1. Also, beim dem eset scanner hat er mir 2 Funde angezeigt (vermutlich einen mehr, weil ich auch ne externe Festplatte angeschlossen habe?!). Sind die Funde jetzt entfernt worden?
2. Außerdem: als ich das Programm geschlossen habe, wurde angezeigt, dass der eset scanner nicht richtig installiert wurde. Wie würde ich das merken? Soll ich alles nochmal machen?
3. Und noch ne Frage zu der Anitmalware, die den ersten Fund gemeldet hat: der erste Fund ist ja da in Quarantäne. Und ich würde das ganz gerne deinstalllieren, da es nur eine Testversion war. Muss ich dabei was beachten oder kann ich es einfach deinstallieren? Nun die gewünschten log-files:
ESETSmartInstaller@High as downloader log:
Can not read file from internet.ESETSmartInstaller@High as downloader log:
Can not read file from internet.# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=4d9de5cc3ca4c1469d6e8112e8202b79
# engine=14944
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-29 06:45:53
# local_time=2013-08-29 08:45:53 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1799 16775165 100 96 8867 148473258 1638 0
# compatibility_mode=5892 16776574 100 100 15914996 215325859 0 0
# scanned=230720
# found=2
# cleaned=0
# scan_time=6692
sh=FA3D088F2B6B17BC71B8619E1D7D2D554D45C0FE ft=0 fh=0000000000000000 vn="INF/Autorun worm" ac=I fn="D:\autorun.inf"
sh=C775756621FD83B0D5DE135CCB7F7497237AE9D5 ft=1 fh=34aaa2cc4a9eb97d vn="Win32/AutoRun.VB.ET worm" ac=I fn="D:\Renate.exe"
Results of screen317's Security Check version 0.99.72
Windows Vista Service Pack 2 x64 (UAC is enabled)
Internet Explorer 8
Out of date!
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 25
Adobe Reader 9
Adobe Reader out of Date!
Mozilla Firefox (23.0.1)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by Notebook (administrator) on 29-08-2013 21:10:59
Running from C:\Users\Notebook\Desktop
Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
() C:\Windows\System32\WLTRYSVC.EXE
(Dell Inc.) C:\Windows\System32\bcmwltry.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Dell Inc.) C:\Windows\System32\WLTRAY.EXE
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(FileHippo.com) C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [305664 2009-03-31] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Windows\system32\WLTRAY.exe [4119552 2008-12-21] (Dell Inc.)
HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\QuickSet.exe [2115664 2009-03-27] (Dell Inc.)
HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-06-15] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [462848 2009-03-31] (IDT, Inc.)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [x]
HKCU\...\Run: [FileHippo.com] - C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [248832 2010-08-09] (FileHippo.com)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Microsoft Default Manager] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [250192 2009-04-24] (Microsoft Corporation)
HKLM-x32\...\Run: [PDVDDXSrv] - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128232 2009-02-05] (CyberLink Corp.)
