Froschkonig | 25.03.2014 22:51 | Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=623d3c561cb11a4bb0c1b43fbb8c7dd8
# engine=17615
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-03-25 09:17:07
# local_time=2014-03-25 10:17:07 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5122 16777214 66 65 97712 158592405 0 0
# compatibility_mode=5893 16776574 100 94 413682 147412077 0 0
# scanned=307656
# found=2
# cleaned=0
# scan_time=6234
sh=10767D23E452D75FE5DFC701B06DBABE360E0EE2 ft=1 fh=0930a45bc232d90d vn="a variant of Win32/Injector.BAFJ trojan" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\05ITmqxz.exe.vir"
sh=70C5579516301E4D1EA4ACE35132C0FA7ECD8BF7 ft=1 fh=bfea9d91d44e88a9 vn="a variant of Win32/Kryptik.BWJC trojan" ac=I fn="K:\Downloads\FirefoxSetup.exe" Code:
Results of screen317's Security Check version 0.99.80
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
McAfee Anti-Virus und Anti-Spyware
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
E-Finance Java
Java 7 Update 45
Java version out of Date!
Adobe Flash Player 12.0.0.77
Mozilla Firefox (28.0)
Google Chrome 33.0.1750.146
Google Chrome 33.0.1750.154 ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by ADMIN (administrator) on PCMUTTER on 25-03-2014 22:49:20
Running from C:\Users\ADMIN\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(McAfee, Inc.) C:\Windows\system32\mfevtps.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(ASBYTE) J:\PROGRAMME\ASBYTESYNCING.NET\SYNCING.NET\bin\SN_Service.exe
() C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe
() J:\PROGRAMME\Synology\Assistant\UsbClientService.exe
() C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Users\ADMIN\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(PCTV Systems S.à r.l.) C:\Program Files (x86)\Common Files\PCTV Systems\RemoTerm\remoterm.exe
(Adobe Systems Inc.) J:\PROGRAMME\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ASBYTE) J:\PROGRAMME\ASBYTESYNCING.NET\SYNCING.NET\bin\SyncingOLWatchService.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6468712 2012-03-20] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [2419512 2012-11-04] (Logitech, Inc.)
HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7406392 2012-11-29] (Logitech Inc.)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [403888 2012-08-23] (Acronis)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [6049096 2012-08-23] (Acronis)
HKLM-x32\...\Run: [AcronisTibMounterMonitor] - C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [943856 2012-07-24] (Acronis)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-01-28] (McAfee, Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\.DEFAULT\...\Run: [SyncService] - J:\PROGRAMME\ASBYTESYNCING.NET\SYNCING.NET\bin\SyncService.exe [1730144 2013-08-15] (ASBYTE)
HKU\S-1-5-21-684775682-3045372353-830408194-1000\...\Run: [SkyDrive] - C:\Users\ADMIN\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257224 2014-02-19] (Microsoft Corporation)
HKU\S-1-5-21-684775682-3045372353-830408194-1000\...\Run: [SyncService] - J:\PROGRAMME\ASBYTESYNCING.NET\SYNCING.NET\bin\SyncService.exe [1730144 2013-08-15] (ASBYTE)
HKU\S-1-5-21-684775682-3045372353-830408194-1000\...\Run: [RemoTerm.exe] - C:\Program Files (x86)\Common Files\PCTV Systems\RemoTerm\RemoTerm.exe [227160 2012-05-10] (PCTV Systems S.à r.l.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=ir_14_13_ie&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azyzy0C0A0FyBtCzy0D0CyEtN0D0Tzu0SzztCyEtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0FtDyEtD0BtDyBtG0B0AtCtDtG0CtB0FzytG0FyBzztDtGtD0F0C0CzzyEtD0E0A0FtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FyDyB0E0ByC0DtGyBtAtD0FtG0CtCtB0CtGyD0B0B0EtGtB0DyE0AyC0A0AtAyCyDtCzz2Q&cr=1893658731&ir=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF60F550500A7CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=ir_14_13_ie&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azyzy0C0A0FyBtCzy0D0CyEtN0D0Tzu0SzztCyEtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0FtDyEtD0BtDyBtG0B0AtCtDtG0CtB0FzytG0FyBzztDtGtD0F0C0CzzyEtD0E0A0FtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FyDyB0E0ByC0DtGyBtAtD0FtG0CtCtB0CtGyD0B0B0EtGtB0DyE0AyC0A0AtAyCyDtCzz2Q&cr=1893658731&ir=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=ir_14_13_ie&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azyzy0C0A0FyBtCzy0D0CyEtN0D0Tzu0SzztCyEtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0FtDyEtD0BtDyBtG0B0AtCtDtG0CtB0FzytG0FyBzztDtGtD0F0C0CzzyEtD0E0A0FtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FyDyB0E0ByC0DtGyBtAtD0FtG0CtCtB0CtGyD0B0B0EtGtB0DyE0AyC0A0AtAyCyDtCzz2Q&cr=1893658731&ir=
