|
Plagegeister aller Art und deren Bekämpfung: COULDN'T LOAD XPCOM - Firefox startet nichtWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.03.2015, 20:24 | #1 |
| COULDN'T LOAD XPCOM - Firefox startet nicht Hallo, nachdem ich eine Systemwiederherstellung durchgeführt habe, kam beim Neustart von Firefox die Meldung COULDN'T LOAD XPCOM. Auch die Auswahl eines anderen Herstellungspunkt (es gab nur noch einen in der Liste) hat das Problem nicht behoben. Kann mir jemand helfen? Da ich gelesen habe, dass man mit dem Programm Farbar Recovery einen Scan durchführen soll, habe ich bereits die 32-bit Version installiert und werde die FRST.txt - Datei und danach die Addition.txt-Datei hier posten, sobald der Scan durchgeführt ist, in der Hoffnung, Zeit zu sparen. Lieben Dank im Voraus, Christian FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-02-2015 Ran by Christian Rietz (administrator) on CHRISTIAN-PC on 01-03-2015 20:20:43 Running from C:\Users\Christian Rietz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RCNZL02F Loaded Profiles: Christian Rietz (Available profiles: Christian Rietz) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PSIService.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\loggingserver.exe (X10) C:\Program Files\Common Files\X10\Common\X10nets.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (ACD Systems, Ltd.) C:\Program Files\Common Files\ACD Systems\DE\DevDetect.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodtray.exe () C:\Program Files\AVG Web TuneUp\vprot.exe (Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Dropbox, Inc.) C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe (Microsoft Corporation) C:\Windows\System32\rstrui.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Dll-FIles.Com) C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\ieuser.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (RealNetworks, Inc.) C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_16_0_0_305_ActiveX.exe (Farbar) C:\Users\Christian Rietz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RCNZL02F\FRST[1].exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512 2008-01-04] (Synaptics, Inc.) HKLM\...\Run: [UpdatePDRShortCut] => C:\Program Files\HomeCinema\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM\...\Run: [RemoteControl] => C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe [71216 2007-02-09] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] => C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe [52256 2007-01-08] () HKLM\...\Run: [UpdatePPShortCut] => C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe [222504 2008-02-21] (CyberLink Corp.) HKLM\...\Run: [UCam_Menu] => C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6294048 2008-09-18] (Realtek Semiconductor) HKLM\...\Run: [Google Desktop Search] => C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [220160 2008-10-26] (Google) HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [Device Detector] => DevDetect.exe -autorun HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5188112 2014-12-16] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation) HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe [2729800 2011-01-25] (O&O Software GmbH) HKLM\...\Run: [vProt] => C:\Program Files\AVG Web TuneUp\vprot.exe [2662424 2014-10-06] () HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-08-05] (Wondershare) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-11] (Google Inc.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ISUSPM] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) AppInit_DLLs: c:\docume~1\ settings\all users\application D즸粖㛉ࠀᖰAA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-209139463-1928718786-3223491114-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ SearchScopes: HKLM -> DefaultScope value is missing. SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-209139463-1928718786-3223491114-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-209139463-1928718786-3223491114-1000 -> No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\3.2.0\ViProtocol.dll (AVG Secure Search) Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF user.js: detected! => C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\user.js FF SearchPlugin: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\searchplugins\search_the_web.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\nppl3260.dll FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-09-01] FF Extension: Avira Browser Safety - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\abs@avira.com [2015-02-02] FF Extension: GMX MailCheck - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\toolbar@gmx(75).net [2015-02-28] FF Extension: No Name - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\toolbar@gmx.net [2014-12-18] FF Extension: DownloadHelper - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-06] FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi [2013-07-02] FF Extension: ProxTube - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-07-28] FF Extension: Adblock Plus - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-07-16] FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-07-11] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-27] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\extensions\cliqz@cliqz.com FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found] Chrome: ======= CHR Profile: C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browser Safety) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-10-20] CHR Extension: (RealDownloader) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-09-24] CHR Extension: (Google Wallet) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-24] CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [Not Found] CHR HKLM\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-04-16] CHR HKU\S-1-5-21-209139463-1928718786-3223491114-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [Not Found] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2013-07-12] () [File not signed] R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [992560 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3247120 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) S3 GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe [69120 2008-10-26] (Google) [File not signed] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2336072 2011-01-25] (O&O Software GmbH) R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] () R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [241734 2008-06-28] () [File not signed] S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2015-02-22] (TuneUp Software) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1050440 2010-04-01] (TuneUp Software) S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) R2 vToolbarUpdater3.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe [1843736 2014-08-29] (AVG Secure Search) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) [File not signed] R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2001-11-12] (X10) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [200984 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [189720 2014-10-24] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-29] (AVG Technologies CZ, s.r.o.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-14] (Avira Operations GmbH & Co. KG) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-29] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-19] (Avira Operations GmbH & Co. KG) S3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1332576 2008-09-25] (NXP Semiconductors Germany GmbH) R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2013-07-12] (Padus, Inc.) [File not signed] S3 PhilCap; C:\Windows\System32\DRIVERS\PhilCap.sys [908896 2007-07-31] (NXP Semiconductors Germany GmbH) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13976 2006-11-17] (X10 Wireless Technology, Inc.) R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] U4 Msetapxe_n; No ImagePath S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-01 19:29 - 2015-03-01 20:09 - 00000300 _____ () C:\Windows\Tasks\DLL-Files.Com Fixer_Updates.job 2015-03-01 19:29 - 2015-03-01 20:09 - 00000284 _____ () C:\Windows\Tasks\DLL-Files.Com Fixer_MONTHLY.job 2015-03-01 19:29 - 2015-03-01 19:29 - 00000889 _____ () C:\Users\Public\Desktop\Dll-Files Fixer.lnk 2015-03-01 19:29 - 2015-03-01 19:29 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\dll-files.com 2015-03-01 19:29 - 2015-03-01 19:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dll-Files Fixer 2015-03-01 19:29 - 2015-03-01 19:29 - 00000000 ____D () C:\Program Files\Dll-Files.com Fixer 2015-03-01 19:29 - 2015-02-27 14:20 - 00018992 _____ (Dll-Files.com) C:\Windows\system32\roboot.exe 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\Documents\Eigene Google Gadgets 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Avg2014 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\AVG Web TuneUp 2015-03-01 18:17 - 2015-03-01 18:17 - 00118304 _____ () C:\Users\TEMP.Christian-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Apple Computer 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Wondershare 2015-03-01 18:16 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\VirtualStore 2015-03-01 18:16 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Google 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\RealNetworks 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Real 2015-03-01 18:15 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC 2015-03-01 18:15 - 2013-09-27 19:12 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Microsoft Help 2015-03-01 18:15 - 2013-09-26 20:06 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\TuneUp Software 2015-02-27 20:28 - 2015-02-27 20:30 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\Playmo-Zoo 2015-02-26 00:25 - 2015-02-26 00:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox(25) 2015-02-25 23:30 - 2015-02-26 00:45 - 106785426 _____ () C:\Users\Christian Rietz\Desktop\Looking S02E06 - Looking for Gordon Freeman.flv 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Skype 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Program Files\Skype(27) 2015-02-22 17:12 - 2015-02-22 17:12 - 00001869 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities.lnk 2015-02-22 17:12 - 2015-02-22 17:12 - 00001857 _____ () C:\Users\Public\Desktop\TuneUp Utilities.lnk 2015-02-22 17:12 - 2015-02-22 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2015-02-22 17:12 - 2010-04-01 15:17 - 00030536 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2015-02-22 17:12 - 2010-04-01 15:11 - 00030024 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2015-02-22 17:12 - 2010-04-01 15:11 - 00021320 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2015-02-22 17:11 - 2015-02-22 17:12 - 00000000 ____D () C:\Program Files\TuneUp Utilities 2010 2015-02-22 17:10 - 2015-02-22 17:10 - 00000000 __SHD () C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} 2015-02-22 16:59 - 2015-02-22 16:59 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\1 Tuneup Utilities 2015-02-22 13:37 - 2015-02-22 13:37 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\LOOKING for Season 2 2015-02-09 22:08 - 2015-02-09 22:09 - 00000000 ____D () C:\Program Files\QuickTime 2015-02-09 22:08 - 2015-02-09 22:08 - 00001730 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2015-02-09 22:08 - 2015-02-09 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2015-02-09 22:01 - 2015-02-09 22:03 - 42096984 _____ (Apple Inc.) C:\Users\Christian Rietz\Downloads\QuickTimeInstaller(1).exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-01 20:20 - 2013-07-16 20:05 - 00000000 ____D () C:\FRST 2015-03-01 20:20 - 2008-10-25 04:29 - 00000438 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job 2015-03-01 20:14 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-01 20:14 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-01 20:09 - 2014-02-03 20:53 - 00000000 ___RD () C:\Users\Christian Rietz\Dropbox 2015-03-01 20:09 - 2014-02-03 20:49 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Dropbox 2015-03-01 20:09 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.dat 2015-03-01 20:09 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.001 2015-03-01 20:08 - 2013-07-11 17:09 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-01 20:08 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Home Cinema 2015-03-01 20:08 - 2013-07-11 14:20 - 01656874 _____ () C:\Windows\WindowsUpdate.log 2015-03-01 20:07 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-01 20:06 - 2014-08-29 19:05 - 00000000 ____D () C:\Program Files\Common Files\AVG Secure Search 2015-03-01 20:06 - 2014-04-17 18:10 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2015-03-01 20:06 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Skype 2015-03-01 20:06 - 2013-09-10 21:42 - 00000000 ____D () C:\ProgramData\MFAData 2015-03-01 20:06 - 2013-07-11 17:24 - 00000000 ___RD () C:\Users\Christian Rietz\Documents\Programme 2015-03-01 20:06 - 2013-07-11 17:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration 2015-03-01 20:03 - 2006-11-02 14:01 - 00032540 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-03-01 19:58 - 2013-10-06 11:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-03-01 19:35 - 2013-07-11 17:09 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-01 18:52 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc 2015-03-01 18:50 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz 2015-03-01 18:50 - 2006-11-02 11:22 - 46661632 _____ () C:\Windows\system32\config\software_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 33554432 _____ () C:\Windows\system32\config\components_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 19660800 _____ () C:\Windows\system32\config\system_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\security_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\default_previous 2015-03-01 18:45 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-03-01 18:38 - 2015-01-26 20:32 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ___RD () C:\Program Files\Skype 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ____D () C:\Program Files\Common Files\Skype 2015-02-26 00:25 - 2013-09-25 21:57 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Skype 2015-02-23 19:24 - 2008-01-21 03:47 - 00731676 _____ () C:\Windows\PFRO.log 2015-02-22 17:10 - 2013-07-11 21:54 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-22 17:02 - 2006-11-02 11:33 - 01418794 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-22 16:16 - 2013-07-11 22:21 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\vlc 2015-02-22 13:20 - 2013-07-11 16:54 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Adobe 2015-02-22 13:20 - 2008-10-20 05:03 - 00000000 ____D () C:\ProgramData\Adobe 2015-02-19 19:07 - 2014-02-03 20:50 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-02-09 22:04 - 2013-07-11 21:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-02-09 22:04 - 2013-07-11 21:03 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-02-09 22:04 - 2013-07-11 21:02 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Adobe 2015-02-09 21:21 - 2014-08-14 20:25 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-09 21:21 - 2013-07-16 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-09 21:20 - 2013-07-16 20:21 - 00000000 ____D () C:\Program Files\Avira ==================== Files in the root of some directories ======= 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\StatusSheet 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\Stingers 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\String Comparison 2014-02-20 21:49 - 2014-02-20 21:49 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\System Image Utility 2014-03-26 19:46 - 2014-03-26 19:46 - 0000047 _____ () C:\Users\Christian Rietz\AppData\Roaming\WB.CFG 2013-08-02 19:34 - 2014-11-20 21:45 - 0001356 _____ () C:\Users\Christian Rietz\AppData\Local\d3d9caps.dat 2013-07-28 13:50 - 2015-01-25 21:05 - 0092672 _____ () C:\Users\Christian Rietz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2008-10-25 04:12 - 2015-03-01 20:09 - 0084921 _____ () C:\ProgramData\nvModes.001 2008-10-25 04:12 - 2015-03-01 20:09 - 0084921 _____ () C:\ProgramData\nvModes.dat 2014-02-20 21:49 - 2014-02-20 21:49 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT 2014-02-20 21:57 - 2014-02-20 22:12 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT 2014-02-20 21:53 - 2014-02-20 22:09 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\Strings 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\ProgramData\Super Strings 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\SupportPrinters Some content of TEMP: ==================== C:\Users\Christian Rietz\AppData\Local\Temp\avgnt.exe C:\Users\Christian Rietz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmph2lvdy.dll C:\Users\Christian Rietz\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Christian Rietz\AppData\Local\Temp\SDShelEx-win32.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-01 20:13 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- |
01.03.2015, 20:28 | #2 |
/// the machine /// TB-Ausbilder | COULDN'T LOAD XPCOM - Firefox startet nicht hi,
__________________dann warte ich noch auf die Addition.txt
__________________ |
01.03.2015, 20:32 | #3 |
| COULDN'T LOAD XPCOM - Firefox startet nichtCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-02-2015 Ran by Christian Rietz at 2015-03-01 20:31:20 Running from C:\Users\Christian Rietz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EFNKQD0L Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 4.42 (HKLM\...\7-Zip) (Version: - ) ACDSee 9 Foto-Manager (HKLM\...\{7AE25201-3E12-4FA2-9E65-67CD475D9263}) (Version: 9.0.55 - ACD Systems Ltd.) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Photoshop CS (HKLM\...\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}) (Version: CS - Adobe Systems, Inc.) Adobe Reader 9 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A90000000001}) (Version: 9.0.0 - Adobe Systems Incorporated) Adobe Shockwave Player 11 (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.) Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E14ADE0E-75F3-4A46-87E5-26692DD626EC}) (Version: 6.1.0.13 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArcSoft Panorama Maker 6 (HKLM\...\{DABFD34E-BE68-4BC6-9254-5D7A7FF76B99}) (Version: 6.0.8.85 - ArcSoft) AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4800 - AVG Technologies) AVG 2014 (Version: 14.0.3614 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4257 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4800 - AVG Technologies) Hidden AVG Web TuneUp (HKLM\...\AVG Web TuneUp) (Version: 3.2.0.18 - AVG Technologies) Avira (HKLM\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG) Avira (Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Avira SearchFree Toolbar plus Web Protection (HKLM\...\{41564952-412D-5637-00A7-A758B70C0201}) (Version: 12.2.1.477 - Ask Partner Network) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Corel Graphics Suite 11 (HKLM\...\InstallShield_{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}) (Version: 11 - Corel Corporation) Corel Graphics Suite 11 (Version: 11 - Corel Corporation) Hidden Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation) CorelDRAW Essential Edition 3 (HKLM\...\_{ADDBE07D-95B8-4789-9C76-187FFF9624B4}) (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) Hidden CyberLink MediaShow (HKLM\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 4.1.2019 - CyberLink Corp.) CyberLink PhotoNow (HKLM\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.5203 - CyberLink Corp.) CyberLink PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2209a - CyberLink Corp.) CyberLink PowerDVD (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 7.0.3118.0 - PowerDVDCorp.) CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0815 - CyberLink Corp.) CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.2109 - CyberLink Corp.) DE (Version: 3.0 - Corel Corporation) Hidden Dll-Files Fixer (HKLM\...\Dll-Files Fixer_is1) (Version: 3.2.81 - Dll-Files.com) Dolby Control Center (HKLM\...\{70E8EBD5-78C9-4258-B20A-5098CCA000F0}) (Version: 1.1.0601 - Dolby) Dropbox (HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.) Free YouTube Download version 3.2.48.1015 (HKLM\...\Free YouTube Download_is1) (Version: 3.2.48.1015 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.48.1015 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.48.1015 - DVDVideoSoft Ltd.) Google Chrome (HKLM\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.) Google Desktop (HKLM\...\Google Desktop) (Version: - - Google) Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden iTunes (HKLM\...\{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}) (Version: 11.0.4.4 - Apple Inc.) Java(TM) 6 Update 7 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160070}) (Version: 1.6.0.70 - Sun Microsystems, Inc.) MAGIX Screenshare (HKLM\...\{A7B517E2-07EB-47BA-877B-3F174FB7760B}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM\...\{9D5B0618-2EFA-4DAA-9B53-A546992824EA}) (Version: 7.0.2.6 - MAGIX AG) MakeDisc (HKLM\...\{B145EC69-66F5-11D8-9D75-000129760D75}) (Version: 3.0.2601 - CyberLink Corp.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 de) (HKLM\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon) Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.9.0 - Nikon) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) O&O Defrag Free Edition (HKLM\...\{E29CFB36-F070-4612-8DB5-7038161B6294}) (Version: 14.1.431 - O&O Software GmbH) Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.5.0 - Nikon) QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) RealDownloader (Version: 1.3.2 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5704 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: 3.0.1.3 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden Samplitude 11 Silver (HKLM\...\MAGIX_MSI_sam11silver) (Version: 11.0.1.0 - MAGIX AG) Samplitude 11 Silver (Version: 11.0.1.0 - MAGIX AG) Hidden Samplitude Music Studio 2008 Trial 14.0.2.0 (D) (HKLM\...\Samplitude Music Studio 2008 Trial D) (Version: 14.0.2.0 - MAGIX AG) Skype™ 6.7 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.7.102 - Skype Technologies S.A.) StreamTransport version: 1.1.6.1 (HKLM\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - ) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.2.2.0 - Synaptics) TuneUp Utilities (HKLM\...\TuneUp Utilities) (Version: 9.0.4100.12 - TuneUp Software) TuneUp Utilities (Version: 9.0.4100.12 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (Version: 9.0.4100.12 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update Manager (Version: 4.60 - Corel Corporation) Hidden VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.9.0 - Nikon) Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN) Windows Live Anmelde-Assistent (HKLM\...\{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}) (Version: 5.000.818.6 - Microsoft Corporation) Windows Live Fotogalerie (HKLM\...\{A1D08B90-AE1A-4885-AC29-731496FD397E}) (Version: 12.0.1347.0718 - Microsoft Corporation) Windows Live installer (HKLM\...\{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}) (Version: 12.0.1471.1025 - Microsoft Corporation) Windows Live Mail (HKLM\...\{82F2B38B-1426-443D-874C-AC25675E7BEB}) (Version: 12.0.1606.1023 - Microsoft Corporation) Windows Live Messenger (HKLM\...\{2B091530-69AA-442E-AB09-39ED06B58220}) (Version: 8.5.1302.1018 - Microsoft Corporation) Windows Live Writer (HKLM\...\{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5}) (Version: 12.0.1370.0325 - Microsoft Corporation) X10 Hardware(TM) (HKLM\...\X10Hardware) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Restore Points ========================= 25-02-2015 23:03:38 Removed Skype™ 6.7 01-03-2015 18:18:56 Wiederherstellungsvorgang 01-03-2015 19:14:16 Wiederherstellungsvorgang 01-03-2015 19:47:21 DLL-Files Fixer So, Mrz 01, 15 19:47 01-03-2015 20:02:59 Wiederherstellungsvorgang ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {2267B247-CB5D-4D37-B206-937EF3607056} - System32\Tasks\DLL-Files.Com Fixer_MONTHLY => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe [2015-02-27] (Dll-FIles.Com) Task: {2A6345ED-9E31-48E2-AAA9-1B8FE0162021} - System32\Tasks\Real Player-Online-Aktualisierungsprogramm => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-07-11] (RealNetworks, Inc.) Task: {2B7E31FE-31CD-4EFD-906B-08D81741F6BA} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {55EEAAEB-9142-4D42-8386-DC56C99A5F5F} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {5C0ECDDC-2000-49E2-903C-6D50008CE73C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-09] (Adobe Systems Incorporated) Task: {635C392F-D422-40B8-99A5-4F0DD50828BD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.) Task: {7BAB9B3A-24B1-4B7B-AE0D-22DE6589D5B2} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {7EBB1EAC-2178-4747-A928-3EE3F7421CB8} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {932074F6-FEAE-4965-AE0E-62D04A8E95B4} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe [2013-04-16] (RealNetworks, Inc.) Task: {AC667962-B3FC-416F-B372-14A3F0B4107B} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe [2010-04-01] (TuneUp Software) Task: {C4B67155-2DB3-4ACF-B7CB-FF0D54206C9A} - System32\Tasks\RDReminder => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe [2015-02-27] (Dll-FIles.Com) Task: {C5C8E683-4485-4155-982B-47742639C45B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.) Task: {EBB55B67-A7DD-4AAD-B756-01DF1A6887AB} - System32\Tasks\DLL-Files.Com Fixer_Updates => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe [2015-02-27] (Dll-FIles.Com) Task: {F4B5D53B-8440-415B-9719-9419C4D509F1} - System32\Tasks\Real Networks Scheduler => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-07-11] (RealNetworks, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DLL-Files.Com Fixer_MONTHLY.job => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe Task: C:\Windows\Tasks\DLL-Files.Com Fixer_Updates.job => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job => C:\Windows\system32\msfeedssync.exe ==================== Loaded Modules (whitelisted) ============== 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2007-06-05 12:20 - 2007-06-05 12:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2013-04-16 02:07 - 2013-04-16 02:07 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe 2008-10-22 06:21 - 2008-06-28 01:00 - 00241734 _____ () C:\Program Files\CyberLink\Shared Files\RichVideo.exe 2014-08-29 19:05 - 2014-08-29 19:05 - 00159768 _____ () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\loggingserver.exe 2014-08-29 19:05 - 2014-08-29 19:05 - 00519704 _____ () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\log4cplusU.dll 2015-01-19 12:03 - 2015-01-19 12:03 - 00245760 _____ () C:\Program Files\Avira\My Avira\System.ComponentModel.Composition.dll 2014-08-29 19:05 - 2014-10-06 21:47 - 02662424 _____ () C:\Program Files\AVG Web TuneUp\vprot.exe 2014-10-20 22:38 - 2014-08-05 09:22 - 01489408 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll 2014-10-20 22:38 - 2014-05-19 16:19 - 00137728 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00750080 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-03-01 20:09 - 2015-03-01 20:09 - 00043008 _____ () c:\Users\Christian Rietz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmph2lvdy.