HKLM-x32\...\Run: [DellSupportCenter] - "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2013-08-28] (RealNetworks, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hotmail.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://spiegel-online.de/
hxxp://www.sparkasse-regensburg.de/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {F5BA914F-3D00-4EC7-A916-4BE2094181D2} URL = hxxp://www.google.de/search?q={searchTerms}
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\ex7cij0m.default
FF SelectedSearchEngine: Yahoo
FF Homepage: hxxp://www.hotmail.de/|hxxp://spiegel-online.de/|hxxp://www.sparkasse-regensburg.de/
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\2.0.31005.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-03] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 wltrysvc; C:\Windows\System32\WLTRYSVC.EXE [32768 2008-12-21] ()
R2 yksvc; RUNDLL32.EXE ykx64coinst,serviceStartProc [x]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-01] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-29 18:38 - 2013-08-29 18:38 - 00891115 _____ C:\Users\Notebook\Desktop\SecurityCheck.exe
2013-08-28 18:54 - 2013-08-28 18:54 - 00001226 _____ C:\Users\Notebook\Desktop\JRT.txt
2013-08-28 18:47 - 2013-08-28 18:47 - 00000000 ____D C:\Windows\ERUNT
2013-08-28 18:40 - 2013-08-28 18:40 - 00001445 _____ C:\Users\Notebook\Desktop\AdwCleaner[S0].txt
2013-08-28 18:37 - 2013-08-28 18:38 - 00000000 ____D C:\AdwCleaner
2013-08-28 18:36 - 2013-08-28 18:36 - 01021434 _____ (Thisisu) C:\Users\Notebook\Desktop\JRT.exe
2013-08-28 18:35 - 2013-08-28 18:35 - 00994642 _____ C:\Users\Notebook\Desktop\adwcleaner.exe
2013-08-28 15:19 - 2013-08-28 15:19 - 00003998 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
2013-08-28 15:19 - 2013-08-28 15:19 - 00003440 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2013-08-28 15:19 - 2013-08-28 15:19 - 00003208 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2013-08-28 15:19 - 2013-08-28 15:19 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows
2013-08-28 15:18 - 2013-08-28 15:19 - 00000000 ____D C:\Program Files\My Dell
2013-08-28 15:03 - 2013-08-28 15:04 - 00022594 _____ C:\Users\Notebook\Desktop\Addition.txt
2013-08-28 15:01 - 2013-08-28 15:01 - 00000000 ____D C:\FRST
2013-08-28 14:59 - 2013-08-28 14:59 - 01579080 _____ (Farbar) C:\Users\Notebook\Desktop\FRST64.exe
2013-08-28 13:56 - 2013-08-28 13:56 - 00000950 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-28 13:56 - 2013-08-28 13:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-28 13:56 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-28 13:52 - 2013-08-29 18:09 - 00003352 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3662071480-2160519904-3827952930-1000
2013-08-28 13:52 - 2013-08-29 18:09 - 00003224 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3662071480-2160519904-3827952930-1000
2013-08-28 13:52 - 2013-08-28 13:52 - 00000000 ____D C:\Users\Notebook\AppData\Roaming\RealNetworks
2013-08-28 13:51 - 2013-08-28 13:51 - 00201872 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2013-08-28 13:51 - 2013-08-28 13:51 - 00006656 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2013-08-28 13:51 - 2013-08-28 13:51 - 00005632 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2013-08-28 13:51 - 2013-08-28 13:51 - 00000000 ____D C:\ProgramData\RealNetworks
2013-08-28 13:51 - 2013-08-28 13:51 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-08-28 13:50 - 2013-08-28 13:52 - 00000000 ____D C:\ProgramData\Real
2013-08-28 13:46 - 2013-08-28 13:46 - 00000890 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\Users\Notebook\AppData\Roaming\Mozilla
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\Users\Notebook\AppData\Local\Mozilla
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\ProgramData\Mozilla
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-28 13:37 - 2013-08-28 13:37 - 00001840 _____ C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update Checker.lnk
2013-08-28 13:37 - 2013-08-28 13:37 - 00000000 ____D C:\Program Files (x86)\FileHippo.com
2013-08-28 13:24 - 2013-08-28 13:24 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-28 13:24 - 2013-08-28 13:24 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-28 13:24 - 2013-08-28 13:24 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-28 13:24 - 2013-08-28 13:24 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-28 13:24 - 2013-08-28 13:24 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-28 13:24 - 2013-08-02 16:06 - 01706496 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-28 13:24 - 2013-08-02 06:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-27 10:57 - 2013-08-27 10:57 - 00002117 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-08-22 10:23 - 2013-08-22 10:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2013-08-18 10:40 - 2013-07-24 20:33 - 12509696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-18 10:40 - 2013-07-24 20:33 - 09340928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-18 10:40 - 2013-07-24 20:33 - 00742912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-18 10:40 - 2013-07-24 02:32 - 11111936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-18 10:40 - 2013-07-24 02:32 - 06016512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-18 10:40 - 2013-07-09 14:04 - 01585256 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-18 10:40 - 2013-07-09 14:04 - 01168088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-18 10:40 - 2013-07-08 06:51 - 04691904 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-18 10:40 - 2013-07-08 06:20 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-18 10:40 - 2013-07-08 06:18 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-18 10:40 - 2013-07-08 06:15 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-18 10:40 - 2013-07-08 06:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-08-18 10:40 - 2013-07-08 03:39 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-18 10:40 - 2013-07-08 03:39 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-18 10:40 - 2013-07-08 03:39 - 00002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-18 10:39 - 2013-07-24 20:33 - 02356736 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 01538560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-18 10:39 - 2013-07-24 20:33 - 