12-22] CHR Extension: (Google Tabellen) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-22] CHR Extension: (Avira Browserschutz) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-12-22] CHR Extension: (Google Wallet) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-22] CHR Extension: (Google Mail) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-22] CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho [Not Found] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho [Not Found] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AVP15.0.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\avp.exe [234520 2014-08-30] (Kaspersky Lab ZAO) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [183488 2014-10-31] () R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [238288 2013-01-14] (Kaspersky Lab UK Ltd) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-12-05] (Disc Soft Ltd) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [468576 2014-03-31] (Kaspersky Lab ZAO) R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46144 2014-07-02] (Kaspersky Lab ZAO) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [150536 2014-12-18] (Kaspersky Lab ZAO) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [246456 2014-08-12] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [818888 2014-12-18] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55872 2014-06-05] (Kaspersky Lab ZAO) R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [77512 2014-12-18] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179776 2014-07-09] (Kaspersky Lab ZAO) R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.) R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39592 2014-09-05] (Razer Inc) R1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-18] (Razer, Inc.) R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-10-31] (Razer, Inc.) R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-11-17] (Razer, Inc.) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-22 23:01 - 2014-12-22 23:02 - 00017403 _____ () C:\Users\Jacko\Downloads\FRST.txt 2014-12-22 23:01 - 2014-12-22 23:01 - 00000000 ____D () C:\FRST 2014-12-22 23:00 - 2014-12-22 23:00 - 02122240 _____ (Farbar) C:\Users\Jacko\Downloads\FRST64.exe 2014-12-22 22:44 - 2014-12-22 22:48 - 00000000 ____D () C:\AdwCleaner 2014-12-22 22:44 - 2014-12-22 22:44 - 02173952 _____ () C:\Users\Jacko\Desktop\adwcleaner_4.106.exe 2014-12-22 18:50 - 2014-12-22 18:50 - 00000000 ____D () C:\Users\Jacko\Downloads\Wireless LAN_Atheros_9.1.0.334_W7x64_A 2014-12-22 18:50 - 2014-12-22 18:50 - 00000000 ____D () C:\Users\Jacko\Downloads\Lan_Broadcom_14.8.0.5_W7x64W7x86_A 2014-12-22 18:48 - 2014-12-22 18:50 - 45806731 _____ () C:\Users\Jacko\Downloads\Wireless LAN_Atheros_9.1.0.334_W7x64_A.zip 2014-12-22 18:48 - 2014-12-22 18:48 - 11633792 _____ () C:\Users\Jacko\Downloads\Lan_Broadcom_14.8.0.5_W7x64W7x86_A.zip 2014-12-22 18:48 - 2014-12-22 18:48 - 02593634 _____ () C:\Users\Jacko\Downloads\Chipset_Intel_9.2.0.1015_W7x64_A.zip 2014-12-22 18:44 - 2014-12-22 18:44 - 00254216 _____ () C:\Users\Jacko\Downloads\DriverTurboSetup.exe 2014-12-22 18:06 - 2014-12-22 18:06 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-12-22 18:06 - 2014-12-22 18:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-12-22 18:04 - 2014-12-22 18:04 - 00000085 _____ () C:\Windows\wininit.ini 2014-12-22 16:32 - 2009-06-10 22:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hosts.20141222-163241.backup 2014-12-22 13:43 - 2014-12-22 18:27 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-12-22 13:43 - 2014-12-22 18:04 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-12-22 13:43 - 2014-12-22 13:43 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-12-22 13:41 - 2014-12-22 13:42 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Jacko\Downloads\spybot-2.4.exe 2014-12-22 12:42 - 2014-12-22 12:42 - 02721168 _____ (Microsoft Corporation) C:\Users\Jacko\Downloads\Windows7-USB-DVD1024-tool.exe 2014-12-22 12:42 - 2014-12-22 12:42 - 02721168 _____ (Microsoft Corporation) C:\Users\Jacko\Downloads\Windows7-USB-DVD1024-tool (1).exe 2014-12-21 19:24 - 2014-12-21 19:24 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-12-21 19:24 - 2014-12-21 19:24 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-12-21 19:24 - 2014-12-21 19:24 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-12-21 19:23 - 2014-12-21 19:44 - 00000000 ____D () C:\ProgramData\Adobe 2014-12-21 19:06 - 2014-12-21 19:43 - 00000000 ____D () C:\Users\Jacko\AppData\Local\Adobe 2014-12-21 19:05 - 2014-12-21 19:05 - 00000000 ____D () C:\Users\Jacko\Downloads\JorgeCervantes-MarihuanaDrinnenAllesüberdenAnbauimHaus 2014-12-21 18:20 - 2014-12-21 19:01 - 122218957 _____ () C:\Users\Jacko\Downloads\JorgeCervantes-MarihuanaDrinnenAllesüberdenAnbauimHaus.rar 2014-12-21 16:07 - 2014-12-21 16:42 - 3192264704 _____ () C:\Users\Jacko\Downloads\X15-65741.iso 2014-12-21 12:23 - 2014-12-21 12:23 - 00000454 _____ () C:\Users\Jacko\Downloads\listen-dsl.asx 2014-12-21 04:05 - 2014-12-21 04:06 - 00000026 _____ () C:\Users\Jacko\Desktop\Neues Textdokument (2).txt 2014-12-21 04:01 - 2014-12-21 04:01 - 00000000 ___HD () C:\Program Files (x86)\Zero G Registry 2014-12-21 04:00 - 2014-12-21 04:00 - 00000000 ___HD () C:\Users\Jacko\InstallAnywhere 2014-12-20 00:27 - 2014-12-20 00:27 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf 2014-12-19 23:51 - 2014-12-19 23:51 - 00000000 ____D () C:\Users\Jacko\AppData\Roaming\NVIDIA 2014-12-18 20:24 - 2014-12-22 21:43 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-12-18 20:24 - 2014-12-18 20:24 - 00002091 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-12-18 20:24 - 2014-12-18 20:24 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-12-18 20:24 - 2014-12-18 20:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2014-12-18 20:24 - 2014-12-18 20:24 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-12-18 20:24 - 2014-08-12 18:33 - 00246456 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klhk.sys 2014-12-18 20:24 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2014-12-18 20:08 - 2014-12-18 20:11 - 202853696 _____ () C:\Users\Jacko\Downloads\kav15.0.1.415de_6845.exe 2014-12-18 10:59 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-18 10:59 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-12-16 13:10 - 2014-12-16 13:10 - 00000000 ____D () C:\Users\Jacko\Downloads\Doom_CooldownPulse 2014-12-16 12:35 - 2014-12-16 12:35 - 00007078 _____ () C:\Users\Jacko\Downloads\Doom_CooldownPulse.zip 2014-12-16 00:21 - 2014-12-16 01:06 - 00000000 ____D () C:\Users\Jacko\AppData\Roaming\TS3Client 2014-12-16 00:21 - 2014-12-16 00:21 - 00000967 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-12-16 00:21 - 2014-12-16 00:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2014-12-16 00:21 - 2014-12-16 00:21 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-12-16 00:20 - 2014-12-16 00:20 - 30014480 _____ (TeamSpeak Systems GmbH) C:\Users\Jacko\Downloads\TeamSpeak3-Client-win64-3.0.16.exe 2014-12-15 19:25 - 2014-12-15 19:25 - 02942368 _____ (Blizzard Entertainment) C:\Users\Jacko\Downloads\World-of-Warcraft-Setup-enGB.exe 2014-12-12 01:22 - 2014-12-12 01:22 - 04739198 _____ () C:\Users\Jacko\Downloads\Crotalus_basiliscus_feeding.mp4 2014-12-11 18:57 - 2014-12-12 23:38 - 00000121 _____ () C:\Users\Jacko\Desktop\Neues Textdokument.txt 2014-12-11 03:05 - 2014-12-11 03:05 - 00000000 ____D () C:\Windows\system32\appraiser 2014-12-11 03:00 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-12-11 03:00 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2014-12-11 03:00 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-12-11 03:00 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-12-11 03:00 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-12-11 03:00 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-12-11 03:00 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2014-12-11 03:00 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2014-12-11 03:00 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2014-12-11 03:00 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2014-12-11 02:14 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2014-12-11 02:14 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2014-12-11 02:14 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-12-11 02:14 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-12-11 02:14 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-12-11 02:14 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-12-11 02:14 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-12-11 02:14 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2014-12-11 02:14 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-11 02:14 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-12-11 02:14 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-11 02:14 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-11 02:14 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-12-11 02:14 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-11 02:14 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-11 02:14 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-11 02:14 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-12-11 02:14 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-12-11 02:14 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-11 02:14 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-11 02:14 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-11 02:14 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-12-11 02:14 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-11 02:14 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-12-11 02:14 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-12-11 02:14 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-12-11 02:14 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-11 02:14 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-12-11 02:14 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-12-11 02:14 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-11 02:14 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-11 02:14 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-12-11 02:14 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-12-11 02:14 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-12-11 02:14 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-11 02:14 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-12-11 02:14 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-12-11 02:14 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-12-11 02:14 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-12-11 02:14 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-12-11 02:14 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-12-11 02:14 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-11 02:14 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-11 02:14 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-12-11 02:14 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-11 02:14 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-12-11 02:14 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-11 02:14 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-12-11 02:14 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-12-11 02:14 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-12-11 02:14 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-12-11 02:14 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-12-11 02:14 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-11 02:14 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-12-11 02:14 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-12-11 02:14 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-12-11 02:14 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-11 02:14 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-12-11 02:14 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-12-11 02:14 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-12-11 02:14 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-12-11 02:14 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-12-11 02:14 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-11 02:14 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-12-11 02:14 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2014-12-11 02:13 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-11 02:13 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-12-11 02:13 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2014-12-11 02:13 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2014-12-11 02:13 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-12-11 02:13 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2014-12-11 02:13 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-12-11 02:13 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2014-12-11 02:13 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2014-12-11 02:13 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-12-11 02:13 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2014-12-11 02:13 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-12-11 02:13 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2014-12-11 02:13 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2014-12-09 19:32 - 2014-12-11 07:24 - 00000000 ____D () C:\Users\Jacko\Desktop\Manou Bewerbung 2014-12-08 21:27 - 2014-12-08 22:13 - 00000000 ____D () C:\Users\Jacko\AppData\Roaming\vlc 2014-12-08 21:26 - 2014-12-08 21:26 - 00000871 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-12-08 21:26 - 2014-12-08 21:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2014-12-08 21:26 - 2014-12-08 21:26 - 00000000 ____D () C:\Program Files\VideoLAN 2014-12-08 21:25 - 2014-12-08 21:25 - 01174352 _____ () C:\Users\Jacko\Downloads\VLC media player 64 Bit - CHIP-Installer.exe 2014-12-08 15:59 - 2014-12-22 22:30 - 00000000 ____D () C:\Users\Jacko\AppData\Roaming\Skype 2014-12-08 15:59 - 2014-12-08 15:59 - 00000000 ____D () C:\Users\Jacko\AppData\Local\Skype 2014-12-08 15:58 - 2014-12-18 20:27 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-12-08 15:58 - 2014-12-18 20:27 - 00000000 ____D () C:\ProgramData\Skype 2014-12-08 15:58 - 2014-12-18 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-12-08 15:58 - 2014-12-08 15:59 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-12-08 15:19 - 2014-12-08 15:19 - 44835432 _____ (Skype Technologies S.A.) C:\Users\Jacko\Downloads\SkypeSetupFull_7.0.0.100.exe 2014-12-07 19:14 - 2014-12-11 07:24 - 00000000 ____D () C:\Users\Jacko\Desktop\Manou Präsentation Praktikum 2014-12-07 01:21 - 2014-12-07 01:21 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-12-06 23:43 - 2014-06-27 03:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-12-06 23:43 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-12-06 20:16 - 2014-12-22 22:30 - 00000000 ____D () C:\Users\Jacko\AppData\Roaming\Spotify 2014-12-06 20:16 - 2014-12-22 17:23 - 00000000 ____D () C:\Users\Jacko\AppData\Local\Spotify 2014-12-06 20:16 - 2014-12-06 20:16 - 00137888 _____ (Spotify Ltd) C:\Users\Jacko\Downloads\SpotifySetup.exe 2014-12-06 20:16 - 2014-12-06 20:16 - 00001767 _____ () C:\Users\Jacko\Desktop\Spotify.lnk 2014-12-06 20:16 - 2014-12-06 20:16 - 00001753 _____ () C:\Users\Jacko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk 2014-12-06 19:45 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-12-06 19:45 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-12-06 19:45 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-12-06 19:45 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-12-06 19:45 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-12-06 19:45 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-12-06 19:45 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-12-06 19:45 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-12-06 19:45 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-12-06 19:45 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-12-06 19:45 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-12-06 19:45 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-12-06 19:45 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-12-06 19:45 - 2014-07-08 23:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-12-06 19:45 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-12-06 