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_13_ie&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azyzy0C0A0FyBtCzy0D0CyEtN0D0Tzu0SzztCyEtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0FtDyEtD0BtDyBtG0B0AtCtDtG0CtB0FzytG0FyBzztDtGtD0F0C0CzzyEtD0E0A0FtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FyDyB0E0ByC0DtGyBtAtD0FtG0CtCtB0CtGyD0B0B0EtGtB0DyE0AyC0A0AtAyCyDtCzz2Q&cr=1893658731&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_13_ie&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azyzy0C0A0FyBtCzy0D0CyEtN0D0Tzu0SzztCyEtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0FtDyEtD0BtDyBtG0B0AtCtDtG0CtB0FzytG0FyBzztDtGtD0F0C0CzzyEtD0E0A0FtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FyDyB0E0ByC0DtGyBtAtD0FtG0CtCtB0CtGyD0B0B0EtGtB0DyE0AyC0A0AtAyCyDtCzz2Q&cr=1893658731&ir=
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_13_ie&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azyzy0C0A0FyBtCzy0D0CyEtN0D0Tzu0SzztCyEtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0FtDyEtD0BtDyBtG0B0AtCtDtG0CtB0FzytG0FyBzztDtGtD0F0C0CzzyEtD0E0A0FtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FyDyB0E0ByC0DtGyBtAtD0FtG0CtCtB0CtGyD0B0B0EtGtB0DyE0AyC0A0AtAyCyDtCzz2Q&cr=1893658731&ir=
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_13_ie&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azyzy0C0A0FyBtCzy0D0CyEtN0D0Tzu0SzztCyEtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0FtDyEtD0BtDyBtG0B0AtCtDtG0CtB0FzytG0FyBzztDtGtD0F0C0CzzyEtD0E0A0FtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FyDyB0E0ByC0DtGyBtAtD0FtG0CtCtB0CtGyD0B0B0EtGtB0DyE0AyC0A0AtAyCyDtCzz2Q&cr=1893658731&ir=
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No File
BHO-x32: Mega Browse - {4e6cd411-ce62-4584-97ff-6afbcf6900af} - C:\Program Files (x86)\Mega Browse\MegaBrowsebho.dll (Mega Browse)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: mysearchdial Helper Object - {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} - C:\Program Files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll (MySearchDial)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll (MySearchDial)
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
ShellExecuteHooks: CExecuteHook Object - {7B0E5486-E11D-437f-AC8B-7901C7D3FCCB} - J:\PROGRAMME\ASBYTESYNCING.NET\SYNCING.NET\bin\ShellUI.dll [1893984 2013-08-15] (ASBYTE)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\yzfbwzaf.default
FF user.js: detected! => C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\yzfbwzaf.default\user.js
FF DefaultSearchEngine: Mysearchdial
FF SearchEngineOrder.1: Mysearchdial
FF SelectedSearchEngine: Mysearchdial
FF Homepage: hxxp://start.mysearchdial.com/?f=1&a=ir_14_13_ie&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azyzy0C0A0FyBtCzy0D0CyEtN0D0Tzu0SzztCyEtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0FtDyEtD0BtDyBtG0B0AtCtDtG0CtB0FzytG0FyBzztDtGtD0F0C0CzzyEtD0E0A0FtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FyDyB0E0ByC0DtGyBtAtD0FtG0CtCtB0CtGyD0B0B0EtGtB0DyE0AyC0A0AtAyCyDtCzz2Q&cr=1893658731&ir=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.1 - J:\PROGRAMME\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.140.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.1.3 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - J:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\ADMIN\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\ADMIN\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\yzfbwzaf.default\searchplugins\Mysearchdial.xml
FF Extension: mysearchdial.com - C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\yzfbwzaf.default\Extensions\ffxtlbr@mysearchdial.com [2014-03-24]
FF Extension: Mega Browse - C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\yzfbwzaf.default\Extensions\{29b136c9-938d-4d3d-8df8-d649d9b74d02}.xpi [2014-03-25]