01489408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-08-18 10:39 - 2013-07-24 20:33 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-18 10:39 - 2013-07-24 02:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-18 10:39 - 2013-07-24 02:33 - 00916480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-18 10:39 - 2013-07-24 02:33 - 00611840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2013-08-18 10:39 - 2013-07-24 02:33 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-08-18 10:39 - 2013-07-24 02:33 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 02004992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 01469440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-08-18 10:39 - 2013-07-24 02:32 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00387584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00043520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-08-18 10:39 - 2013-07-24 02:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-18 10:39 - 2013-07-24 02:22 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-08-18 10:39 - 2013-07-24 02:09 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-18 10:39 - 2013-07-24 02:09 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-18 10:39 - 2013-07-24 02:09 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-18 10:39 - 2013-07-24 02:09 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-08-18 10:39 - 2013-07-24 01:56 - 00385024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-08-18 10:39 - 2013-07-24 01:49 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-18 10:39 - 2013-07-24 01:49 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2013-08-18 10:39 - 2013-07-24 01:49 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-08-18 10:39 - 2013-07-24 01:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-08-18 10:27 - 2013-07-17 22:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-18 10:27 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-18 10:27 - 2013-07-10 11:47 - 00677888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-18 10:27 - 2013-07-10 11:42 - 01303552 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-18 10:27 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-18 10:27 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-18 10:27 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-18 10:27 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-18 10:27 - 2013-07-08 06:15 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-18 10:27 - 2013-07-08 06:12 - 01276416 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-18 10:27 - 2013-07-08 06:12 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-18 10:27 - 2013-07-08 06:12 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-18 10:27 - 2013-07-05 06:45 - 01423808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-18 10:27 - 2013-06-15 15:27 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2013-08-18 10:27 - 2013-06-15 13:38 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-16 20:50 - 2013-08-16 20:53 - 00000000 ____D C:\Windows\system32\MRT
==================== One Month Modified Files and Folders =======
2013-08-29 21:10 - 2013-08-29 21:10 - 00001031 _____ C:\Users\Notebook\Desktop\checkup.txt
2013-08-29 21:07 - 2012-05-27 13:34 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-29 20:43 - 2012-08-29 13:30 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-29 20:08 - 2006-11-02 17:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-29 20:08 - 2006-11-02 17:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-29 18:41 - 2008-01-21 13:10 - 01445546 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-29 18:41 - 2008-01-21 13:09 - 00628992 _____ C:\Windows\system32\perfh007.dat
2013-08-29 18:41 - 2008-01-21 13:09 - 00126704 _____ C:\Windows\system32\perfc007.dat
2013-08-29 18:38 - 2013-08-29 18:38 - 00891115 _____ C:\Users\Notebook\Desktop\SecurityCheck.exe
2013-08-29 18:24 - 2009-09-23 19:51 - 00003982 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{48C094BC-A2A6-42F0-8064-E2A12E55E201}
2013-08-29 18:24 - 2009-09-23 19:51 - 00000424 ____H C:\Windows\Tasks\User_Feed_Synchronization-{48C094BC-A2A6-42F0-8064-E2A12E55E201}.job
2013-08-29 18:15 - 2009-09-17 09:13 - 01462114 _____ C:\Windows\WindowsUpdate.log
2013-08-29 18:09 - 2013-08-28 13:52 - 00003352 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3662071480-2160519904-3827952930-1000
2013-08-29 18:09 - 2013-08-28 13:52 - 00003224 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3662071480-2160519904-3827952930-1000
2013-08-29 18:08 - 2012-08-29 13:30 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-29 18:08 - 2006-11-02 17:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-28 20:19 - 2006-11-02 17:42 - 00032510 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-28 18:54 - 2013-08-28 18:54 - 00001226 _____ C:\Users\Notebook\Desktop\JRT.txt
2013-08-28 18:47 - 2013-08-28 18:47 - 00000000 ____D C:\Windows\ERUNT
2013-08-28 18:40 - 2013-08-28 18:40 - 00001445 _____ C:\Users\Notebook\Desktop\AdwCleaner[S0].txt
2013-08-28 18:38 - 2013-08-28 18:37 - 00000000 ____D C:\AdwCleaner
2013-08-28 18:36 - 2013-08-28 18:36 - 01021434 _____ (Thisisu) C:\Users\Notebook\Desktop\JRT.exe
2013-08-28 18:35 - 2013-08-28 18:35 - 00994642 _____ C:\Users\Notebook\Desktop\adwcleaner.exe
2013-08-28 15:19 - 2013-08-28 15:19 - 00003998 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
2013-08-28 15:19 - 2013-08-28 15:19 - 00003440 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2013-08-28 15:19 - 2013-08-28 15:19 - 00003208 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2013-08-28 15:19 - 2013-08-28 15:19 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows
2013-08-28 15:19 - 2013-08-28 15:18 - 00000000 ____D C:\Program Files\My Dell
2013-08-28 15:19 - 2011-07-15 16:23 - 00000000 ____D C:\Program Files\Dell Support Center
2013-08-28 15:18 - 2009-09-17 14:47 - 00000000 ____D C:\ProgramData\PCDr
2013-08-28 15:04 - 2013-08-28 15:03 - 00022594 _____ C:\Users\Notebook\Desktop\Addition.txt
2013-08-28 15:01 - 2013-08-28 15:01 - 00000000 ____D C:\FRST
2013-08-28 14:59 - 2013-08-28 14:59 - 01579080 _____ (Farbar) C:\Users\Notebook\Desktop\FRST64.exe
2013-08-28 14:18 - 2013-03-01 15:30 - 00000000 ____D C:\Windows\pss
2013-08-28 14:18 - 2009-09-23 18:39 - 00000000 ___RD C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-28 14:05 - 2008-01-21 05:26 - 00485276 _____ C:\Windows\PFRO.log