19:45 - 2014-06-24 04:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-12-06 19:45 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-12-06 19:45 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-12-06 19:45 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-12-06 19:45 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-12-06 19:45 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-12-06 19:45 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2014-12-06 19:45 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2014-12-06 19:45 - 2011-03-11 07:41 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys 2014-12-06 19:45 - 2011-03-11 07:41 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys 2014-12-06 19:45 - 2011-03-11 07:41 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys 2014-12-06 19:45 - 2011-03-11 07:41 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys 2014-12-06 19:45 - 2011-03-11 07:41 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys 2014-12-06 19:45 - 2011-03-11 07:33 - 02565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2014-12-06 19:45 - 2011-03-11 07:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe 2014-12-06 19:45 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2014-12-06 19:45 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe 2014-12-06 19:45 - 2011-03-11 05:37 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2014-12-06 19:45 - 2011-02-25 07:19 - 02871808 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2014-12-06 19:45 - 2011-02-25 06:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2014-12-06 14:59 - 2014-12-06 14:59 - 00000000 ____D () C:\Users\Jacko\AppData\Local\Activision 2014-12-06 14:55 - 2014-12-22 17:48 - 00000000 ____D () C:\Users\Jacko\Desktop\Bilder 2014-12-06 14:28 - 2014-12-06 14:28 - 00000000 ____D () C:\Users\Jacko\AppData\Roaming\WinRAR 2014-12-06 14:23 - 2014-12-06 14:23 - 00000000 ____D () C:\Users\Jacko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-12-06 14:23 - 2014-12-06 14:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-12-06 14:23 - 2014-12-06 14:23 - 00000000 ____D () C:\Program Files\WinRAR 2014-12-06 13:34 - 2014-12-06 13:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-12-06 13:19 - 2014-12-06 13:19 - 00000860 _____ () C:\Users\Public\Desktop\Hearthstone.lnk 2014-12-06 13:19 - 2014-12-06 13:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone 2014-12-06 06:07 - 2014-12-05 21:18 - 00000000 ____D () C:\Windows\Panther 2014-12-06 02:22 - 2014-12-06 02:22 - 00000861 _____ () C:\Users\Public\Desktop\Diablo III.lnk 2014-12-06 02:22 - 2014-12-06 02:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III 2014-12-06 02:18 - 2014-12-22 18:06 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-12-06 02:18 - 2014-12-06 13:19 - 00000000 ____D () C:\Games 2014-12-06 02:14 - 2014-12-06 02:14 - 00000000 ____D () C:\Program Files (x86)\predm 2014-12-06 01:37 - 2014-05-08 10:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-12-06 01:21 - 2014-12-06 01:21 - 00000000 ____D () C:\Users\Jacko\AppData\Local\RzStats 2014-12-06 01:20 - 2014-12-06 01:20 - 00000000 ____D () C:\dumps 2014-12-06 01:18 - 2014-12-06 01:19 - 00000000 ____D () C:\Users\Jacko\AppData\Local\Razer 2014-12-06 01:15 - 2014-12-06 01:15 - 00002674 _____ () C:\Windows\system32\RaCoInst.log 2014-12-06 01:14 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-12-06 01:14 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-12-06 01:14 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-12-06 01:14 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-12-06 01:14 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-12-06 01:14 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-12-06 01:14 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-12-06 01:14 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-12-06 01:14 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-12-06 01:14 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-12-06 01:14 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-12-06 01:14 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-12-06 01:14 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-12-06 01:14 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-12-06 01:14 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-12-06 01:14 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-12-06 01:13 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-12-06 01:13 - 2012-08-23 15:12 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\terminpt.sys 2014-12-06 01:13 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-12-06 01:13 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2014-12-06 01:13 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-12-06 01:13 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-12-06 01:05 - 2014-12-06 01:05 - 00000000 ____D () C:\Windows\SysWOW64\Drivers\sk-SK 2014-12-06 01:05 - 2014-12-06 01:05 - 00000000 ____D () C:\Windows\system32\Drivers\sk-SK 2014-12-06 01:05 - 2014-12-06 01:05 - 00000000 ____D () C:\Windows\sk-SK 2014-12-06 01:01 - 2014-12-22 21:09 - 00696528 _____ () C:\Windows\system32\perfh007.dat 2014-12-06 01:01 - 2014-12-22 21:09 - 00148496 _____ () C:\Windows\system32\perfc007.dat 2014-12-06 01:01 - 2014-12-06 01:01 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer 2014-12-06 01:01 - 2014-12-06 01:01 - 00000000 ____D () C:\Windows\SysWOW64\0407 2014-12-06 01:01 - 2014-12-06 01:01 - 00000000 ____D () C:\Users\Jacko\AppData\Local\Razer_Inc 2014-12-06 01:01 - 2014-12-06 01:00 - 00295922 _____ () C:\Windows\system32\perfi007.dat 2014-12-06 01:01 - 2014-12-06 01:00 - 00038104 _____ () C:\Windows\system32\perfd007.dat 2014-12-06 01:00 - 2014-12-06 01:00 - 00000000 ____D () C:\Windows\SysWOW64\de 2014-12-06 01:00 - 2014-12-06 01:00 - 00000000 ____D () C:\Windows\system32\de 2014-12-06 01:00 - 2014-12-06 01:00 - 00000000 ____D () C:\Windows\system32\0407 2014-12-06 00:59 - 2014-11-17 22:37 - 00129600 _____ (Razer, Inc.) C:\Windows\system32\Drivers\rzpnk.sys 2014-12-06 00:59 - 2014-10-31 23:27 - 00037184 _____ (Razer, Inc.) C:\Windows\system32\Drivers\rzpmgrk.sys 2014-12-06 00:58 - 2014-12-06 00:58 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzudd_01009.Wdf 2014-12-06 00:58 - 2014-12-06 00:58 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzendpt_01009.Wdf 2014-12-06 00:57 - 2014-12-06 00:58 - 00065286 _____ () C:\Windows\DPINST.LOG 2014-12-06 00:56 - 2014-12-06 00:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_RzFilter_01009.Wdf 2014-12-06 00:56 - 2014-12-06 00:56 - 00000000 ____D () C:\Windows\Razer Core 2014-12-06 00:56 - 2014-12-06 00:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer 2014-12-06 00:56 - 2014-04-18 17:02 - 00129472 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzDxgk.sys 2014-12-06 00:56 - 2014-04-18 17:02 - 00074432 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzFilter.sys 2014-12-06 00:42 - 2014-12-20 00:09 - 00000000 ____D () C:\Program Files (x86)\Razer 2014-12-06 00:42 - 2014-12-06 00:59 - 00000000 ____D () C:\ProgramData\Razer 2014-12-06 00:41 - 2014-12-22 22:32 - 00078275 _____ () C:\Windows\DirectX.log 2014-12-06 00:41 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-12-06 00:41 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-12-06 00:41 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-12-06 00:41 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-12-06 00:41 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-12-06 00:41 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-12-06 00:41 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-12-06 00:41 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-12-06 00:41 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-12-06 00:41 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-12-06 00:41 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-12-06 00:41 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-12-06 00:41 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-12-06 00:41 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-12-06 00:41 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-12-06 00:41 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-12-06 00:41 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-12-06 00:41 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-12-06 00:41 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-12-06 00:41 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-12-06 00:41 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-12-06 00:41 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-12-06 00:41 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-12-06 00:41 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-12-06 00:41 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-12-06 00:41 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-12-06 00:41 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-12-06 00:41 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-12-06 00:41 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-12-06 00:41 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-12-06 00:41 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-12-06 00:41 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-12-06 00:41 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-12-06 00:41 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-12-06 00:41 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-12-06 00:41 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-12-06 00:41 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-12-06 00:41 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-12-06 00:41 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-12-06 00:41 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-12-06 00:41 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-12-06 00:41 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-12-06 00:41 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-12-06 00:41 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-12-06 00:41 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-12-06 00:41 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-12-06 00:41 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-12-06 00:41 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-12-06 00:41 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-12-06 00:41 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-12-06 00:41 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-12-06 00:41 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-12-06 00:41 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-12-06 00:41 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-12-06 00:41 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2014-12-06 00:41 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-12-06 00:41 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2014-12-06 00:41 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-12-06 00:41 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2014-12-06 00:41 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-12-06 00:41 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-12-06 00:41 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-12-06 00:41 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-12-06 00:41 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-12-06 00:41 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-12-06 00:41 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-12-06 00:41 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-12-06 00:41 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-12-06 00:41 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-12-06 00:41 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-12-06 00:41 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-12-06 00:41 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-12-06 00:41 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-12-06 00:41 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-12-06 00:41 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-12-06 00:41 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-12-06 00:41 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-12-06 00:41 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-12-06 00:41 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-12-06 00:41 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-12-06 00:41 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-12-06 00:41 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-12-06 00:41 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-12-06 00:41 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-12-06 00:41 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-12-06 00:41 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-12-06 00:41 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-12-06 00:41 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-12-06 00:41 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-12-06 00:41 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-12-06 00:41 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-12-06 00:41 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-12-06 00:41 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-12-06 00:41 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-12-06 00:41 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-12-06 00:41 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-12-06 00:41 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-12-06 00:41 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-12-06 00:41 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-12-06 00:41 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-12-06 00:41 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-12-06 00:41 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-12-06 00:41 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-12-06 00:41 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-12-06 00:41 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-12-06 00:41 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-12-06 00:41 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-12-06 00:41 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-12-06 00:41 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-12-06 00:41 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-12-06 00:41 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-12-06 00:41 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-12-06 00:41 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-12-06 00:41 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-12-06 00:41 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-12-06 00:41 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2014-12-06 00:41 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-12-06 00:41 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-12-06 00:41 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-12-06 00:41 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-12-06 00:41 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-12-06 00:41 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-12-06 00:41 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-12-06 00:41 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-12-06 00:41 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-12-06 00:41 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-12-06 00:41 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-12-06 00:41 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-12-06 00:41 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-12-06 00:41 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-12-06 00:41 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-12-06 00:41 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-12-06 00:41 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-12-06 00:41 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2014-12-06 00:41 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-12-06 00:41 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-12-06 00:41 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-12-06 00:41 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-12-06 00:41 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-12-06 00:41 