Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 06.01.2014, 18:54   #1
Heradi
 
Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten - Standard

Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten



Guten Tag liebe TrojanerBoard Helfer,

ich habe heute ein paar Videos geschaut und bei einem ist ein Download gestartet den ich noch abbrechen wollte aber ohne Erfolg. Danach habe ich in all meinen Internet Browsern eine Startseite die www.nationzoom.com heisst und ich bekomme diese nicht weg.

Ich möchte mich dafür entschuldigen das ich schon selbstständig versucht habe diese Seite loszuwerden nach folgenden beiden Anleitungen:
hxxp://praxistipps.chip.de/nationzoom-virus-entfernen-so-gehts_20339
und
hxxp://www.browserdoktor.de/nationzoom-entfernen/

Die ersten beiden Links wenn man bei Google "Nation Zoom Entfernen" eingibt falls ihr die Links als unsicher ansehen solltet.

Keine dieser beiden Anleitungen hat geholfen somit wende ich mich nun an dieses Forum weil das hier ja professionelle Hilfe bietet.

Ich habe ausserdem einen FRST Scan durchgeführt den ich nachfolgend poste.

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014
Ran by Ozoma (administrator) on OZOMA-PC on 06-01-2014 19:47:26
Running from C:\Users\Ozoma\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.)
HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1389015938&from=amt&uid=ST31000524AS_9VPFBC69XXXX9VPFBC69
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"

FireFox:
========
FF ProfilePath: C:\Users\Ozoma\AppData\Roaming\Mozilla\Firefox\Profiles\xf4j3rjr.default-1389032603445
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\nationzoom.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afurladvisor@anchorfree.com
FF StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome: 
=======
CHR Extension: (Adblock Plus) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0
CHR Extension: (AdBlock) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (Google Wallet) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1
CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Ozoma\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1389015938&from=amt&uid=ST31000524AS_9VPFBC69XXXX9VPFBC69
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-07-12] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-31] (DT Soft Ltd)
S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-07-24] (AnchorFree Inc.)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-06 19:47 - 2014-01-06 19:47 - 01931762 _____ (Farbar) C:\Users\Ozoma\Downloads\FRST64.exe
2014-01-06 19:47 - 2014-01-06 19:47 - 00011153 _____ C:\Users\Ozoma\Downloads\FRST.txt
2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt
2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox
2014-01-06 19:23 - 2014-01-06 19:23 - 00000000 ____D C:\Users\Ozoma\Desktop\Alte Firefox-Daten
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat
2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group
2014-01-06 19:12 - 2014-01-06 19:13 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP
2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe
2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-01-06 15:17 - 2014-01-06 15:18 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe
2014-01-06 14:46 - 2014-01-06 14:48 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Mobogenie
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\Documents\Mobogenie
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt
2014-01-06 14:45 - 2014-01-06 14:55 - 00000000 ____D C:\ProgramData\WPM
2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url
2014-01-05 16:01 - 2014-01-05 16:02 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar
2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip
2014-01-05 12:47 - 2014-01-05 12:48 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar
2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer
2014-01-02 20:13 - 2014-01-02 20:14 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip
2014-01-02 18:52 - 2014-01-02 20:42 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt
2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip
2014-01-02 14:50 - 2013-11-15 04:48 - 00336896 _____ C:\Users\Ozoma\Desktop\WSplit.exe
2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip
2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url
2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip
2013-12-31 15:19 - 2013-12-31 15:20 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip
2013-12-31 14:41 - 2013-12-31 14:42 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar
2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip
2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url
2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url
2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV
2013-12-21 22:10 - 2013-12-31 04:08 - 00000050 _____ C:\Users\Ozoma\Desktop\save1
2013-12-21 22:09 - 2013-12-31 04:12 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime
2013-12-21 22:09 - 2013-11-23 09:22 - 147172145 _____ () C:\Users\Ozoma\Desktop\I wanna go the Parallel World.exe
2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4
2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url
2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg
2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg
2013-12-18 21:50 - 2013-12-31 00:35 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1
2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip
2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url
2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk
2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe
2013-12-14 22:12 - 2013-12-14 23:26 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip
2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar
2013-12-12 03:01 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 03:01 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 03:01 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 03:01 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 03:00 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 03:00 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 03:00 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:00 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 03:00 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 03:00 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:00 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 03:00 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 03:00 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 03:00 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 03:00 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 03:00 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 03:00 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:00 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 03:00 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 03:00 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 03:00 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 03:00 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 03:00 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 03:00 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 03:00 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 03:00 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 03:00 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 03:00 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 03:00 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 03:00 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 03:00 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 03:00 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 03:00 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 03:00 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 03:00 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 15:28 - 2013-12-11 16:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 12:45 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 12:45 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 12:45 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 12:45 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 12:45 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 12:45 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 12:45 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 12:45 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 12:45 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 12:45 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 12:45 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 12:45 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 12:45 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 12:45 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 12:45 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 12:45 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 12:45 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 12:45 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 12:45 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 03:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-11 02:59 - 2013-12-11 03:03 - 00010277 _____ C:\Windows\IE11_main.log
2013-12-08 00:51 - 2014-01-04 23:15 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update
2013-12-08 00:50 - 2013-12-31 14:52 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode
2013-12-07 19:33 - 2013-12-07 19:33 - 00000000 ____D C:\Users\Ozoma\AppData\Local\{919835E6-46EA-4053-B5E2-458DB270630D}
2013-12-07 15:49 - 2013-12-07 15:52 - 79259754 _____ C:\Users\Ozoma\Downloads\MegaManUnlimited.zip
2013-12-07 15:48 - 2013-12-07 15:50 - 79316716 _____ C:\Users\Ozoma\Downloads\MegaManUnlimited1.1.0SR.zip

