ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=1b6ac6f1a7427d4ca23d74513d0b03e4
# engine=14572
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-29 09:41:46
# local_time=2013-07-29 11:41:46 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.2.9200 NT
# compatibility_mode=5893 16776574 100 94 9338361 34597017 0 0
# scanned=359
# found=0
# cleaned=0
# scan_time=33
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=1b6ac6f1a7427d4ca23d74513d0b03e4
# engine=14596
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-31 12:54:45
# local_time=2013-07-31 02:54:45 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.2.9200 NT
# compatibility_mode=5893 16776574 100 94 9522740 34781396 0 0
# scanned=344924
# found=2
# cleaned=0
# scan_time=14154
sh=D1DE140C2ECEECE8D4CFDB2C22D4D8A9BAAA34E2 ft=1 fh=736736a39589b0e9 vn="probably a variant of Win32/Agent.EODGEND trojan" ac=I fn="D:\Wolfgang\Spiele\Crysis WARHEAD\CrysisWh_Trn.exe"
sh=D1DE140C2ECEECE8D4CFDB2C22D4D8A9BAAA34E2 ft=1 fh=736736a39589b0e9 vn="probably a variant of Win32/Agent.EODGEND trojan" ac=I fn="D:\Wolfgang\Spiele\Crysis WARHEAD\CrysisWh_Trn\CrysisWh_Trn.exe"
Results of screen317's Security Check version 0.99.71
x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
avast! Antivirus
Windows Defender
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
TuneUp Utilities 2013
TuneUp Utilities Language Pack (de-DE)
Adobe Flash Player 11.8.800.94
Adobe Reader XI
Mozilla Firefox (22.0)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes' Anti-Malware mbamscheduler.exe
Avast5 AvastSvc.exe
Avast5 AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013
Ran by Wolfgang (administrator) on 31-07-2013 16:42:22
Running from C:\Users\Wolfgang\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) D:\Programme\Avast5\AvastSvc.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(Malwarebytes Corporation) D:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
(TuneUp Software) D:\Programme\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(TuneUp Software) D:\Programme\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4396.1016_x64__8wekyb3d8bbwe\LiveComm.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AVAST Software) D:\Programme\Avast5\AvastUI.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKCU\...\Run: [] - D:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1106288 2013-05-23] (Samsung)
HKCU\...\Run: [KiesPreload] - D:\Programme\Samsung\Kies\Kies.exe [1561968 2013-05-23] (Samsung)
HKCU\...\Run: [KiesAirMessage] - D:\Programme\Samsung\Kies\KiesAirMessage.exe [578560 2013-05-22] (Samsung Electronics)
HKLM-x32\...\Run: [avast] - D:\Programme\Avast5\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NeroCheck] - C:\Windows\SysWOW64\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM-x32\...\Run: [KiesTrayAgent] - D:\Programme\Samsung\Kies\KiesTrayAgent.exe [311152 2013-05-23] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
IMEO\cdspeed.exe: [Debugger] "D:\Programme\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IMEO\coverdes.exe: [Debugger] "D:\Programme\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IMEO\drivespeed.exe: [Debugger] "D:\Programme\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IMEO\kiesagent.exe: [Debugger] "D:\Programme\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IMEO\kiessetup.exe: [Debugger] "D:\Programme\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IMEO\nero.exe: [Debugger] "D:\Programme\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IMEO\setup.exe: [Debugger] "D:\Programme\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IMEO\waveedit.exe: [Debugger] "D:\Programme\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IMEO\wmdc.exe: [Debugger] "D:\Programme\TuneUp Utilities 2013\TUAutoReactivator64.exe"
Startup: C:\Users\Wolfgang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN AT: Hotmail, Outlook, Messenger, Skype, Unterhaltung, Nachrichten & Lifestyle
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = QVO6
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = QVO6
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = QVO6
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = QVO6
StartMenuInternet: IEXPLORE.EXE - "C:\Program Files (x86)\Internet Explorer\iexplore.exe" QVO6
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = QVO6
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = QVO6
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = QVO6
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = QVO6
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Programme\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~3\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programme\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~3\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Programme\Avast5\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programme\Avast5\aswWebRepIE.dll (AVAST Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Wolfgang\AppData\Roaming\Mozilla\Firefox\Profiles\ybhc94j6.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~3\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~3\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - D:\Programme\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101799.dll (Amazon.com, Inc.)