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-12-06 00:41 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2014-12-06 00:41 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-12-06 00:41 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-12-06 00:41 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2014-12-06 00:41 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-12-06 00:41 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2014-12-06 00:41 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-12-06 00:41 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-12-06 00:41 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-12-06 00:41 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2014-12-06 00:41 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-12-06 00:41 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2014-12-06 00:41 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-12-06 00:41 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-12-06 00:41 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-12-06 00:41 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2014-12-06 00:41 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-12-06 00:41 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2014-12-06 00:41 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-12-06 00:41 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2014-12-06 00:41 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-12-06 00:41 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2014-12-06 00:41 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-12-06 00:41 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2014-12-06 00:16 - 2014-12-06 00:16 - 00000000 __SHD () C:\Users\Jacko\AppData\Local\EmieUserList 2014-12-06 00:16 - 2014-12-06 00:16 - 00000000 __SHD () C:\Users\Jacko\AppData\Local\EmieSiteList 2014-12-06 00:16 - 2014-12-06 00:16 - 00000000 __SHD () C:\Users\Jacko\AppData\Local\EmieBrowserModeList 2014-12-06 00:11 - 2014-12-21 19:43 - 00000000 ____D () C:\Users\Jacko\AppData\Roaming\Adobe 2014-12-06 00:11 - 2014-12-06 00:11 - 00000000 ____D () C:\Users\Jacko\AppData\Local\NVIDIA 2014-12-06 00:11 - 2014-12-06 00:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2014-12-05 23:52 - 2014-12-11 03:05 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-12-05 23:47 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-12-05 23:47 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-12-05 23:47 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-12-05 23:47 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-12-05 23:38 - 2014-12-12 02:14 - 01589404 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-12-05 23:32 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-12-05 23:28 - 2014-12-05 23:28 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-12-05 23:28 - 2014-12-05 23:28 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-12-05 23:28 - 2014-12-05 23:28 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-12-05 23:28 - 2014-12-05 23:28 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-12-05 23:28 - 2014-12-05 23:28 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-12-05 23:28 - 2014-12-05 23:28 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-12-05 23:28 - 2014-12-05 23:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-12-05 23:28 - 2014-12-05 23:28 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-12-05 23:28 - 2014-12-05 23:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-12-05 23:23 - 2014-12-05 23:23 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-12-05 23:23 - 2014-12-05 23:23 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-12-05 23:22 - 2014-12-05 23:32 - 00013143 _____ () C:\Windows\IE11_main.log 2014-12-05 22:50 - 2010-02-23 09:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2014-12-05 22:39 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2014-12-05 22:39 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2014-12-05 22:39 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2014-12-05 22:39 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2014-12-05 22:39 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2014-12-05 22:39 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2014-12-05 22:39 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2014-12-05 22:39 - 2012-06-02 15:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2014-12-05 22:31 - 2014-12-11 03:04 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-05 22:31 - 2014-12-11 03:02 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-12-05 22:30 - 2014-12-22 21:03 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-12-05 22:29 - 2014-12-05 22:30 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-12-05 22:29 - 2014-12-05 22:30 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-12-05 22:29 - 2014-12-05 22:30 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-12-05 22:29 - 2014-08-19 22:15 - 00075040 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-12-05 22:29 - 2014-08-19 22:15 - 00061912 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-12-05 22:29 - 2014-07-02 19:55 - 06783776 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-12-05 22:29 - 2014-07-02 19:55 - 03522392 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-12-05 22:29 - 2014-07-02 19:55 - 02559960 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-12-05 22:29 - 2014-07-02 19:55 - 00935368 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-12-05 22:29 - 2014-07-02 19:55 - 00386520 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-12-05 22:29 - 2014-07-02 19:55 - 00062808 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-12-05 22:29 - 2014-07-02 18:44 - 00609240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-12-05 22:29 - 2014-07-02 11:14 - 03826628 _____ () C:\Windows\system32\nvcoproc.bin 2014-12-05 22:28 - 2014-12-05 22:28 - 00000000 ____D () C:\Users\Jacko\AppData\Local\TVWizard 2014-12-05 22:28 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2014-12-05 22:28 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2014-12-05 22:28 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2014-12-05 22:24 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-12-05 22:24 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-12-05 22:24 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-12-05 22:24 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-12-05 22:23 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-12-05 22:23 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-12-05 22:23 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-12-05 22:23 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-12-05 22:22 - 2014-03-04 10:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-12-05 22:22 - 2014-03-04 10:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-12-05 22:22 - 2014-03-04 10:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-12-05 22:22 - 2014-03-04 10:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-12-05 22:22 - 2014-03-04 10:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-12-05 22:22 - 2014-03-04 10:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-12-05 22:22 - 2014-03-04 10:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-12-05 22:22 - 2014-03-04 10:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-12-05 22:22 - 2014-03-04 10:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-12-05 22:22 - 2014-03-04 10:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-12-05 22:22 - 2014-03-04 10:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-12-05 22:22 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-12-05 22:22 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-12-05 22:22 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-12-05 22:22 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-12-05 22:22 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-12-05 22:22 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-12-05 22:22 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-12-05 22:22 - 2014-03-04 10:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-12-05 22:22 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-12-05 22:22 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-12-05 22:22 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-12-05 22:22 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-12-05 22:22 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-12-05 22:22 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-12-05 22:22 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-12-05 22:22 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-12-05 22:22 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-12-05 22:22 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-12-05 22:22 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-12-05 22:22 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-12-05 22:22 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-12-05 22:22 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-12-05 22:22 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-12-05 22:22 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-12-05 22:22 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-12-05 22:22 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-12-05 22:22 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2014-12-05 22:22 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2014-12-05 22:22 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2014-12-05 22:22 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2014-12-05 22:22 - 2010-12-23 11:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll 2014-12-05 22:22 - 2010-12-23 11:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2014-12-05 22:22 - 2010-12-23 11:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax 2014-12-05 22:22 - 2010-12-23 06:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll 2014-12-05 22:22 - 2010-12-23 06:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2014-12-05 22:22 - 2010-12-23 06:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax 2014-12-05 22:21 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-12-05 22:21 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-12-05 22:21 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-12-05 22:21 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2014-12-05 22:21 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-12-05 22:21 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-12-05 22:21 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-12-05 22:21 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-12-05 22:21 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-12-05 22:21 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-12-05 22:21 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-12-05 22:21 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-12-05 22:21 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-12-05 22:21 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-12-05 22:21 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-12-05 22:21 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-12-05 22:21 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-12-05 22:21 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-12-05 22:21 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-12-05 22:21 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-12-05 22:21 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll 2014-12-05 22:21 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-12-05 22:21 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-12-05 22:21 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-12-05 22:21 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2014-12-05 22:21 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2014-12-05 22:21 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-12-05 22:21 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2014-12-05 22:21 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2014-12-05 22:21 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2014-12-05 22:21 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2014-12-05 22:21 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2014-12-05 22:20 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-12-05 22:20 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-12-05 22:20 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-12-05 22:20 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-12-05 22:20 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-12-05 22:20 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-12-05 22:20 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-12-05 22:20 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-12-05 22:20 - 2014-08-01 12:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-12-05 22:20 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-12-05 22:20 - 2014-04-12 03:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-12-05 22:20 - 2014-04-12 03:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-12-05 22:20 - 2014-04-12 03:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-12-05 22:20 - 2014-04-12 03:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-12-05 22:20 - 2014-04-12 03:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-12-05 22:20 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2014-12-05 22:20 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2014-12-05 22:20 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2014-12-05 22:20 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2014-12-05 22:20 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2014-12-05 22:20 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2014-12-05 22:20 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2014-12-05 22:20 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2014-12-05 22:20 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2014-12-05 22:20 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2014-12-05 22:20 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2014-12-05 22:20 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2014-12-05 22:20 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2014-12-05 22:20 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2014-12-05 22:20 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2014-12-05 22:20 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2014-12-05 22:20 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2014-12-05 22:20 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2014-12-05 22:20 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2014-12-05 22:20 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2014-12-05 22:20 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2014-12-05 22:20 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2014-12-05 22:20 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2014-12-05 22:20 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2014-12-05 22:20 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2014-12-05 22:20 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2014-12-05 22:20 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2014-12-05 22:20 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2014-12-05 22:20 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2014-12-05 22:20 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2014-12-05 22:20 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-12-05 22:20 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2014-12-05 22:20 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2014-12-05 22:19 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-12-05 22:19 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-12-05 22:19 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-12-05 22:19 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-12-05 22:19 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-12-05 22:19 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-12-05 22:19 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-12-05 22:19 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-12-05 22:19 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-12-05 22:19 - 2014-03-04 10:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-12-05 22:19 - 2014-03-04 10:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-12-05 22:19 - 2014-03-04 10:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-12-05 22:19 - 2014-03-04 10:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-12-05 22:19 - 2014-03-04 10:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-12-05 22:19 - 2014-03-04 10:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-12-05 22:19 - 2014-03-04 10:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-12-05 22:19 - 2014-03-04 10:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-12-05 22:19 - 2014-03-04 10:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-12-05 22:19 - 2014-03-04 09:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-12-05 22:19 - 2014-03-04 09:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-12-05 22:19 - 2014-02-04 03:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-12-05 22:19 - 2014-02-04 03:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-12-05 22:19 - 2014-02-04 03:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-12-05 22:19 - 2014-02-04 03:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-12-05 22:19 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-12-05 22:19 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2014-12-05 22:19 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2014-12-05 22:19 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2014-12-05 22:19 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll |
23.12.2014, 00:27 | #4 |
| Virus erwischt oder nicht?Code:
ATTFilter ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-22 22:06 - 2009-07-14 05:45 - 00026112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-22 22:06 - 2009-07-14 05:45 - 00026112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-22 21:09 - 2009-07-14 06:13 - 00843184 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-22 21:06 - 2009-07-14 05:51 - 00035370 _____ () C:\Windows\setupact.log 2014-12-22 21:03 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-22 18:27 - 2010-11-21 04:47 - 00142222 _____ () C:\Windows\PFRO.log 2014-12-21 03:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-12-18 20:40 - 2014-08-20 18:04 - 00818888 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-12-18 20:40 - 2014-08-18 14:43 - 00150536 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-12-18 20:40 - 2014-08-13 19:34 - 00077512 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klwtp.sys 2014-12-14 15:09 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-12-13 00:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\sk-SK 2014-12-13 00:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sk-SK 2014-12-11 03:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-12-11 03:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-12-07 00:21 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-12-07 00:20 - 2009-07-14 05:45 - 00268152 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-06 23:48 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-12-06 06:07 - 2009-07-14 06:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2014-12-06 06:07 - 2009-07-14 06:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template 2014-12-06 01:18 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-12-06 01:06 - 2010-11-21 08:16 - 00000000 ____D () C:\Program Files\Windows Journal 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Sidebar 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-12-06 01:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz 2014-12-06 01:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\servicing 2014-12-06 01:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System 2014-12-06 01:05 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN 2014-12-06 01:05 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\WCN 2014-12-06 01:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep 2014-12-06 01:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\oobe 2014-12-06 01:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\migwiz 2014-12-06 01:01 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm 2014-12-06 01:01 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\sysprep 2014-12-06 01:01 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr 2014-12-06 01:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup 2014-12-06 01:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe 2014-12-06 01:00 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-12-06 01:00 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\winrm 2014-12-06 01:00 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\slmgr 2014-12-06 01:00 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts 2014-12-06 01:00 - 2009-07-14 06:37 - 00000000 ____D () C:\Windows\DigitalLocker 2014-12-06 01:00 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\com 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Setup 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\MUI 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\com 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\IME 2014-12-05 23:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK 2014-12-05 23:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR 2014-12-05 23:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\zh-HK 2014-12-05 23:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\tr-TR 2014-12-05 22:29 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help 2014-12-05 21:37 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-05 21:28 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\restore 2014-12-05 21:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Recovery 2014-12-05 21:10 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-12-05 21:10 - 2009-07-14 05:46 - 00002790 _____ () C:\Windows\DtcInstall.log 2014-12-05 21:08 - 2010-11-21 08:16 - 00000000 ____D () C:\Windows\CSC 2014-11-24 14:04 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\Jacko\AppData\Local\Temp\avgnt.exe C:\Users\Jacko\AppData\Local\Temp\Quarantine.exe C:\Users\Jacko\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 14:32 ==================== End Of Log + Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-12-2014 01 Ran by Jacko at 2014-12-22 23:02:44 Running from C:\Users\Jacko\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Kaspersky Anti-Virus (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Anti-Virus (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Call of Duty: Black Ops - Multiplayer (HKLM-x32\...\Steam App 42710) (Version: - Treyarch) Call of Duty: Black Ops (HKLM-x32\...\Steam App 42700) (Version: - Treyarch) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Kaspersky Anti-Virus (HKLM-x32\...\InstallWIX_{8ED07EBD-22AD-415A-B71E-C1AD86862C2E}) (Version: 15.0.1.415 - Kaspersky Lab) Kaspersky Anti-Virus (x32 Version: 15.0.1.415 - Kaspersky Lab) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) NVIDIA 3D Vision Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation) NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation) NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation) Portal (HKLM-x32\...\Steam App 400) (Version: - Valve) Razer Core (HKLM-x32\...\Razer Core) (Version: 1.0.1.66 - Razer Inc) Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.18.23036 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.77.1126.2013 - Realtek) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.100 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) The Elder Scrolls Online (HKLM-x32\...\Steam App 306130) (Version: - Zenimax Online Studios) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) WinRAR 5.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 21-12-2014 03:58:17 DirectX wurde installiert 21-12-2014 19:58:14 DirectX wurde installiert 21-12-2014 22:11:00 DirectX wurde installiert 22-12-2014 12:42:55 Installed Windows 7 USB/DVD Download Tool 22-12-2014 18:05:48 Removed Windows 7 USB/DVD Download Tool 22-12-2014 22:17:17 DirectX wurde installiert 22-12-2014 22:31:33 DirectX wurde installiert ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2014-12-22 16:32 - 00450771 ____R C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {922B44DA-C57D-4193-A705-4AFFD728378B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-22] (Google Inc.) Task: {9898644D-2AD5-4B60-8C25-BC44EB19B614} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-22] (Google Inc.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-12-05 22:29 - 2014-07-02 19:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-10-31 23:27 - 2014-10-31 23:27 - 00183488 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2014-11-20 09:23 - 2014-11-20 09:23 - 00289792 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe 2014-12-22 18:06 - 2014-12-06 02:16 - 01408328 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libglesv2.dll 2014-12-22 18:06 - 2014-12-06 02:16 - 00204616 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libegl.dll 2014-12-22 18:06 - 2014-12-06 02:17 - 10689352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll 2014-12-22 18:06 - 2014-12-06 02:16 - 01856840 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll 2014-12-22 22:44 - 2014-12-22 22:44 - 02173952 _____ () C:\Users\Jacko\Desktop\adwcleaner_4.106.exe 2014-08-30 17:12 - 2014-08-30 17:12 - 01269952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\kpcengine.2.3.dll 2014-12-06 01:19 - 2014-01-04 01:20 - 34755072 _____ () C:\Users\Jacko\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll 2014-11-20 07:02 - 2014-11-20 07:02 - 00193024 _____ () C:\ProgramData\Razer\Synapse\RzStats\RigWrapper.dll 2014-12-06 01:19 - 2014-01-04 01:20 - 00970240 _____ () C:\Users\Jacko\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\ffmpegsumo.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 01171456 _____ () C:\Games\Steam\libavcodec-56.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 00442368 _____ () C:\Games\Steam\libavutil-54.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 00332800 _____ () C:\Games\Steam\libavresample-2.dll 2014-12-06 13:14 - 2014-11-11 19:47 - 00774656 _____ () C:\Games\Steam\SDL2.dll 2014-12-06 13:14 - 2014-11-18 21:23 - 02227904 _____ () C:\Games\Steam\video.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 00403968 _____ () C:\Games\Steam\libavformat-56.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 00485888 _____ () C:\Games\Steam\libswscale-3.dll 2014-12-06 13:15 - 2014-11-18 21:23 - 00690880 _____ () C:\Games\Steam\bin\chromehtml.DLL 2014-12-06 13:15 - 2014-11-18 21:23 - 00138432 _____ () C:\Games\Steam\bin\audio.dll 2014-12-06 13:15 - 2014-11-11 19:48 - 00071680 _____ () C:\Games\Steam\bin\mssmp3.asi 2014-12-06 13:15 - 2014-11-11 19:48 - 00153088 _____ () C:\Games\Steam\bin\mssvoice.asi 2014-12-06 13:15 - 2014-11-11 19:48 - 34589888 _____ () C:\Games\Steam\bin\libcef.dll 2014-12-06 13:15 - 2014-11-11 19:48 - 00837824 _____ () C:\Games\Steam\bin\ffmpegsumo.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 26065408 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\libcef.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00739840 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\libGLESv2.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00907776 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\platforms\qwindows.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00130048 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\libEGL.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00020992 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\imageformats\qgif.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00021504 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\imageformats\qico.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00205312 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\imageformats\qjpeg.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00225792 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\imageformats\qmng.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00015872 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\imageformats\qsvg.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00312832 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\imageformats\qtiff.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00010240 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\qml\QtQuick.2\qtquick2plugin.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00054272 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\qml\QtQuick\Layouts\qquicklayoutsplugin.dll 2014-12-10 20:08 - 2014-12-10 20:08 - 00010240 _____ () C:\Program Files (x86)\Battle.net\Battle.net.5383\qml\QtQml\Models.2\modelsplugin.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: Steam => "C:\Games\Steam.exe" -silent ========================= Accounts: ========================== Administrator (S-1-5-21-1241592699-1578615748-785451789-500 - Administrator - Disabled) Guest (S-1-5-21-1241592699-1578615748-785451789-501 - Limited - Disabled) Jacko (S-1-5-21-1241592699-1578615748-785451789-1000 - Administrator - Enabled) => C:\Users\Jacko ==================== Faulty Device Manager Devices ============= Name: USB (Universal Serial Bus)-Controller Description: USB (Universal Serial Bus)-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/22/2014 09:05:14 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 08:52:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 08:28:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 08:15:04 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 07:28:48 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 06:57:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 06:40:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 06:29:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 05:54:38 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 05:23:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/22/2014 08:51:06 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "HomeGroup Provider" ist vom Dienst "Function Discovery Provider Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (12/22/2014 08:51:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (12/22/2014 08:51:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (12/22/2014 08:51:05 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error: (12/22/2014 08:51:03 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (12/22/2014 08:51:02 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1084EventSystem{1BE1F766-5536-11D1-B726-00C04FB926AF} Error: (12/22/2014 08:50:56 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1084ShellHWDetection{DD522ACC-F821-461A-A407-50B198B896DC} Error: (12/22/2014 08:50:54 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: discache klhk KLIF klpd kneps spldr Wanarpv6 Error: (12/22/2014 08:50:52 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 22.12.2014 um 20:47:46 unerwartet heruntergefahren. Error: (12/22/2014 08:41:55 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1084wuauserv{E60687F7-01A1-40AA-86AC-DB1CBF673334} Microsoft Office Sessions: ========================= Error: (12/22/2014 09:05:14 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 08:52:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 08:28:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 08:15:04 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 07:28:48 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 06:57:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 06:40:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 06:29:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 05:54:38 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2014 05:23:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Processor: AMD FX(tm)-6300 Six-Core Processor Percentage of memory in use: 36% Total physical RAM: 8148.75 MB Available physical RAM: 5207.27 MB Total Pagefile: 16295.68 MB Available Pagefile: 12814.36 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.29 GB) (Free:744.18 GB) NTFS Drive d: (GRMCHPXFRER_DE_DVD) (CDROM) (Total:2.97 GB) (Free:0 GB) UDF Drive f: (GRMCHPXFRER_DE_DVD) (CDROM) (Total:2.97 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
23.12.2014, 00:28 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virus erwischt oder nicht? Fehlerbeschreibung? Was ist mit meiner Frage nach bisherigen Virenscannerfunden und den Logs dazu?