2013-08-28 13:56 - 2013-08-28 13:56 - 00000950 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-28 13:56 - 2013-08-28 13:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-28 13:52 - 2013-08-28 13:52 - 00000000 ____D C:\Users\Notebook\AppData\Roaming\RealNetworks
2013-08-28 13:52 - 2013-08-28 13:50 - 00000000 ____D C:\ProgramData\Real
2013-08-28 13:52 - 2009-09-24 14:27 - 00000000 ____D C:\Users\Notebook\AppData\Roaming\Real
2013-08-28 13:51 - 2013-08-28 13:51 - 00201872 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2013-08-28 13:51 - 2013-08-28 13:51 - 00006656 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2013-08-28 13:51 - 2013-08-28 13:51 - 00005632 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2013-08-28 13:51 - 2013-08-28 13:51 - 00000000 ____D C:\ProgramData\RealNetworks
2013-08-28 13:51 - 2013-08-28 13:51 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-08-28 13:51 - 2009-09-24 14:27 - 00000000 ____D C:\Program Files (x86)\Real
2013-08-28 13:50 - 2009-09-24 14:27 - 00272896 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2013-08-28 13:50 - 2009-09-23 18:39 - 00000000 ___RD C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-08-28 13:50 - 2009-09-17 14:55 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2013-08-28 13:50 - 2009-09-17 14:55 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2013-08-28 13:46 - 2013-08-28 13:46 - 00000890 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\Users\Notebook\AppData\Roaming\Mozilla
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\Users\Notebook\AppData\Local\Mozilla
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\ProgramData\Mozilla
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-28 13:46 - 2013-08-28 13:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-28 13:43 - 2009-09-24 13:12 - 00000000 ____D C:\Users\Notebook\AppData\Local\Paint.NET
2013-08-28 13:42 - 2009-09-23 19:34 - 00000992 _____ C:\Users\Public\Desktop\Paint.NET.lnk
2013-08-28 13:41 - 2009-09-23 19:34 - 00000000 ____D C:\Program Files\Paint.NET
2013-08-28 13:37 - 2013-08-28 13:37 - 00001840 _____ C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update Checker.lnk
2013-08-28 13:37 - 2013-08-28 13:37 - 00000000 ____D C:\Program Files (x86)\FileHippo.com
2013-08-28 13:24 - 2013-08-28 13:24 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-28 13:24 - 2013-08-28 13:24 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-28 13:24 - 2013-08-28 13:24 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-28 13:24 - 2013-08-28 13:24 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-28 13:24 - 2013-08-28 13:24 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-28 13:24 - 2012-06-24 13:53 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll
2013-08-28 13:24 - 2010-10-24 18:53 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-08-27 10:57 - 2013-08-27 10:57 - 00002117 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-08-27 10:56 - 2012-08-29 13:30 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-22 10:23 - 2013-08-22 10:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2013-08-22 10:23 - 2006-11-02 17:27 - 00240494 _____ C:\Windows\setupact.log
2013-08-22 10:22 - 2006-11-02 15:33 - 00000000 ____D C:\Windows\rescache
2013-08-22 10:15 - 2012-05-27 13:34 - 00003736 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-22 10:15 - 2012-05-27 13:33 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-22 10:15 - 2012-05-27 13:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-16 20:53 - 2013-08-16 20:50 - 00000000 ____D C:\Windows\system32\MRT
2013-08-16 20:50 - 2006-11-02 14:35 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-08-09 20:09 - 2012-08-29 13:22 - 00000000 ____D C:\Users\Notebook\Desktop\Sonstiges
2013-08-02 16:06 - 2013-08-28 13:24 - 01706496 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-02 06:09 - 2013-08-28 13:24 - 01548288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
Files to move or delete:
====================
C:\Users\Notebook\AppData\Local\Temp\AskSLib.dll
C:\Users\Notebook\AppData\Local\Temp\Connection.dll
C:\Users\Notebook\AppData\Local\Temp\Dbwork.dll
C:\Users\Notebook\AppData\Local\Temp\Dialogs.dll
C:\Users\Notebook\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Notebook\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Notebook\AppData\Local\Temp\IPC.dll
C:\Users\Notebook\AppData\Local\Temp\Jobs.dll
C:\Users\Notebook\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe
C:\Users\Notebook\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Notebook\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe
C:\Users\Notebook\AppData\Local\Temp\jre-6u30-windows-i586-iftw-rv.exe
C:\Users\Notebook\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Users\Notebook\AppData\Local\Temp\jre-6u32-windows-i586-iftw.exe
C:\Users\Notebook\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe
C:\Users\Notebook\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
C:\Users\Notebook\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Notebook\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Notebook\AppData\Local\Temp\libeay32.dll
C:\Users\Notebook\AppData\Local\Temp\mfc80.dll
C:\Users\Notebook\AppData\Local\Temp\msvcp80.dll
C:\Users\Notebook\AppData\Local\Temp\msvcr80.dll
C:\Users\Notebook\AppData\Local\Temp\Permissions.dll
C:\Users\Notebook\AppData\Local\Temp\QFA.EXE
C:\Users\Notebook\AppData\Local\Temp\QfaInvoke.dll
C:\Users\Notebook\AppData\Local\Temp\Quarantine.exe
C:\Users\Notebook\AppData\Local\Temp\Report.dll
C:\Users\Notebook\AppData\Local\Temp\SkinMagic.dll
C:\Users\Notebook\AppData\Local\Temp\Smarti.dll
C:\Users\Notebook\AppData\Local\Temp\SmartiComm.dll
C:\Users\Notebook\AppData\Local\Temp\SmartIcon.exe
C:\Users\Notebook\AppData\Local\Temp\SmartSurfer.exe
C:\Users\Notebook\AppData\Local\Temp\smurf.dll
C:\Users\Notebook\AppData\Local\Temp\SmurfService.dll
C:\Users\Notebook\AppData\Local\Temp\SmurfService.exe
C:\Users\Notebook\AppData\Local\Temp\SmurfUpd.exe
C:\Users\Notebook\AppData\Local\Temp\SmurfUpdEng.exe
C:\Users\Notebook\AppData\Local\Temp\Sqlite.dll
C:\Users\Notebook\AppData\Local\Temp\ssleay32.dll
C:\Users\Notebook\AppData\Local\Temp\Threads.dll
C:\Users\Notebook\AppData\Local\Temp\Vars.dll
C:\Users\Notebook\AppData\Local\Temp\WEBDE_ServiceInstall.exe