FF Extension: No Name - C:\Users\Wolfgang\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] D:\Programme\Avast5\WebRep\FF
FF Extension: avast! Online Security - D:\Programme\Avast5\WebRep\FF
==================== Services (Whitelisted) =================
R2 avast! Antivirus; D:\Programme\Avast5\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 MBAMScheduler; D:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; D:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 TuneUp.UtilitiesSvc; D:\Programme\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2402080 2013-01-28] (TuneUp Software)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-28] ()
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-18] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-18] (Windows (R) Win 7 DDK provider)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-06-25] (GFI Software)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R3 TuneUpUtilitiesDrv; D:\Programme\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-08-28] (TuneUp Software)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-31 11:01 - 2013-07-31 11:01 - 00891098 _____ C:\Users\Wolfgang\Downloads\SecurityCheck.exe
2013-07-31 10:57 - 2013-07-31 10:57 - 02347384 _____ (ESET) C:\Users\Wolfgang\Downloads\esetsmartinstaller_enu.exe
2013-07-31 07:37 - 2013-07-31 07:37 - 00000000 ____D C:\Windows\ERUNT
2013-07-31 07:36 - 2013-07-31 07:36 - 00562430 _____ (Oleg N. Scherbakov) C:\Users\Wolfgang\Downloads\JRT.exe
2013-07-29 13:52 - 2013-07-29 13:52 - 00490078 _____ C:\Users\Wolfgang\Downloads\F1 2012 - Safety Car Fix.rar
2013-07-29 12:52 - 2013-07-29 12:52 - 00001282 _____ C:\Users\Wolfgang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-07-29 12:46 - 2013-07-29 12:46 - 00000000 ____D C:\Users\Wolfgang\Desktop\Alte Firefox-Daten
2013-07-29 11:42 - 2013-07-29 11:42 - 01780547 _____ (Farbar) C:\Users\Wolfgang\Downloads\FRST64.exe
2013-07-29 11:37 - 2013-07-29 11:37 - 00000000 ____D C:\Program Files (x86)\ESET
2013-07-29 11:15 - 2013-07-29 11:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-29 11:14 - 2013-07-29 11:15 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-29 11:06 - 2013-07-29 11:06 - 21703480 _____ (Mozilla) C:\Users\Wolfgang\Downloads\Firefox_Setup_22.0.exe
2013-07-29 11:02 - 2013-07-29 11:02 - 02828552 _____ (AVAST Software) C:\Users\Wolfgang\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-07-29 10:44 - 2013-07-29 10:45 - 00424016 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-29 10:35 - 2013-07-29 11:09 - 00000000 ____D C:\ProgramData\eSafe
2013-07-29 10:34 - 2013-07-29 10:34 - 00000000 ____D C:\Users\Wolfgang\AppData\Roaming\eIntaller
2013-07-20 10:33 - 2013-06-28 00:04 - 00693112 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-20 10:33 - 2013-06-28 00:04 - 00078200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-19 21:08 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2013-07-19 21:07 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2013-07-19 21:07 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2013-07-19 21:07 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2013-07-19 21:07 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-07-19 21:07 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2013-07-19 21:07 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS
2013-07-19 21:07 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-07-19 21:07 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2013-07-19 21:07 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2013-07-19 21:07 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-07-19 21:07 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2013-07-19 21:07 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2013-07-19 21:07 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2013-07-19 21:07 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2013-07-19 21:07 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2013-07-19 21:07 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2013-07-19 21:07 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-07-19 21:07 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-07-19 21:07 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2013-07-19 21:07 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe
2013-07-19 21:07 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2013-07-19 21:07 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2013-07-19 21:07 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2013-07-19 21:07 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2013-07-19 21:07 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2013-07-19 21:07 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2013-07-19 21:07 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2013-07-19 21:07 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll
2013-07-19 21:07 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys
2013-07-19 21:07 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2013-07-19 21:07 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2013-07-19 21:07 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2013-07-19 21:07 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2013-07-19 21:07 - 2013-05-20 02:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml
2013-07-19 21:01 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-19 21:00 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-19 21:00 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-19 20:59 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-19 20:59 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-19 20:58 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-19 20:58 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-19 20:58 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-19 20:58 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-19 20:58 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-19 20:58 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-19 20:58 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-19 20:58 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-19 20:58 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-19 20:58 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-19 20:58 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-19 20:58 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-19 20:58 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-19 20:58 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-19 20:58 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-19 20:58 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-19 20:58 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-19 20:58 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-19 20:58 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-04 17:14 - 2013-07-04 17:26 - 00000000 ____D C:\Users\Wolfgang\Desktop\Laura SD
2013-07-04 08:24 - 2013-07-04 08:25 - 00000000 ____D C:\Users\Wolfgang\Downloads\Hilfestellung
2013-07-04 07:40 - 2013-05-16 00:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
==================== One Month Modified Files and Folders =======
2013-07-31 16:14 - 2012-12-07 16:33 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-31 16:07 - 2012-12-07 15:52 - 01106876 _____ C:\Windows\WindowsUpdate.log
2013-07-31 16:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2013-07-31 13:18 - 2012-07-26 12:27 - 00751892 _____ C:\Windows\system32\perfh007.dat
2013-07-31 13:18 - 2012-07-26 12:27 - 00155620 _____ C:\Windows\system32\perfc007.dat
2013-07-31 13:18 - 2012-07-26 09:28 - 01745416 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-31 13:16 - 2012-12-13 00:02 - 00000000 ____D C:\Users\Wolfgang\Documents\My PSP Files
2013-07-31 11:01 - 2013-07-31 11:01 - 00891098 _____ C:\Users\Wolfgang\Downloads\SecurityCheck.exe
2013-07-31 10:57 - 2013-07-31 10:57 - 02347384 _____ (ESET) C:\Users\Wolfgang\Downloads\esetsmartinstaller_enu.exe
2013-07-31 09:03 - 2012-12-07 17:08 - 00000000 ____D C:\Users\Wolfgang\Documents\Outlook-Dateien
2013-07-31 08:33 - 2012-12-07 16:00 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2248620764-1602766578-3412886822-1001
2013-07-31 07:45 - 2012-12-07 15:53 - 00001001 _____ C:\Users\Wolfgang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-31 07:37 - 2013-07-31 07:37 - 00000000 ____D C:\Windows\ERUNT
2013-07-31 07:36 - 2013-07-31 07:36 - 00562430 _____ (Oleg N. Scherbakov) C:\Users\Wolfgang\Downloads\JRT.exe
2013-07-29 15:18 - 2012-12-12 21:33 - 00000000 ____D C:\Users\Wolfgang\Downloads\F1 2012
2013-07-29 13:52 - 2013-07-29 13:52 - 00490078 _____ C:\Users\Wolfgang\Downloads\F1 2012 - Safety Car Fix.rar
2013-07-29 12:52 - 2013-07-29 12:52 - 00001282 _____ C:\Users\Wolfgang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-07-29 12:46 - 2013-07-29 12:46 - 00000000 ____D C:\Users\Wolfgang\Desktop\Alte Firefox-Daten
2013-07-29 11:42 - 2013-07-29 11:42 - 01780547 _____ (Farbar) C:\Users\Wolfgang\Downloads\FRST64.exe
2013-07-29 11:37 - 2013-07-29 11:37 - 00000000 ____D C:\Program Files (x86)\ESET
2013-07-29 11:15 - 2013-07-29 11:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-29 11:15 - 2013-07-29 11:14 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-29 11:15 - 2013-06-24 14:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-29 11:09 - 2013-07-29 10:35 - 00000000 ____D C:\ProgramData\eSafe
2013-07-29 11:09 - 2012-12-07 16:11 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-29 11:09 - 2012-12-07 15:39 - 00157028 _____ C:\Windows\PFRO.log
2013-07-29 11:09 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-29 11:08 - 2012-07-26 07:26 - 00524288 ___SH C:\Windows\system32\config\BBI
2013-07-29 11:06 - 2013-07-29 11:06 - 21703480 _____ (Mozilla) C:\Users\Wolfgang\Downloads\Firefox_Setup_22.0.exe
2013-07-29 11:02 - 2013-07-29 11:02 - 02828552 _____ (AVAST Software) C:\Users\Wolfgang\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-07-29 10:45 - 2013-07-29 10:44 - 00424016 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-29 10:34 - 2013-07-29 10:34 - 00000000 ____D C:\Users\Wolfgang\AppData\Roaming\eIntaller
2013-07-29 10:34 - 2011-06-11 02:58 - 00773712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2013-07-29 10:34 - 2011-06-11 02:58 - 00420944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2013-07-29 08:26 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-07-24 18:40 - 2012-07-26 09:21 - 00035864 _____ C:\Windows\setupact.log
2013-07-22 10:04 - 2012-12-24 08:52 - 00000000 ____D C:\Users\Wolfgang\Downloads\Neuer Ordner
2013-07-22 09:46 - 2012-12-07 17:09 - 00003888 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-07-22 09:46 - 2012-12-07 17:09 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-07-20 10:30 - 2012-07-26 12:29 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-20 10:29 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe
2013-07-19 08:45 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF
2013-07-19 08:40 - 2013-03-16 12:43 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-19 08:40 - 2013-03-16 12:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-19 08:38 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-07-16 21:17 - 2012-12-07 16:51 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-16 21:14 - 2012-12-13 00:11 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-07-16 20:33 - 2012-12-12 21:56 - 00000000 ____D C:\Users\Wolfgang\AppData\Local\Adobe
2013-07-16 20:31 - 2012-12-07 16:33 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-04 17:26 - 2013-07-04 17:14 - 00000000 ____D C:\Users\Wolfgang\Desktop\Laura SD
2013-07-04 08:25 - 2013-07-04 08:24 - 00000000 ____D C:\Users\Wolfgang\Downloads\Hilfestellung
2013-07-03 10:55 - 2013-03-23 18:53 - 00105984 ___SH C:\Users\Wolfgang\Desktop\Thumbs.db
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-20 09:40
==================== End Of Log ============================
--- --- ---
--- --- ---