NeedHelp08 | 16.05.2014 07:57 | Vielen Dank für die Tipps, hier sind die Logs Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.05.2014
Suchlauf-Zeit: 15:59:20
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.15.04
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Katrin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 251082
Verstrichene Zeit: 22 Min, 13 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 2
PUP.Optional.InstallCore.A, HKU\S-1-5-21-905575457-879607011-4093534939-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [426e262bee8d83b3d1290e8b29d94eb2],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-905575457-879607011-4093534939-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [9917bd94ceadcc6a55be9f11cf344db3],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-905575457-879607011-4093534939-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0G2Y1R2X0G1M2S1M0G1S1H, In Quarantäne, [9917bd94ceadcc6a55be9f11cf344db3]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 0
(No malicious items detected)
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.208 - Bericht erstellt am 15/05/2014 um 16:03:50
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : Katrin - KATRIN-PC
# Gestartet von : C:\Users\xxxx\Downloads\adwcleaner_3.208.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Datei Gelöscht : C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\n5mi6n41.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKLM\Software\PIP
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\n5mi6n41.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [1438 octets] - [15/05/2014 16:02:13]
AdwCleaner[S0].txt - [1359 octets] - [15/05/2014 16:03:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1419 octets] ######### Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x86
Ran by Katrin on 15.05.2014 at 16:08:51,82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\xxxx\AppData\Roaming\mozilla\firefox\profiles\n5mi6n41.default\minidumps [90 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.05.2014 at 16:16:44,24
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-05-2014
Ran by Katrin (administrator) on KATRIN-PC on 16-05-2014 08:47:37
Running from C:\Users\xxxx\Downloads
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Atheros) C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Realsil Microelectronics Inc.) C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe
(Atheros Communications) C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AthBtTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(AppEx Networks Corporation) C:\Program Files\AMD Quick Stream\AMDQuickStream.exe
(AMD) C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
(CyberLink) C:\Program Files\CyberLink\YouCam\YCMMirage.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [6253160 2011-09-15] (Realtek Semiconductor)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files\Bluetooth Suite\BtvStack.exe [490656 2011-03-01] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files\Bluetooth Suite\AthBtTray.exe [302240 2011-03-01] (Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2299176 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-05-12] (AVAST Software)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748256 2014-04-17] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-905575457-879607011-4093534939-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-905575457-879607011-4093534939-1000\...\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [370912 2014-03-31] (AppEx Networks Corporation)
HKU\S-1-5-21-905575457-879607011-4093534939-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe [1967616 2014-04-17] (AMD)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\n5mi6n41.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\n5mi6n41.default\searchplugins\suche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\n5mi6n41.default\Extensions\ich@maltegoetz.de [2014-01-15]
FF Extension: WOT - C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\n5mi6n41.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-01-15]
FF Extension: Adblock Plus - C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\n5mi6n41.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-05-11]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-05-10]
========================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2014-04-17] (Advanced Micro Devices, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-12] (AVAST Software)
R2 IconMan_R; C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1817088 2010-12-27] (Realsil Microelectronics Inc.)
==================== Drivers (Whitelisted) ====================
R0 amd_sata; C:\Windows\System32\DRIVERS\amd_sata.sys [66688 2011-04-16] (Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\DRIVERS\amd_xata.sys [33408 2011-04-16] (Advanced Micro Devices)
R2 APXACC; C:\Windows\System32\DRIVERS\appexDrv.sys [184032 2014-03-28] (AppEx Networks Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-05-12] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-05-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-05-12] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-05-12] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [777488 2014-05-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [411680 2014-05-14] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [68312 2014-05-14] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180632 2014-05-12] ()
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [2957312 2012-06-20] (Qualcomm Atheros Communications, Inc.)
R3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [24736 2011-03-01] (Atheros)
R3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [242336 2011-03-01] (Atheros)
R3 RSPCIESTOR; C:\Windows\System32\DRIVERS\RtsPStor.sys [251496 2011-02-15] (Realtek Semiconductor Corp.)