FF Extension: MySearchDial - C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\yzfbwzaf.default\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}.xpi [2014-03-25]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2012-11-08]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2014-03-22]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-03-22]
Chrome:
=======
CHR HomePage: hxxp://start.mysearchdial.com/?f=1&a=ir_14_13_ie&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azyzy0C0A0FyBtCzy0D0CyEtN0D0Tzu0SzztCyEtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0FtDyEtD0BtDyBtG0B0AtCtDtG0CtB0FzytG0FyBzztDtGtD0F0C0CzzyEtD0E0A0FtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FyDyB0E0ByC0DtGyBtAtD0FtG0CtCtB0CtGyD0B0B0EtGtB0DyE0AyC0A0AtAyCyDtCzz2Q&cr=1893658731&ir=
CHR DefaultSearchProvider: "name": "Mysearchdial"
CHR Plugin: (Shockwave Flash) - C:\Users\ADMIN\AppData\Local\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\ADMIN\AppData\Local\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\ADMIN\AppData\Local\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB)
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2013) - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\ADMIN\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Microsoft Office 2010) - J:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Extension: (YouTube) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-11]
CHR Extension: (Google-Suche) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-11]
CHR Extension: (Logitech SetPoint) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd [2012-11-11]
CHR Extension: (SiteAdvisor) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2014-03-22]
CHR Extension: (Google Wallet) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-28]
CHR Extension: (Google Mail) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-11]
CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2012-11-08]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-03-22]
==================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2169016 2014-03-01] (Microsoft Corporation)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-06] (Intel Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-01-28] (McAfee, Inc.)
S3 McAWFwk; C:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [334608 2013-04-09] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1025712 2014-01-21] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-01-27] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [185792 2014-01-27] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-10-11] ()
R2 SN_Service; J:\PROGRAMME\ASBYTESYNCING.NET\SYNCING.NET\bin\SN_Service.exe [32768 2013-05-03] (ASBYTE)
R2 Update Mega Browse; C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe [348448 2014-03-24] ()
R2 UsbClientService; J:\PROGRAMME\Synology\Assistant\UsbClientService.exe [245760 2011-02-18] ()
R2 Util Mega Browse; C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe [348448 2014-03-24] ()
S2 TcSysSrv; C:\TwinCAT\TCATSysSrv.exe [X]
==================== Drivers (Whitelisted) ====================
R3 azvusb; C:\Windows\System32\DRIVERS\azvusb.sys [54784 2009-08-24] (AzureWave Technologies, Inc.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70592 2014-01-27] (McAfee, Inc.)
S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2012-11-08] (Siemens Home and Office Communication Devices GmbH & Co. KG)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66360 2012-10-02] (Logitech Inc.)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-03-24] (Malwarebytes Corporation)
R2 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [180272 2014-01-27] (McAfee, Inc.)
R2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311600 2014-01-27] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [520696 2014-01-27] (McAfee, Inc.)
R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [783864 2014-01-27] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [422712 2014-01-21] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-01-21] (McAfee, Inc.)
R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [344688 2014-01-27] (McAfee, Inc.)
S3 MyPenPro; C:\Windows\SysWOW64\Drivers\MyPenPro.sys [13056 2003-06-18] (C Technologies)
S3 OV550I; C:\Windows\System32\Drivers\FilmScan.sys [196992 2009-09-03] (Omnivision Technologies, Inc.)