C:\Users\Notebook\AppData\Local\Temp\Wizzard.dll
C:\Users\Notebook\AppData\Local\Temp\xmlparse.dll
C:\Users\Notebook\AppData\Local\Temp\xmltok.dll
C:\Users\Notebook\AppData\Local\Temp\{0B366C17-4154-4D3E-BE1A-0C2F023553D4}-GoogleEarth-Win-Bundle-7.1.1.1888.exe
C:\Users\Notebook\AppData\Local\Temp\{3F8FA7EE-CC38-4F2E-AF96-AB58A9119761}-GoogleEarth-Win-Bundle-7.1.1.1888.exe
C:\Users\Notebook\AppData\Local\Temp\{4CA146DB-6C38-4969-A8D0-D1419932BBC1}-GoogleEarth-Win-Bundle-7.1.1.1888.exe
C:\Users\Notebook\AppData\Local\Temp\{64B71A84-25A4-4C58-ADA8-800EF31AB4FE}-GoogleEarth-Win-Bundle-7.0.3.8542.exe
C:\Users\Notebook\AppData\Local\Temp\{672E0877-CF4F-43F7-90C8-CE2994E0FD50}-GoogleEarth-Win-Bundle-7.0.3.8542.exe
C:\Users\Notebook\AppData\Local\Temp\{A51F5C72-0E73-413E-9907-AA3727A6F527}-GoogleEarth-Win-Bundle-7.0.3.8542.exe
C:\Users\Notebook\AppData\Local\Temp\{BC21B5B5-7508-4B06-B3CE-DFEF7895E1F7}-GoogleEarth-Win-Bundle-7.1.1.1888.exe
C:\Users\Notebook\AppData\Local\Temp\{F11648AC-70F7-47AA-B0E7-73EF0F9B3874}-GoogleEarth-Win-Bundle-7.0.3.8542.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg7\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg7\setup.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg45\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg45\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg44\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg44\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg42\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg42\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg41\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg41\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg40\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg40\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg39\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg39\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg38\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg38\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg37\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg37\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg36\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg36\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg35\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg35\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg34\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg34\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg33\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg33\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg32\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg32\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg30\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg30\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg29\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg29\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg28\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg28\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg27\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg27\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg26\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg26\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg25\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg25\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg24\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg24\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg23\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg23\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg22\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg22\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg21\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg21\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg20\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg20\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg19\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg19\rnupgagent.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg18\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg18\setup.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg17\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg17\setup.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg16\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg16\setup.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg15\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg15\setup.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg14\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg14\setup.exe
C:\Users\Notebook\AppData\Local\Temp\~Upg13\install.dll
C:\Users\Notebook\AppData\Local\Temp\~Upg13\setup.exe
C:\Users\Notebook\AppData\Local\Temp\~rnsetup\pncrt.dll
C:\Users\Notebook\AppData\Local\Temp\~rnsetup\pnrs3260.dll
C:\Users\Notebook\AppData\Local\Temp\~rnsetu0\GEMSETUP\msvcr100.dll
C:\Users\Notebook\AppData\Local\Temp\~rnsetu0\GEMSETUP\pnrs3260.dll
C:\Users\Notebook\AppData\Local\Temp\{4DDA9E92-2FF5-4A60-B5EA-2D6F23D9395D}\InstallFlashPlayer.exe
C:\Users\Notebook\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_.exe
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\avmres.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\avwebloader.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\avwebloader.exe
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\avwebloadergui.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\msvcp100.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\msvcr100.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcimage.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_de.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_en.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_es.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_fr.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_it.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_jp.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_ko.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_nl.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_pt.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_ru.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_tr.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_zhcn.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\rcnwload_zhtw.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\scewxmlw.dll