S3 amdiox86; system32\DRIVERS\amdiox86.sys [X]
S3 catchme; \??\C:\Users\xxxx\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-16 08:47 - 2014-05-16 08:47 - 00000000 ____D () C:\Users\xxxx\Downloads\FRST-OlderVersion
2014-05-15 16:19 - 2014-05-15 16:19 - 00001499 _____ () C:\Users\xxxx\Desktop\AdwCleaner[S0].txt
2014-05-15 16:16 - 2014-05-15 16:19 - 00000862 _____ () C:\Users\xxxx\Desktop\JRT.txt
2014-05-15 16:08 - 2014-05-15 16:08 - 01016261 _____ (Thisisu) C:\Users\xxxx\Downloads\JRT.exe
2014-05-15 16:08 - 2014-05-15 16:08 - 00000000 ____D () C:\Windows\ERUNT
2014-05-15 16:05 - 2014-05-15 16:05 - 00000306 _____ () C:\Windows\PFRO.log
2014-05-15 16:02 - 2014-05-15 16:03 - 00000000 ____D () C:\AdwCleaner
2014-05-15 16:01 - 2014-05-15 16:01 - 01325827 _____ () C:\Users\xxxx\Downloads\adwcleaner_3.208.exe
2014-05-15 16:01 - 2014-05-15 16:01 - 00001703 _____ () C:\Users\xxxx\Desktop\mbam.txt
2014-05-15 15:36 - 2014-05-15 15:36 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-15 15:35 - 2014-05-15 15:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-15 15:35 - 2014-05-15 15:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 15:35 - 2014-05-15 15:35 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-05-15 15:35 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-15 15:35 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-15 15:35 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-15 15:34 - 2014-05-15 15:35 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\xxxx\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 15:29 - 2014-05-15 16:05 - 00000112 _____ () C:\Windows\setupact.log
2014-05-15 15:29 - 2014-05-15 15:29 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-14 12:31 - 2014-05-14 12:31 - 00001060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-05-14 12:27 - 2014-05-14 12:27 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-05-14 12:27 - 2014-05-14 12:26 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-05-14 12:26 - 2014-05-14 12:26 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-05-14 12:26 - 2014-05-14 12:26 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-05-14 12:26 - 2014-05-14 12:26 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-05-14 12:26 - 2014-05-14 12:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-14 12:26 - 2014-05-14 12:26 - 00000000 ____D () C:\Program Files\Java
2014-05-14 11:27 - 2014-05-14 11:27 - 00000000 ____D () C:\Users\xxxx\AppData\Roaming\Oracle
2014-05-14 11:20 - 2014-05-14 11:20 - 00000000 ____D () C:\Users\xxxx\AppData\Local\Adobe
2014-05-14 11:19 - 2014-05-14 11:19 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-05-14 11:17 - 2014-05-14 11:18 - 00000000 ____D () C:\Program Files\OpenOffice 4
2014-05-14 10:22 - 2014-05-14 10:22 - 00000000 ____D () C:\ProgramData\ATI
2014-05-14 10:21 - 2014-05-14 10:21 - 00000000 ____D () C:\Users\xxxx\AppData\Local\AppEx Networks
2014-05-14 10:15 - 2014-05-14 10:15 - 00000000 ____D () C:\Users\xxxx\AppData\Roaming\Raptr
2014-05-14 10:15 - 2014-05-14 10:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Quick Stream
2014-05-14 10:15 - 2014-05-14 10:15 - 00000000 ____D () C:\Program Files\Raptr
2014-05-14 10:14 - 2014-05-14 10:15 - 00000000 ____D () C:\Program Files\AMD Quick Stream
2014-05-14 10:14 - 2014-05-14 10:14 - 00059870 _____ () C:\Windows\system32\CCCInstall_201405141014308821.log
2014-05-14 10:14 - 2014-05-14 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-05-14 10:14 - 2014-05-14 10:14 - 00000000 ____D () C:\Program Files\AMD AVT
2014-05-14 10:14 - 2014-03-28 11:52 - 00184032 _____ (AppEx Networks Corporation) C:\Windows\system32\Drivers\appexDrv.sys
2014-05-14 10:10 - 2014-05-14 10:14 - 00000000 ____D () C:\Program Files\AMD
2014-05-14 10:08 - 2014-05-14 10:08 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-14 10:04 - 2014-05-14 10:04 - 00000000 ____D () C:\AMD
2014-05-14 10:00 - 2014-05-14 10:00 - 00000000 __SHD () C:\Users\xxxx\AppData\Local\EmieUserList
2014-05-14 10:00 - 2014-05-14 10:00 - 00000000 __SHD () C:\Users\xxxx\AppData\Local\EmieSiteList