S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [113704 2008-10-21] (MCCI Corporation)
S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-10-21] (MCCI Corporation)
S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [152616 2008-10-21] (MCCI Corporation)
S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [133160 2008-10-21] (MCCI Corporation)
S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-10-21] (MCCI Corporation)
S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [128552 2008-10-21] (MCCI Corporation)
S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [145960 2008-10-21] (MCCI Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [1093256 2013-01-09] (Acronis)
R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [166024 2013-01-09] (Acronis)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61120 2014-03-25] (StdLib)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP5c\WNt500x64\Sandra.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-25 22:49 - 2014-03-25 22:49 - 00030018 _____ () C:\Users\ADMIN\Desktop\FRST.txt
2014-03-25 22:37 - 2014-03-25 22:37 - 00987442 _____ () C:\Users\ADMIN\Desktop\SecurityCheck.exe
2014-03-25 22:36 - 2014-03-25 22:36 - 00016593 _____ () C:\Users\ADMIN\Desktop\download-securitycheck.htm
2014-03-25 20:58 - 2014-03-25 20:58 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG64.sys
2014-03-25 20:30 - 2014-03-25 20:30 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-25 20:27 - 2014-03-25 20:27 - 00000056 _____ () C:\Windows\setupact.log
2014-03-25 20:27 - 2014-03-25 20:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-24 22:51 - 2014-03-24 22:51 - 00000000 ____D () C:\Users\ADMIN\AppData\Roaming\mysearchdial
2014-03-24 22:51 - 2014-03-24 22:51 - 00000000 ____D () C:\Program Files (x86)\Mysearchdial
2014-03-24 22:50 - 2014-03-25 20:27 - 00000000 ____D () C:\Program Files (x86)\Mega Browse
2014-03-24 22:50 - 2014-03-24 22:50 - 00000000 ____D () C:\Users\ADMIN\AppData\Roaming\Mozilla
2014-03-24 22:50 - 2014-03-24 22:50 - 00000000 ____D () C:\Users\ADMIN\AppData\Roaming\1H1Q
2014-03-24 22:50 - 2014-03-24 22:50 - 00000000 ____D () C:\Users\ADMIN\AppData\Local\Mozilla
2014-03-24 22:49 - 2014-03-24 22:59 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
2014-03-24 22:49 - 2014-03-24 22:49 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-24 22:49 - 2014-03-24 22:49 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-24 22:49 - 2014-03-24 22:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-24 22:49 - 2014-03-24 22:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-24 22:35 - 2014-03-24 22:41 - 00000000 ____D () C:\Windows\Minidump
2014-03-24 20:22 - 2014-03-24 20:22 - 00000000 ____D () C:\Windows\ERUNT
2014-03-24 20:19 - 2014-03-24 20:19 - 01038974 _____ (Thisisu) C:\Users\ADMIN\Desktop\JRT.exe
2014-03-24 19:27 - 2014-03-24 22:42 - 00000000 ____D () C:\AdwCleaner
2014-03-24 19:26 - 2014-03-24 19:26 - 01950720 _____ () C:\Users\ADMIN\Desktop\adwcleaner.exe
2014-03-24 18:42 - 2014-03-24 22:44 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-24 18:41 - 2014-03-24 18:41 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-23 19:57 - 2014-03-23 19:57 - 00032318 _____ () C:\ComboFix.txt
2014-03-23 19:45 - 2014-03-23 19:57 - 00000000 ____D () C:\Qoobox
2014-03-23 19:45 - 2014-03-23 19:49 - 00000000 ____D () C:\Windows\erdnt
2014-03-23 19:45 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-03-23 19:45 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-03-23 19:45 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-03-23 19:45 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-03-23 19:45 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-03-23 19:45 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-03-23 19:45 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-03-23 19:45 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-03-22 10:31 - 2014-03-22 10:31 - 00000000 ____D () C:\Windows\rescache
2014-03-22 09:08 - 2014-03-22 09:08 - 02157056 _____ (Farbar) C:\Users\ADMIN\Desktop\FRST64.exe
2014-03-22 02:39 - 2014-03-25 22:49 - 00000000 ____D () C:\FRST
2014-03-22 01:24 - 2014-03-25 21:16 - 00001844 _____ () C:\Users\Public\Desktop\McAfee Internet Security.lnk
2014-03-22 01:23 - 2014-03-24 20:20 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-03-22 01:23 - 2014-03-22 01:24 - 00000000 ____D () C:\Program Files\McAfee
2014-03-22 01:23 - 2014-03-22 01:23 - 00000000 ____D () C:\Program Files\McAfee.com
2014-03-22 01:23 - 2014-03-22 01:23 - 00000000 ____D () C:\Program Files (x86)\McAfee.com
2014-03-22 01:23 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2014-03-22 01:17 - 2014-03-25 20:31 - 00225721 _____ () C:\Windows\WindowsUpdate.log
2014-03-21 22:14 - 2014-03-21 22:16 - 00000000 ____D () C:\Users\ADMIN\AppData\Local\WEKA DVD Interface