C:\Users\Notebook\AppData\Local\Temp\RarSFX0\update.dll
C:\Users\Notebook\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\64bitProxy.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aebb.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aecore.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aeemu.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aeexp.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aegen.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aehelp.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aeheur.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aeoffice.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aepack.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aerdl.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aesbx.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aescn.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aescript.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\aevdf.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\apcfile.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ApnIC.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ApnStub.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ApnToolbarInstaller.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\AppRemover_64.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\AppRemover_API.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\AppRemover_CLI.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avacl.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avadmin.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avarkt.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avbb.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avcenter.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avconfig.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avconfig.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avesvc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avevtlog.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avgio.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avgnt.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avguard.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avinet.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avipc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avlode.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avmres.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avnotify.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avpref.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avreg.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avrep.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avrestart.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avscan.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avscplr.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avsda.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avsda64.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avsmtp.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avupgsvc.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avwebgrd.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avwebloader.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avwebloader.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avwebloadergui.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avwinll.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avwmi.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\avwsc.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccavscanex.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccev.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccevw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccgen.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccgenw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccgrdw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccguard.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\cchips.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\cclic.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\cclicw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccmsg.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccprofil.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccquamgr.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccquaw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccreport.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccrepow.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccscanw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccsched.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccschedw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccupdate.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccupdw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccwebtabs.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccwgrd.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccwgrdw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ccwkrlib.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\cfglib.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\extdlgfw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\fact.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gpavgio.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gpevtlog.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gpgavid.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gpgen.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gpgenrep.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gpgrd.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gpgui.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gpipc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gplegacy.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\gpschd.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\grdcore.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\guardgui.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\imp64b.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\inssda64.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\insthlp.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ipmgui.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\libapr-1.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\libapriconv-1.