__________________ Logfiles bitte immer in CODE-Tags posten |
23.12.2014, 00:29 | #6 |
| Virus erwischt oder nicht?Code:
ATTFilter ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-22 22:06 - 2009-07-14 05:45 - 00026112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-22 22:06 - 2009-07-14 05:45 - 00026112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-22 21:09 - 2009-07-14 06:13 - 00843184 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-22 21:06 - 2009-07-14 05:51 - 00035370 _____ () C:\Windows\setupact.log 2014-12-22 21:03 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-22 18:27 - 2010-11-21 04:47 - 00142222 _____ () C:\Windows\PFRO.log 2014-12-21 03:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-12-18 20:40 - 2014-08-20 18:04 - 00818888 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-12-18 20:40 - 2014-08-18 14:43 - 00150536 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-12-18 20:40 - 2014-08-13 19:34 - 00077512 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klwtp.sys 2014-12-14 15:09 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-12-13 00:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\sk-SK 2014-12-13 00:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sk-SK 2014-12-11 03:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-12-11 03:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-12-07 00:21 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-12-07 00:20 - 2009-07-14 05:45 - 00268152 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-06 23:48 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-12-06 06:07 - 2009-07-14 06:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2014-12-06 06:07 - 2009-07-14 06:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template 2014-12-06 01:18 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-12-06 01:06 - 2010-11-21 08:16 - 00000000 ____D () C:\Program Files\Windows Journal 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Sidebar 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer 2014-12-06 01:06 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-12-06 01:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz 2014-12-06 01:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\servicing 2014-12-06 01:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System 2014-12-06 01:05 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN 2014-12-06 01:05 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\WCN 2014-12-06 01:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep 2014-12-06 01:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\oobe 2014-12-06 01:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\migwiz 2014-12-06 01:01 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm 2014-12-06 01:01 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\sysprep 2014-12-06 01:01 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr 2014-12-06 01:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup 2014-12-06 01:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe 2014-12-06 01:00 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-12-06 01:00 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\winrm 2014-12-06 01:00 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\slmgr 2014-12-06 01:00 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts 2014-12-06 01:00 - 2009-07-14 06:37 - 00000000 ____D () C:\Windows\DigitalLocker 2014-12-06 01:00 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\com 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Setup 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\MUI 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\com 2014-12-06 01:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\IME 2014-12-05 23:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK 2014-12-05 23:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR 2014-12-05 23:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\zh-HK 2014-12-05 23:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\tr-TR 2014-12-05 22:29 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help 2014-12-05 21:37 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-05 21:28 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\restore 2014-12-05 21:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Recovery 2014-12-05 21:10 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-12-05 21:10 - 2009-07-14 05:46 - 00002790 _____ () C:\Windows\DtcInstall.log 2014-12-05 21:08 - 2010-11-21 08:16 - 00000000 ____D () C:\Windows\CSC 2014-11-24 14:04 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\Jacko\AppData\Local\Temp\avgnt.exe C:\Users\Jacko\AppData\Local\Temp\Quarantine.exe C:\Users\Jacko\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 14:32 ==================== End Of Log fehlerbeschreibung ja sry keine virenscans vorhanden weil kein antivir draufwar pc hat nur übelst gelagt als er in facebook mit jmd geschrieben hat und seitdem spinnts rum kleine zusatzinfo er meint als er Avira gepatcht hat (sah dann anders aus usw) trat ein problem auf undzwar PC einfrieren ohne sich auszuschalten geschweige denn einen bluescreen anzuzeigen Geändert von YouWin (23.12.2014 um 00:40 Uhr) |
23.12.2014, 00:46 | #7 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virus erwischt oder nicht?Zitat:
Da ist kein Avira drauf!
__________________ Logfiles bitte immer in CODE-Tags posten |
23.12.2014, 00:51 | #8 |
| Virus erwischt oder nicht? ja war drauf wurde runtergeschmissen für kaspersky |
23.12.2014, 01:15 | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virus erwischt oder nicht? Was versteht ihr unter "gepatchtem" Avira?
__________________ Logfiles bitte immer in CODE-Tags posten |
23.12.2014, 01:18 | #10 |
| Virus erwischt oder nicht? Also er meinte jetz er war im chrome unterwegs dann kam sone umfrage für iwas (keine ahnung) dann hat er das nicht schließen können und hat die umfrage dann gemacht und am ende kam dann "gratuliere du hast gutschein gewonnen" passierte erstmal nichts nächsten tag kam Avira update (neue version) dann war komplett Avira aussehen usw verändert und bei Facebook hats dann angefangen mit pc einfrieren solang man z.b. 5min afk geht achja hab zwar nicht die übelsten skills aber hab bisher aus den logs rausgelesen das es sich um eine Spyware namens HKLM handelt? Die soll sehr böse sein, kann man das denn entfernen? oder ratest du zu einer neuaufsetzung achja hab veranlasst das er mal mit malewarebyte scant hier die logs Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 23.12.2014 Scan Time: 01:05:37 Logfile: !@#$.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2014.12.22.11 Rootkit Database: v2014.12.14.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Jacko Scan Type: Threat Scan Result: Completed Objects Scanned: 315240 Time Elapsed: 5 min, 56 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 11 PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, , [b330ff663646ad8931ff09d256acfc04], PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, , [b330ff663646ad8931ff09d256acfc04], PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, , [bc2777ee611b8babf90638a217eb669a], PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, , [bc2777ee611b8babf90638a217eb669a], PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [bd26263f017b7abc344c3f7d05ff9967], PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\GAMESDESKTOP, , [2ab9c3a29ae25adca36966f4fe0521df], PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, , [bd2644219ae2c5718718f26b90739b65], PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [776c8adb4e2eb581423e06b64abaa35d], PUP.Optional.DesktopDockApp.A, HKU\S-1-5-21-1241592699-1578615748-785451789-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DesktopDockApp, , [7e655f0653299f977614b6a4eb189a66], PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-1241592699-1578615748-785451789-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TutoTag, , [a34030359ce0dd59f7107c58b252a858], PUP.Optional.MultiIE.A, HKU\S-1-5-21-1241592699-1578615748-785451789-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, , [42a1372ef884eb4bb0926a649d676799], Registry Values: 1 PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_de_12, , [1ec568fd740844f28bfade7c18eb39c7], Registry Data: 9 PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms}),,[7172fb6a5b21c96da87dfa7348bd0bf5] PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms}),,[ac376df8483448ee0a1c37360cf9817f] PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[925182e3b2ca13230af72257e32254ac] PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms}),,[d50e78edd7a585b1e144de8f000535cb] PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms}),,[9c47fd68a3d955e154d298d525e013ed] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[08db8adb502c7eb80ff23d3c29dcd828] PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1241592699-1578615748-785451789-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE, Good: (www.google.com), Bad: (hxxp://www.mystartsearch.com/?type=hp&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE),,[26bd263fc1bb87af397f4f2b7392f30d] PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1241592699-1578615748-785451789-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE, Good: (www.google.com), Bad: (hxxp://www.mystartsearch.com/?type=hp&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE),,[20c3f96ce498280e959280ed57ae2dd3] Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{F77548F7-36AA-4552-845A-9A58B59FAE10}|NameServer, 31.168.224.106,5.135.12.52, Good: (), Bad: (31.168.224.106,5.135.12.52),,[73700c591e5e57df81036a1160a5d62a] Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end) *EDIT oder ist das nurn browser hijacker? nennt man das so? hxxp://www.mystartsearch.com/ wir verstehen auch nicht was dieser ordner hier zu bedeuten hat > TVWizard Geändert von YouWin (23.12.2014 um 01:53 Uhr) |
23.12.2014, 01:36 | #11 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virus erwischt oder nicht? Dann bitte jetzt Combofix ausführen: Scan mit Combofix
__________________ Logfiles bitte immer in CODE-Tags posten |
23.12.2014, 03:19 | #12 |
| Virus erwischt oder nicht?Code:
ATTFilter ComboFix 14-12-14.01 - Jacko 23.12.2014 2:23.1.6 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1033.18.8149.6171 [GMT 1:00] ausgeführt von:: c:\users\Jacko\Desktop\ComboFix.exe AV: Kaspersky Anti-Virus *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886} SP: Kaspersky Anti-Virus *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2014-11-23 bis 2014-12-23 )))))))))))))))))))))))))))))) . . 2014-12-23 01:27 . 2014-12-23 01:27 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-12-23 00:03 . 2014-12-23 00:03 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-12-23 00:02 . 2014-12-23 00:02 -------- d-----w- c:\program files (x86)\ Malwarebytes Anti-Malware 2014-12-23 00:02 . 2014-12-23 00:02 -------- d-----w- c:\programdata\Malwarebytes 2014-12-23 00:02 . 2014-11-21 05:14 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-12-23 00:02 . 2014-11-21 05:14 93400 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-12-23 00:02 . 2014-11-21 05:14 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-12-22 22:01 . 2014-12-22 22:03 -------- d-----w- C:\FRST 2014-12-22 21:44 . 2014-12-22 21:48 -------- d-----w- C:\AdwCleaner 2014-12-22 17:06 . 2014-12-22 21:00 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{645DB370-0E9F-4EE3-B439-7DB44A9152DB}\offreg.dll 2014-12-22 12:43 . 2014-12-22 17:04 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2014-12-22 12:43 . 2014-12-22 17:27 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2 2014-12-21 18:24 . 2014-12-21 18:24 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2014-12-21 03:01 . 2014-12-21 03:01 -------- d--h--w- c:\program files (x86)\Zero G Registry 2014-12-19 10:05 . 2014-12-15 03:13 11870360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{645DB370-0E9F-4EE3-B439-7DB44A9152DB}\mpengine.dll 2014-12-18 19:24 . 2013-05-06 08:13 110176 ----a-w- c:\windows\system32\klfphc.dll 2014-12-18 19:24 . 2014-12-18 19:24 -------- d-----w- c:\windows\ELAMBKUP 2014-12-18 19:24 . 2014-12-23 00:45 -------- d-----w- c:\programdata\Kaspersky Lab 2014-12-18 19:24 . 2014-12-18 19:24 -------- d-----w- c:\program files (x86)\Kaspersky Lab 2014-12-18 19:24 . 2014-08-12 17:33 246456 ----a-w- c:\windows\system32\drivers\klhk.sys 2014-12-18 09:59 . 2014-12-13 05:09 144384 ----a-w- c:\windows\system32\ieUnatt.exe 2014-12-18 09:59 . 2014-12-13 03:33 115712 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-12-15 23:21 . 2014-12-15 23:21 -------- d-----w- c:\program files\TeamSpeak 3 Client 2014-12-11 02:05 . 2014-12-11 02:05 -------- d-----w- c:\windows\system32\appraiser 2014-12-11 02:00 . 2014-07-07 02:06 55808 ----a-w- c:\windows\system32\rrinstaller.exe 2014-12-11 02:00 . 2014-07-07 02:06 24576 ----a-w- c:\windows\system32\mfpmp.exe 2014-12-11 02:00 . 2014-07-07 02:02 2048 ----a-w- c:\windows\system32\mferror.dll 2014-12-11 02:00 . 2014-07-07 01:39 23040 ----a-w- c:\windows\SysWow64\mfpmp.exe 2014-12-11 02:00 . 2014-07-07 01:37 2048 ----a-w- c:\windows\SysWow64\mferror.dll 2014-12-11 02:00 . 2014-10-18 02:05 4121600 ----a-w- c:\windows\system32\mf.dll 2014-12-11 02:00 . 2014-10-18 01:33 3209728 ----a-w- c:\windows\SysWow64\mf.dll 2014-12-11 02:00 . 2014-07-07 02:06 206848 ----a-w- c:\windows\system32\mfps.dll 2014-12-11 02:00 . 2014-07-07 01:40 103424 ----a-w- c:\windows\SysWow64\mfps.dll 2014-12-11 02:00 . 2014-07-07 01:39 50176 ----a-w- c:\windows\SysWow64\rrinstaller.exe 2014-12-11 01:13 . 2014-10-30 02:03 165888 ----a-w- c:\windows\system32\charmap.exe 2014-12-08 20:26 . 2014-12-08 20:26 -------- d-----w- c:\program files\VideoLAN 2014-12-08 19:36 . 2014-02-10 17:04 430080 ----a-w- c:\windows\mod_frst.exe 2014-12-08 14:58 . 2014-12-08 14:59 -------- d-----r- c:\program files (x86)\Skype 2014-12-08 14:58 . 2014-12-08 14:58 -------- d-----w- c:\program files (x86)\Common Files\Skype 2014-12-08 14:58 . 2014-12-18 19:27 -------- d-----w- c:\programdata\Skype 2014-12-06 22:43 . 2014-06-27 02:08 2777088 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2014-12-06 22:43 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2014-12-06 13:23 . 2014-12-06 13:23 -------- d-----w- c:\program files\WinRAR 2014-12-06 05:07 . 2014-12-05 20:18 -------- d-----w- c:\windows\Panther 2014-12-06 01:18 . 2014-12-06 12:19 -------- d-----w- C:\Games 2014-12-06 01:18 . 2014-12-22 17:06 -------- d-----w- c:\windows\system32\appmgmt 2014-12-06 01:14 . 2014-12-06 01:14 -------- d-----w- c:\program files (x86)\predm 2014-12-06 00:37 . 2014-05-08 09:32 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll 2014-12-06 00:20 . 2014-12-06 00:20 -------- d-----w- C:\dumps 2014-12-06 00:13 . 2012-08-23 14:12 29696 ----a-w- c:\windows\system32\drivers\terminpt.sys 2014-12-06 00:13 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys 2014-12-06 00:13 . 2012-08-23 14:08 30208 ----a-w- c:\windows\system32\drivers\TsUsbGD.sys 2014-12-06 00:13 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll 2014-12-06 00:13 . 2012-08-23 14:13 243200 ----a-w- c:\windows\system32\rdpudd.dll 2014-12-06 00:13 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll 2014-12-06 00:05 . 2014-12-06 00:05 -------- d-----w- c:\windows\SysWow64\wbem\sk-SK 2014-12-06 00:05 . 2014-12-06 00:05 -------- d-----w- c:\windows\SysWow64\drivers\sk-SK 2014-12-06 00:05 . 2014-12-06 00:05 -------- d-----w- c:\windows\sk-SK 2014-12-06 00:05 . 2014-12-06 00:05 -------- d-----w- c:\windows\system32\drivers\sk-SK 2014-12-06 00:05 . 2014-12-06 00:05 -------- d-----w- c:\windows\system32\wbem\sk-SK 2014-12-06 00:01 . 2014-12-06 00:01 -------- d-----w- c:\windows\de-DE 2014-12-06 00:01 . 2014-12-06 00:01 -------- d-----w- c:\windows\SysWow64\XPSViewer 2014-12-06 00:01 . 2014-12-06 00:01 -------- d-----w- c:\windows\SysWow64\0407 2014-12-06 00:00 . 2014-12-06 00:15 -------- d-----w- c:\windows\SysWow64\wbem\de-DE 2014-12-06 00:00 . 2014-12-06 00:01 -------- d-----w- c:\windows\SysWow64\drivers\de-DE 2014-12-06 00:00 . 2014-12-06 00:00 -------- d-----w- c:\windows\SysWow64\drivers\UMDF\de-DE 2014-12-06 00:00 . 2014-12-06 00:00 -------- d-----w- c:\windows\SysWow64\de 2014-12-06 00:00 . 2014-12-06 00:44 -------- d-----w- c:\windows\system32\drivers\de-DE 2014-12-06 00:00 . 2014-12-06 00:00 -------- d-----w- c:\windows\system32\drivers\UMDF\de-DE 2014-12-06 00:00 . 2014-12-06 00:00 -------- d-----w- c:\windows\system32\0407 2014-12-06 00:00 . 2014-12-06 00:00 -------- d-----w- c:\windows\system32\de 2014-12-06 00:00 . 2014-12-06 00:15 -------- d-----w- c:\windows\system32\wbem\de-DE 2014-12-05 23:59 . 2014-11-17 21:37 129600 ----a-w- c:\windows\system32\drivers\rzpnk.sys 2014-12-05 23:59 . 2014-10-31 22:27 37184 ----a-w- c:\windows\system32\drivers\rzpmgrk.sys 2014-12-05 23:56 . 2014-04-18 16:02 74432 ----a-w- c:\windows\system32\drivers\RzFilter.sys 2014-12-05 23:56 . 2014-04-18 16:02 129472 ----a-w- c:\windows\system32\drivers\RzDxgk.sys 2014-12-05 23:56 . 2014-12-05 23:56 -------- d-----w- c:\windows\Razer Core 2014-12-05 23:55 . 2009-07-13 18:05 3584 ----a-w- c:\windows\system32\Spool\prtprocs\x64\de-DE\LXKPTPRC.DLL.mui 2014-12-05 23:53 . 2014-12-07 01:02 -------- d-----w- c:\program files (x86)\Common Files\Steam 2014-12-05 23:42 . 2014-12-05 23:59 -------- d-----w- c:\programdata\Razer 2014-12-05 23:42 . 2014-12-19 23:09 -------- d-----w- c:\program files (x86)\Razer 2014-12-05 22:52 . 2014-12-11 02:05 -------- d-s---w- c:\windows\system32\CompatTel 2014-12-05 22:47 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2014-12-05 22:47 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe 2014-12-05 22:47 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL 2014-12-05 22:47 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL 2014-12-05 22:47 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll 2014-12-05 22:37 . 2014-12-05 22:37 -------- d-----w- c:\program files (x86)\Microsoft.NET 2014-12-05 22:37 . 2014-12-05 22:37 -------- d-----w- c:\windows\Migration 2014-12-05 22:32 . 2013-10-14 17:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE 2014-12-05 22:23 . 2014-12-05 22:23 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-12-05 21:59 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui 2014-12-05 21:50 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe 2014-12-05 21:39 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe 2014-12-05 21:39 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll 2014-12-05 21:39 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll 2014-12-05 21:39 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2014-12-05 21:39 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll 2014-12-05 21:39 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2014-12-05 21:39 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2014-12-05 21:31 . 2014-12-11 02:04 -------- d-----w- c:\windows\system32\MRT 2014-12-05 21:28 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2014-12-05 21:28 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll 2014-12-05 21:28 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2014-12-05 21:24 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll 2014-12-05 21:24 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe 2014-12-05 21:24 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll 2014-12-05 21:24 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe 2014-12-05 21:23 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll 2014-12-05 21:23 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll 2014-12-05 21:23 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe 2014-12-05 21:23 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe 2014-12-05 21:21 . 2013-08-29 02:16 1732032 ----a-w- c:\windows\system32\ntdll.dll 2014-12-05 21:20 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll 2014-12-05 21:19 . 2014-03-04 09:44 362496 ----a-w- c:\windows\system32\wow64win.dll 2014-12-05 21:18 . 2013-10-04 02:28 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll 2014-12-05 21:17 . 2014-06-16 02:10 985536 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2014-12-05 21:16 . 2012-05-05 08:36 503808 ----a-w- c:\windows\system32\srcore.dll 2014-12-05 21:06 . 2013-10-12 02:29 859648 ----a-w- c:\windows\system32\IKEEXT.DLL 2014-12-05 21:05 . 2013-10-12 02:30 830464 ----a-w- c:\windows\system32\nshwfp.dll 2014-12-05 21:05 . 2013-10-12 02:29 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2014-12-05 21:05 . 2013-10-12 02:03 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll 2014-12-05 21:05 . 2013-10-12 02:01 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL 2014-12-05 21:02 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll 2014-12-05 21:02 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-12-18 19:40 . 2014-08-13 18:34 77512 ----a-w- c:\windows\system32\drivers\klwtp.sys 2014-12-18 19:40 . 2014-08-20 17:04 818888 ----a-w- c:\windows\system32\drivers\klif.sys 2014-12-18 19:40 . 2014-08-18 13:43 150536 ----a-w- c:\windows\system32\drivers\klflt.sys 2014-11-24 13:04 . 2010-11-21 03:27 275080 ------w- c:\windows\system32\MpSigStub.exe 2014-11-20 08:23 . 2014-11-20 08:23 9728 ----a-w- c:\windows\SysWow64\RzStats.IPC.dll 2014-11-11 04:27 . 