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00047616 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\libEGL.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00865280 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00200704 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\system32\oobe\info\wallpaper1.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-209139463-1928718786-3223491114-500 - Administrator - Disabled) Christian Rietz (S-1-5-21-209139463-1928718786-3223491114-1000 - Administrator - Enabled) => C:\Users\Christian Rietz Gast (S-1-5-21-209139463-1928718786-3223491114-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/01/2015 08:08:45 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/01/2015 08:08:44 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/01/2015 08:08:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/01/2015 08:08:09 PM) (Source: System Restore) (EventID: 8209) (User: ) Description: Unbekannter Fehler bei der Systemwiederherstellung: (Removed Skype™ 6.7). Zusätzliche Informationen: . Error: (03/01/2015 08:07:38 PM) (Source: Avira Antivirus) (EventID: 4117) (User: NT-AUTORITÄT) Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet! Error: (03/01/2015 07:47:20 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {27b9c954-8c70-438f-a2f5-0812d3d02c66} Error: (03/01/2015 07:20:15 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/01/2015 07:19:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/01/2015 07:19:36 PM) (Source: System Restore) (EventID: 8209) (User: ) Description: Unbekannter Fehler bei der Systemwiederherstellung: (Removed Skype™ 6.7). Zusätzliche Informationen: . Error: (03/01/2015 07:19:34 PM) (Source: Avira Antivirus) (EventID: 4117) (User: NT-AUTORITÄT) Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet! System errors: ============= Error: (03/01/2015 08:08:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (03/01/2015 08:07:18 PM) (Source: HTTP) (EventID: 15016) (User: ) Description: \Device\Http\ReqQueueKerberos Error: (03/01/2015 07:19:58 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Avira Echtzeit-Scanner101Neustart des Diensts Error: (03/01/2015 07:19:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (03/01/2015 07:18:45 PM) (Source: HTTP) (EventID: 15016) (User: ) Description: \Device\Http\ReqQueueKerberos Error: (03/01/2015 06:53:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (03/01/2015 06:52:44 PM) (Source: HTTP) (EventID: 15016) (User: ) Description: \Device\Http\ReqQueueKerberos Error: (03/01/2015 06:20:22 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: AVGIDSAgent Error: (03/01/2015 06:03:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (03/01/2015 06:01:53 PM) (Source: HTTP) (EventID: 15016) (User: ) Description: \Device\Http\ReqQueueKerberos Microsoft Office Sessions: ========================= Error: (07/28/2013 02:06:52 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 9 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2015-03-01 20:30:55.012 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-01 20:30:54.918 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-01 20:30:54.824 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-01 20:30:54.731 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-01 20:30:54.590 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-01 20:30:54.497 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-01 20:30:54.403 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-01 20:30:54.310 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-01 20:30:44.606 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-01 20:30:44.528 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz Percentage of memory in use: 56% Total physical RAM: 2301.44 MB Available physical RAM: 993.19 MB Total Pagefile: 4833.86 MB Available Pagefile: 3284.62 MB Total Virtual: 2047.88 MB Available Virtual: 1928.3 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:141.25 GB) (Free:45.18 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:15.81 GB) (Free:4.4 GB) FAT32 Drive g: (Volume) (Fixed) (Total:141.01 GB) (Free:127.5 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: DAE4C35C) Partition 1: (Active) - (Size=141.3 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=141 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15.8 GB) - (Type=0C) ==================== End Of Log ============================ |
02.03.2015, 12:21 | #4 |
/// the machine /// TB-Ausbilder | COULDN'T LOAD XPCOM - Firefox startet nicht Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.03.2015, 23:44 | #5 |
| COULDN'T LOAD XPCOM - Firefox startet nichtCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Update, 02.03.2015 22:47:30, SYSTEM, CHRISTIAN-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1, Update, 02.03.2015 22:47:31, SYSTEM, CHRISTIAN-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.2.25.1, Update, 02.03.2015 22:48:01, SYSTEM, CHRISTIAN-PC, Manual, Malware Database, 2014.11.20.6, 2015.3.2.6, Update, 02.03.2015 22:48:36, SYSTEM, CHRISTIAN-PC, Manual, Malware Database, 2015.3.2.6, 2015.3.2.7, (end) Code:
ATTFilter # AdwCleaner v4.111 - Bericht erstellt 02/03/2015 um 23:20:35 # Aktualisiert 18/02/2015 von Xplode # Datenbank : 2015-03-02.1 [Server] # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 1 (x86) # Benutzername : Christian Rietz - CHRISTIAN-PC # Gestarted von : C:\Users\Christian Rietz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T8UQQG8I\AdwCleaner_4.111[1].exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : vToolbarUpdater3.2.0 ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\AVG Secure Search Ordner Gelöscht : C:\ProgramData\AVG Security Toolbar Ordner Gelöscht : C:\Program Files\Dll-Files.com Fixer Ordner Gelöscht : C:\Program Files\Common Files\AVG Secure Search Ordner Gelöscht : C:\Users\Christian Rietz\AppData\Roaming\RHEng Ordner Gelöscht : C:\Users\Christian Rietz\AppData\Roaming\dll-files.com Datei Gelöscht : C:\Users\Public\Desktop\Dll-Files Fixer.lnk Datei Gelöscht : C:\Windows\system32\roboot.exe Datei Gelöscht : C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\foxydeal.sqlite Datei Gelöscht : C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\invalidprefs.js Datei Gelöscht : C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\searchplugins\avg-secure-search.xml Datei Gelöscht : C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\user.js Datei Gelöscht : C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovigo.com_0.localstorage-journal ***** [ Geplante Tasks ] ***** Task Gelöscht : RDReminder Task Gelöscht : DLL-Files.Com Fixer_Updates Task Gelöscht : DLL-Files.Com Fixer_MONTHLY ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41564952-412D-5637-00A7-7A786E7484D7} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{41564952-412D-5637-00A7-7A786E7484D7}] Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\dll-files.com Schlüssel Gelöscht : HKLM\SOFTWARE\dll-files.com Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dll-Files Fixer_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local ***** [ Internetbrowser ] ***** -\\ Internet Explorer v7.0.6001.18639 -\\ Mozilla Firefox v35.0.1 (x86 de) [ltp2kpr9.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml"); [ltp2kpr9.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.xpiState", "{\"app-profile\":{\"2020Player_IKEA@2020Technologies.com\":{\"d\":\"C:\\\\Users\\\\Christian Rietz\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ltp2kpr9[...] -\\ Google Chrome v40.0.2214.115 [C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.fbdownloader.com/search.php?channel=sfde203fbdgy21&q={searchTerms} [C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=5450002220030F1A&affID=121565&tsp=4993 [C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3319434&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP50113B4A-887F-4A93-9ECD-B4026E0E8DE1&q={searchTerms}&SSPV= ************************* AdwCleaner[R0].txt - [12112 Bytes] - [24/09/2013 22:44:24] AdwCleaner[R1].txt - [4212 Bytes] - [26/03/2014 19:38:13] AdwCleaner[R2].txt - [8957 Bytes] - [26/03/2014 19:59:08] AdwCleaner[R3].txt - [8066 Bytes] - [02/03/2015 23:17:10] AdwCleaner[S0].txt - [12093 Bytes] - [24/09/2013 22:45:52] AdwCleaner[S1].txt - [7762 Bytes] - [26/03/2014 19:48:33] AdwCleaner[S2].txt - [9068 Bytes] - [26/03/2014 20:02:09] AdwCleaner[S3].txt - [7976 Bytes] - [02/03/2015 23:20:35] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [8035 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.3 (03.01.2015:1) OS: Windows Vista (TM) Home Premium x86 Ran by Christian Rietz on 02.03.2015 at 23:28:05,86 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted: [File] C:\Users\Christian Rietz\AppData\Roaming\mozilla\firefox\profiles\ltp2kpr9.default\extensions\toolbar_avira-v7@apn.ask.com.xpi Successfully deleted: [Folder] C:\Users\Christian Rietz\AppData\Roaming\mozilla\firefox\profiles\ltp2kpr9.default\extensions\toolbar@gmx.net Emptied folder: C:\Users\Christian Rietz\AppData\Roaming\mozilla\firefox\profiles\ltp2kpr9.default\minidumps [144 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 02.03.2015 at 23:36:20,57 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-03-2015 Ran by Christian Rietz (administrator) on CHRISTIAN-PC on 02-03-2015 23:40:08 Running from C:\Users\Christian Rietz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z8T9JQTC Loaded Profiles: Christian Rietz (Available profiles: Christian Rietz) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PSIService.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (X10) C:\Program Files\Common Files\X10\Common\X10nets.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (ACD Systems, Ltd.) C:\Program Files\Common Files\ACD Systems\DE\DevDetect.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodtray.exe (Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Dropbox, Inc.) C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\ieuser.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (RealNetworks, Inc.) C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe (Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Farbar) C:\Users\Christian Rietz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z8T9JQTC\FRST[1].exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512 2008-01-04] (Synaptics, Inc.) HKLM\...\Run: [UpdatePDRShortCut] => C:\Program Files\HomeCinema\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM\...\Run: [RemoteControl] => C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe [71216 2007-02-09] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] => C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe [52256 2007-01-08] () HKLM\...\Run: [UpdatePPShortCut] => C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe [222504 2008-02-21] (CyberLink Corp.) HKLM\...\Run: [UCam_Menu] => C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6294048 2008-09-18] (Realtek Semiconductor) HKLM\...\Run: [Google Desktop Search] => C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [220160 2008-10-26] (Google) HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [Device Detector] => DevDetect.exe -autorun HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5188112 2014-12-16] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation) HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe [2729800 2011-01-25] (O&O Software GmbH) HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-08-05] (Wondershare) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-07-11] (RealNetworks, Inc.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-11] (Google Inc.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ISUSPM] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) AppInit_DLLs: c:\docume~1\ settings\all users\application D즸粖㛉ࠀᖰAA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-209139463-1928718786-3223491114-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll (Google Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-209139463-1928718786-3223491114-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF SearchPlugin: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\searchplugins\search_the_web.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\nppl3260.dll FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-09-01] FF Extension: Avira Browser Safety - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\abs@avira.com [2015-02-02] FF Extension: GMX MailCheck - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\toolbar@gmx(75).net [2015-02-28] FF Extension: DownloadHelper - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-06] FF Extension: ProxTube - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-07-28] FF Extension: Adblock Plus - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-07-16] FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-07-11] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-27] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\extensions\cliqz@cliqz.com FF Extension: No Name - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\extensions\toolbar@gmx.net [Not Found] FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found] Chrome: ======= CHR Profile: C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browser Safety) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-10-20] CHR Extension: (RealDownloader) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-09-24] CHR Extension: (Google Wallet) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-24] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-04-16] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2013-07-12] () [File not signed] R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [992560 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3247120 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) S3 GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe [69120 2008-10-26] (Google) [File not signed] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2336072 2011-01-25] (O&O Software GmbH) R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] () R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [241734 2008-06-28] () [File not signed] S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2015-02-22] (TuneUp Software) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1050440 2010-04-01] (TuneUp Software) S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) [File not signed] R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2001-11-12] (X10) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [200984 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [189720 2014-10-24] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-29] (AVG Technologies CZ, s.r.o.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-14] (Avira Operations GmbH & Co. KG) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-29] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-19] (Avira Operations GmbH & Co. KG) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-03-02] (Malwarebytes Corporation) S3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1332576 2008-09-25] (NXP Semiconductors Germany GmbH) R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2013-07-12] (Padus, Inc.) [File not signed] S3 PhilCap; C:\Windows\System32\DRIVERS\PhilCap.sys [908896 2007-07-31] (NXP Semiconductors Germany GmbH) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13976 2006-11-17] (X10 Wireless Technology, Inc.) R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] U4 Msetapxe_n; No ImagePath S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-02 23:36 - 2015-03-02 23:36 - 00001086 _____ () C:\Users\Christian Rietz\Desktop\JRT.txt 2015-03-02 23:24 - 2015-03-02 23:24 - 00008115 _____ () C:\Users\Christian Rietz\Desktop\AdwCleaner[S3].txt 2015-03-02 23:07 - 2015-03-02 23:07 - 00000484 _____ () C:\Users\Christian Rietz\Desktop\mbam.txt 2015-03-02 22:47 - 2015-03-02 22:47 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-03-02 22:47 - 2015-03-02 22:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-03-02 22:47 - 2015-03-02 22:47 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2015-03-02 22:47 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-03-02 22:47 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-03-02 22:47 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-03-01 19:29 - 2015-03-01 19:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dll-Files Fixer 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\Documents\Eigene Google Gadgets 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Avg2014 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\AVG Web TuneUp 2015-03-01 18:17 - 2015-03-01 18:17 - 00118304 _____ () C:\Users\TEMP.Christian-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Apple Computer 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Wondershare 2015-03-01 18:16 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\VirtualStore 2015-03-01 18:16 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Google 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\RealNetworks 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Real 2015-03-01 18:15 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC 2015-03-01 18:15 - 2013-09-27 19:12 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Microsoft Help 2015-03-01 18:15 - 2013-09-26 20:06 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\TuneUp Software 2015-02-27 20:28 - 2015-02-27 20:30 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\Playmo-Zoo 2015-02-26 00:25 - 2015-02-26 00:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox(25) 2015-02-25 23:30 - 2015-02-26 00:45 - 106785426 _____ () C:\Users\Christian Rietz\Desktop\Looking S02E06 - Looking for Gordon Freeman.flv 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Skype 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Program Files\Skype(27) 2015-02-22 17:12 - 2015-02-22 17:12 - 00001869 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities.lnk 2015-02-22 17:12 - 2015-02-22 17:12 - 00001857 _____ () C:\Users\Public\Desktop\TuneUp Utilities.lnk 2015-02-22 17:12 - 2015-02-22 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2015-02-22 17:12 - 2010-04-01 15:17 - 00030536 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2015-02-22 17:12 - 2010-04-01 15:11 - 00030024 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2015-02-22 17:12 - 2010-04-01 15:11 - 00021320 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2015-02-22 17:11 - 2015-02-22 17:12 - 00000000 ____D () C:\Program Files\TuneUp Utilities 2010 2015-02-22 17:10 - 2015-02-22 17:10 - 00000000 __SHD () C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} 2015-02-22 16:59 - 2015-02-22 16:59 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\1 Tuneup Utilities 2015-02-22 13:37 - 2015-02-22 13:37 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\LOOKING for Season 2 2015-02-09 22:08 - 2015-02-09 22:09 - 00000000 ____D () C:\Program Files\QuickTime 2015-02-09 22:08 - 2015-02-09 22:08 - 00001730 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2015-02-09 22:08 - 2015-02-09 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2015-02-09 22:01 - 2015-02-09 22:03 - 42096984 _____ (Apple Inc.) C:\Users\Christian Rietz\Downloads\QuickTimeInstaller(1).exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-02 23:40 - 2013-07-16 20:05 - 00000000 ____D () C:\FRST 2015-03-02 23:40 - 2008-10-25 04:29 - 00000438 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job 2015-03-02 23:35 - 2013-07-11 17:09 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-02 23:27 - 2013-07-11 14:20 - 01683207 _____ () C:\Windows\WindowsUpdate.log 2015-03-02 23:27 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.dat 2015-03-02 23:27 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.001 2015-03-02 23:26 - 2014-02-03 20:53 - 00000000 ___RD () C:\Users\Christian Rietz\Dropbox 2015-03-02 23:25 - 2014-02-03 20:49 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Dropbox 2015-03-02 23:23 - 2013-07-11 17:09 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-02 23:23 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Home Cinema 2015-03-02 23:22 - 2008-01-21 03:47 - 00734022 _____ () C:\Windows\PFRO.log 2015-03-02 23:22 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-02 23:22 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-02 23:22 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-02 23:21 - 2006-11-02 14:01 - 00032540 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-03-02 23:20 - 2013-09-24 22:44 - 00000000 ____D () C:\AdwCleaner 2015-03-02 22:58 - 2013-10-06 11:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-03-02 22:48 - 2014-03-26 19:47 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-03-02 22:37 - 2013-07-11 14:24 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Google 2015-03-02 17:54 - 2013-09-10 21:42 - 00000000 ____D () C:\ProgramData\MFAData 2015-03-01 20:06 - 2014-04-17 18:10 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2015-03-01 20:06 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Skype 2015-03-01 20:06 - 2013-07-11 17:24 - 00000000 ___RD () C:\Users\Christian Rietz\Documents\Programme 2015-03-01 20:06 - 2013-07-11 17:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration 2015-03-01 18:52 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc 2015-03-01 18:50 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz 2015-03-01 18:50 - 2006-11-02 11:22 - 46661632 _____ () C:\Windows\system32\config\software_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 33554432 _____ () C:\Windows\system32\config\components_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 19660800 _____ () C:\Windows\system32\config\system_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\security_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\default_previous 2015-03-01 18:45 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-03-01 18:38 - 2015-01-26 20:32 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ___RD () C:\Program Files\Skype 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ____D () C:\Program Files\Common Files\Skype 2015-02-26 00:25 - 2013-09-25 21:57 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Skype 2015-02-22 17:10 - 2013-07-11 21:54 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-22 17:02 - 2006-11-02 11:33 - 01418794 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-22 16:16 - 2013-07-11 22:21 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\vlc 2015-02-22 13:20 - 2013-07-11 16:54 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Adobe 2015-02-22 13:20 - 2008-10-20 05:03 - 00000000 ____D () C:\ProgramData\Adobe 2015-02-19 19:07 - 2014-02-03 20:50 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-02-09 22:04 - 2013-07-11 21:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-02-09 22:04 - 2013-07-11 21:03 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-02-09 22:04 - 2013-07-11 21:02 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Adobe 2015-02-09 21:21 - 2014-08-14 20:25 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-09 21:21 - 2013-07-16 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-09 21:20 - 2013-07-16 20:21 - 00000000 ____D () C:\Program Files\Avira ==================== Files in the root of some directories ======= 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\StatusSheet 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\Stingers 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\String Comparison 2014-02-20 21:49 - 2014-02-20 21:49 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\System Image Utility 2014-03-26 19:46 - 2014-03-26 19:46 - 0000047 _____ () C:\Users\Christian Rietz\AppData\Roaming\WB.CFG 2013-08-02 19:34 - 2014-11-20 21:45 - 0001356 _____ () C:\Users\Christian Rietz\AppData\Local\d3d9caps.dat 2013-07-28 13:50 - 2015-01-25 21:05 - 0092672 _____ () C:\Users\Christian Rietz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2008-10-25 04:12 - 2015-03-02 23:27 - 0084921 _____ () C:\ProgramData\nvModes.001 2008-10-25 04:12 - 2015-03-02 23:27 - 0084921 _____ () C:\ProgramData\nvModes.dat 2014-02-20 21:49 - 2014-02-20 21:49 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT 2014-02-20 21:57 - 2014-02-20 22:12 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT 2014-02-20 21:53 - 2014-02-20 22:09 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\Strings 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\ProgramData\Super Strings 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\SupportPrinters Some content of TEMP: ==================== C:\Users\Christian Rietz\AppData\Local\Temp\avgnt.exe C:\Users\Christian Rietz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqja78w.dll C:\Users\Christian Rietz\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Christian Rietz\AppData\Local\Temp\Quarantine.exe C:\Users\Christian Rietz\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Christian Rietz\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-02 23:32 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-03-2015 Ran by Christian Rietz at 2015-03-02 23:41:31 Running from C:\Users\Christian Rietz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z8T9JQTC Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 4.42 (HKLM\...\7-Zip) (Version: - ) ACDSee 9 Foto-Manager (HKLM\...\{7AE25201-3E12-4FA2-9E65-67CD475D9263}) (Version: 9.0.55 - ACD Systems Ltd.) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Photoshop CS (HKLM\...\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}) (Version: CS - Adobe Systems, Inc.) Adobe Reader 9 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A90000000001}) (Version: 9.0.0 - Adobe Systems Incorporated) Adobe Shockwave Player 11 (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.) Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E14ADE0E-75F3-4A46-87E5-26692DD626EC}) (Version: 6.1.0.13 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArcSoft Panorama Maker 6 (HKLM\...\{DABFD34E-BE68-4BC6-9254-5D7A7FF76B99}) (Version: 6.0.8.85 - ArcSoft) AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4800 - AVG Technologies) AVG 2014 (Version: 14.0.3614 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4257 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4800 - AVG Technologies) Hidden AVG Web TuneUp (HKLM\...\AVG Web TuneUp) (Version: 3.2.0.18 - AVG Technologies) Avira (HKLM\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG) Avira (Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Avira SearchFree Toolbar plus Web Protection (HKLM\...\{41564952-412D-5637-00A7-A758B70C0201}) (Version: 12.2.1.477 - Ask Partner Network) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Corel Graphics Suite 11 (HKLM\...