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\libaprutil-1.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\libcurl.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\libdb44.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\libeay32.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\licmgr.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\luke.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\mgrs.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\msgclient.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\msvcp80.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\msvcr80.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\netnt.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\onlcfg.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\presetup.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_ar.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_de.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_en.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_es.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_fr.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_it.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_jp.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_ko.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_nl.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_pt.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_ru.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_tr.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_zhcn.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_zhtw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\scewxmlw.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\sched.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\setup.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\setuppending.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\shlext.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\shlext64.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\sqlite3.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\ssleay32.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\thorwac.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\toastNotifier.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\unacev2.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\update.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\update.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\updext.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\updgui.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\updrgui.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\vcredist_x86.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\wksstats.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\wsctool.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\xp\avshadow.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\vista64\avipc64.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\vista64\avshadow.exe
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\avconfigrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\avesvcr.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\avevtrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\avnotify.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\avscanrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\avwebgrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccavscanexrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccevrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccgenrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccgrdrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\cchipsrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\cclicrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccmainrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccmsgrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccquarc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccreporc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccscanrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccscherc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccupdrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccwebtabsrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccwgrdrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\factrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\guardmsg.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\licmgr.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\lukeres.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\rchelp.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\rcimage.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\rctext.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\restartrc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\schedr.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\setup.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\updaterc.dll
C:\Users\Notebook\AppData\Local\Temp\avnwldrtemp\setup\de-de\updguirc.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\GoogleEarth.exe
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\earthps.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\geplugin.exe
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\ge_expat.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\googleearth_free.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\msvcp100.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\msvcr100.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\npgeplugin.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\plugin_ax.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\earthflashsol.exe
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\earthps.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\ge_expat.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\googleearth.exe
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\googleearth_free.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\gpsbabel.exe
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\msvcp100.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\msvcr100.dll
C:\Users\Notebook\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\Plugins\npgeinprocessplugin.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-29 18:15
==================== End Of Log ============================
--- --- ---