2014-11-11 04:27 80384 ----a-w- c:\windows\system32\RazerCoinstaller.dll 2014-10-09 09:07 . 2014-10-09 09:07 89088 ----a-w- c:\windows\SysWow64\rzdevinfo.dll 2014-09-30 05:32 . 2014-09-30 05:32 901632 ----a-w- c:\windows\SysWow64\rzdevicedll.dll 2014-09-30 05:32 . 2014-09-30 05:32 419840 ----a-w- c:\windows\SysWow64\rzaudiodll.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\games\Steam\steam.exe" [2014-11-18 1940160] "Spotify Web Helper"="c:\users\Jacko\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-12-12 1676344] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-12-03 30876768] "Spotify"="c:\users\Jacko\AppData\Roaming\Spotify\spotify.exe" [2014-12-12 6737976] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2014-11-03 585536] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-12-03 1021128] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "DXTempFolder"="c:\windows\system32\advpack.dll" [2009-07-14 126464] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 tsusbhub;tsusbhub;tsusbhub [x] S0 cm_km_w;Kaspersky Lab Crypto Module (FDE PDK);c:\windows\system32\DRIVERS\cm_km_w.sys;c:\windows\SYSNATIVE\DRIVERS\cm_km_w.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S1 klhk;klhk;c:\windows\system32\DRIVERS\klhk.sys;c:\windows\SYSNATIVE\DRIVERS\klhk.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x] S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x] S1 Klwtp;Klwtp;c:\windows\system32\DRIVERS\klwtp.sys;c:\windows\SYSNATIVE\DRIVERS\klwtp.sys [x] S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x] S1 RzFilter;RzFilter;c:\windows\system32\drivers\RzFilter.sys;c:\windows\SYSNATIVE\drivers\RzFilter.sys [x] S2 AVP15.0.1;Kaspersky Anti-Virus Service 15.0.1;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\avp.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\avp.exe [x] S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x] S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x] S2 kldisk;kldisk;c:\windows\system32\DRIVERS\kldisk.sys;c:\windows\SYSNATIVE\DRIVERS\kldisk.sys [x] S2 Razer Game Scanner Service;Razer Game Scanner;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [x] S2 RzOvlMon;Razer Overlay Subsystem Emergency Service;c:\program files (x86)\Razer\Core\64bit\rzovlmon.exe;c:\program files (x86)\Razer\Core\64bit\rzovlmon.exe [x] S2 rzpmgrk;rzpmgrk;c:\windows\system32\drivers\rzpmgrk.sys;c:\windows\SYSNATIVE\drivers\rzpmgrk.sys [x] S2 rzpnk;rzpnk;c:\windows\system32\drivers\rzpnk.sys;c:\windows\SYSNATIVE\drivers\rzpnk.sys [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 klflt;Kaspersky Lab Kernel DLL;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x] S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 RzDxgk;RzDxgk;c:\windows\system32\drivers\RzDxgk.sys;c:\windows\SYSNATIVE\drivers\RzDxgk.sys [x] S3 rzendpt;rzendpt;c:\windows\system32\DRIVERS\rzendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzendpt.sys [x] S3 rzudd;Razer Keyboard Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - MBAMPROTECTOR *NewlyCreated* - MBAMSWISSARMY *NewlyCreated* - MBAMWEBACCESSCONTROL . Inhalt des "geplante Tasks" Ordners . 2014-12-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-12-22 17:05] . 2014-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-12-22 17:05] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-08-19 1796056] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.mystartsearch.com/?type=hp&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE mDefault_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1417812451&from=tugs&uid=ST1000DX001-1CM162_Z1DDBRCEXXXXZ1DDBRCE&q={searchTerms} uInternet Settings,ProxyServer = localhost:8080 IE: {{09A10376-994C-4BBF-9121-F50CF7BA237E} - {F2A56BFE-7911-451A-BC74-A9C3C2E95126} - c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\IEExt\ie_plugin.dll TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{F77548F7-36AA-4552-845A-9A58B59FAE10}: NameServer = 31.168.224.106,5.135.12.52 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-<NO NAME> - (no file) Wow6432Node-HKLM-Run-gmsd_de_12 - (no file) AddRemove-Steam App 42700 - e:\games\Steam\steam.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-12-23 02:29:46 ComboFix-quarantined-files.txt 2014-12-23 01:29 . Vor Suchlauf: 10 Verzeichnis(se), 805.583.929.344 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 805.325.959.168 Bytes frei . - - End Of File - - E41BEB6DC48256F6CC94DCA2E5368F3B A36C5E4F47E84449FF07ED3517B43A31 Neuer Malwarebytes Anti-Malware log NACH ComboFix Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 23.12.2014 Scan Time: 03:01:07 Logfile: no !@#$.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2014.12.22.11 Rootkit Database: v2014.12.14.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Jacko Scan Type: Threat Scan Result: Completed Objects Scanned: 327741 Time Elapsed: 4 min, 39 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v4.106 - Report created 23/12/2014 at 03:13:16 # Updated 21/12/2014 by Xplode # Database : 2014-12-21.4 [Live] # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits) # Username : Jacko - JACKO-PC # Running from : C:\Users\Jacko\Desktop\adwcleaner_4.106.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\TVWizard Folder Deleted : C:\Program Files (x86)\predm Folder Deleted : C:\Users\Jacko\AppData\Local\TVWizard ***** [ Scheduled Tasks ] ***** ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\InetStat Key Deleted : HKCU\Software\OCS Key Deleted : HKCU\Software\Wnkey ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17496 -\\ Mozilla Firefox v -\\ Google Chrome v39.0.2171.95 ************************* AdwCleaner[R0].txt - [4047 octets] - [22/12/2014 22:44:37] AdwCleaner[R1].txt - [4105 octets] - [22/12/2014 22:47:28] AdwCleaner[R2].txt - [1992 octets] - [23/12/2014 03:11:51] AdwCleaner[S0].txt - [1813 octets] - [23/12/2014 03:13:16] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1873 octets] ########## Geändert von YouWin (23.12.2014 um 03:18 Uhr) |
23.12.2014, 17:48 | #13 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virus erwischt oder nicht? Adware/Junkware/Toolbars entfernen 1. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
2. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
23.12.2014, 23:01 | #14 |
| Virus erwischt oder nicht? Junkware Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.0 (11.29.2014:1) OS: Windows 7 Ultimate x64 Ran by Jacko on 23.12.2014 at 21:43:34,26 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 23.12.2014 at 21:50:07,43 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST kommt gleich FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-12-2014 01 Ran by Jacko (administrator) on JACKO-PC on 23-12-2014 22:46:44 Running from C:\Users\Jacko\Downloads Loaded Profile: Jacko (Available profiles: Jacko) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\avp.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Spotify Ltd) C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Spotify Ltd) C:\Users\Jacko\AppData\Roaming\Spotify\spotify.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe () C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\avpui.exe () C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe (Valve Corporation) C:\Games\Steam\Steam.exe (Valve Corporation) C:\Games\Steam\bin\steamwebhelper.exe (Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe (Razer, Inc.) C:\Users\Jacko\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Blizzard Entertainment) C:\Games\World of Warcraft\Wow-64.exe (Blizzard Entertainment) C:\Games\World of Warcraft\Utils\WowBrowserProxy.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1796056 2014-08-19] (NVIDIA Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2014-11-03] (Razer Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-12-03] (Adobe Systems Incorporated) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [Steam] => C:\Games\Steam\steam.exe [1940160 2014-11-18] (Valve Corporation) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [Spotify Web Helper] => C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-13] (Spotify Ltd) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30876768 2014-12-03] (Skype Technologies S.A.) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [Spotify] => C:\Users\Jacko\AppData\Roaming\Spotify\spotify.exe [6737976 2014-12-13] (Spotify Ltd) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1241592699-1578615748-785451789-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyServer: [S-1-5-21-1241592699-1578615748-785451789-1000] => localhost:8080 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1241592699-1578615748-785451789-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 [CODE] Code:
ATTFilter FireFox: ======== FF ProfilePath: C:\Users\Jacko\AppData\Roaming\Mozilla\Firefox\Profiles\0JhA7EB1.default FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @kaspersky.com/content_blocker_6418E0D362104DADA084DC312DFA8ABC -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\content_blocker@kaspersky.com () FF Plugin-x32: @kaspersky.com/virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\virtual_keyboard@kaspersky.com () FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Avira Browser Safety - C:\Users\Jacko\AppData\Roaming\Mozilla\Firefox\Profiles\0JhA7EB1.default\Extensions\abs@avira.com [2014-12-05] FF HKLM-x32\...\Firefox\Extensions: [content_blocker_6418E0D362104DADA084DC312DFA8ABC@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\content_blocker@kaspersky.com FF Extension: Модуль блокування небезпечних веб-сайтів - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\content_blocker@kaspersky.com [2014-12-18] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\virtual_keyboard@kaspersky.com FF Extension: Віртуальна клавіатура - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2014-12-18] Chrome: ======= CHR Profile: C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-22] CHR Extension: (Google Docs) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-22] CHR Extension: (Google Drive) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-22] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-22] CHR Extension: (YouTube) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-22] CHR Extension: (Adblock Plus) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-22] CHR Extension: (Google-Suche) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-22] CHR Extension: (Kaspersky Protection) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2014-12-22] CHR Extension: (Google Tabellen) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-22] CHR Extension: (Avira Browserschutz) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-12-22] CHR Extension: (Google Wallet) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-22] CHR Extension: (Google Mail) - C:\Users\Jacko\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-22] CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho [Not Found] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho [Not Found] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AVP15.0.