2014-05-14 09:48 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 09:48 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-14 09:48 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 09:47 - 2014-04-12 04:11 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 09:47 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-05-14 09:47 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 09:47 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 09:47 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 09:46 - 2014-05-09 09:06 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-14 09:46 - 2014-05-09 09:04 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-14 09:46 - 2014-04-12 04:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 09:46 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 09:46 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 09:46 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 09:46 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 09:46 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 09:46 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 09:46 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 09:46 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 09:37 - 2014-05-14 09:37 - 00008931 _____ () C:\ComboFix.txt
2014-05-14 09:11 - 2014-05-14 09:11 - 05200050 ____R (Swearware) C:\Users\xxxx\Downloads\ComboFix.exe
2014-05-12 09:51 - 2014-05-12 09:56 - 00018095 _____ () C:\Users\xxxx\Downloads\Addition.txt
2014-05-12 09:50 - 2014-05-16 08:47 - 00009430 _____ () C:\Users\xxxx\Downloads\FRST.txt
2014-05-12 09:50 - 2014-05-16 08:47 - 00000000 ____D () C:\FRST
2014-05-12 09:49 - 2014-05-16 08:47 - 01056768 _____ (Farbar) C:\Users\xxxx\Downloads\FRST.exe
2014-05-12 09:35 - 2014-05-12 09:36 - 00004410 _____ () C:\Windows\system32\jupdate-1.7.0_55-b14.log
2014-05-12 09:33 - 2014-05-14 10:26 - 00068312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-12 09:33 - 2014-05-12 09:33 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-12 09:33 - 2014-05-12 09:33 - 00024184 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-11 11:52 - 2014-05-11 11:52 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-05-11 11:40 - 2014-05-14 09:54 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-24 16:45 - 2014-03-06 10:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-24 16:45 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-24 16:45 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-24 16:45 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-24 16:45 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-24 16:45 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-24 16:45 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-24 16:45 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-24 16:45 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-24 16:45 - 2014-03-06 09:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-24 16:45 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-24 16:45 - 2014-03-06 09:28 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-24 16:45 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-24 16:45 - 2014-03-06 09:18 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-24 16:45 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-24 16:45 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-24 16:45 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-24 16:45 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-24 16:45 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-24 16:45 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-24 16:45 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-24 16:44 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-24 16:44 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-24 16:44 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-18 04:43 - 2014-04-18 04:43 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc32.dll
2014-04-18 04:43 - 2014-04-18 04:43 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom32.dll