\InstallShield_{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}) (Version: 11 - Corel Corporation) Corel Graphics Suite 11 (Version: 11 - Corel Corporation) Hidden Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation) CorelDRAW Essential Edition 3 (HKLM\...\_{ADDBE07D-95B8-4789-9C76-187FFF9624B4}) (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) Hidden CyberLink MediaShow (HKLM\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 4.1.2019 - CyberLink Corp.) CyberLink PhotoNow (HKLM\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.5203 - CyberLink Corp.) CyberLink PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2209a - CyberLink Corp.) CyberLink PowerDVD (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 7.0.3118.0 - PowerDVDCorp.) CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0815 - CyberLink Corp.) CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.2109 - CyberLink Corp.) DE (Version: 3.0 - Corel Corporation) Hidden Dolby Control Center (HKLM\...\{70E8EBD5-78C9-4258-B20A-5098CCA000F0}) (Version: 1.1.0601 - Dolby) Dropbox (HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.) Free YouTube Download version 3.2.48.1015 (HKLM\...\Free YouTube Download_is1) (Version: 3.2.48.1015 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.48.1015 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.48.1015 - DVDVideoSoft Ltd.) Google Chrome (HKLM\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.) Google Desktop (HKLM\...\Google Desktop) (Version: - - Google) Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden iTunes (HKLM\...\{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}) (Version: 11.0.4.4 - Apple Inc.) Java(TM) 6 Update 7 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160070}) (Version: 1.6.0.70 - Sun Microsystems, Inc.) MAGIX Screenshare (HKLM\...\{A7B517E2-07EB-47BA-877B-3F174FB7760B}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM\...\{9D5B0618-2EFA-4DAA-9B53-A546992824EA}) (Version: 7.0.2.6 - MAGIX AG) MakeDisc (HKLM\...\{B145EC69-66F5-11D8-9D75-000129760D75}) (Version: 3.0.2601 - CyberLink Corp.) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 de) (HKLM\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon) Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.9.0 - Nikon) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) O&O Defrag Free Edition (HKLM\...\{E29CFB36-F070-4612-8DB5-7038161B6294}) (Version: 14.1.431 - O&O Software GmbH) Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.5.0 - Nikon) QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) RealDownloader (Version: 1.3.2 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5704 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: 3.0.1.3 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden Samplitude 11 Silver (HKLM\...\MAGIX_MSI_sam11silver) (Version: 11.0.1.0 - MAGIX AG) Samplitude 11 Silver (Version: 11.0.1.0 - MAGIX AG) Hidden Samplitude Music Studio 2008 Trial 14.0.2.0 (D) (HKLM\...\Samplitude Music Studio 2008 Trial D) (Version: 14.0.2.0 - MAGIX AG) Skype™ 6.7 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.7.102 - Skype Technologies S.A.) StreamTransport version: 1.1.6.1 (HKLM\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - ) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.2.2.0 - Synaptics) TuneUp Utilities (HKLM\...\TuneUp Utilities) (Version: 9.0.4100.12 - TuneUp Software) TuneUp Utilities (Version: 9.0.4100.12 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (Version: 9.0.4100.12 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update Manager (Version: 4.60 - Corel Corporation) Hidden VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.9.0 - Nikon) Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN) Windows Live Anmelde-Assistent (HKLM\...\{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}) (Version: 5.000.818.6 - Microsoft Corporation) Windows Live Fotogalerie (HKLM\...\{A1D08B90-AE1A-4885-AC29-731496FD397E}) (Version: 12.0.1347.0718 - Microsoft Corporation) Windows Live installer (HKLM\...\{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}) (Version: 12.0.1471.1025 - Microsoft Corporation) Windows Live Mail (HKLM\...\{82F2B38B-1426-443D-874C-AC25675E7BEB}) (Version: 12.0.1606.1023 - Microsoft Corporation) Windows Live Messenger (HKLM\...\{2B091530-69AA-442E-AB09-39ED06B58220}) (Version: 8.5.1302.1018 - Microsoft Corporation) Windows Live Writer (HKLM\...\{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5}) (Version: 12.0.1370.0325 - Microsoft Corporation) X10 Hardware(TM) (HKLM\...\X10Hardware) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Restore Points ========================= 25-02-2015 23:03:38 Removed Skype™ 6.7 01-03-2015 18:18:56 Wiederherstellungsvorgang 01-03-2015 19:14:16 Wiederherstellungsvorgang 01-03-2015 19:47:21 DLL-Files Fixer So, Mrz 01, 15 19:47 01-03-2015 20:02:59 Wiederherstellungsvorgang 02-03-2015 18:38:46 Geplanter Prüfpunkt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {2A6345ED-9E31-48E2-AAA9-1B8FE0162021} - System32\Tasks\Real Player-Online-Aktualisierungsprogramm => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-07-11] (RealNetworks, Inc.) Task: {55EEAAEB-9142-4D42-8386-DC56C99A5F5F} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {5C0ECDDC-2000-49E2-903C-6D50008CE73C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-09] (Adobe Systems Incorporated) Task: {635C392F-D422-40B8-99A5-4F0DD50828BD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.) Task: {76780D4E-1472-4D15-8F1D-33CC50612792} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {7BAB9B3A-24B1-4B7B-AE0D-22DE6589D5B2} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {932074F6-FEAE-4965-AE0E-62D04A8E95B4} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe [2013-04-16] (RealNetworks, Inc.) Task: {AC667962-B3FC-416F-B372-14A3F0B4107B} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe [2010-04-01] (TuneUp Software) Task: {C5C8E683-4485-4155-982B-47742639C45B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.) Task: {D3BD0A79-9FEB-4F90-B0F7-2E7DD23CE352} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {F4B5D53B-8440-415B-9719-9419C4D509F1} - System32\Tasks\Real Networks Scheduler => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-07-11] (RealNetworks, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job => C:\Windows\system32\msfeedssync.exe ==================== Loaded Modules (whitelisted) ============== 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2007-06-05 12:20 - 2007-06-05 12:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2013-04-16 02:07 - 2013-04-16 02:07 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe 2008-10-22 06:21 - 2008-06-28 01:00 - 00241734 _____ () C:\Program Files\CyberLink\Shared Files\RichVideo.exe 2015-01-19 12:03 - 2015-01-19 12:03 - 00245760 _____ () C:\Program Files\Avira\My Avira\System.ComponentModel.Composition.dll 2014-10-20 22:38 - 2014-08-05 09:22 - 01489408 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll 2014-10-20 22:38 - 2014-05-19 16:19 - 00137728 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00750080 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-03-02 23:25 - 2015-03-02 23:25 - 00043008 _____ () c:\Users\Christian Rietz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqja78w.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00047616 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\libEGL.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00865280 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00200704 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\system32\oobe\info\wallpaper1.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-209139463-1928718786-3223491114-500 - Administrator - Disabled) Christian Rietz (S-1-5-21-209139463-1928718786-3223491114-1000 - Administrator - Enabled) => C:\Users\Christian Rietz Gast (S-1-5-21-209139463-1928718786-3223491114-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= Error: (07/28/2013 02:06:52 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 9 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2015-03-02 23:41:18.652 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-02 23:41:18.574 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-02 23:41:18.496 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-02 23:41:18.418 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-02 23:41:18.075 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-02 23:41:17.997 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-02 23:41:17.904 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-02 23:41:17.826 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-02 23:40:55.689 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-02 23:40:55.611 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz Percentage of memory in use: 60% Total physical RAM: 2301.44 MB Available physical RAM: 898.57 MB Total Pagefile: 4833.9 MB Available Pagefile: 3111.99 MB Total Virtual: 2047.88 MB Available Virtual: 1922.07 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:141.25 GB) (Free:44.44 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:15.81 GB) (Free:4.4 GB) FAT32 Drive g: (Volume) (Fixed) (Total:141.01 GB) (Free:127.5 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: DAE4C35C) Partition 1: (Active) - (Size=141.3 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=141 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15.8 GB) - (Type=0C) ==================== End Of Log ============================ |
03.03.2015, 08:34 | #6 |
/// the machine /// TB-Ausbilder | COULDN'T LOAD XPCOM - Firefox startet nicht Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> COULDN'T LOAD XPCOM - Firefox startet nicht |
03.03.2015, 22:04 | #7 |
| COULDN'T LOAD XPCOM - Firefox startet nicht Hallo, ich habe Firefox mit dem Revo Uninstaller installiert, aber verstehe nicht, was du mit "Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen" meinst, da der Firefox sich ja nicht mehr auf dem Rechner befindet! Ich kann da nichts zurücksetzen! Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=e5bdb5ac0354f248896ade1b7ff0ba07 # engine=22737 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-03-03 08:49:21 # local_time=2015-03-03 09:49:21 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.0.6001 NT Service Pack 1 # compatibility_mode_1='AVG AntiVirus Free Edition 2014' # compatibility_mode=1051 16777213 100 93 3720958 50048535 0 0 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 7730 51413519 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 50734002 262948489 0 0 # scanned=184426 # found=32 # cleaned=32 # scan_time=5681 sh=34622C0C9B0F72AB2F67AE3BD7CF94EF76B2B54D ft=1 fh=422f90d5b5335443 vn="Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\delta\delta\1.8.24.6\deltaApp.dll.vir" sh=80C8F13A1918FAEEAB9673C1CCF96E52325EE695 ft=1 fh=0aefb751d92be997 vn="Variante von Win32/Toolbar.Montiera.U evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\delta\delta\1.8.24.6\deltaEng.dll.vir" sh=4400797578E17E511E6164469770A80E828DDA3A ft=1 fh=56dbbea16253a143 vn="Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\delta\delta\1.8.24.6\deltasrv.exe.vir" sh=610CDC3A03DA21A83EB90193BACF1347AAA39A0F ft=1 fh=6544723ffe1f3f66 vn="Variante von Win32/Toolbar.Montiera.F evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\delta\delta\1.8.24.6\deltaTlbr.dll.vir" sh=AFD5B25F86CFD3045CCFF940A249A1DA89DEDE5D ft=1 fh=c55a3c08e5709f9a vn="Win32/Toolbar.Montiera.B evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\delta\delta\1.8.24.6\uninstall.exe.vir" sh=66AE7973E507FF0471DECFFF3BF7FFD40EA4D00D ft=1 fh=1b697967a44eb4e0 vn="Variante von Win32/Toolbar.Escort.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\delta\delta\1.8.24.6\bh\delta.dll.vir" sh=75DE1AA38FBBCC5BEF2AB69EA42CBFCC392308CD ft=1 fh=3aaadc3bc1e3d2d5 vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Dll-Files.com Fixer\DLLFixer.exe.vir" sh=D6A5DC7A4B717224CC176094F60D61086E4733DC ft=1 fh=b7e2079953f7b9d4 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\CltMngSvc.exe.vir" sh=0235B5E13704F2A1B3BC3D137D79ADDA89FE1B86 ft=1 fh=361f43e80eb2f2cf vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\SPTool.dll.vir" sh=BB3752D2131C964718E918AEB456F2A20F9C3D56 ft=1 fh=a8d087ddbacdd236 vn="Win32/Conduit.SearchProtect.Q evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\uninstall.exe.vir" sh=D493FF871C74B06FB61AE00D09ADDC28B5422F80 ft=1 fh=a6346613b831fe49 vn="Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe.vir" sh=4C5B9BDB2083C372DFF084BAEFE4A34E773C3335 ft=1 fh=65740079bac0d1d2 vn="Variante von Win64/Conduit.SearchProtect.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\SPTool64.exe.vir" sh=8C20259C7435390185EA2E2CA9E0B8F06ADE36AB ft=1 fh=62fc332d4a4d02fc vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\SPVC32.dll.vir" sh=12B7DD7ED27BA706CC32A3EA2BDD2E4E16A22E11 ft=1 fh=9bbbc70f0dbb4fe4 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\SPVC32Loader.dll.vir" sh=BEAF3026FE73CCDF7E3981D93E5207A0E5057BD2 ft=1 fh=44ac08ee4120e3f7 vn="Variante von Win64/Conduit.SearchProtect.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir" sh=7DC19763FCFB8BE9846DD4405485A92AA3E50163 ft=1 fh=f4eca9bc8299d3bc vn="Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\UI\bin\cltmngui.exe.vir" sh=B1CC1BBCD9FE490869E78FFA57CBBF7ABCB5CB24 ft=0 fh=0000000000000000 vn="JS/OfferMosquito.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\0.5_0\offermosquito.js.vir" sh=16068B8977B4DC562AE782D91BC009472667E331 ft=1 fh=c3b5a87b7d152749 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Christian Rietz\AppData\Local\Temp\OCS\ocs_v71a.exe.vir" sh=1549CF4F9282F1B42A58B5E050E12EF0AD669798 ft=1 fh=ffe6693d8bc7d6c5 vn="Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Christian Rietz\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir" sh=7331DA1665EC65944AE668DDB0B0B60C25B17733 ft=1 fh=a4d6195669612fcc vn="Variante von Win32/Toolbar.Babylon.W evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Christian Rietz\AppData\Roaming\BabSolution\Shared\enhancedNT.dll.vir" sh=F66F477B53B39DF2C2C561D4AF1C7C8F87C89046 ft=1 fh=d0f38e5e390c9502 vn="Win32/Toolbar.Montiera.B evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\Extensions\ffxtlbr@delta.com\uninstall.exe.vir" sh=37CCAD86409E08816A4C00F1DBEA4604BA36D3A1 ft=1 fh=919a9505016e0e1e vn="Variante von Win32/Toolbar.Babylon.F evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Christian Rietz\AppData\Roaming\OpenCandy\42AC881364EE447F850BA5C108B8E0FC\DeltaTB.exe.vir" sh=843DF0FD9F9C356D5336452FCC2B3374A2BD06DC ft=1 fh=137ef7008edb618f vn="Win32/Toolbar.Conduit.R evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Christian Rietz\AppData\Roaming\OpenCandy\5C4FDA590F684F87AF6029D47DAFE48E\SSStub_SearchProtect_p1v0.exe.vir" sh=476063885747EDD774A6B8CB2790703503A75A55 ft=1 fh=d7bb79193adaee2e vn="Win32/Systweak.G evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Christian Rietz\AppData\Roaming\Systweak\ssd\SSDPTstub.exe.vir" sh=F75F81FD857FD42839BC3051B67B36E339BBD360 ft=1 fh=54ff0f72c0ee6a19 vn="Variante von Win32/Systweak.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Windows\System32\roboot.exe.vir" sh=4FCBF0CFC895212752F223C652C6FF2BE4211EBB ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.PBD Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\Christian Rietz\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\38b6c00-580856b5" sh=BB1F1AD5EFFE1AF9B35552E88261677B9A9E79E7 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.PBU Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\Christian Rietz\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\18a55bd4-6736fd4b" sh=6E8FDAC4C60E167A411C5D2C8CC51346B16EDA0A ft=1 fh=3324afa619144b0d vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Christian Rietz\Downloads\Net Transport 32 Bit - CHIP-Installer.exe" sh=EDDAF9B9ADD2CB80078B0176A84D0592C54D2C86 ft=1 fh=73eed34924432772 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Christian Rietz\Downloads\StreamTransport - CHIP-Installer.exe" sh=E18B5242B0C893DF09E34A9E89DE551503F31591 ft=1 fh=5a1a58d6d884f372 vn="Win32/Somoto.Q evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Christian Rietz\Downloads\streamtransport_setup.exe" sh=075478ED256C74207FB1540F41BE4934B47D549B ft=1 fh=5a1a58d6a5023955 vn="Win32/Somoto.Q evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Christian Rietz\Downloads\streamtransport_1.1.6.2\streamtransport_chrome_setup1.1.6.2.exe" sh=E18B5242B0C893DF09E34A9E89DE551503F31591 ft=1 fh=5a1a58d6d884f372 vn="Win32/Somoto.Q evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Christian Rietz\Downloads\streamtransport_1.1.6.2\Streamtransport IE10\streamtransport_setup.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.96 Windows Vista Service Pack 1 x86 (UAC is enabled) Out of date service pack!! ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop AVG AntiVirus Free Edition 2014 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` AVG Web TuneUp TuneUp Utilities TuneUp Utilities Language Pack (de-DE) TuneUp Utilities Java(TM) 6 Update 7 Java version 32-bit out of Date! Java 64-bit 8 Update 31 Adobe Flash Player 16.0.0.305 Adobe Reader 9 Adobe Reader out of Date! Google Chrome (40.0.2214.111) Google Chrome (40.0.2214.115) ````````Process Check: objlist.exe by Laurent```````` AVG avgwdsvc.exe AVG avgrsx.exe AVG avgemc.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
04.03.2015, 08:54 | #8 |
/// the machine /// TB-Ausbilder | COULDN'T LOAD XPCOM - Firefox startet nicht Dann lies den Part mit Firefox und Revo nochmal, da steht am Ende Firefox dann neu installieren
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.03.2015, 17:35 | #9 |
| COULDN'T LOAD XPCOM - Firefox startet nicht Ok, mache ich. Muss ich die anderen schritte dann erneut durchführen? firefox läuft nämlich wieder.... Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=e5bdb5ac0354f248896ade1b7ff0ba07 # engine=22749 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-03-04 04:08:05 # local_time=2015-03-04 05:08:05 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.0.6001 NT Service Pack 1 # compatibility_mode_1='AVG AntiVirus Free Edition 2014' # compatibility_mode=1051 16777213 100 93 3790482 50118059 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 50803526 263018013 0 0 # scanned=188952 # found=2 # cleaned=0 # scan_time=11555 sh=4FB10415B81B03D51DB12E524C8FD767555C8DE1 ft=0 fh=0000000000000000 vn="JS/OfferMosquito.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\om@offermosquito.com.xpi" sh=F346D91A2E5F5FBEFF8F19023463F079E6E89B7A ft=0 fh=0000000000000000 vn="Win32/Somoto.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian Rietz\Downloads\streamtransport_1.1.6.2.zip" Code:
ATTFilter Results of screen317's Security Check version 0.99.96 Windows Vista Service Pack 1 x86 (UAC is enabled) Out of date service pack!! ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop AVG AntiVirus Free Edition 2014 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` AVG Web TuneUp TuneUp Utilities TuneUp Utilities Language Pack (de-DE) TuneUp Utilities Java(TM) 6 Update 7 Java version 32-bit out of Date! Java 64-bit 8 Update 31 Adobe Flash Player 16.0.0.305 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (36.0) Google Chrome (40.0.2214.111) Google Chrome (40.0.2214.115) ````````Process Check: objlist.exe by Laurent```````` AVG avgwdsvc.exe AVG avgrsx.exe AVG avgemc.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-03-2015 Ran by Christian Rietz (administrator) on CHRISTIAN-PC on 04-03-2015 17:34:15 Running from C:\Users\Christian Rietz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RCNZL02F Loaded Profiles: Christian Rietz (Available profiles: Christian Rietz) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PSIService.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (X10) C:\Program Files\Common Files\X10\Common\X10nets.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (ACD Systems, Ltd.) C:\Program Files\Common Files\ACD Systems\DE\DevDetect.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodtray.exe (Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Dropbox, Inc.) C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\Program Files\Internet Explorer\ieuser.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (RealNetworks, Inc.) C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_16_0_0_305_ActiveX.exe (Farbar) C:\Users\Christian Rietz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RCNZL02F\FRST[1].exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512 2008-01-04] (Synaptics, Inc.) HKLM\...\Run: [UpdatePDRShortCut] => C:\Program Files\HomeCinema\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM\...\Run: [RemoteControl] => C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe [71216 2007-02-09] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] => C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe [52256 2007-01-08] () HKLM\...\Run: [UpdatePPShortCut] => C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe [222504 2008-02-21] (CyberLink Corp.) HKLM\...\Run: [UCam_Menu] => C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6294048 2008-09-18] (Realtek Semiconductor) HKLM\...\Run: [Google Desktop Search] => C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [220160 2008-10-26] (Google) HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [Device Detector] => DevDetect.exe -autorun HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703280 2015-03-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5188112 2014-12-16] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation) HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe [2729800 2011-01-25] (O&O Software GmbH) HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-08-05] (Wondershare) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-11] (Google Inc.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ISUSPM] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) AppInit_DLLs: c:\docume~1\ settings\all users\application D즸粖㛉ࠀᖰAA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-209139463-1928718786-3223491114-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll (Google Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-209139463-1928718786-3223491114-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\p2be4a2p.default-1425473419208 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Extension: DownloadHelper - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\p2be4a2p.default-1425473419208\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2015-03-04] FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-07-11] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-27] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\extensions\cliqz@cliqz.com Chrome: ======= CHR Profile: C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browser Safety) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-10-20] CHR Extension: (RealDownloader) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-09-24] CHR Extension: (Google Wallet) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-24] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-04-16] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2013-07-12] () [File not signed] R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2015-03-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-04] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [992504 2015-03-04] (Avira Operations GmbH & Co. KG) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3247120 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) S3 GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe [69120 2008-10-26] (Google) [File not signed] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2336072 2011-01-25] (O&O Software GmbH) R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] () R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [241734 2008-06-28] () [File not signed] S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2015-02-22] (TuneUp Software) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1050440 2010-04-01] (TuneUp Software) S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) [File not signed] R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2001-11-12] (X10) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [200984 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [189720 2014-10-24] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-29] (AVG Technologies CZ, s.r.o.