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\avp.exe [234520 2014-08-30] (Kaspersky Lab ZAO) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [183488 2014-10-31] () R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [238288 2013-01-14] (Kaspersky Lab UK Ltd) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-12-05] (Disc Soft Ltd) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [468576 2014-03-31] (Kaspersky Lab ZAO) R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46144 2014-07-02] (Kaspersky Lab ZAO) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [150536 2014-12-18] (Kaspersky Lab ZAO) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [246456 2014-08-12] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [818888 2014-12-18] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55872 2014-06-05] (Kaspersky Lab ZAO) R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [77512 2014-12-18] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179776 2014-07-09] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-23] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.) R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39592 2014-09-05] (Razer Inc) R1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-18] (Razer, Inc.) R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-10-31] (Razer, Inc.) R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-11-17] (Razer, Inc.) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-23 22:46 - 2014-12-23 22:46 - 00016464 _____ () C:\Users\Jacko\Downloads\FRST.txt 2014-12-23 21:50 - 2014-12-23 21:50 - 00000621 _____ () C:\Users\Jacko\Desktop\JRT.txt 2014-12-23 21:43 - 2014-12-23 21:43 - 00000000 ____D () C:\Windows\ERUNT 2014-12-23 21:42 - 2014-12-23 21:42 - 01707646 _____ (Thisisu) C:\Users\Jacko\Desktop\JRT64.exe 2014-12-23 03:06 - 2014-12-23 03:06 - 00001057 _____ () C:\Users\Jacko\Desktop\no shit.txt 2014-12-23 02:29 - 2014-12-23 02:29 - 00021197 _____ () C:\ComboFix.txt 2014-12-23 02:22 - 2014-12-23 02:29 - 00000000 ____D () C:\Qoobox 2014-12-23 02:22 - 2014-12-23 02:29 - 00000000 ____D () C:\ComboFix 2014-12-23 02:22 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-12-23 02:22 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-12-23 02:22 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-12-23 02:22 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-12-23 02:22 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-12-23 02:22 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-12-23 02:22 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-12-23 02:22 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-12-23 02:21 - 2014-12-23 02:28 - 00000000 ____D () C:\Windows\erdnt Code:
ATTFilter 2014-12-05 21:10 - 2009-07-14 05:46 - 00002790 _____ () C:\Windows\DtcInstall.log 2014-12-05 21:08 - 2010-11-21 08:16 - 00000000 ____D () C:\Windows\CSC 2014-11-24 14:04 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\Jacko\AppData\Local\Temp\Quarantine.exe C:\Users\Jacko\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 14:32 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-12-2014 01 Ran by Jacko at 2014-12-23 22:47:24 Running from C:\Users\Jacko\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Kaspersky Anti-Virus (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Anti-Virus (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Call of Duty: Black Ops - Multiplayer (HKLM-x32\...\Steam App 42710) (Version: - Treyarch) Call of Duty: Black Ops (HKLM-x32\...\Steam App 42700) (Version: - Treyarch) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Kaspersky Anti-Virus (HKLM-x32\...\InstallWIX_{8ED07EBD-22AD-415A-B71E-C1AD86862C2E}) (Version: 15.0.1.415 - Kaspersky Lab) Kaspersky Anti-Virus (x32 Version: 15.0.1.415 - Kaspersky Lab) Hidden Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) NVIDIA 3D Vision Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation) NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation) NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation) Portal (HKLM-x32\...\Steam App 400) (Version: - Valve) Razer Core (HKLM-x32\...\Razer Core) (Version: 1.0.1.66 - Razer Inc) Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.18.23036 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.77.1126.2013 - Realtek) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.100 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-1241592699-1578615748-785451789-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) The Elder Scrolls Online (HKLM-x32\...\Steam App 306130) (Version: - Zenimax Online Studios) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) WinRAR 5.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 21-12-2014 03:58:17 DirectX wurde installiert 21-12-2014 19:58:14 DirectX wurde installiert 21-12-2014 22:11:00 DirectX wurde installiert 22-12-2014 12:42:55 Installed Windows 7 USB/DVD Download Tool 22-12-2014 18:05:48 Removed Windows 7 USB/DVD Download Tool 22-12-2014 22:17:17 DirectX wurde installiert 22-12-2014 22:31:33 DirectX wurde installiert 23-12-2014 03:27:09 DirectX wurde installiert 23-12-2014 20:04:41 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2014-12-23 02:27 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {922B44DA-C57D-4193-A705-4AFFD728378B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-22] (Google Inc.) Task: {9898644D-2AD5-4B60-8C25-BC44EB19B614} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-22] (Google Inc.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-12-05 22:29 - 2014-07-02 19:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-10-31 23:27 - 2014-10-31 23:27 - 00183488 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2014-12-06 20:16 - 2014-12-13 00:05 - 00374840 _____ () C:\Users\Jacko\AppData\Roaming\Spotify\Data\SpotifyHelper.exe 2014-11-20 09:23 - 2014-11-20 09:23 - 00289792 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe 2014-12-22 18:06 - 2014-12-06 02:16 - 01408328 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libglesv2.dll 2014-12-22 18:06 - 2014-12-06 02:16 - 00204616 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libegl.dll 2014-12-22 18:06 - 2014-12-06 02:17 - 10689352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll 2014-12-22 18:06 - 2014-12-06 02:16 - 01856840 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll 2014-12-22 18:06 - 2014-12-06 02:17 - 26725192 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll 2014-08-30 17:12 - 2014-08-30 17:12 - 01269952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.1\kpcengine.2.3.dll 2014-12-06 20:16 - 2014-12-13 00:05 - 36966968 _____ () C:\Users\Jacko\AppData\Roaming\Spotify\Data\libcef.dll 2014-12-06 20:16 - 2014-12-13 00:05 - 00867896 _____ () C:\Users\Jacko\AppData\Roaming\Spotify\Data\ffmpegsumo.dll 2014-12-06 20:16 - 2014-12-13 00:05 - 00886840 _____ () C:\Users\Jacko\AppData\Roaming\Spotify\Data\libglesv2.dll 2014-12-06 20:16 - 2014-12-13 00:05 - 00108600 _____ () C:\Users\Jacko\AppData\Roaming\Spotify\Data\libegl.dll 2014-12-06 01:19 - 2014-01-04 01:20 - 34755072 _____ () C:\Users\Jacko\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll 2014-11-20 07:02 - 2014-11-20 07:02 - 00193024 _____ () C:\ProgramData\Razer\Synapse\RzStats\RigWrapper.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 01171456 _____ () C:\Games\Steam\libavcodec-56.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 00442368 _____ () C:\Games\Steam\libavutil-54.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 00332800 _____ () C:\Games\Steam\libavresample-2.dll 2014-12-06 13:14 - 2014-11-11 19:47 - 00774656 _____ () C:\Games\Steam\SDL2.dll 2014-12-06 13:14 - 2014-11-18 21:23 - 02227904 _____ () C:\Games\Steam\video.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 00403968 _____ () C:\Games\Steam\libavformat-56.dll 2014-12-06 13:14 - 2014-11-11 19:48 - 00485888 _____ () C:\Games\Steam\libswscale-3.dll 2014-12-06 13:15 - 2014-11-18 21:23 - 00690880 _____ () C:\Games\Steam\bin\chromehtml.DLL 2014-12-06 13:15 - 2014-11-11 19:48 - 34589888 _____ () C:\Games\Steam\bin\libcef.dll 2014-12-06 01:19 - 2014-01-04 01:20 - 00970240 _____ () C:\Users\Jacko\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\ffmpegsumo.dll 2014-12-05 22:18 - 2014-12-19 16:30 - 23950848 _____ () C:\Games\World of Warcraft\Utils\libcef.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: Steam => "C:\Games\Steam.exe" -silent ========================= Accounts: ========================== Administrator (S-1-5-21-1241592699-1578615748-785451789-500 - Administrator - Disabled) Guest (S-1-5-21-1241592699-1578615748-785451789-501 - Limited - Disabled) Jacko (S-1-5-21-1241592699-1578615748-785451789-1000 - Administrator - Enabled) => C:\Users\Jacko ==================== Faulty Device Manager Devices ============= Name: USB (Universal Serial Bus)-Controller Description: USB (Universal Serial Bus)-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-12-23 02:27:27.146 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-23 02:27:27.073 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: AMD FX(tm)-6300 Six-Core Processor Percentage of memory in use: 69% Total physical RAM: 8148.75 MB Available physical RAM: 2510.25 MB Total Pagefile: 16295.68 MB Available Pagefile: 9557.78 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.29 GB) (Free:748.65 GB) NTFS Drive d: (GRMCHPXFRER_DE_DVD) (CDROM) (Total:2.97 GB) (Free:0 GB) UDF Drive f: (GRMCHPXFRER_DE_DVD) (CDROM) (Total:2.97 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
23.12.2014, 23:35 | #15 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virus erwischt oder nicht? Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\S-1-5-21-1241592699-1578615748-785451789-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyServer: [S-1-5-21-1241592699-1578615748-785451789-1000] => localhost:8080 EmptyTemp: Hosts: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Virus erwischt oder nicht? |
appdata, browser, code, desktop, erwischt, explorer, firefox, google, helper, internet, internet explorer, live, microsoft, mozilla, opera, registry, service, services, software, system, temp, version, virus, windows, windows 7 |