2014-04-18 04:35 - 2014-04-18 04:35 - 13515264 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2014-04-18 04:23 - 2014-04-18 04:23 - 00200704 _____ () C:\Windows\system32\clinfo.exe
2014-04-18 04:22 - 2014-04-18 04:22 - 00995342 _____ () C:\Windows\system32\amdocl_as32.exe
2014-04-18 04:22 - 2014-04-18 04:22 - 00798734 _____ () C:\Windows\system32\amdocl_ld32.exe
2014-04-18 04:22 - 2014-04-18 04:22 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo.dll
2014-04-18 04:22 - 2014-04-18 04:22 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode.dll
2014-04-18 04:19 - 2014-04-18 04:19 - 24107520 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl.dll
2014-04-18 04:17 - 2014-04-18 04:17 - 00058880 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-04-18 04:13 - 2014-04-18 04:13 - 00113664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle32.dll
2014-04-18 03:58 - 2014-04-18 03:58 - 04358656 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle32.dll
2014-04-18 03:51 - 2014-04-18 03:51 - 23409152 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atioglxx.dll
2014-04-18 03:46 - 2014-04-18 03:46 - 00580816 _____ () C:\Windows\system32\atiapfxx.blb
2014-04-18 03:46 - 2014-04-18 03:46 - 00368128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2014-04-18 03:46 - 2014-04-18 03:46 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt.dll
2014-04-18 03:46 - 2014-04-18 03:46 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl.dll
2014-04-18 03:45 - 2014-04-18 03:45 - 00085504 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl32.dll
2014-04-18 03:42 - 2014-04-18 03:42 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd.dll
2014-04-18 03:33 - 2014-04-18 03:33 - 00037888 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl.dll
2014-04-18 03:30 - 2014-04-18 03:30 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2014-04-18 03:29 - 2014-04-18 03:29 - 00491520 _____ (AMD) C:\Windows\system32\atieclxx.exe
2014-04-18 03:29 - 2014-04-18 03:29 - 00208896 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2014-04-18 03:29 - 2014-04-18 03:29 - 00030720 _____ (AMD) C:\Windows\system32\atimuixx.dll
2014-04-18 03:28 - 2014-04-18 03:28 - 00164352 _____ (AMD) C:\Windows\system32\atitmmxx.dll
2014-04-18 03:21 - 2014-04-18 03:21 - 00616960 _____ (AMD) C:\Windows\system32\coinst_14.100.dll
2014-04-18 03:17 - 2014-04-18 03:17 - 03471376 _____ () C:\Windows\system32\atiumdva.cap
2014-04-18 03:14 - 2014-04-18 03:14 - 00204952 _____ () C:\Windows\system32\ativvsvl.dat
2014-04-18 03:14 - 2014-04-18 03:14 - 00157144 _____ () C:\Windows\system32\ativvsva.dat
2014-04-18 03:08 - 2014-04-18 03:08 - 00848896 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2014-04-18 03:07 - 2014-04-18 03:07 - 00133632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atigktxx.dll
2014-04-18 03:07 - 2014-04-18 03:07 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2014-04-18 03:06 - 2014-04-18 03:06 - 00512000 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2014-04-18 03:04 - 2014-04-18 03:04 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2014-04-17 22:28 - 2014-04-17 22:28 - 00038912 _____ () C:\Windows\system32\kdbsdk32.dll
==================== One Month Modified Files and Folders =======
2014-05-16 08:48 - 2014-05-12 09:50 - 00009430 _____ () C:\Users\xxxx\Downloads\FRST.txt
2014-05-16 08:47 - 2014-05-16 08:47 - 00000000 ____D () C:\Users\xxxx\Downloads\FRST-OlderVersion
2014-05-16 08:47 - 2014-05-12 09:50 - 00000000 ____D () C:\FRST
2014-05-16 08:47 - 2014-05-12 09:49 - 01056768 _____ (Farbar) C:\Users\xxxx\Downloads\FRST.exe
2014-05-16 08:44 - 2012-05-11 00:29 - 00000000 ____D () C:\Users\xxxx\AppData\Roaming\Skype
2014-05-16 08:44 - 2012-05-11 00:10 - 00000035 _____ () C:\Users\Public\Documents\AtherosServiceConfig.ini
2014-05-16 08:43 - 2012-05-11 00:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-15 16:19 - 2014-05-15 16:19 - 00001499 _____ () C:\Users\xxxx\Desktop\AdwCleaner[S0].txt
2014-05-15 16:19 - 2014-05-15 16:16 - 00000862 _____ () C:\Users\xxxx\Desktop\JRT.txt