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-04] (Avira Operations GmbH & Co. KG) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-29] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-19] (Avira Operations GmbH & Co. KG) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-03-02] (Malwarebytes Corporation) S3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1332576 2008-09-25] (NXP Semiconductors Germany GmbH) R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2013-07-12] (Padus, Inc.) [File not signed] S3 PhilCap; C:\Windows\System32\DRIVERS\PhilCap.sys [908896 2007-07-31] (NXP Semiconductors Germany GmbH) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13976 2006-11-17] (X10 Wireless Technology, Inc.) R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] U4 Msetapxe_n; No ImagePath S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-04 13:51 - 2015-03-04 13:51 - 02347384 _____ (ESET) C:\Users\Christian Rietz\Desktop\esetsmartinstaller_deu.exe 2015-03-04 13:44 - 2015-03-04 13:44 - 00000862 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-03-04 13:44 - 2015-03-04 13:44 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-03-03 22:32 - 2015-03-03 22:32 - 06723986 _____ () C:\Users\Christian Rietz\Desktop\Geburtstagsvideo-von-Heiko.mov 2015-03-03 21:57 - 2015-03-03 21:57 - 00852594 _____ () C:\Users\Christian Rietz\Desktop\SecurityCheck.exe 2015-03-03 19:53 - 2015-03-03 19:53 - 00001061 _____ () C:\Users\Christian Rietz\Desktop\Revo Uninstaller.lnk 2015-03-03 19:53 - 2015-03-03 19:53 - 00000000 ____D () C:\Program Files\VS Revo Group 2015-03-02 23:50 - 2015-03-02 23:50 - 10196653 _____ () C:\Users\Christian Rietz\Desktop\ChristianHBDklein.m4v 2015-03-02 23:36 - 2015-03-02 23:36 - 00001086 _____ () C:\Users\Christian Rietz\Desktop\JRT.txt 2015-03-02 23:24 - 2015-03-02 23:24 - 00008115 _____ () C:\Users\Christian Rietz\Desktop\AdwCleaner[S3].txt 2015-03-02 23:07 - 2015-03-02 23:07 - 00000484 _____ () C:\Users\Christian Rietz\Desktop\mbam.txt 2015-03-02 22:47 - 2015-03-02 22:47 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-03-02 22:47 - 2015-03-02 22:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-03-02 22:47 - 2015-03-02 22:47 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2015-03-02 22:47 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-03-02 22:47 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-03-02 22:47 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\Documents\Eigene Google Gadgets 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Avg2014 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\AVG Web TuneUp 2015-03-01 18:17 - 2015-03-01 18:17 - 00118304 _____ () C:\Users\TEMP.Christian-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Apple Computer 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Wondershare 2015-03-01 18:16 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\VirtualStore 2015-03-01 18:16 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Google 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\RealNetworks 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Real 2015-03-01 18:15 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC 2015-03-01 18:15 - 2013-09-27 19:12 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Microsoft Help 2015-03-01 18:15 - 2013-09-26 20:06 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\TuneUp Software 2015-02-27 20:28 - 2015-03-04 15:03 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\Playmo-Zoo 2015-02-26 00:25 - 2015-02-26 00:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox(25) 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Skype 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Program Files\Skype(27) 2015-02-22 17:12 - 2015-02-22 17:12 - 00001869 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities.lnk 2015-02-22 17:12 - 2015-02-22 17:12 - 00001857 _____ () C:\Users\Public\Desktop\TuneUp Utilities.lnk 2015-02-22 17:12 - 2015-02-22 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2015-02-22 17:12 - 2010-04-01 15:17 - 00030536 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2015-02-22 17:12 - 2010-04-01 15:11 - 00030024 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2015-02-22 17:12 - 2010-04-01 15:11 - 00021320 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2015-02-22 17:11 - 2015-02-22 17:12 - 00000000 ____D () C:\Program Files\TuneUp Utilities 2010 2015-02-22 17:10 - 2015-02-22 17:10 - 00000000 __SHD () C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} 2015-02-22 16:59 - 2015-02-22 16:59 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\1 Tuneup Utilities 2015-02-22 13:37 - 2015-03-04 14:59 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\LOOKING for Season 2 2015-02-09 22:08 - 2015-02-09 22:09 - 00000000 ____D () C:\Program Files\QuickTime 2015-02-09 22:08 - 2015-02-09 22:08 - 00001730 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2015-02-09 22:08 - 2015-02-09 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2015-02-09 22:01 - 2015-02-09 22:03 - 42096984 _____ (Apple Inc.) C:\Users\Christian Rietz\Downloads\QuickTimeInstaller(1).exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-04 17:34 - 2013-07-16 20:05 - 00000000 ____D () C:\FRST 2015-03-04 17:30 - 2008-10-25 04:29 - 00000438 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job 2015-03-04 17:26 - 2013-09-10 21:42 - 00000000 ____D () C:\ProgramData\MFAData 2015-03-04 17:00 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-04 17:00 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-04 16:58 - 2013-10-06 11:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-03-04 16:35 - 2013-07-11 17:09 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-04 14:59 - 2013-07-11 22:21 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\vlc 2015-03-04 14:43 - 2013-07-11 14:20 - 01709040 _____ () C:\Windows\WindowsUpdate.log 2015-03-04 13:44 - 2013-07-11 17:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-03-04 13:42 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.dat 2015-03-04 13:42 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.001 2015-03-04 13:36 - 2013-07-11 16:54 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Adobe 2015-03-04 13:36 - 2008-10-20 05:03 - 00000000 ____D () C:\ProgramData\Adobe 2015-03-04 13:06 - 2013-07-16 20:21 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-03-04 13:06 - 2013-07-16 20:21 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-03-04 13:02 - 2014-02-03 20:53 - 00000000 ___RD () C:\Users\Christian Rietz\Dropbox 2015-03-04 13:02 - 2014-02-03 20:49 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Dropbox 2015-03-04 13:00 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Home Cinema 2015-03-04 12:59 - 2013-07-11 17:09 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-04 12:59 - 2008-01-21 03:47 - 00734812 _____ () C:\Windows\PFRO.log 2015-03-04 12:59 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-03 22:53 - 2006-11-02 14:01 - 00032540 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-03-03 21:47 - 2014-10-20 23:22 - 00000000 ____D () C:\Users\Christian Rietz\Downloads\streamtransport_1.1.6.2 2015-03-02 23:20 - 2013-09-24 22:44 - 00000000 ____D () C:\AdwCleaner 2015-03-02 22:48 - 2014-03-26 19:47 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-03-02 22:37 - 2013-07-11 14:24 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Google 2015-03-01 20:06 - 2014-04-17 18:10 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2015-03-01 20:06 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Skype 2015-03-01 20:06 - 2013-07-11 17:24 - 00000000 ___RD () C:\Users\Christian Rietz\Documents\Programme 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration 2015-03-01 18:52 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc 2015-03-01 18:50 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz 2015-03-01 18:50 - 2006-11-02 11:22 - 46661632 _____ () C:\Windows\system32\config\software_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 33554432 _____ () C:\Windows\system32\config\components_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 19660800 _____ () C:\Windows\system32\config\system_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\security_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\default_previous 2015-03-01 18:45 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ___RD () C:\Program Files\Skype 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ____D () C:\Program Files\Common Files\Skype 2015-02-26 00:25 - 2013-09-25 21:57 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Skype 2015-02-22 17:10 - 2013-07-11 21:54 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-22 17:02 - 2006-11-02 11:33 - 01418794 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-19 19:07 - 2014-02-03 20:50 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-02-09 22:04 - 2013-07-11 21:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-02-09 22:04 - 2013-07-11 21:03 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-02-09 22:04 - 2013-07-11 21:02 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Adobe 2015-02-09 21:21 - 2014-08-14 20:25 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-09 21:21 - 2013-07-16 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-09 21:20 - 2013-07-16 20:21 - 00000000 ____D () C:\Program Files\Avira ==================== Files in the root of some directories ======= 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\StatusSheet 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\Stingers 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\String Comparison 2014-02-20 21:49 - 2014-02-20 21:49 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\System Image Utility 2014-03-26 19:46 - 2014-03-26 19:46 - 0000047 _____ () C:\Users\Christian Rietz\AppData\Roaming\WB.CFG 2013-08-02 19:34 - 2014-11-20 21:45 - 0001356 _____ () C:\Users\Christian Rietz\AppData\Local\d3d9caps.dat 2013-07-28 13:50 - 2015-01-25 21:05 - 0092672 _____ () C:\Users\Christian Rietz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2008-10-25 04:12 - 2015-03-04 13:42 - 0084921 _____ () C:\ProgramData\nvModes.001 2008-10-25 04:12 - 2015-03-04 13:42 - 0084921 _____ () C:\ProgramData\nvModes.dat 2014-02-20 21:49 - 2014-02-20 21:49 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT 2014-02-20 21:57 - 2014-02-20 22:12 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT 2014-02-20 21:53 - 2014-02-20 22:09 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\Strings 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\ProgramData\Super Strings 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\SupportPrinters Some content of TEMP: ==================== C:\Users\Christian Rietz\AppData\Local\Temp\avgnt.exe C:\Users\Christian Rietz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpzgpp7q.dll C:\Users\Christian Rietz\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Christian Rietz\AppData\Local\Temp\Quarantine.exe C:\Users\Christian Rietz\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Christian Rietz\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-04 13:06 ==================== End Of Log ============================ --- --- --- |
05.03.2015, 07:02 | #10 |
/// the machine /// TB-Ausbilder | COULDN'T LOAD XPCOM - Firefox startet nicht Java und Adobe updaten. Windows updaten, da fehlen 5 Jahre Updates inklusive Servicepack 2! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter AppInit_DLLs: c:\docume~1\ settings\all users\application D즸粖㛉ࠀᖰAA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.03.2015, 19:41 | #11 |
| COULDN'T LOAD XPCOM - Firefox startet nichtCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-03-2015 Ran by Christian Rietz at 2015-03-05 19:24:02 Run:3 Running from C:\Users\Christian Rietz\Desktop Loaded Profiles: Christian Rietz (Available profiles: Christian Rietz) Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs: c:\docume~1\ settings\all users\application D?????AA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Emptytemp: ***************** "c:\docume~1\ settings\all users\application D?????AA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL" => Value Data not found. EmptyTemp: => Removed 1.8 GB temporary data. The system needed a reboot. ==== End of Fixlog 19:28:03 ==== Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-03-2015 Ran by Christian Rietz (administrator) on CHRISTIAN-PC on 05-03-2015 19:35:26 Running from C:\Users\Christian Rietz\Desktop Loaded Profiles: Christian Rietz (Available profiles: Christian Rietz) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PSIService.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (X10) C:\Program Files\Common Files\X10\Common\X10nets.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (ACD Systems, Ltd.) C:\Program Files\Common Files\ACD Systems\DE\DevDetect.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodtray.exe (Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Dropbox, Inc.) C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512 2008-01-04] (Synaptics, Inc.) HKLM\...\Run: [UpdatePDRShortCut] => C:\Program Files\HomeCinema\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM\...\Run: [RemoteControl] => C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe [71216 2007-02-09] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] => C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe [52256 2007-01-08] () HKLM\...\Run: [UpdatePPShortCut] => C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe [222504 2008-02-21] (CyberLink Corp.) HKLM\...\Run: [UCam_Menu] => C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6294048 2008-09-18] (Realtek Semiconductor) HKLM\...\Run: [Google Desktop Search] => C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [220160 2008-10-26] (Google) HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [Device Detector] => DevDetect.exe -autorun HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703280 2015-03-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5188112 2014-12-16] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation) HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe [2729800 2011-01-25] (O&O Software GmbH) HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-08-05] (Wondershare) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [127792 2015-02-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [SunJavaUpdateSched] => "C:\Program Files\Java\jre1.8.0_40\bin\jusched.exe" HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-11] (Google Inc.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ISUSPM] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) AppInit_DLLs: c:\docume~1\ settings\all users\application D즸粖㛉ࠀᖰAA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-209139463-1928718786-3223491114-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll (Oracle Corporation) BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-209139463-1928718786-3223491114-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_40-windows-i586.cab DPF: {CAFEEFAC-0018-0000-0040-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_40-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_40-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\p2be4a2p.default-1425473419208 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Extension: DownloadHelper - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\p2be4a2p.default-1425473419208\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2015-03-04] FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-07-11] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-27] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\extensions\cliqz@cliqz.com Chrome: ======= CHR Profile: C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browser Safety) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-10-20] CHR Extension: (RealDownloader) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-09-24] CHR Extension: (Google Wallet) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-24] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-04-16] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2013-07-12] () [File not signed] R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2015-03-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-04] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [992504 2015-03-04] (Avira Operations GmbH & Co. KG) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3247120 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [184056 2015-02-12] (Avira Operations GmbH & Co. KG) S3 GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe [69120 2008-10-26] (Google) [File not signed] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2336072 2011-01-25] (O&O Software GmbH) R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] () R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [241734 2008-06-28] () [File not signed] S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2015-02-22] (TuneUp Software) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1050440 2010-04-01] (TuneUp Software) S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) [File not signed] R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2001-11-12] (X10) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [200984 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [189720 2014-10-24] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-29] (AVG Technologies CZ, s.r.o.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-04] (Avira Operations GmbH & Co. KG) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-29] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-19] (Avira Operations GmbH & Co. KG) S3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1332576 2008-09-25] (NXP Semiconductors Germany GmbH) R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2013-07-12] (Padus, Inc.) [File not signed] S3 PhilCap; C:\Windows\System32\DRIVERS\PhilCap.sys [908896 2007-07-31] (NXP Semiconductors Germany GmbH) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13976 2006-11-17] (X10 Wireless Technology, Inc.) R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] U4 Msetapxe_n; No ImagePath S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-05 19:35 - 2015-03-05 19:37 - 00024242 _____ () C:\Users\Christian Rietz\Desktop\FRST.txt 2015-03-05 19:22 - 2015-03-05 19:22 - 01132544 _____ (Farbar) C:\Users\Christian Rietz\Desktop\FRST.exe 2015-03-05 19:14 - 2015-03-05 19:14 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Oracle 2015-03-05 18:41 - 2015-03-05 18:44 - 00000000 ____D () C:\Windows\system32\ca-ES 2015-03-05 18:41 - 2015-03-05 18:43 - 00000000 ____D () C:\Windows\system32\vi-VN 2015-03-05 18:41 - 2015-03-05 18:43 - 00000000 ____D () C:\Windows\system32\eu-ES 2015-03-05 18:41 - 2015-03-05 18:41 - 00000000 ____D () C:\Windows\nvtmpinst 2015-03-05 18:34 - 2015-03-05 18:34 - 00000000 ____D () C:\Windows\system32\SPReview 2015-03-05 18:11 - 2009-04-10 23:28 - 00928768 _____ (Microsoft Corporation) C:\Windows\system32\scavenge.dll 2015-03-05 18:11 - 2009-04-10 23:27 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\compcln.exe 2015-03-05 18:10 - 2009-04-10 23:32 - 01083880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00265688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00190424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00149480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00141288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00099816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2015-03-05 18:10 - 2009-04-10 23:32 - 00054248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00053736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00050664 _____ (Microsoft Corporation) C:\Windows\system32\PSHED.DLL 2015-03-05 18:10 - 2009-04-10 23:32 - 00035304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00027624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Dumpata.sys 2015-03-05 18:10 - 2009-04-10 23:28 - 02515968 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 02153472 _____ (Microsoft Corporation) C:\Windows\system32\oobefldr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 02134528 _____ (Microsoft Corporation) C:\Windows\system32\FunctionDiscoveryFolder.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01985024 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01823744 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01730560 _____ (Microsoft Corporation) C:\Windows\system32\apds.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01645568 _____ (Microsoft Corporation) C:\Windows\system32\connect.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01591296 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01541120 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01459200 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01342464 _____ (Microsoft Corporation) C:\Windows\system32\brcpl.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01324032 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayCpl.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01209856 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01107968 _____ (Microsoft Corporation) C:\Windows\system32\pidgenx.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01078784 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00978432 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00950784 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00869888 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00825856 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\powercpl.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00644608 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\rasgcw.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00612864 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2015-03-05 18:10 - 2009-04-10 23:28 - 00593408 _____ (Microsoft Corporation) C:\Windows\system32\comuid.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00551936 _____ (Microsoft Corporation) C:\Windows\system32\prnntfy.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00550400 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00542720 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\pnpui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00516608 _____ (Microsoft Corporation) C:\Windows\system32\autoplay.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00476672 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00472064 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00466944 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00464384 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\IasMigReader.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00454144 _____ (Microsoft) C:\Windows\system32\IasMigPlugin.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\dsound.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00441344 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00425472 _____ (Microsoft Corporation) C:\Windows\system32\PhotoMetadataHandler.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\devmgr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\rasplap.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\RelMon.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00334848 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2015-03-05 18:10 - 2009-04-10 23:28 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\P2PGraph.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\sdohlp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00306176 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\QAGENTRT.DLL 2015-03-05 18:10 - 2009-04-10 23:28 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00286720 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\es.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\scansetting.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\adsldpc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\offfilt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\pnpsetup.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceTypes.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\rasmontr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\fundisc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iasnap.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\fontext.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\dsprop.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\nlhtml.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\extmgr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\ntmarta.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\EhStorAPI.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00117248 _____ () C:\Windows\system32\EhStorAuthn.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayDriverLib.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\EhStorShell.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\regsvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\dmsynth.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayServices.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\dmusic.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\powrprof.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\oleprn.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\SCardSvr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceClassExtension.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\fdBth.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\propdefs.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\iashlpr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\sendmail.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\PNPXAssoc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\fdSSDP.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\fdWSD.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\iasads.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\feclient.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\dot3cfg.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\iasdatastore.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\bthci.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\rtffilt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\EhStorPwdMgr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\perfdisk.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\bitsigd.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelineprxy.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\hidserv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\fdProxy.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\fdBthProxy.dll 2015-03-05 18:10 - 2009-04-10 23:27 - 02926592 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 02092544 _____ (Microsoft Corporation) C:\Windows\system32\dfsr.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 01122304 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl 2015-03-05 18:10 - 2009-04-10 23:27 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr 2015-03-05 18:10 - 2009-04-10 23:27 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelinesvc.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00636416 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00518144 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00407040 _____ (Microsoft Corporation) C:\Windows\system32\dpapimig.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00241128 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll 2015-03-05 18:10 - 2009-04-10 23:27 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\diskraid.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2015-03-05 18:10 - 2009-04-10 23:27 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\eudcedit.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\PresentationSettings.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00130024 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll 2015-03-05 18:10 - 2009-04-10 23:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\gpresult.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\nslookup.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\dwm.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\hdwwiz.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\conime.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\reg.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\findstr.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\PnPUnattend.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\rekeywiz.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\ocsetup.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\PnPutil.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\fc.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\rasdial.