2014-03-21 19:29 - 2014-03-22 18:43 - 00000000 ____D () C:\ProgramData\McAfee
2014-03-21 19:29 - 2014-03-22 01:23 - 00000000 ____D () C:\Program Files\Common Files\McAfee
2014-03-21 19:29 - 2013-04-03 18:33 - 00772944 ____R (McAfee, Inc.) C:\Windows\system32\Drivers\mfehidk.sys.0631.deleteme
2014-03-21 19:29 - 2013-04-03 18:31 - 00179664 ____R (McAfee, Inc.) C:\Windows\system32\Drivers\mfeapfk.sys.a71e.deleteme
2014-03-13 21:45 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 21:45 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 21:45 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 21:45 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 21:45 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 21:45 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 21:45 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 21:45 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 21:45 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 21:45 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 21:45 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 21:45 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 21:45 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-13 21:45 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 21:45 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 21:45 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-13 21:45 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 21:45 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 21:45 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-13 21:45 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-13 21:45 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-13 21:45 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-13 21:45 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-13 21:45 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 21:45 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-13 21:45 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-13 21:45 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-13 21:45 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 21:45 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 21:45 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-13 21:45 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-13 21:45 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 21:45 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-13 21:45 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-13 21:45 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-13 21:45 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 21:45 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-13 21:45 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-13 21:45 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 21:45 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-13 21:45 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 21:45 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 21:45 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-13 21:45 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-13 21:42 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-13 21:42 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 21:42 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-13 21:42 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-07 20:22 - 2014-03-07 20:22 - 00000000 ____D () C:\Users\ADMIN\AppData\Local\Sonos,_Inc
2014-03-05 20:41 - 2014-03-05 20:41 - 00000840 _____ () C:\Users\Public\Desktop\Steuer 2012.lnk
2014-03-05 20:32 - 2014-03-05 20:32 - 00000840 _____ () C:\Users\Public\Desktop\Steuer 2013.lnk
==================== One Month Modified Files and Folders =======
2014-03-25 22:49 - 2014-03-25 22:49 - 00030018 _____ () C:\Users\ADMIN\Desktop\FRST.txt
2014-03-25 22:49 - 2014-03-22 02:39 - 00000000 ____D () C:\FRST
2014-03-25 22:37 - 2014-03-25 22:37 - 00987442 _____ () C:\Users\ADMIN\Desktop\SecurityCheck.exe
2014-03-25 22:36 - 2014-03-25 22:36 - 00016593 _____ () C:\Users\ADMIN\Desktop\download-securitycheck.htm
2014-03-25 22:18 - 2012-10-10 17:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-25 22:05 - 2012-10-11 07:17 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-684775682-3045372353-830408194-1000UA.job
2014-03-25 21:54 - 2013-10-23 22:37 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-25 21:16 - 2014-03-22 01:24 - 00001844 _____ () C:\Users\Public\Desktop\McAfee Internet Security.lnk
2014-03-25 20:58 - 2014-03-25 20:58 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG64.sys
2014-03-25 20:50 - 2013-03-16 14:56 - 00005136 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for PCMUTTER-ADMIN PCMutter