2014-05-15 16:13 - 2009-07-14 06:34 - 00021280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-15 16:13 - 2009-07-14 06:34 - 00021280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-15 16:09 - 2012-05-10 19:50 - 01879055 _____ () C:\Windows\WindowsUpdate.log
2014-05-15 16:09 - 2010-11-20 23:01 - 01619700 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-15 16:08 - 2014-05-15 16:08 - 01016261 _____ (Thisisu) C:\Users\xxxx\Downloads\JRT.exe
2014-05-15 16:08 - 2014-05-15 16:08 - 00000000 ____D () C:\Windows\ERUNT
2014-05-15 16:05 - 2014-05-15 16:05 - 00000306 _____ () C:\Windows\PFRO.log
2014-05-15 16:05 - 2014-05-15 15:29 - 00000112 _____ () C:\Windows\setupact.log
2014-05-15 16:05 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-15 16:03 - 2014-05-15 16:02 - 00000000 ____D () C:\AdwCleaner
2014-05-15 16:01 - 2014-05-15 16:01 - 01325827 _____ () C:\Users\xxxx\Downloads\adwcleaner_3.208.exe
2014-05-15 16:01 - 2014-05-15 16:01 - 00001703 _____ () C:\Users\xxxx\Desktop\mbam.txt
2014-05-15 15:52 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-15 15:36 - 2014-05-15 15:36 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-15 15:36 - 2012-05-10 23:50 - 00064768 _____ () C:\Users\xxxx\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-15 15:35 - 2014-05-15 15:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-15 15:35 - 2014-05-15 15:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 15:35 - 2014-05-15 15:35 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-05-15 15:35 - 2014-05-15 15:34 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\xxxx\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 15:29 - 2014-05-15 15:29 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-15 15:29 - 2009-07-14 06:33 - 00299512 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-14 12:31 - 2014-05-14 12:31 - 00001060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-05-14 12:31 - 2012-05-10 23:02 - 00000000 ____D () C:\Program Files\TeamViewer
2014-05-14 12:27 - 2014-05-14 12:27 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-05-14 12:27 - 2013-11-06 11:43 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-14 12:26 - 2014-05-14 12:27 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-05-14 12:26 - 2014-05-14 12:26 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-05-14 12:26 - 2014-05-14 12:26 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-05-14 12:26 - 2014-05-14 12:26 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-05-14 12:26 - 2014-05-14 12:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-14 12:26 - 2014-05-14 12:26 - 00000000 ____D () C:\Program Files\Java
2014-05-14 11:29 - 2012-05-10 20:46 - 00000000 ____D () C:\Windows\Panther
2014-05-14 11:27 - 2014-05-14 11:27 - 00000000 ____D () C:\Users\xxxx\AppData\Roaming\Oracle
2014-05-14 11:20 - 2014-05-14 11:20 - 00000000 ____D () C:\Users\xxxx\AppData\Local\Adobe
2014-05-14 11:20 - 2012-05-11 00:42 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-05-14 11:20 - 2012-05-11 00:42 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-05-14 11:19 - 2014-05-14 11:19 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-05-14 11:18 - 2014-05-14 11:17 - 00000000 ____D () C:\Program Files\OpenOffice 4
2014-05-14 11:16 - 2012-05-10 23:00 - 00000000 ____D () C:\Program Files\OpenOffice.org 3
2014-05-14 10:41 - 2013-06-06 10:01 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-14 10:31 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-05-14 10:26 - 2014-05-12 09:33 - 00068312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-14 10:26 - 2012-05-10 23:05 - 00777488 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-14 10:26 - 2012-05-10 23:05 - 00411680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-05-14 10:22 - 2014-05-14 10:22 - 00000000 ____D () C:\ProgramData\ATI
2014-05-14 10:21 - 2014-05-14 10:21 - 00000000 ____D () C:\Users\xxxx\AppData\Local\AppEx Networks
2014-05-14 10:15 - 2014-05-14 10:15 - 00000000 ____D () C:\Users\xxxx\AppData\Roaming\Raptr