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\gpupdate.exe 2015-03-05 18:10 - 2009-04-10 23:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime 2015-03-05 18:10 - 2009-04-10 23:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime 2015-03-05 18:10 - 2009-04-10 23:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime 2015-03-05 18:10 - 2009-04-10 23:23 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime 2015-03-05 18:10 - 2009-04-10 23:22 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\f3ahvoas.dll 2015-03-05 18:10 - 2009-04-10 22:42 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys 2015-03-05 18:10 - 2009-04-10 22:03 - 12240896 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0007.dll 2015-03-05 18:10 - 2009-04-10 22:03 - 02644480 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0009.dll 2015-03-05 18:10 - 2009-04-10 21:51 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2015-03-05 18:10 - 2009-04-10 21:48 - 00344698 _____ () C:\Windows\system32\eaphost.tmf 2015-03-05 18:10 - 2009-04-10 21:46 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rassstp.sys 2015-03-05 18:10 - 2009-04-10 21:46 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\raspppoe.sys 2015-03-05 18:10 - 2009-04-10 21:46 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2015-03-05 18:10 - 2009-04-10 21:45 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-03-05 18:10 - 2009-04-10 21:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys 2015-03-05 18:10 - 2009-04-10 21:43 - 00442788 _____ () C:\Windows\system32\dot3.tmf 2015-03-05 18:10 - 2009-04-10 21:43 - 00392170 _____ () C:\Windows\system32\onex.tmf 2015-03-05 18:10 - 2009-04-10 21:43 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2015-03-05 18:10 - 2009-04-10 21:42 - 00561152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys 2015-03-05 18:10 - 2009-04-10 21:42 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2015-03-05 18:10 - 2009-04-10 21:42 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2015-03-05 18:10 - 2009-04-10 21:42 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys 2015-03-05 18:10 - 2009-04-10 21:39 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2015-03-05 18:10 - 2009-04-10 21:23 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2015-03-05 18:10 - 2009-04-10 21:23 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxg.sys 2015-03-05 18:10 - 2009-04-10 21:14 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2015-03-05 18:10 - 2009-04-10 21:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\npfs.sys 2015-03-05 18:10 - 2009-04-10 21:13 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2015-03-05 18:10 - 2009-04-10 21:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys 2015-03-05 18:10 - 2009-04-10 21:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-03-05 18:10 - 2009-02-19 17:20 - 00009212 _____ () C:\Windows\system32\RacUR.xml 2015-03-05 18:10 - 2009-02-18 11:39 - 00779136 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2015-03-05 18:10 - 2009-02-18 11:39 - 00102816 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-03-05 18:09 - 2009-04-10 23:33 - 00614376 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2015-03-05 18:09 - 2009-04-10 23:32 - 00527848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00438744 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll 2015-03-05 18:09 - 2009-04-10 23:32 - 00245736 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00223208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00180712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00161752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00125928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00048104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mup.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00019944 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2015-03-05 18:09 - 2009-04-10 23:32 - 00017896 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2015-03-05 18:09 - 2009-04-10 23:32 - 00017384 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 06103040 _____ (Microsoft Corporation) C:\Windows\system32\chtbrkr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 03174400 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 03072000 _____ (Microsoft Corporation) C:\Windows\system32\networkmap.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02226688 _____ (Microsoft Corporation) C:\Windows\system32\networkexplorer.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02225664 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02167808 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02012160 _____ (Microsoft Corporation) C:\Windows\system32\milcore.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01856512 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01788416 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01671680 _____ (Microsoft Corporation) C:\Windows\system32\chsbrkr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01589248 _____ (Microsoft Corporation) C:\Windows\system32\msjet40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01502720 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01480704 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\wercon.exe 2015-03-05 18:09 - 2009-04-10 23:28 - 01112064 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01086464 _____ (Microsoft Corporation) C:\Windows\system32\NetProjW.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01053696 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01020928 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00971264 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00876032 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\mswdat10.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00852992 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00807424 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00759296 _____ (Microsoft Corporation) C:\Windows\system32\ipsecsnp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00712704 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00679936 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00677376 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00670720 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\msrepl40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\CertEnrollUI.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00618496 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2VDEC.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\msdtcprx.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00481792 _____ (Microsoft Corporation) C:\Windows\system32\cmdial32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00469504 _____ (Microsoft Corporation) C:\Windows\system32\newdev.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\msxbde40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\msexch40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\msvcp60.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00398848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\ipsmsnap.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\mspbde40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00368640 _____ () C:\Windows\system32\msjetoledb40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00364032 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00356864 _____ (Microsoft Corporation) C:\Windows\system32\MediaMetadataHandler.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00351744 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00339968 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00332800 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\msjtes40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\modemui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\mstext40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\iassdo.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\msltus40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\wdscore.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\mscandui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00217600 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00200704 _____ (Microsoft Corporation) C:\Windows\system32\input.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\iassam.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00163328 _____ (Microsoft Corporation) C:\Windows\system32\msutb.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\korwbrkr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\imapi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\msctfui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mstlsapi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\msctfp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\iassvcs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\mpr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\msjter40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingProxy.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\mmci.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\l2nacp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\dataclen.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msstrc.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\mimefilt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\bthserv.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\networkitemfactory.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\msscb.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iaspolcy.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\msimtf.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\ifmon.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\NcdProp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\MsCtfMonitor.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\midimap.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msisip.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mmcico.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\CHxReadingStringIME.dll 2015-03-05 18:09 - 2009-04-10 23:27 - 01827840 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-05 18:09 - 2009-04-10 23:27 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 01102848 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl 2015-03-05 18:09 - 2009-04-10 23:27 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\mblctr.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00799744 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl 2015-03-05 18:09 - 2009-04-10 23:27 - 00408064 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\certreq.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv 2015-03-05 18:09 - 2009-04-10 23:27 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\logagent.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\Kswdmcap.ax 2015-03-05 18:09 - 2009-04-10 23:27 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax 2015-03-05 18:09 - 2009-04-10 23:27 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\newdev.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingWizard.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\cipher.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\cmmon32.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\csrstub.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cbsra.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\bthudtask.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\ipconfig.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEject.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\msacm32.drv 2015-03-05 18:09 - 2009-04-10 23:23 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime 2015-03-05 18:09 - 2009-04-10 23:22 - 00883712 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME 2015-03-05 18:09 - 2009-04-10 23:22 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime 2015-03-05 18:09 - 2009-04-10 23:22 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime 2015-03-05 18:09 - 2009-04-10 23:21 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2015-03-05 18:09 - 2009-04-10 21:46 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys 2015-03-05 18:09 - 2009-04-10 21:45 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2015-03-05 18:09 - 2009-04-10 21:39 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys 2015-03-05 18:09 - 2009-04-10 21:39 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\iscsilog.dll 2015-03-05 18:09 - 2009-04-10 21:38 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys 2015-03-05 18:09 - 2009-04-10 21:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys 2015-03-05 18:09 - 2009-04-10 21:27 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2015-03-05 18:09 - 2009-04-10 21:14 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-03-05 18:09 - 2009-04-10 18:54 - 03662128 _____ () C:\Windows\system32\locale.nls 2015-03-05 18:09 - 2009-03-29 21:42 - 00155456 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2015-03-05 18:09 - 2009-03-29 21:42 - 00080720 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2015-03-05 18:09 - 2009-02-18 11:38 - 11967524 _____ () C:\Windows\system32\korwbrkr.lex 2015-03-05 18:09 - 2009-02-18 11:38 - 00619864 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2015-03-05 18:09 - 2009-02-18 11:38 - 00099680 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2015-03-05 18:09 - 2009-02-18 11:38 - 00035168 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl 2015-03-05 18:09 - 2009-02-18 11:38 - 00009048 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2015-03-05 18:08 - 2009-04-10 23:33 - 00986600 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-03-05 18:08 - 2009-04-10 23:33 - 00926184 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-03-05 18:08 - 2009-04-10 23:33 - 00292840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys 2015-03-05 18:08 - 2009-04-10 23:32 - 00226280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2015-03-05 18:08 - 2009-04-10 23:32 - 00122344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Storport.sys 2015-03-05 18:08 - 2009-04-10 23:32 - 00053224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys 2015-03-05 18:08 - 2009-04-10 23:28 - 03217408 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 02205184 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01695232 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01671680 _____ (Microsoft Corporation) C:\Windows\system32\wlanpref.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01580544 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01576960 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01575936 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL 2015-03-05 18:08 - 2009-04-10 23:28 - 01533440 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01524736 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01382912 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL 2015-03-05 18:08 - 2009-04-10 23:28 - 01224192 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01152000 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01081344 _____ (Microsoft Corporation) C:\Windows\system32\SLCExt.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01055232 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 01017856 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00996352 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00968192 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz2.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00777216 _____ (Microsoft Corporation) C:\Windows\system32\slcc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00747008 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\SmiEngine.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00657408 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL 2015-03-05 18:08 - 2009-04-10 23:28 - 00638976 _____ (Microsoft Corporation) C:\Windows\system32\Utilman.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00615424 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00582144 _____ (Microsoft Corporation) C:\Windows\system32\SLCommDlg.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\wiaaut.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00533504 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00532992 _____ (Microsoft Corporation) C:\Windows\system32\wpcao.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00507904 _____ (Microsoft Corporation) C:\Windows\system32\vdsdyn.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00449024 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00443392 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00425472 _____ (Microsoft Corporation) C:\Windows\system32\shwebsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00399360 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00385536 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\SLUI.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00342528 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00313344 _____ (Microsoft Corporation) C:\Windows\system32\thawbrkr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\WscEapPr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\w32time.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\SnippingTool.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\wow32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00250368 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\SLC.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\wscntfy.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\sperror.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\SLLUA.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\WcnNetsh.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\wevtutil.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\spoolss.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wpcsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\tcpmon.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\softkbd.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\ulib.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\wshext.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00083456 _____ (Microsoft) C:\Windows\system32\SMBHelperClass.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\wlgpclnt.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\slwmi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\SLUINotify.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\xmlfilter.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Storprop.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\slcinst.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\TSTheme.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\whealogr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\wsepno.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\uxsms.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\wsdchngr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\version.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\winrnr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wscisvif.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\vdmdbg.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\spcmsg.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\spwinsat.dll 2015-03-05 18:08 - 2009-04-10 23:27 - 03408896 _____ (Microsoft Corporation) C:\Windows\system32\SLsvc.exe 2015-03-05 18:08 - 2009-04-10 23:27 - 01689600 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl 2015-03-05 18:08 - 2009-04-10 23:27 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx 2015-03-05 18:08 - 2009-04-10 23:27 - 00280064 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp 2015-03-05 18:08 - 2009-04-10 23:27 - 00258048 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv 2015-03-05 18:08 - 2009-04-10 23:27 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2015-03-05 18:08 - 2009-04-10 23:23 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime 2015-03-05 18:08 - 2009-04-10 21:46 - 00208966 _____ () C:\Windows\system32\WFP.TMF 2015-03-05 18:08 - 2009-04-10 21:46 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2015-03-05 18:08 - 2009-04-10 21:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-03-05 18:08 - 2009-04-10 21:45 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\smb.sys 2015-03-05 18:08 - 2009-04-10 21:43 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2015-03-05 18:08 - 2009-04-10 21:42 - 00052992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD2.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2015-03-05 18:08 - 2009-04-10 21:22 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\watchdog.sys 2015-03-05 18:08 - 2009-04-10 21:14 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys 2015-03-05 18:08 - 2009-04-10 19:52 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spsys.sys 2015-03-05 18:08 - 2009-04-10 18:59 - 00107612 _____ () C:\Windows\system32\StructuredQuerySchema.bin 2015-03-05 18:08 - 2009-04-10 18:59 - 00018904 _____ () C:\Windows\system32\StructuredQuerySchemaTrivial.bin 2015-03-05 18:08 - 2009-03-06 18:11 - 00130008 _____ () C:\Windows\system32\systemsf.ebd 2015-03-05 18:08 - 2009-02-19 17:20 - 00009239 _____ () C:\Windows\system32\spcinstrumentation.man 2015-03-05 18:08 - 2009-02-18 11:39 - 00092918 _____ () C:\Windows\system32\slmgr.vbs 2015-03-05 18:08 - 2009-02-18 11:39 - 00035680 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2015-03-05 17:51 - 2015-03-05 18:00 - 365230920 _____ (Microsoft Corporation) C:\Users\Christian Rietz\Downloads\Windows6.0-KB948465-X86(1).exe 2015-03-05 17:30 - 2015-03-05 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-03-05 17:29 - 2015-03-05 17:29 - 00000000 ____D () C:\ProgramData\Oracle 2015-03-05 17:27 - 2015-03-05 17:27 - 00561064 _____ (Oracle Corporation) C:\Users\Christian Rietz\Downloads\jxpiinstall.exe 2015-03-05 12:03 - 2015-03-05 12:26 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-04 13:44 - 2015-03-05 19:16 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-03-04 13:44 - 2015-03-04 13:44 - 00000862 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-03-03 22:32 - 2015-03-03 22:32 - 06723986 _____ () C:\Users\Christian Rietz\Desktop\Geburtstagsvideo-von-Heiko.mov 2015-03-03 21:57 - 2015-03-03 21:57 - 00852594 _____ () C:\Users\Christian Rietz\Desktop\SecurityCheck.exe 2015-03-03 19:53 - 2015-03-04 21:49 - 00000000 ____D () C:\Program Files\VS Revo Group 2015-03-02 23:50 - 2015-03-02 23:50 - 10196653 _____ () C:\Users\Christian Rietz\Desktop\ChristianHBDklein.m4v 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\Documents\Eigene Google Gadgets 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Avg2014 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\AVG Web TuneUp 2015-03-01 18:17 - 2015-03-01 18:17 - 00118304 _____ () C:\Users\TEMP.Christian-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Apple Computer 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Wondershare 2015-03-01 18:16 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\VirtualStore 2015-03-01 18:16 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Google 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\RealNetworks 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Real 2015-03-01 18:15 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC 2015-03-01 18:15 - 2013-09-27 19:12 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Microsoft Help 2015-03-01 18:15 - 2013-09-26 20:06 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\TuneUp Software 2015-02-27 20:28 - 2015-03-04 22:02 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\Playmo-Zoo 2015-02-26 00:25 - 2015-02-26 00:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox(25) 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Skype 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Program Files\Skype(27) 2015-02-22 17:12 - 2015-02-22 17:12 - 00001869 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities.lnk 2015-02-22 17:12 - 2015-02-22 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2015-02-22 17:12 - 2010-04-01 15:17 - 00030536 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2015-02-22 17:12 - 2010-04-01 15:11 - 00030024 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2015-02-22 17:12 - 2010-04-01 15:11 - 00021320 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2015-02-22 17:11 - 2015-02-22 17:12 - 00000000 ____D () C:\Program Files\TuneUp Utilities 2010 2015-02-22 17:10 - 2015-02-22 17:10 - 00000000 __SHD () C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} 2015-02-22 16:59 - 2015-02-22 16:59 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\1 Tuneup Utilities 2015-02-22 13:37 - 2015-03-04 14:59 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\LOOKING for Season 2 2015-02-09 22:08 - 2015-02-09 22:09 - 00000000 ____D () C:\Program Files\QuickTime 2015-02-09 22:08 - 2015-02-09 22:08 - 00001730 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2015-02-09 22:08 - 2015-02-09 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2015-02-09 22:01 - 2015-02-09 22:03 - 42096984 _____ (Apple Inc.) C:\Users\Christian Rietz\Downloads\QuickTimeInstaller(1).exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-05 19:37 - 2006-11-02 11:33 - 01418806 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-03-05 19:35 - 2013-07-16 20:05 - 00000000 ____D () C:\FRST 2015-03-05 19:35 - 2013-07-11 17:09 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-05 19:35 - 2008-10-25 04:29 - 00000438 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job 2015-03-05 19:34 - 2013-07-11 14:20 - 01779604 _____ () C:\Windows\WindowsUpdate.log 2015-03-05 19:33 - 2014-02-03 20:53 - 00000000 ___RD () C:\Users\Christian Rietz\Dropbox 2015-03-05 19:33 - 2014-02-03 20:49 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Dropbox 2015-03-05 19:33 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.dat 2015-03-05 19:33 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.001 2015-03-05 19:31 - 2013-07-11 17:09 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-05 19:31 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Home Cinema 2015-03-05 19:30 - 2008-01-21 03:47 - 00767408 _____ () C:\Windows\PFRO.log 2015-03-05 19:30 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-05 19:30 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-05 19:30 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-05 19:28 - 2006-11-02 14:01 - 00032540 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-03-05 19:17 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache 2015-03-05 19:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-03-05 18:59 - 2008-10-22 04:40 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-03-05 18:58 - 2013-10-06 11:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-03-05 18:57 - 2013-07-11 14:24 - 00000953 _____ () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-03-05 18:57 - 2013-07-11 14:23 - 00000919 _____ () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2015-03-05 18:50 - 2006-11-02 13:47 - 00408096 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Sidebar 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Photo Gallery 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Journal 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Collaboration 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Calendar 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Movie Maker 2015-03-05 18:45 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\System 2015-03-05 18:44 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\system32\XPSViewer 2015-03-05 18:44 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Defender 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sk-SK 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\lv-LV 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ko-KR 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\hr-HR 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\et-EE 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\IME 2015-03-05 18:43 - 2008-10-20 13:36 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\zh-TW 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\zh-CN 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\uk-UA 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\tr-TR 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\th-TH 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sv-SE 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\SLUI 