2014-03-25 20:35 - 2009-07-14 05:45 - 00031904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-25 20:35 - 2009-07-14 05:45 - 00031904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-25 20:33 - 2011-04-12 08:43 - 00702964 _____ () C:\Windows\system32\perfh007.dat
2014-03-25 20:33 - 2011-04-12 08:43 - 00150604 _____ () C:\Windows\system32\perfc007.dat
2014-03-25 20:33 - 2009-07-14 06:13 - 01629372 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-25 20:31 - 2014-03-22 01:17 - 00225721 _____ () C:\Windows\WindowsUpdate.log
2014-03-25 20:30 - 2014-03-25 20:30 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-25 20:28 - 2013-10-23 22:37 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-25 20:27 - 2014-03-25 20:27 - 00000056 _____ () C:\Windows\setupact.log
2014-03-25 20:27 - 2014-03-25 20:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-25 20:27 - 2014-03-24 22:50 - 00000000 ____D () C:\Program Files (x86)\Mega Browse
2014-03-25 20:27 - 2012-11-08 22:40 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs
2014-03-25 20:27 - 2012-10-10 16:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-03-25 20:27 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-25 00:05 - 2012-10-11 07:17 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-684775682-3045372353-830408194-1000Core.job
2014-03-24 22:59 - 2014-03-24 22:49 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
2014-03-24 22:57 - 2013-03-25 23:03 - 00000000 ____D () C:\Users\ADMIN\Documents\Outlook-Dateien
2014-03-24 22:54 - 2012-10-10 17:31 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-24 22:54 - 2012-10-10 17:31 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-24 22:54 - 2012-10-10 17:31 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-24 22:51 - 2014-03-24 22:51 - 00000000 ____D () C:\Users\ADMIN\AppData\Roaming\mysearchdial
2014-03-24 22:51 - 2014-03-24 22:51 - 00000000 ____D () C:\Program Files (x86)\Mysearchdial
2014-03-24 22:50 - 2014-03-24 22:50 - 00000000 ____D () C:\Users\ADMIN\AppData\Roaming\Mozilla
2014-03-24 22:50 - 2014-03-24 22:50 - 00000000 ____D () C:\Users\ADMIN\AppData\Roaming\1H1Q
2014-03-24 22:50 - 2014-03-24 22:50 - 00000000 ____D () C:\Users\ADMIN\AppData\Local\Mozilla
2014-03-24 22:49 - 2014-03-24 22:49 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-24 22:49 - 2014-03-24 22:49 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-24 22:49 - 2014-03-24 22:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-24 22:49 - 2014-03-24 22:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-24 22:44 - 2014-03-24 18:42 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-24 22:42 - 2014-03-24 19:27 - 00000000 ____D () C:\AdwCleaner
2014-03-24 22:41 - 2014-03-24 22:35 - 00000000 ____D () C:\Windows\Minidump
2014-03-24 20:22 - 2014-03-24 20:22 - 00000000 ____D () C:\Windows\ERUNT
2014-03-24 20:20 - 2014-03-22 01:23 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-03-24 20:19 - 2014-03-24 20:19 - 01038974 _____ (Thisisu) C:\Users\ADMIN\Desktop\JRT.exe
2014-03-24 19:26 - 2014-03-24 19:26 - 01950720 _____ () C:\Users\ADMIN\Desktop\adwcleaner.exe
2014-03-24 18:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Cursors
2014-03-24 18:41 - 2014-03-24 18:41 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-23 19:57 - 2014-03-23 19:57 - 00032318 _____ () C:\ComboFix.txt
2014-03-23 19:57 - 2014-03-23 19:45 - 00000000 ____D () C:\Qoobox
2014-03-23 19:56 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-03-23 19:50 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-03-23 19:49 - 2014-03-23 19:45 - 00000000 ____D () C:\Windows\erdnt
2014-03-23 07:54 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-22 21:13 - 2012-10-10 18:03 - 01602716 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-22 18:43 - 2014-03-21 19:29 - 00000000 ____D () C:\ProgramData\McAfee
2014-03-22 18:05 - 2013-02-24 09:50 - 00000349 _____ () C:\Users\Public\Documents\PCLECHAL.INI
2014-03-22 10:31 - 2014-03-22 10:31 - 00000000 ____D () C:\Windows\rescache
2014-03-22 09:08 - 2014-03-22 09:08 - 02157056 _____ (Farbar) C:\Users\ADMIN\Desktop\FRST64.exe
2014-03-22 01:41 - 2012-10-10 23:47 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-22 01:41 - 2009-07-14 03:34 - 00000510 _____ () C:\Windows\win.ini
2014-03-22 01:39 - 2013-03-16 14:39 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-03-22 01:24 - 2014-03-22 01:23 - 00000000 ____D () C:\Program Files\McAfee
2014-03-22 01:23 - 2014-03-22 01:23 - 00000000 ____D () C:\Program Files\McAfee.com
2014-03-22 01:23 - 2014-03-22 01:23 - 00000000 ____D () C:\Program Files (x86)\McAfee.com
2014-03-22 01:23 - 2014-03-21 19:29 - 00000000 ____D () C:\Program Files\Common Files\McAfee
2014-03-21 23:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-03-21 22:25 - 2012-11-09 01:01 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-21 22:24 - 2012-11-08 22:31 - 00000000 ____D () C:\ProgramData\Logishrd