2014-05-14 10:15 - 2014-05-14 10:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Quick Stream
2014-05-14 10:15 - 2014-05-14 10:15 - 00000000 ____D () C:\Program Files\Raptr
2014-05-14 10:15 - 2014-05-14 10:14 - 00000000 ____D () C:\Program Files\AMD Quick Stream
2014-05-14 10:14 - 2014-05-14 10:14 - 00059870 _____ () C:\Windows\system32\CCCInstall_201405141014308821.log
2014-05-14 10:14 - 2014-05-14 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-05-14 10:14 - 2014-05-14 10:14 - 00000000 ____D () C:\Program Files\AMD AVT
2014-05-14 10:14 - 2014-05-14 10:10 - 00000000 ____D () C:\Program Files\AMD
2014-05-14 10:14 - 2012-05-10 23:41 - 00000000 ____D () C:\ProgramData\AMD
2014-05-14 10:14 - 2012-05-10 23:39 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-05-14 10:08 - 2014-05-14 10:08 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-14 10:04 - 2014-05-14 10:04 - 00000000 ____D () C:\AMD
2014-05-14 10:00 - 2014-05-14 10:00 - 00000000 __SHD () C:\Users\xxxx\AppData\Local\EmieUserList
2014-05-14 10:00 - 2014-05-14 10:00 - 00000000 __SHD () C:\Users\xxxx\AppData\Local\EmieSiteList
2014-05-14 09:55 - 2012-05-10 22:54 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-05-14 09:54 - 2014-05-11 11:40 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-14 09:54 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-05-14 09:52 - 2013-08-20 14:48 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 09:50 - 2012-05-11 00:47 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 09:37 - 2014-05-14 09:37 - 00008931 _____ () C:\ComboFix.txt
2014-05-14 09:37 - 2013-06-06 10:09 - 00000000 ____D () C:\Qoobox
2014-05-14 09:33 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-05-14 09:11 - 2014-05-14 09:11 - 05200050 ____R (Swearware) C:\Users\xxxx\Downloads\ComboFix.exe
2014-05-12 09:56 - 2014-05-12 09:51 - 00018095 _____ () C:\Users\xxxx\Downloads\Addition.txt
2014-05-12 09:47 - 2014-03-06 15:00 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak
2014-05-12 09:36 - 2014-05-12 09:35 - 00004410 _____ () C:\Windows\system32\jupdate-1.7.0_55-b14.log
2014-05-12 09:34 - 2013-11-06 11:48 - 00002047 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-05-12 09:33 - 2014-05-12 09:33 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-12 09:33 - 2014-05-12 09:33 - 00024184 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-12 09:33 - 2013-04-02 12:30 - 00180632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-05-12 09:33 - 2013-04-02 12:30 - 00049944 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-05-12 09:33 - 2012-05-10 23:05 - 00776976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1400055992270
2014-05-12 09:33 - 2012-05-10 23:05 - 00411552 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1400055992270
2014-05-12 09:33 - 2012-05-10 23:05 - 00081768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-05-12 09:33 - 2012-05-10 23:05 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-05-12 09:33 - 2012-05-10 23:04 - 00271264 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-05-11 11:52 - 2014-05-11 11:52 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-05-09 09:06 - 2014-05-14 09:46 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 09:04 - 2014-05-14 09:46 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-06 05:25 - 2014-05-14 09:48 - 17382912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 05:07 - 2014-05-14 09:48 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 04:10 - 2014-05-14 09:48 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-18 04:43 - 2014-04-18 04:43 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc32.dll
2014-04-18 04:43 - 2014-04-18 04:43 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom32.dll
2014-04-18 04:42 - 2011-07-05 23:12 - 01117184 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx32.dll
2014-04-18 04:42 - 2011-07-05 23:04 - 08866928 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx32.dll
2014-04-18 04:42 - 2011-07-05 22:45 - 06799688 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumdag.dll