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sl-SI 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ru-RU 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ro-RO 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pt-PT 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pt-BR 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pl-PL 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\nl-NL 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\nb-NO 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\lt-LT 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ja-JP 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\it-IT 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\hu-HU 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\he-IL 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\fr-FR 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\fi-FI 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\el-GR 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\de-DE 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\bg-BG 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ar-SA 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers 2015-03-05 18:38 - 2008-10-20 04:37 - 00000000 ____D () C:\Windows\system32\RTCOM 2015-03-05 18:38 - 2006-11-02 13:52 - 00145158 _____ () C:\Windows\setupact.log 2015-03-05 18:26 - 2013-09-10 21:42 - 00000000 ____D () C:\ProgramData\MFAData 2015-03-05 17:39 - 2013-07-11 21:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-03-05 17:39 - 2013-07-11 21:03 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-03-05 17:38 - 2013-07-11 21:02 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Adobe 2015-03-05 17:29 - 2008-10-20 06:08 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2015-03-05 17:29 - 2008-10-20 06:08 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2015-03-05 17:29 - 2008-10-20 06:08 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2015-03-05 17:29 - 2008-10-20 06:08 - 00000000 ____D () C:\Program Files\Java 2015-03-05 12:01 - 2014-08-14 20:25 - 00000000 ____D () C:\ProgramData\Package Cache 2015-03-05 12:01 - 2013-07-16 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-03-05 12:01 - 2013-07-16 20:21 - 00000000 ____D () C:\Program Files\Avira 2015-03-05 11:51 - 2013-07-11 17:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-03-04 22:05 - 2013-07-11 17:24 - 00000000 ___RD () C:\Users\Christian Rietz\Documents\Programme 2015-03-04 21:40 - 2014-06-11 18:01 - 00000000 ____D () C:\Windows\system32\oodag 2015-03-04 19:38 - 2013-08-07 21:48 - 00000000 ____D () C:\Users\Christian Rietz\dwhelper 2015-03-04 14:59 - 2013-07-11 22:21 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\vlc 2015-03-04 13:36 - 2013-07-11 16:54 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Adobe 2015-03-04 13:36 - 2008-10-20 05:03 - 00000000 ____D () C:\ProgramData\Adobe 2015-03-04 13:06 - 2013-07-16 20:21 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-03-04 13:06 - 2013-07-16 20:21 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-03-03 21:47 - 2014-10-20 23:22 - 00000000 ____D () C:\Users\Christian Rietz\Downloads\streamtransport_1.1.6.2 2015-03-02 23:20 - 2013-09-24 22:44 - 00000000 ____D () C:\AdwCleaner 2015-03-02 22:37 - 2013-07-11 14:24 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Google 2015-03-01 20:06 - 2014-04-17 18:10 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2015-03-01 20:06 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Skype 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration 2015-03-01 18:52 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc 2015-03-01 18:50 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz 2015-03-01 18:50 - 2006-11-02 11:22 - 46661632 _____ () C:\Windows\system32\config\software_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 33554432 _____ () C:\Windows\system32\config\components_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 19660800 _____ () C:\Windows\system32\config\system_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\security_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\default_previous 2015-03-01 18:45 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ___RD () C:\Program Files\Skype 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ____D () C:\Program Files\Common Files\Skype 2015-02-26 00:25 - 2013-09-25 21:57 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Skype 2015-02-22 17:10 - 2013-07-11 21:54 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-19 19:07 - 2014-02-03 20:50 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox ==================== Files in the root of some directories ======= 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\StatusSheet 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\Stingers 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\String Comparison 2014-02-20 21:49 - 2014-02-20 21:49 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\System Image Utility 2014-03-26 19:46 - 2014-03-26 19:46 - 0000047 _____ () C:\Users\Christian Rietz\AppData\Roaming\WB.CFG 2013-08-02 19:34 - 2014-11-20 21:45 - 0001356 _____ () C:\Users\Christian Rietz\AppData\Local\d3d9caps.dat 2013-07-28 13:50 - 2015-01-25 21:05 - 0092672 _____ () C:\Users\Christian Rietz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2008-10-25 04:12 - 2015-03-05 19:33 - 0084921 _____ () C:\ProgramData\nvModes.001 2008-10-25 04:12 - 2015-03-05 19:33 - 0084921 _____ () C:\ProgramData\nvModes.dat 2014-02-20 21:49 - 2014-02-20 21:49 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT 2014-02-20 21:57 - 2014-02-20 22:12 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT 2014-02-20 21:53 - 2014-02-20 22:09 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\Strings 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\ProgramData\Super Strings 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\SupportPrinters Some content of TEMP: ==================== C:\Users\Christian Rietz\AppData\Local\Temp\avgnt.exe C:\Users\Christian Rietz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkdmqep.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed |
05.03.2015, 19:48 | #12 |
| COULDN'T LOAD XPCOM - Firefox startet nichtCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 04-03-2015 Ran by Christian Rietz at 2015-03-05 19:40:39 Running from C:\Users\Christian Rietz\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 4.42 (HKLM\...\7-Zip) (Version: - ) ACDSee 9 Foto-Manager (HKLM\...\{7AE25201-3E12-4FA2-9E65-67CD475D9263}) (Version: 9.0.55 - ACD Systems Ltd.) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Photoshop CS (HKLM\...\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}) (Version: CS - Adobe Systems, Inc.) Adobe Reader 9 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A90000000001}) (Version: 9.0.0 - Adobe Systems Incorporated) Adobe Shockwave Player 11 (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.) Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E14ADE0E-75F3-4A46-87E5-26692DD626EC}) (Version: 6.1.0.13 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArcSoft Panorama Maker 6 (HKLM\...\{DABFD34E-BE68-4BC6-9254-5D7A7FF76B99}) (Version: 6.0.8.85 - ArcSoft) AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4800 - AVG Technologies) AVG 2014 (Version: 14.0.3614 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4257 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4800 - AVG Technologies) Hidden AVG Web TuneUp (HKLM\...\AVG Web TuneUp) (Version: 3.2.0.18 - AVG Technologies) Avira (HKLM\...\{d9ed6dcf-6bfc-4fbb-802e-81dd5b767d6e}) (Version: 1.1.32.25147 - Avira Operations & Co. KG) Avira (Version: 1.1.32.25147 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 15.0.8.650 - Avira) Avira SearchFree Toolbar plus Web Protection (HKLM\...\{41564952-412D-5637-00A7-A758B70C0201}) (Version: 12.2.1.477 - Ask Partner Network) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Corel Graphics Suite 11 (HKLM\...\InstallShield_{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}) (Version: 11 - Corel Corporation) Corel Graphics Suite 11 (Version: 11 - Corel Corporation) Hidden Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation) CorelDRAW Essential Edition 3 (HKLM\...\_{ADDBE07D-95B8-4789-9C76-187FFF9624B4}) (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) Hidden CyberLink MediaShow (HKLM\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 4.1.2019 - CyberLink Corp.) CyberLink PhotoNow (HKLM\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.5203 - CyberLink Corp.) CyberLink PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2209a - CyberLink Corp.) CyberLink PowerDVD (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 7.0.3118.0 - PowerDVDCorp.) CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0815 - CyberLink Corp.) CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.2109 - CyberLink Corp.) DE (Version: 3.0 - Corel Corporation) Hidden Dolby Control Center (HKLM\...\{70E8EBD5-78C9-4258-B20A-5098CCA000F0}) (Version: 1.1.0601 - Dolby) Dropbox (HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.) Free YouTube Download version 3.2.48.1015 (HKLM\...\Free YouTube Download_is1) (Version: 3.2.48.1015 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.48.1015 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.48.1015 - DVDVideoSoft Ltd.) Google Chrome (HKLM\...\Google Chrome) (Version: 41.0.2272.76 - Google Inc.) Google Desktop (HKLM\...\Google Desktop) (Version: - - Google) Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden iTunes (HKLM\...\{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}) (Version: 11.0.4.4 - Apple Inc.) MAGIX Screenshare (HKLM\...\{A7B517E2-07EB-47BA-877B-3F174FB7760B}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM\...\{9D5B0618-2EFA-4DAA-9B53-A546992824EA}) (Version: 7.0.2.6 - MAGIX AG) MakeDisc (HKLM\...\{B145EC69-66F5-11D8-9D75-000129760D75}) (Version: 3.0.2601 - CyberLink Corp.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 36.0 (x86 de) (HKLM\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 36.0 - Mozilla) MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon) Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.9.0 - Nikon) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) O&O Defrag Free Edition (HKLM\...\{E29CFB36-F070-4612-8DB5-7038161B6294}) (Version: 14.1.431 - O&O Software GmbH) Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.5.0 - Nikon) QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) RealDownloader (Version: 1.3.2 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5704 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: 3.0.1.3 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden Samplitude 11 Silver (HKLM\...\MAGIX_MSI_sam11silver) (Version: 11.0.1.0 - MAGIX AG) Samplitude 11 Silver (Version: 11.0.1.0 - MAGIX AG) Hidden Samplitude Music Studio 2008 Trial 14.0.2.0 (D) (HKLM\...\Samplitude Music Studio 2008 Trial D) (Version: 14.0.2.0 - MAGIX AG) Skype™ 6.7 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.7.102 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.2.2.0 - Synaptics) TuneUp Utilities (HKLM\...\TuneUp Utilities) (Version: 9.0.4100.12 - TuneUp Software) TuneUp Utilities (Version: 9.0.4100.12 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (Version: 9.0.4100.12 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update Manager (Version: 4.60 - Corel Corporation) Hidden VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.9.0 - Nikon) Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN) Windows Live Anmelde-Assistent (HKLM\...\{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}) (Version: 5.000.818.6 - Microsoft Corporation) Windows Live Fotogalerie (HKLM\...\{A1D08B90-AE1A-4885-AC29-731496FD397E}) (Version: 12.0.1347.0718 - Microsoft Corporation) Windows Live installer (HKLM\...\{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}) (Version: 12.0.1471.1025 - Microsoft Corporation) Windows Live Mail (HKLM\...\{82F2B38B-1426-443D-874C-AC25675E7BEB}) (Version: 12.0.1606.1023 - Microsoft Corporation) Windows Live Messenger (HKLM\...\{2B091530-69AA-442E-AB09-39ED06B58220}) (Version: 8.5.1302.1018 - Microsoft Corporation) Windows Live Writer (HKLM\...\{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5}) (Version: 12.0.1370.0325 - Microsoft Corporation) X10 Hardware(TM) (HKLM\...\X10Hardware) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Restore Points ========================= Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-03-2015 Ran by Christian Rietz at 2015-03-05 19:24:02 Run:3 Running from C:\Users\Christian Rietz\Desktop Loaded Profiles: Christian Rietz (Available profiles: Christian Rietz) Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs: c:\docume~1\ settings\all users\application D?????AA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Emptytemp: ***************** "c:\docume~1\ settings\all users\application D?????AA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL" => Value Data not found. EmptyTemp: => Removed 1.8 GB temporary data. The system needed a reboot. ==== End of Fixlog 19:28:03 ==== Ran by Christian Rietz at 2015-03-05 19:24:02 Run:3 Running from C:\Users\Christian Rietz\Desktop Loaded Profiles: Christian Rietz (Available profiles: Christian Rietz) Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs: c:\docume~1\ settings\all users\application D?????AA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Emptytemp: ***************** "c:\docume~1\ settings\all users\application D?????AA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL" => Value Data not found. EmptyTemp: => Removed 1.8 GB temporary data. The system needed a reboot. ==== End of Fixlog 19:28:03 ==== Sorry, Farbar war noch nicht fertig. Hier die endgültigen Txt-Dateien: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-03-2015 Ran by Christian Rietz at 2015-03-05 19:24:02 Run:3 Running from C:\Users\Christian Rietz\Desktop Loaded Profiles: Christian Rietz (Available profiles: Christian Rietz) Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs: c:\docume~1\ settings\all users\application D?????AA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Emptytemp: ***************** "c:\docume~1\ settings\all users\application D?????AA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL" => Value Data not found. EmptyTemp: => Removed 1.8 GB temporary data. The system needed a reboot. ==== End of Fixlog 19:28:03 ==== |
05.03.2015, 19:49 | #13 |
| COULDN'T LOAD XPCOM - Firefox startet nichtFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-03-2015 Ran by Christian Rietz (administrator) on CHRISTIAN-PC on 05-03-2015 19:35:26 Running from C:\Users\Christian Rietz\Desktop Loaded Profiles: Christian Rietz (Available profiles: Christian Rietz) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PSIService.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (X10) C:\Program Files\Common Files\X10\Common\X10nets.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (ACD Systems, Ltd.) C:\Program Files\Common Files\ACD Systems\DE\DevDetect.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodtray.exe (Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Dropbox, Inc.) C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512 2008-01-04] (Synaptics, Inc.) HKLM\...\Run: [UpdatePDRShortCut] => C:\Program Files\HomeCinema\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM\...\Run: [RemoteControl] => C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe [71216 2007-02-09] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] => C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe [52256 2007-01-08] () HKLM\...\Run: [UpdatePPShortCut] => C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe [222504 2008-02-21] (CyberLink Corp.) HKLM\...\Run: [UCam_Menu] => C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6294048 2008-09-18] (Realtek Semiconductor) HKLM\...\Run: [Google Desktop Search] => C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [220160 2008-10-26] (Google) HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [Device Detector] => DevDetect.exe -autorun HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703280 2015-03-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5188112 2014-12-16] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation) HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe [2729800 2011-01-25] (O&O Software GmbH) HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-08-05] (Wondershare) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [127792 2015-02-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [SunJavaUpdateSched] => "C:\Program Files\Java\jre1.8.0_40\bin\jusched.exe" HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-11] (Google Inc.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [ISUSPM] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) AppInit_DLLs: c:\docume~1\ settings\all users\application D즸粖㛉ࠀᖰAA C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [146432 2008-10-26] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-209139463-1928718786-3223491114-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll (Oracle Corporation) BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-209139463-1928718786-3223491114-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_40-windows-i586.cab DPF: {CAFEEFAC-0018-0000-0040-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_40-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_40-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\p2be4a2p.default-1425473419208 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.2.32 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Extension: DownloadHelper - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\p2be4a2p.default-1425473419208\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2015-03-04] FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-07-11] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-27] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Christian Rietz\AppData\Roaming\Mozilla\Firefox\Profiles\ltp2kpr9.default\extensions\cliqz@cliqz.com Chrome: ======= CHR Profile: C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browser Safety) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-10-20] CHR Extension: (RealDownloader) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-09-24] CHR Extension: (Google Wallet) - C:\Users\Christian Rietz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-24] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-04-16] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2013-07-12] () [File not signed] R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2015-03-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-04] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [992504 2015-03-04] (Avira Operations GmbH & Co. KG) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3247120 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [184056 2015-02-12] (Avira Operations GmbH & Co. KG) S3 GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe [69120 2008-10-26] (Google) [File not signed] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2336072 2011-01-25] (O&O Software GmbH) R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] () R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [241734 2008-06-28] () [File not signed] S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2015-02-22] (TuneUp Software) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1050440 2010-04-01] (TuneUp Software) S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) [File not signed] R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2001-11-12] (X10) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [200984 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [189720 2014-10-24] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-29] (AVG Technologies CZ, s.r.o.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-04] (Avira Operations GmbH & Co. KG) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-29] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-19] (Avira Operations GmbH & Co. KG) S3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1332576 2008-09-25] (NXP Semiconductors Germany GmbH) R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2013-07-12] (Padus, Inc.) [File not signed] S3 PhilCap; C:\Windows\System32\DRIVERS\PhilCap.sys [908896 2007-07-31] (NXP Semiconductors Germany GmbH) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-16] (Avira GmbH) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13976 2006-11-17] (X10 Wireless Technology, Inc.) R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] U4 Msetapxe_n; No ImagePath S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-05 19:35 - 2015-03-05 19:37 - 00024242 _____ () C:\Users\Christian Rietz\Desktop\FRST.txt 2015-03-05 19:22 - 2015-03-05 19:22 - 01132544 _____ (Farbar) C:\Users\Christian Rietz\Desktop\FRST.exe 2015-03-05 19:14 - 2015-03-05 19:14 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Oracle 2015-03-05 18:41 - 2015-03-05 18:44 - 00000000 ____D () C:\Windows\system32\ca-ES 2015-03-05 18:41 - 2015-03-05 18:43 - 00000000 ____D () C:\Windows\system32\vi-VN 2015-03-05 18:41 - 2015-03-05 18:43 - 00000000 ____D () C:\Windows\system32\eu-ES 2015-03-05 18:41 - 2015-03-05 18:41 - 00000000 ____D () C:\Windows\nvtmpinst 2015-03-05 18:34 - 2015-03-05 18:34 - 00000000 ____D () C:\Windows\system32\SPReview 2015-03-05 18:11 - 2009-04-10 23:28 - 00928768 _____ (Microsoft Corporation) C:\Windows\system32\scavenge.dll 2015-03-05 18:11 - 2009-04-10 23:27 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\compcln.exe 2015-03-05 18:10 - 2009-04-10 23:32 - 01083880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00265688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00190424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00149480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00141288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00099816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2015-03-05 18:10 - 2009-04-10 23:32 - 00054248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00053736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00050664 _____ (Microsoft Corporation) C:\Windows\system32\PSHED.DLL 2015-03-05 18:10 - 2009-04-10 23:32 - 00035304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys 2015-03-05 18:10 - 2009-04-10 23:32 - 00027624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Dumpata.sys 2015-03-05 18:10 - 2009-04-10 23:28 - 02515968 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 02153472 _____ (Microsoft Corporation) C:\Windows\system32\oobefldr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 02134528 _____ (Microsoft Corporation) C:\Windows\system32\FunctionDiscoveryFolder.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01985024 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01823744 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01730560 _____ (Microsoft Corporation) C:\Windows\system32\apds.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01645568 _____ (Microsoft Corporation) C:\Windows\system32\connect.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01591296 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01541120 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01459200 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01342464 _____ (Microsoft Corporation) C:\Windows\system32\brcpl.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01324032 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayCpl.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01209856 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01107968 _____ (Microsoft Corporation) C:\Windows\system32\pidgenx.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01078784 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00978432 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00950784 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00869888 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00825856 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\powercpl.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00644608 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\rasgcw.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00612864 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2015-03-05 18:10 - 2009-04-10 23:28 - 00593408 _____ (Microsoft Corporation) C:\Windows\system32\comuid.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00551936 _____ (Microsoft Corporation) C:\Windows\system32\prnntfy.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00550400 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00542720 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\pnpui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00516608 _____ (Microsoft Corporation) C:\Windows\system32\autoplay.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00476672 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00472064 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00466944 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00464384 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\IasMigReader.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00454144 _____ (Microsoft) C:\Windows\system32\IasMigPlugin.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\dsound.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00441344 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00425472 _____ (Microsoft Corporation) C:\Windows\system32\PhotoMetadataHandler.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\devmgr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\rasplap.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\RelMon.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00334848 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2015-03-05 18:10 - 2009-04-10 23:28 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\P2PGraph.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\sdohlp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00306176 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\QAGENTRT.DLL 2015-03-05 18:10 - 2009-04-10 23:28 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00286720 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\es.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\scansetting.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\adsldpc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\offfilt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\pnpsetup.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceTypes.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\rasmontr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\fundisc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iasnap.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\fontext.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\dsprop.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\nlhtml.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\extmgr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\ntmarta.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\EhStorAPI.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00117248 _____ () C:\Windows\system32\EhStorAuthn.