==================== One Month Modified Files and Folders =======

2014-01-06 19:47 - 2014-01-06 19:47 - 01931762 _____ (Farbar) C:\Users\Ozoma\Downloads\FRST64.exe
2014-01-06 19:47 - 2014-01-06 19:47 - 00011153 _____ C:\Users\Ozoma\Downloads\FRST.txt
2014-01-06 19:47 - 2012-04-24 07:18 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Skype
2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt
2014-01-06 19:42 - 2012-07-31 10:22 - 00000000 ____D C:\Qoobox
2014-01-06 19:40 - 2013-04-29 19:53 - 00000000 ____D C:\Users\Ozoma\AppData\Local\LogMeIn Hamachi
2014-01-06 19:40 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-06 19:35 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-06 19:35 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-06 19:31 - 2012-04-20 22:40 - 01311990 _____ C:\Windows\WindowsUpdate.log
2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox
2014-01-06 19:28 - 2013-01-03 23:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-06 19:27 - 2013-05-11 13:54 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-06 19:27 - 2012-04-18 06:46 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-06 19:27 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-06 19:27 - 2009-07-14 05:51 - 00876558 _____ C:\Windows\setupact.log
2014-01-06 19:26 - 2013-11-25 15:24 - 00000000 ____D C:\AdwCleaner
2014-01-06 19:23 - 2014-01-06 19:23 - 00000000 ____D C:\Users\Ozoma\Desktop\Alte Firefox-Daten
2014-01-06 19:21 - 2013-05-11 13:54 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat
2014-01-06 19:16 - 2013-11-25 15:28 - 05160001 ____R (Swearware) C:\Users\Ozoma\Downloads\ComboFix.exe
2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group
2014-01-06 19:13 - 2014-01-06 19:12 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP
2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe
2014-01-06 19:03 - 2010-11-21 04:47 - 00907684 _____ C:\Windows\PFRO.log
2014-01-06 18:53 - 2012-04-20 22:59 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\TS3Client
2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-01-06 15:30 - 2013-11-25 16:34 - 00000000 ____D C:\ProgramData\AVAST Software
2014-01-06 15:27 - 2012-04-20 22:45 - 00000000 ___RD C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-06 15:24 - 2013-01-20 02:32 - 00000000 ____D C:\Program Files (x86)\Sony
2014-01-06 15:18 - 2014-01-06 15:17 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe
2014-01-06 14:55 - 2014-01-06 14:45 - 00000000 ____D C:\ProgramData\WPM
2014-01-06 14:48 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Mobogenie
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\Documents\Mobogenie
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt
2014-01-06 14:46 - 2012-04-20 22:45 - 00000000 ____D C:\Users\Ozoma
2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-06 14:45 - 2013-05-11 13:54 - 00002373 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-06 14:45 - 2013-03-02 11:33 - 00001328 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-01-06 14:45 - 2012-04-20 22:45 - 00001631 _____ C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-06 13:46 - 2012-08-16 23:56 - 00029696 _____ C:\Users\Ozoma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-06 12:42 - 2012-04-21 10:44 - 00000000 ____D C:\Users\Ozoma\Desktop\Let's plays und fails
2014-01-05 21:18 - 2013-08-15 19:52 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Mumble
2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url
2014-01-05 16:02 - 2014-01-05 16:01 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar
2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip
2014-01-05 12:49 - 2012-10-01 16:39 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Paint.NET
2014-01-05 12:48 - 2014-01-05 12:47 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar
2014-01-04 23:15 - 2013-12-08 00:51 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update
2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer
2014-01-02 20:42 - 2014-01-02 18:52 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt
2014-01-02 20:14 - 2014-01-02 20:13 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip
2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip
2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip
2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url
2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip
2013-12-31 15:20 - 2013-12-31 15:19 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip
2013-12-31 14:52 - 2013-12-08 00:50 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode
2013-12-31 14:42 - 2013-12-31 14:41 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar
2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip
2013-12-31 04:12 - 2013-12-21 22:09 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime
2013-12-31 04:08 - 2013-12-21 22:10 - 00000050 _____ C:\Users\Ozoma\Desktop\save1
2013-12-31 00:35 - 2013-12-18 21:50 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1
2013-12-30 10:21 - 2013-11-11 06:09 - 00001945 _____ C:\Users\Ozoma\Desktop\Warp 9,975.txt
2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url
2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url
2013-12-23 04:55 - 2013-06-27 19:58 - 00000000 ____D C:\Users\Ozoma\Desktop\JoyToKey_en
2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV
2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4
2013-12-21 04:20 - 2012-05-11 14:51 - 00000000 ____D C:\Users\Ozoma\Documents\StarCraft II
2013-12-20 21:16 - 2012-04-20 22:44 - 00407840 _____ C:\Windows\DirectX.log
2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url
2013-12-20 07:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-19 15:42 - 2012-05-23 10:35 - 00002884 _____ C:\Users\Ozoma\Desktop\Tag.txt
2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg
2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg
2013-12-18 21:50 - 2013-08-15 19:51 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplit
2013-12-18 18:58 - 2013-11-25 15:29 - 00001467 _____ C:\Users\Ozoma\Desktop\ComboFix - Verknüpfung.lnk
2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip
2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url
2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk
2013-12-15 22:49 - 2012-04-18 06:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe
2013-12-14 23:26 - 2013-12-14 22:12 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip
2013-12-14 18:43 - 2012-07-08 22:49 - 00007601 _____ C:\Users\Ozoma\AppData\Local\Resmon.ResmonCfg
2013-12-14 03:02 - 2013-09-06 00:05 - 00000000 ____D C:\Windows\system32\MRT
2013-12-14 03:00 - 2012-07-23 16:49 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-13 14:56 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar
2013-12-12 14:02 - 2011-04-12 08:43 - 05873572 _____ C:\Windows\system32\perfh007.dat
2013-12-12 14:02 - 2011-04-12 08:43 - 01756324 _____ C:\Windows\system32\perfc007.dat
2013-12-12 14:02 - 2009-07-14 06:13 - 00005884 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-12 13:56 - 2009-07-14 05:45 - 04918320 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-11 16:28 - 2013-12-11 15:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 16:28 - 2013-01-03 23:39 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 16:28 - 2012-04-21 18:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 12:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-11 03:03 - 2013-12-11 02:59 - 00010277 _____ C:\Windows\IE11_main.log
2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-07 19:33 - 2013-12-07 19:33 - 00000000 ____D C:\Users\Ozoma\AppData\Local\{919835E6-46EA-4053-B5E2-458DB270630D}
2013-12-07 15:52 - 2013-12-07 15:49 - 79259754 _____ C:\Users\Ozoma\Downloads\MegaManUnlimited.zip
2013-12-07 15:50 - 2013-12-07 15:48 - 79316716 _____ C:\Users\Ozoma\Downloads\MegaManUnlimited1.1.0SR.zip
2013-12-07 15:41 - 2013-07-17 06:09 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Orginal

Files to move or delete:
====================
C:\Users\Ozoma\AppData\Roaming\Camdata.ini
C:\Users\Ozoma\AppData\Roaming\CamLayout.ini
C:\Users\Ozoma\AppData\Roaming\CamShapes.ini
C:\Users\Ozoma\AppData\Roaming\CamStudio.Producer.Data.ini


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-31 15:55

==================== End Of Log ============================
         
Ich danke schonmal im Vorraus für Eventuelle Hilfe!