2014-04-18 04:42 - 2011-07-05 22:45 - 06796592 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumdva.dll
2014-04-18 04:42 - 2011-07-05 22:31 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxpag.dll
2014-04-18 04:42 - 2011-07-05 22:31 - 00099520 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9pag.dll
2014-04-18 04:35 - 2014-04-18 04:35 - 13515264 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2014-04-18 04:23 - 2014-04-18 04:23 - 00200704 _____ () C:\Windows\system32\clinfo.exe
2014-04-18 04:22 - 2014-04-18 04:22 - 00995342 _____ () C:\Windows\system32\amdocl_as32.exe
2014-04-18 04:22 - 2014-04-18 04:22 - 00798734 _____ () C:\Windows\system32\amdocl_ld32.exe
2014-04-18 04:22 - 2014-04-18 04:22 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo.dll
2014-04-18 04:22 - 2014-04-18 04:22 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode.dll
2014-04-18 04:19 - 2014-04-18 04:19 - 24107520 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl.dll
2014-04-18 04:17 - 2014-04-18 04:17 - 00058880 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-04-18 04:13 - 2014-04-18 04:13 - 00113664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle32.dll
2014-04-18 03:58 - 2014-04-18 03:58 - 04358656 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle32.dll
2014-04-18 03:51 - 2014-04-18 03:51 - 23409152 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atioglxx.dll
2014-04-18 03:46 - 2014-04-18 03:46 - 00580816 _____ () C:\Windows\system32\atiapfxx.blb
2014-04-18 03:46 - 2014-04-18 03:46 - 00368128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2014-04-18 03:46 - 2014-04-18 03:46 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt.dll
2014-04-18 03:46 - 2014-04-18 03:46 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl.dll
2014-04-18 03:45 - 2014-04-18 03:45 - 00085504 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl32.dll
2014-04-18 03:42 - 2014-04-18 03:42 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd.dll
2014-04-18 03:33 - 2014-04-18 03:33 - 00037888 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl.dll
2014-04-18 03:30 - 2014-04-18 03:30 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2014-04-18 03:29 - 2014-04-18 03:29 - 00491520 _____ (AMD) C:\Windows\system32\atieclxx.exe
2014-04-18 03:29 - 2014-04-18 03:29 - 00208896 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2014-04-18 03:29 - 2014-04-18 03:29 - 00030720 _____ (AMD) C:\Windows\system32\atimuixx.dll
2014-04-18 03:28 - 2014-04-18 03:28 - 00164352 _____ (AMD) C:\Windows\system32\atitmmxx.dll
2014-04-18 03:21 - 2014-04-18 03:21 - 00616960 _____ (AMD) C:\Windows\system32\coinst_14.100.dll
2014-04-18 03:17 - 2014-04-18 03:17 - 03471376 _____ () C:\Windows\system32\atiumdva.cap
2014-04-18 03:14 - 2014-04-18 03:14 - 00204952 _____ () C:\Windows\system32\ativvsvl.dat
2014-04-18 03:14 - 2014-04-18 03:14 - 00157144 _____ () C:\Windows\system32\ativvsva.dat
2014-04-18 03:08 - 2014-04-18 03:08 - 00848896 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2014-04-18 03:07 - 2014-04-18 03:07 - 00133632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atigktxx.dll
2014-04-18 03:07 - 2014-04-18 03:07 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2014-04-18 03:06 - 2014-04-18 03:06 - 00512000 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2014-04-18 03:04 - 2014-04-18 03:04 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2014-04-17 22:28 - 2014-04-17 22:28 - 00038912 _____ () C:\Windows\system32\kdbsdk32.dll
Some content of TEMP:
====================
C:\Users\xxxx\AppData\Local\Temp\14-4-mobility-win7-win8-win8.1-32-dd-ccc-whql.exe
C:\Users\xxxx\AppData\Local\Temp\devcon.exe
C:\Users\xxxx\AppData\Local\Temp\Quarantine.exe
C:\Users\xxxx\AppData\Local\Temp\raptr_stub.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe
[2014-05-14 09:46] - [2014-03-04 11:17] - 0304128 ____A (Microsoft Corporation) 998507B046BA314CE8245364C686FA67
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2012-11-11 15:25
==================== End Of Log ============================ --- --- --- |