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayDriverLib.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\EhStorShell.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\regsvc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\dmsynth.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayServices.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\dmusic.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\powrprof.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\oleprn.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\SCardSvr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceClassExtension.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\fdBth.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2015-03-05 18:10 - 2009-04-10 23:28 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\propdefs.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\iashlpr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\sendmail.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\PNPXAssoc.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\fdSSDP.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\fdWSD.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\iasads.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\feclient.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\dot3cfg.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\iasdatastore.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\bthci.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\rtffilt.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\EhStorPwdMgr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\perfdisk.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\bitsigd.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelineprxy.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\hidserv.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\fdProxy.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2015-03-05 18:10 - 2009-04-10 23:28 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\fdBthProxy.dll 2015-03-05 18:10 - 2009-04-10 23:27 - 02926592 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 02092544 _____ (Microsoft Corporation) C:\Windows\system32\dfsr.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 01122304 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl 2015-03-05 18:10 - 2009-04-10 23:27 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr 2015-03-05 18:10 - 2009-04-10 23:27 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelinesvc.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00636416 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00518144 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00407040 _____ (Microsoft Corporation) C:\Windows\system32\dpapimig.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00241128 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll 2015-03-05 18:10 - 2009-04-10 23:27 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\diskraid.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2015-03-05 18:10 - 2009-04-10 23:27 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\eudcedit.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\PresentationSettings.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00130024 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll 2015-03-05 18:10 - 2009-04-10 23:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\gpresult.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\nslookup.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\dwm.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\hdwwiz.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\conime.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\reg.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\findstr.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\PnPUnattend.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\rekeywiz.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\ocsetup.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\PnPutil.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\fc.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\rasdial.exe 2015-03-05 18:10 - 2009-04-10 23:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\gpupdate.exe 2015-03-05 18:10 - 2009-04-10 23:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime 2015-03-05 18:10 - 2009-04-10 23:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime 2015-03-05 18:10 - 2009-04-10 23:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime 2015-03-05 18:10 - 2009-04-10 23:23 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime 2015-03-05 18:10 - 2009-04-10 23:22 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\f3ahvoas.dll 2015-03-05 18:10 - 2009-04-10 22:42 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys 2015-03-05 18:10 - 2009-04-10 22:03 - 12240896 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0007.dll 2015-03-05 18:10 - 2009-04-10 22:03 - 02644480 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0009.dll 2015-03-05 18:10 - 2009-04-10 21:51 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2015-03-05 18:10 - 2009-04-10 21:48 - 00344698 _____ () C:\Windows\system32\eaphost.tmf 2015-03-05 18:10 - 2009-04-10 21:46 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rassstp.sys 2015-03-05 18:10 - 2009-04-10 21:46 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\raspppoe.sys 2015-03-05 18:10 - 2009-04-10 21:46 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2015-03-05 18:10 - 2009-04-10 21:45 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-03-05 18:10 - 2009-04-10 21:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys 2015-03-05 18:10 - 2009-04-10 21:43 - 00442788 _____ () C:\Windows\system32\dot3.tmf 2015-03-05 18:10 - 2009-04-10 21:43 - 00392170 _____ () C:\Windows\system32\onex.tmf 2015-03-05 18:10 - 2009-04-10 21:43 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2015-03-05 18:10 - 2009-04-10 21:42 - 00561152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys 2015-03-05 18:10 - 2009-04-10 21:42 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2015-03-05 18:10 - 2009-04-10 21:42 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2015-03-05 18:10 - 2009-04-10 21:42 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys 2015-03-05 18:10 - 2009-04-10 21:39 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2015-03-05 18:10 - 2009-04-10 21:23 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2015-03-05 18:10 - 2009-04-10 21:23 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxg.sys 2015-03-05 18:10 - 2009-04-10 21:14 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2015-03-05 18:10 - 2009-04-10 21:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\npfs.sys 2015-03-05 18:10 - 2009-04-10 21:13 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2015-03-05 18:10 - 2009-04-10 21:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys 2015-03-05 18:10 - 2009-04-10 21:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-03-05 18:10 - 2009-02-19 17:20 - 00009212 _____ () C:\Windows\system32\RacUR.xml 2015-03-05 18:10 - 2009-02-18 11:39 - 00779136 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2015-03-05 18:10 - 2009-02-18 11:39 - 00102816 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-03-05 18:09 - 2009-04-10 23:33 - 00614376 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2015-03-05 18:09 - 2009-04-10 23:32 - 00527848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00438744 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll 2015-03-05 18:09 - 2009-04-10 23:32 - 00245736 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00223208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00180712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00161752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00125928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00048104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mup.sys 2015-03-05 18:09 - 2009-04-10 23:32 - 00019944 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2015-03-05 18:09 - 2009-04-10 23:32 - 00017896 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2015-03-05 18:09 - 2009-04-10 23:32 - 00017384 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 06103040 _____ (Microsoft Corporation) C:\Windows\system32\chtbrkr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 03174400 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 03072000 _____ (Microsoft Corporation) C:\Windows\system32\networkmap.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02226688 _____ (Microsoft Corporation) C:\Windows\system32\networkexplorer.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02225664 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02167808 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 02012160 _____ (Microsoft Corporation) C:\Windows\system32\milcore.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01856512 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01788416 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01671680 _____ (Microsoft Corporation) C:\Windows\system32\chsbrkr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01589248 _____ (Microsoft Corporation) C:\Windows\system32\msjet40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01502720 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01480704 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\wercon.exe 2015-03-05 18:09 - 2009-04-10 23:28 - 01112064 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01086464 _____ (Microsoft Corporation) C:\Windows\system32\NetProjW.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01053696 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 01020928 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00971264 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00876032 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\mswdat10.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00852992 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00807424 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00759296 _____ (Microsoft Corporation) C:\Windows\system32\ipsecsnp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00712704 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00679936 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00677376 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00670720 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\msrepl40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\CertEnrollUI.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00618496 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2VDEC.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\msdtcprx.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00481792 _____ (Microsoft Corporation) C:\Windows\system32\cmdial32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00469504 _____ (Microsoft Corporation) C:\Windows\system32\newdev.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\msxbde40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\msexch40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\msvcp60.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00398848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\ipsmsnap.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\mspbde40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00368640 _____ () C:\Windows\system32\msjetoledb40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00364032 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00356864 _____ (Microsoft Corporation) C:\Windows\system32\MediaMetadataHandler.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00351744 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00339968 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00332800 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\msjtes40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\modemui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\mstext40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\iassdo.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\msltus40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\wdscore.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\mscandui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00217600 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00200704 _____ (Microsoft Corporation) C:\Windows\system32\input.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\iassam.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00163328 _____ (Microsoft Corporation) C:\Windows\system32\msutb.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\korwbrkr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\imapi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL 2015-03-05 18:09 - 2009-04-10 23:28 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\msctfui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mstlsapi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\msctfp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\iassvcs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\mpr.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\msjter40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingProxy.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\mmci.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\l2nacp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\dataclen.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msstrc.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\mimefilt.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\bthserv.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\networkitemfactory.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\msscb.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iaspolcy.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\msimtf.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\ifmon.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\NcdProp.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\MsCtfMonitor.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\midimap.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msisip.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mmcico.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2015-03-05 18:09 - 2009-04-10 23:28 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\CHxReadingStringIME.dll 2015-03-05 18:09 - 2009-04-10 23:27 - 01827840 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-05 18:09 - 2009-04-10 23:27 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 01102848 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl 2015-03-05 18:09 - 2009-04-10 23:27 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\mblctr.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00799744 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl 2015-03-05 18:09 - 2009-04-10 23:27 - 00408064 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\certreq.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv 2015-03-05 18:09 - 2009-04-10 23:27 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\logagent.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\Kswdmcap.ax 2015-03-05 18:09 - 2009-04-10 23:27 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax 2015-03-05 18:09 - 2009-04-10 23:27 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\newdev.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingWizard.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\cipher.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\cmmon32.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\csrstub.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cbsra.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\bthudtask.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\ipconfig.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEject.exe 2015-03-05 18:09 - 2009-04-10 23:27 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\msacm32.drv 2015-03-05 18:09 - 2009-04-10 23:23 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime 2015-03-05 18:09 - 2009-04-10 23:22 - 00883712 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME 2015-03-05 18:09 - 2009-04-10 23:22 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime 2015-03-05 18:09 - 2009-04-10 23:22 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime 2015-03-05 18:09 - 2009-04-10 23:21 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2015-03-05 18:09 - 2009-04-10 21:46 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys 2015-03-05 18:09 - 2009-04-10 21:45 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2015-03-05 18:09 - 2009-04-10 21:39 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys 2015-03-05 18:09 - 2009-04-10 21:39 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\iscsilog.dll 2015-03-05 18:09 - 2009-04-10 21:38 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys 2015-03-05 18:09 - 2009-04-10 21:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys 2015-03-05 18:09 - 2009-04-10 21:27 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2015-03-05 18:09 - 2009-04-10 21:14 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-03-05 18:09 - 2009-04-10 18:54 - 03662128 _____ () C:\Windows\system32\locale.nls 2015-03-05 18:09 - 2009-03-29 21:42 - 00155456 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2015-03-05 18:09 - 2009-03-29 21:42 - 00080720 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2015-03-05 18:09 - 2009-02-18 11:38 - 11967524 _____ () C:\Windows\system32\korwbrkr.lex 2015-03-05 18:09 - 2009-02-18 11:38 - 00619864 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2015-03-05 18:09 - 2009-02-18 11:38 - 00099680 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2015-03-05 18:09 - 2009-02-18 11:38 - 00035168 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl 2015-03-05 18:09 - 2009-02-18 11:38 - 00009048 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2015-03-05 18:08 - 2009-04-10 23:33 - 00986600 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-03-05 18:08 - 2009-04-10 23:33 - 00926184 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-03-05 18:08 - 2009-04-10 23:33 - 00292840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys 2015-03-05 18:08 - 2009-04-10 23:32 - 00226280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2015-03-05 18:08 - 2009-04-10 23:32 - 00122344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Storport.sys 2015-03-05 18:08 - 2009-04-10 23:32 - 00053224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys 2015-03-05 18:08 - 2009-04-10 23:28 - 03217408 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 02205184 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01695232 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01671680 _____ (Microsoft Corporation) C:\Windows\system32\wlanpref.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01580544 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01576960 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01575936 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL 2015-03-05 18:08 - 2009-04-10 23:28 - 01533440 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01524736 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01382912 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL 2015-03-05 18:08 - 2009-04-10 23:28 - 01224192 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01152000 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01081344 _____ (Microsoft Corporation) C:\Windows\system32\SLCExt.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 01055232 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 01017856 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00996352 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00968192 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz2.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00777216 _____ (Microsoft Corporation) C:\Windows\system32\slcc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00747008 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\SmiEngine.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00657408 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL 2015-03-05 18:08 - 2009-04-10 23:28 - 00638976 _____ (Microsoft Corporation) C:\Windows\system32\Utilman.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00615424 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00582144 _____ (Microsoft Corporation) C:\Windows\system32\SLCommDlg.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\wiaaut.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00533504 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00532992 _____ (Microsoft Corporation) C:\Windows\system32\wpcao.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00507904 _____ (Microsoft Corporation) C:\Windows\system32\vdsdyn.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00449024 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00443392 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00425472 _____ (Microsoft Corporation) C:\Windows\system32\shwebsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00399360 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00385536 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\SLUI.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00342528 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00313344 _____ (Microsoft Corporation) C:\Windows\system32\thawbrkr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\WscEapPr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\w32time.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\SnippingTool.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\wow32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00250368 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\SLC.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\wscntfy.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\sperror.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\SLLUA.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\WcnNetsh.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\wevtutil.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\spoolss.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wpcsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\tcpmon.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\softkbd.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\ulib.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\wshext.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00083456 _____ (Microsoft) C:\Windows\system32\SMBHelperClass.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\wlgpclnt.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\slwmi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\SLUINotify.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\xmlfilter.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Storprop.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\slcinst.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\TSTheme.exe 2015-03-05 18:08 - 2009-04-10 23:28 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\whealogr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\wsepno.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\uxsms.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\wsdchngr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\version.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\winrnr.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wscisvif.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\vdmdbg.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\spcmsg.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll 2015-03-05 18:08 - 2009-04-10 23:28 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\spwinsat.dll 2015-03-05 18:08 - 2009-04-10 23:27 - 03408896 _____ (Microsoft Corporation) C:\Windows\system32\SLsvc.exe 2015-03-05 18:08 - 2009-04-10 23:27 - 01689600 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl 2015-03-05 18:08 - 2009-04-10 23:27 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx 2015-03-05 18:08 - 2009-04-10 23:27 - 00280064 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp 2015-03-05 18:08 - 2009-04-10 23:27 - 00258048 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv 2015-03-05 18:08 - 2009-04-10 23:27 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2015-03-05 18:08 - 2009-04-10 23:23 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime 2015-03-05 18:08 - 2009-04-10 21:46 - 00208966 _____ () C:\Windows\system32\WFP.TMF 2015-03-05 18:08 - 2009-04-10 21:46 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2015-03-05 18:08 - 2009-04-10 21:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-03-05 18:08 - 2009-04-10 21:45 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\smb.sys 2015-03-05 18:08 - 2009-04-10 21:43 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2015-03-05 18:08 - 2009-04-10 21:42 - 00052992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD2.