2014-03-21 22:24 - 2012-11-08 22:30 - 00000000 ____D () C:\Program Files\Common Files\Logishrd
2014-03-21 22:19 - 2012-10-10 17:37 - 00000000 ____D () C:\Program Files\SiSoftware
2014-03-21 22:16 - 2014-03-21 22:14 - 00000000 ____D () C:\Users\ADMIN\AppData\Local\WEKA DVD Interface
2014-03-18 08:04 - 2013-08-14 22:20 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 08:04 - 2012-11-01 00:51 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-14 00:38 - 2013-03-10 01:59 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-14 00:38 - 2013-03-10 01:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-14 00:38 - 2009-07-14 05:45 - 00745624 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-07 20:22 - 2014-03-07 20:22 - 00000000 ____D () C:\Users\ADMIN\AppData\Local\Sonos,_Inc
2014-03-07 19:43 - 2013-02-24 01:42 - 00007680 _____ () C:\Users\ADMIN\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-06 22:01 - 2013-05-19 13:49 - 00000000 ____D () C:\Users\ADMIN\Documents\Steuerfälle
2014-03-05 20:41 - 2014-03-05 20:41 - 00000840 _____ () C:\Users\Public\Desktop\Steuer 2012.lnk
2014-03-05 20:32 - 2014-03-05 20:32 - 00000840 _____ () C:\Users\Public\Desktop\Steuer 2013.lnk
2014-03-05 20:32 - 2013-05-19 13:49 - 00000000 ____D () C:\Users\ADMIN\AppData\Local\Information Factory
2014-03-01 07:05 - 2014-03-13 21:45 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 06:17 - 2014-03-13 21:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 06:16 - 2014-03-13 21:45 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 05:58 - 2014-03-13 21:45 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 05:52 - 2014-03-13 21:45 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 05:51 - 2014-03-13 21:45 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 05:42 - 2014-03-13 21:45 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 05:40 - 2014-03-13 21:45 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 05:37 - 2014-03-13 21:45 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 05:33 - 2014-03-13 21:45 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 05:33 - 2014-03-13 21:45 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 05:32 - 2014-03-13 21:45 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 05:30 - 2014-03-13 21:45 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-01 05:23 - 2014-03-13 21:45 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 05:17 - 2014-03-13 21:45 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 05:11 - 2014-03-13 21:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-01 05:02 - 2014-03-13 21:45 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 04:54 - 2014-03-13 21:45 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 04:52 - 2014-03-13 21:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-01 04:51 - 2014-03-13 21:45 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-01 04:47 - 2014-03-13 21:45 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-01 04:43 - 2014-03-13 21:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-01 04:43 - 2014-03-13 21:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-01 04:42 - 2014-03-13 21:45 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 04:40 - 2014-03-13 21:45 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-01 04:38 - 2014-03-13 21:45 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-01 04:37 - 2014-03-13 21:45 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-01 04:35 - 2014-03-13 21:45 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 04:18 - 2014-03-13 21:45 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 04:16 - 2014-03-13 21:45 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-01 04:14 - 2014-03-13 21:45 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-01 04:10 - 2014-03-13 21:45 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 04:03 - 2014-03-13 21:45 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-01 04:00 - 2014-03-13 21:45 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-01 03:57 - 2014-03-13 21:45 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-01 03:38 - 2014-03-13 21:45 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 03:32 - 2014-03-13 21:45 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-01 03:27 - 2014-03-13 21:45 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-01 03:25 - 2014-03-13 21:45 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-01 03:25 - 2014-03-13 21:45 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-26 21:52 - 2013-03-16 15:11 - 00000000 ____D () C:\Users\ADMIN\AppData\Local\Windows Live
2014-02-23 15:23 - 2012-10-10 21:32 - 00000000 ____D () C:\Users\ADMIN\.gimp-2.8
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-13 21:51
==================== End Of Log ============================ --- --- ---
--- --- --- |