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD.sys 2015-03-05 18:08 - 2009-04-10 21:42 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2015-03-05 18:08 - 2009-04-10 21:22 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\watchdog.sys 2015-03-05 18:08 - 2009-04-10 21:14 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys 2015-03-05 18:08 - 2009-04-10 19:52 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spsys.sys 2015-03-05 18:08 - 2009-04-10 18:59 - 00107612 _____ () C:\Windows\system32\StructuredQuerySchema.bin 2015-03-05 18:08 - 2009-04-10 18:59 - 00018904 _____ () C:\Windows\system32\StructuredQuerySchemaTrivial.bin 2015-03-05 18:08 - 2009-03-06 18:11 - 00130008 _____ () C:\Windows\system32\systemsf.ebd 2015-03-05 18:08 - 2009-02-19 17:20 - 00009239 _____ () C:\Windows\system32\spcinstrumentation.man 2015-03-05 18:08 - 2009-02-18 11:39 - 00092918 _____ () C:\Windows\system32\slmgr.vbs 2015-03-05 18:08 - 2009-02-18 11:39 - 00035680 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2015-03-05 17:51 - 2015-03-05 18:00 - 365230920 _____ (Microsoft Corporation) C:\Users\Christian Rietz\Downloads\Windows6.0-KB948465-X86(1).exe 2015-03-05 17:30 - 2015-03-05 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-03-05 17:29 - 2015-03-05 17:29 - 00000000 ____D () C:\ProgramData\Oracle 2015-03-05 17:27 - 2015-03-05 17:27 - 00561064 _____ (Oracle Corporation) C:\Users\Christian Rietz\Downloads\jxpiinstall.exe 2015-03-05 12:03 - 2015-03-05 12:26 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-04 13:44 - 2015-03-05 19:16 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-03-04 13:44 - 2015-03-04 13:44 - 00000862 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-03-03 22:32 - 2015-03-03 22:32 - 06723986 _____ () C:\Users\Christian Rietz\Desktop\Geburtstagsvideo-von-Heiko.mov 2015-03-03 21:57 - 2015-03-03 21:57 - 00852594 _____ () C:\Users\Christian Rietz\Desktop\SecurityCheck.exe 2015-03-03 19:53 - 2015-03-04 21:49 - 00000000 ____D () C:\Program Files\VS Revo Group 2015-03-02 23:50 - 2015-03-02 23:50 - 10196653 _____ () C:\Users\Christian Rietz\Desktop\ChristianHBDklein.m4v 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\Documents\Eigene Google Gadgets 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Avg2014 2015-03-01 18:18 - 2015-03-01 18:18 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\AVG Web TuneUp 2015-03-01 18:17 - 2015-03-01 18:17 - 00118304 _____ () C:\Users\TEMP.Christian-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Apple Computer 2015-03-01 18:17 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Wondershare 2015-03-01 18:16 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\VirtualStore 2015-03-01 18:16 - 2015-03-01 18:17 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Google 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\RealNetworks 2015-03-01 18:16 - 2015-03-01 18:16 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\Real 2015-03-01 18:15 - 2015-03-01 18:52 - 00000000 ____D () C:\Users\TEMP.Christian-PC 2015-03-01 18:15 - 2013-09-27 19:12 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Local\Microsoft Help 2015-03-01 18:15 - 2013-09-26 20:06 - 00000000 ____D () C:\Users\TEMP.Christian-PC\AppData\Roaming\TuneUp Software 2015-02-27 20:28 - 2015-03-04 22:02 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\Playmo-Zoo 2015-02-26 00:25 - 2015-02-26 00:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox(25) 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Skype 2015-02-25 23:09 - 2015-02-25 23:09 - 00000000 ____D () C:\Program Files\Skype(27) 2015-02-22 17:12 - 2015-02-22 17:12 - 00001869 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities.lnk 2015-02-22 17:12 - 2015-02-22 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2015-02-22 17:12 - 2010-04-01 15:17 - 00030536 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2015-02-22 17:12 - 2010-04-01 15:11 - 00030024 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2015-02-22 17:12 - 2010-04-01 15:11 - 00021320 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2015-02-22 17:11 - 2015-02-22 17:12 - 00000000 ____D () C:\Program Files\TuneUp Utilities 2010 2015-02-22 17:10 - 2015-02-22 17:10 - 00000000 __SHD () C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} 2015-02-22 16:59 - 2015-02-22 16:59 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\1 Tuneup Utilities 2015-02-22 13:37 - 2015-03-04 14:59 - 00000000 ____D () C:\Users\Christian Rietz\Desktop\LOOKING for Season 2 2015-02-09 22:08 - 2015-02-09 22:09 - 00000000 ____D () C:\Program Files\QuickTime 2015-02-09 22:08 - 2015-02-09 22:08 - 00001730 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2015-02-09 22:08 - 2015-02-09 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2015-02-09 22:01 - 2015-02-09 22:03 - 42096984 _____ (Apple Inc.) C:\Users\Christian Rietz\Downloads\QuickTimeInstaller(1).exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-05 19:37 - 2006-11-02 11:33 - 01418806 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-03-05 19:35 - 2013-07-16 20:05 - 00000000 ____D () C:\FRST 2015-03-05 19:35 - 2013-07-11 17:09 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-05 19:35 - 2008-10-25 04:29 - 00000438 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job 2015-03-05 19:34 - 2013-07-11 14:20 - 01779604 _____ () C:\Windows\WindowsUpdate.log 2015-03-05 19:33 - 2014-02-03 20:53 - 00000000 ___RD () C:\Users\Christian Rietz\Dropbox 2015-03-05 19:33 - 2014-02-03 20:49 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Dropbox 2015-03-05 19:33 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.dat 2015-03-05 19:33 - 2008-10-25 04:12 - 00084921 _____ () C:\ProgramData\nvModes.001 2015-03-05 19:31 - 2013-07-11 17:09 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-05 19:31 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Home Cinema 2015-03-05 19:30 - 2008-01-21 03:47 - 00767408 _____ () C:\Windows\PFRO.log 2015-03-05 19:30 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-05 19:30 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-05 19:30 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-05 19:28 - 2006-11-02 14:01 - 00032540 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-03-05 19:17 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache 2015-03-05 19:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-03-05 18:59 - 2008-10-22 04:40 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-03-05 18:58 - 2013-10-06 11:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-03-05 18:57 - 2013-07-11 14:24 - 00000953 _____ () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-03-05 18:57 - 2013-07-11 14:23 - 00000919 _____ () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2015-03-05 18:50 - 2006-11-02 13:47 - 00408096 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Sidebar 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Photo Gallery 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Journal 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Collaboration 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Calendar 2015-03-05 18:45 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Movie Maker 2015-03-05 18:45 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\System 2015-03-05 18:44 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\system32\XPSViewer 2015-03-05 18:44 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Defender 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sk-SK 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\lv-LV 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ko-KR 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\hr-HR 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\et-EE 2015-03-05 18:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\IME 2015-03-05 18:43 - 2008-10-20 13:36 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\zh-TW 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\zh-CN 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\uk-UA 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\tr-TR 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\th-TH 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sv-SE 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\SLUI 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sl-SI 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ru-RU 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ro-RO 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pt-PT 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pt-BR 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pl-PL 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\nl-NL 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\nb-NO 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\lt-LT 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ja-JP 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\it-IT 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\hu-HU 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\he-IL 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\fr-FR 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\fi-FI 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\el-GR 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\de-DE 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\bg-BG 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ar-SA 2015-03-05 18:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers 2015-03-05 18:38 - 2008-10-20 04:37 - 00000000 ____D () C:\Windows\system32\RTCOM 2015-03-05 18:38 - 2006-11-02 13:52 - 00145158 _____ () C:\Windows\setupact.log 2015-03-05 18:26 - 2013-09-10 21:42 - 00000000 ____D () C:\ProgramData\MFAData 2015-03-05 17:39 - 2013-07-11 21:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-03-05 17:39 - 2013-07-11 21:03 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-03-05 17:38 - 2013-07-11 21:02 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Adobe 2015-03-05 17:29 - 2008-10-20 06:08 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2015-03-05 17:29 - 2008-10-20 06:08 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2015-03-05 17:29 - 2008-10-20 06:08 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2015-03-05 17:29 - 2008-10-20 06:08 - 00000000 ____D () C:\Program Files\Java 2015-03-05 12:01 - 2014-08-14 20:25 - 00000000 ____D () C:\ProgramData\Package Cache 2015-03-05 12:01 - 2013-07-16 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-03-05 12:01 - 2013-07-16 20:21 - 00000000 ____D () C:\Program Files\Avira 2015-03-05 11:51 - 2013-07-11 17:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-03-04 22:05 - 2013-07-11 17:24 - 00000000 ___RD () C:\Users\Christian Rietz\Documents\Programme 2015-03-04 21:40 - 2014-06-11 18:01 - 00000000 ____D () C:\Windows\system32\oodag 2015-03-04 19:38 - 2013-08-07 21:48 - 00000000 ____D () C:\Users\Christian Rietz\dwhelper 2015-03-04 14:59 - 2013-07-11 22:21 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\vlc 2015-03-04 13:36 - 2013-07-11 16:54 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Adobe 2015-03-04 13:36 - 2008-10-20 05:03 - 00000000 ____D () C:\ProgramData\Adobe 2015-03-04 13:06 - 2013-07-16 20:21 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-03-04 13:06 - 2013-07-16 20:21 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-03-03 21:47 - 2014-10-20 23:22 - 00000000 ____D () C:\Users\Christian Rietz\Downloads\streamtransport_1.1.6.2 2015-03-02 23:20 - 2013-09-24 22:44 - 00000000 ____D () C:\AdwCleaner 2015-03-02 22:37 - 2013-07-11 14:24 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Local\Google 2015-03-01 20:06 - 2014-04-17 18:10 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2015-03-01 20:06 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Skype 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool 2015-03-01 20:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration 2015-03-01 18:52 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc 2015-03-01 18:50 - 2013-07-11 14:23 - 00000000 ____D () C:\Users\Christian Rietz 2015-03-01 18:50 - 2006-11-02 11:22 - 46661632 _____ () C:\Windows\system32\config\software_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 33554432 _____ () C:\Windows\system32\config\components_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 19660800 _____ () C:\Windows\system32\config\system_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\security_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous 2015-03-01 18:50 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\default_previous 2015-03-01 18:45 - 2013-09-25 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ___RD () C:\Program Files\Skype 2015-03-01 18:38 - 2013-09-25 21:57 - 00000000 ____D () C:\Program Files\Common Files\Skype 2015-02-26 00:25 - 2013-09-25 21:57 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Skype 2015-02-22 17:10 - 2013-07-11 21:54 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-19 19:07 - 2014-02-03 20:50 - 00000000 ____D () C:\Users\Christian Rietz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox ==================== Files in the root of some directories ======= 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\StatusSheet 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\Stingers 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\String Comparison 2014-02-20 21:49 - 2014-02-20 21:49 - 0000268 ___RH () C:\Users\Christian Rietz\AppData\Roaming\System Image Utility 2014-03-26 19:46 - 2014-03-26 19:46 - 0000047 _____ () C:\Users\Christian Rietz\AppData\Roaming\WB.CFG 2013-08-02 19:34 - 2014-11-20 21:45 - 0001356 _____ () C:\Users\Christian Rietz\AppData\Local\d3d9caps.dat 2013-07-28 13:50 - 2015-01-25 21:05 - 0092672 _____ () C:\Users\Christian Rietz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2008-10-25 04:12 - 2015-03-05 19:33 - 0084921 _____ () C:\ProgramData\nvModes.001 2008-10-25 04:12 - 2015-03-05 19:33 - 0084921 _____ () C:\ProgramData\nvModes.dat 2014-02-20 21:49 - 2014-02-20 21:49 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT 2014-02-20 21:57 - 2014-02-20 22:12 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT 2014-02-20 21:53 - 2014-02-20 22:09 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\Strings 2014-02-20 21:57 - 2014-02-20 21:57 - 0000268 ___RH () C:\ProgramData\Super Strings 2014-02-20 21:53 - 2014-02-20 21:53 - 0000268 ___RH () C:\ProgramData\SupportPrinters Some content of TEMP: ==================== C:\Users\Christian Rietz\AppData\Local\Temp\avgnt.exe C:\Users\Christian Rietz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkdmqep.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-05 19:38 ==================== End Of Log ============================ |
05.03.2015, 19:51 | #14 |
| COULDN'T LOAD XPCOM - Firefox startet nichtCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 04-03-2015 Ran by Christian Rietz at 2015-03-05 19:40:39 Running from C:\Users\Christian Rietz\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 4.42 (HKLM\...\7-Zip) (Version: - ) ACDSee 9 Foto-Manager (HKLM\...\{7AE25201-3E12-4FA2-9E65-67CD475D9263}) (Version: 9.0.55 - ACD Systems Ltd.) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Photoshop CS (HKLM\...\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}) (Version: CS - Adobe Systems, Inc.) Adobe Reader 9 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A90000000001}) (Version: 9.0.0 - Adobe Systems Incorporated) Adobe Shockwave Player 11 (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.) Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E14ADE0E-75F3-4A46-87E5-26692DD626EC}) (Version: 6.1.0.13 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArcSoft Panorama Maker 6 (HKLM\...\{DABFD34E-BE68-4BC6-9254-5D7A7FF76B99}) (Version: 6.0.8.85 - ArcSoft) AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4800 - AVG Technologies) AVG 2014 (Version: 14.0.3614 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4257 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4800 - AVG Technologies) Hidden AVG Web TuneUp (HKLM\...\AVG Web TuneUp) (Version: 3.2.0.18 - AVG Technologies) Avira (HKLM\...\{d9ed6dcf-6bfc-4fbb-802e-81dd5b767d6e}) (Version: 1.1.32.25147 - Avira Operations & Co. KG) Avira (Version: 1.1.32.25147 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 15.0.8.650 - Avira) Avira SearchFree Toolbar plus Web Protection (HKLM\...\{41564952-412D-5637-00A7-A758B70C0201}) (Version: 12.2.1.477 - Ask Partner Network) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Corel Graphics Suite 11 (HKLM\...\InstallShield_{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}) (Version: 11 - Corel Corporation) Corel Graphics Suite 11 (Version: 11 - Corel Corporation) Hidden Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation) CorelDRAW Essential Edition 3 (HKLM\...\_{ADDBE07D-95B8-4789-9C76-187FFF9624B4}) (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) Hidden CyberLink MediaShow (HKLM\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 4.1.2019 - CyberLink Corp.) CyberLink PhotoNow (HKLM\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.5203 - CyberLink Corp.) CyberLink PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2209a - CyberLink Corp.) CyberLink PowerDVD (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 7.0.3118.0 - PowerDVDCorp.) CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0815 - CyberLink Corp.) CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.2109 - CyberLink Corp.) DE (Version: 3.0 - Corel Corporation) Hidden Dolby Control Center (HKLM\...\{70E8EBD5-78C9-4258-B20A-5098CCA000F0}) (Version: 1.1.0601 - Dolby) Dropbox (HKU\S-1-5-21-209139463-1928718786-3223491114-1000\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.) Free YouTube Download version 3.2.48.1015 (HKLM\...\Free YouTube Download_is1) (Version: 3.2.48.1015 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.48.1015 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.48.1015 - DVDVideoSoft Ltd.) Google Chrome (HKLM\...\Google Chrome) (Version: 41.0.2272.76 - Google Inc.) Google Desktop (HKLM\...\Google Desktop) (Version: - - Google) Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden iTunes (HKLM\...\{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}) (Version: 11.0.4.4 - Apple Inc.) MAGIX Screenshare (HKLM\...\{A7B517E2-07EB-47BA-877B-3F174FB7760B}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM\...\{9D5B0618-2EFA-4DAA-9B53-A546992824EA}) (Version: 7.0.2.6 - MAGIX AG) MakeDisc (HKLM\...\{B145EC69-66F5-11D8-9D75-000129760D75}) (Version: 3.0.2601 - CyberLink Corp.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 36.0 (x86 de) (HKLM\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 36.0 - Mozilla) MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon) Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.9.0 - Nikon) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) O&O Defrag Free Edition (HKLM\...\{E29CFB36-F070-4612-8DB5-7038161B6294}) (Version: 14.1.431 - O&O Software GmbH) Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.5.0 - Nikon) QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) RealDownloader (Version: 1.3.2 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5704 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: 3.0.1.3 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden Samplitude 11 Silver (HKLM\...\MAGIX_MSI_sam11silver) (Version: 11.0.1.0 - MAGIX AG) Samplitude 11 Silver (Version: 11.0.1.0 - MAGIX AG) Hidden Samplitude Music Studio 2008 Trial 14.0.2.0 (D) (HKLM\...\Samplitude Music Studio 2008 Trial D) (Version: 14.0.2.0 - MAGIX AG) Skype™ 6.7 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.7.102 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.2.2.0 - Synaptics) TuneUp Utilities (HKLM\...\TuneUp Utilities) (Version: 9.0.4100.12 - TuneUp Software) TuneUp Utilities (Version: 9.0.4100.12 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (Version: 9.0.4100.12 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update Manager (Version: 4.60 - Corel Corporation) Hidden VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.9.0 - Nikon) Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN) Windows Live Anmelde-Assistent (HKLM\...\{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}) (Version: 5.000.818.6 - Microsoft Corporation) Windows Live Fotogalerie (HKLM\...\{A1D08B90-AE1A-4885-AC29-731496FD397E}) (Version: 12.0.1347.0718 - Microsoft Corporation) Windows Live installer (HKLM\...\{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}) (Version: 12.0.1471.1025 - Microsoft Corporation) Windows Live Mail (HKLM\...\{82F2B38B-1426-443D-874C-AC25675E7BEB}) (Version: 12.0.1606.1023 - Microsoft Corporation) Windows Live Messenger (HKLM\...\{2B091530-69AA-442E-AB09-39ED06B58220}) (Version: 8.5.1302.1018 - Microsoft Corporation) Windows Live Writer (HKLM\...\{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5}) (Version: 12.0.1370.0325 - Microsoft Corporation) X10 Hardware(TM) (HKLM\...\X10Hardware) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-209139463-1928718786-3223491114-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Restore Points ========================= 05-03-2015 12:02:24 Windows Update 05-03-2015 18:06:09 Windows Vista™ Service Pack 2 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {2A6345ED-9E31-48E2-AAA9-1B8FE0162021} - System32\Tasks\Real Player-Online-Aktualisierungsprogramm => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-07-11] (RealNetworks, Inc.) Task: {55EEAAEB-9142-4D42-8386-DC56C99A5F5F} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {5C0ECDDC-2000-49E2-903C-6D50008CE73C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-05] (Adobe Systems Incorporated) Task: {635C392F-D422-40B8-99A5-4F0DD50828BD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.) Task: {7BAB9B3A-24B1-4B7B-AE0D-22DE6589D5B2} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {932074F6-FEAE-4965-AE0E-62D04A8E95B4} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe [2013-04-16] (RealNetworks, Inc.) Task: {993A7B12-0956-40B2-85A6-74F02B81D11A} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {AC667962-B3FC-416F-B372-14A3F0B4107B} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe [2010-04-01] (TuneUp Software) Task: {C5C8E683-4485-4155-982B-47742639C45B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.) Task: {DAB7D552-09F1-47AC-AC6D-850CF353F9F6} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-209139463-1928718786-3223491114-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {F4B5D53B-8440-415B-9719-9419C4D509F1} - System32\Tasks\Real Networks Scheduler => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-07-11] (RealNetworks, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job => C:\Windows\system32\msfeedssync.exe ==================== Loaded Modules (whitelisted) ============== 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2007-06-05 12:20 - 2007-06-05 12:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2013-04-16 02:07 - 2013-04-16 02:07 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe 2008-10-22 06:21 - 2008-06-28 01:00 - 00241734 _____ () C:\Program Files\CyberLink\Shared Files\RichVideo.exe 2015-02-12 13:57 - 2015-02-12 13:57 - 00245760 _____ () C:\Program Files\Avira\My Avira\System.ComponentModel.Composition.dll 2014-10-20 22:38 - 2014-08-05 09:22 - 01489408 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll 2014-10-20 22:38 - 2014-05-19 16:19 - 00137728 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00750080 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-03-05 19:32 - 2015-03-05 19:32 - 00043008 _____ () c:\Users\Christian Rietz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkdmqep.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00047616 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\libEGL.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00865280 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00200704 _____ () C:\Users\Christian Rietz\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll 2015-02-09 21:58 - 2015-03-05 17:39 - 16852144 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-209139463-1928718786-3223491114-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\system32\oobe\info\wallpaper1.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-209139463-1928718786-3223491114-500 - Administrator - Disabled) Christian Rietz (S-1-5-21-209139463-1928718786-3223491114-1000 - Administrator - Enabled) => C:\Users\Christian Rietz Gast (S-1-5-21-209139463-1928718786-3223491114-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/05/2015 07:33:24 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/05/2015 07:31:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2015 07:24:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung plugin-container.exe, Version 36.0.0.5531, Zeitstempel 0x54eb029a, fehlerhaftes Modul mozalloc.dll, Version 36.0.0.5531, Zeitstempel 0x54eaf3b7, Ausnahmecode 0x80000003, Fehleroffset 0x00001e02, Prozess-ID 0x17b8, Anwendungsstartzeit plugin-container.exe0. Error: (03/05/2015 06:58:57 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/05/2015 06:58:57 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/05/2015 06:57:41 PM) (Source: ESENT) (EventID: 215) (User: ) Description: WinMail (1452) WindowsMail0: Die Sicherung wurde abgebrochen, weil sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen wurde. Error: (03/05/2015 06:54:53 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2015 06:51:22 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2015 06:34:43 PM) (Source: MsiInstaller) (EventID: 11722) (User: Christian-PC) Description: Produkt: Java 8 Update 40 -- Fehler 1722. Es liegt ein Problem mit diesem Windows Installer-Paket vor. Ein Programm, das im Rahmen der Installation ausgeführt wurde, wurde nicht erfolgreich abgeschlossen. Wenden Sie sich an den Support oder den Hersteller des Pakets. Aktion: installexe, Pfad: C:\Program Files\Java\jre1.8.0_40\installer.exe, Befehl: /s INSTALLDIR="C:\Program Files\Java\jre1.8.0_40\\" REPAIRMODE=0 Error: (03/05/2015 06:04:49 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm jxpiinstall.exe, Version 8.0.400.25 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: 15c4 Anfangszeit: 01d0576142c7a42e Zeitpunkt der Beendigung: 0 System errors: ============= Error: (03/05/2015 07:31:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (03/05/2015 06:51:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (03/05/2015 06:37:52 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED} Error: (03/05/2015 04:45:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (03/05/2015 04:44:03 PM) (Source: HTTP) (EventID: 15016) (User: ) Description: \Device\Http\ReqQueueKerberos Error: (03/05/2015 11:53:21 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (03/05/2015 11:51:34 AM) (Source: HTTP) (EventID: 15016) (User: ) Description: \Device\Http\ReqQueueKerberos Error: (03/04/2015 11:38:48 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: AVGIDSAgent Error: (03/04/2015 09:25:56 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (03/04/2015 01:01:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Microsoft Office Sessions: ========================= Error: (07/28/2013 02:06:52 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 9 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2015-03-05 19:36:38.085 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-05 19:36:37.981 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-05 19:36:37.882 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-05 19:36:37.780 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-05 19:36:37.477 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-05 19:36:37.212 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-05 19:36:37.065 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-05 19:36:36.835 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-05 18:06:01.146 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-03-05 18:06:01.052 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz Percentage of memory in use: 92% Total physical RAM: 2301.44 MB Available physical RAM: 165.67 MB Total Pagefile: 4835.95 MB Available Pagefile: 1953.45 MB Total Virtual: 2047.88 MB Available Virtual: 1915.33 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:141.25 GB) (Free:48.34 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:15.81 GB) (Free:4.4 GB) FAT32 Drive g: (Volume) (Fixed) (Total:141.01 GB) (Free:127.5 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: DAE4C35C) Partition 1: (Active) - (Size=141.3 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=141 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15.8 GB) - (Type=0C) ==================== End Of Log ============================ Allerdings ist seitdem Mozilla wieder wahnsinnig langsam. Gestern Abend funktionierte eigentlich alles ganz gut... |
06.03.2015, 10:48 | #15 |
/// the machine /// TB-Ausbilder | COULDN'T LOAD XPCOM - Firefox startet nicht Setz FF nochmal komplett zurück.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu COULDN'T LOAD XPCOM - Firefox startet nicht |
andere, anderen, chris, christian, could, couldn't load xpcom, durchgeführt, dvdvideosoft ltd., ellung, firefox, liste, meldung, neustart, newtab, problem, secure search, starte, startet, startet nicht, super, system image, systemwiederherstellung, vtoolbarupdater, xpcom |