Alt 07.01.2014, 08:21   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten - Standard

Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten



hi,

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.



Downloade dir bitte Shortcut Cleaner (by Grinler) auf deinen Desktop.
  • Starte die sc-cleaner.exe mit einem Doppelclick.
  • Bestätige die Meldung Shortcut Cleaner Finished am Ende des Suchlaufs mit Ok.
  • Eine Logdatei wird sich öffnen (sc-cleaner.txt).
  • Poste den Inhalt mit deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________

__________________

Alt 07.01.2014, 12:20   #3
Heradi
 
Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten - Standard

Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten



Code:
ATTFilter
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2014.01.07.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Ozoma :: OZOMA-PC [Administrator]

07.01.2014 12:52:12
mbam-log-2014-01-07 (12-52-12).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 251291
Laufzeit: 4 Minute(n), 33 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         
Code:
ATTFilter
# AdwCleaner v3.016 - Bericht erstellt am 07/01/2014 um 13:06:35
# Aktualisiert 23/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Ozoma - OZOMA-PC
# Gestartet von : C:\Users\Ozoma\Desktop\adwcleaner (1).exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\WinterSoft
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Users\Ozoma\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Ozoma\Documents\Mobogenie
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\nationzoom.xml
Datei Gelöscht : C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx

***** [ Verknüpfungen ] *****

Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk
Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (3).lnk
Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk

***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKCU\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Wow6432Node\BabylonToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Schlüssel Gelöscht : HKLM\Software\supWPM

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16428

Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v21.0 (de)

[ Datei : C:\Users\Ozoma\AppData\Roaming\Mozilla\Firefox\Profiles\xf4j3rjr.default-1389032603445\prefs.js ]


-\\ Google Chrome v31.0.1650.63

[ Datei : C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [84667 octets] - [25/11/2013 15:25:03]
AdwCleaner[R1].txt - [3877 octets] - [06/01/2014 18:36:43]
AdwCleaner[R2].txt - [1182 octets] - [06/01/2014 19:26:03]
AdwCleaner[R3].txt - [5424 octets] - [07/01/2014 13:05:55]
AdwCleaner[S0].txt - [83297 octets] - [25/11/2013 15:25:39]
AdwCleaner[S1].txt - [3854 octets] - [06/01/2014 18:53:12]
AdwCleaner[S2].txt - [1244 octets] - [06/01/2014 19:26:46]
AdwCleaner[S3].txt - [3845 octets] - [07/01/2014 13:06:35]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [3905 octets] ##########
         
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.9 (01.01.2014:1)
OS: Windows 7 Home Premium x64
Ran by Ozoma on 07.01.2014 at 13:10:58,03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3620531602-815428446-3748077359-1001\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{00E890CA-5DA7-4904-AE0F-43458599A628}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{03C50279-C4C6-46CF-A4B3-F68EB0587FC1}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{05443243-56DA-4485-A753-3E14B983AF11}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{05A195B3-E966-4187-9AED-5B013E926ACA}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0614505A-B061-453F-8385-236AADCF4FF3}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{069C4023-D72E-48A2-9BB8-3428CECB706B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{06E99575-174B-4BA6-BE90-B84A22C7FA77}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{08265246-73E1-46B4-8363-31EC2B0B1AE5}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0896BB66-47B1-4A6C-9D87-7B78D9E1F79B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{092F806D-5906-487A-B9D6-2DEE9875FD73}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0944BDCA-DD69-42B2-AC6E-A4B6E4AB45FE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0966C301-5756-4117-BCB5-12B14BB158DE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{09909E29-F17C-491D-A332-30445BE68EFF}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0B064596-335F-4BA1-AE12-877861C8FA50}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0B9FE55D-F937-44A3-9B0B-01FEE99569AB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0CCF3722-CB5B-487A-8CB2-8483F8F34467}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0D6FA4A3-34A8-4C54-89A6-EF42F619A204}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0DD1A340-F165-40AC-A06C-BBD4299310D6}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0F5392A3-29B6-4177-A52A-3FCA2661C99F}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0F565785-E0DF-45D8-8E17-F94EDD61D6FF}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0FDC1137-78FD-4345-8B95-647379CDAD30}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{10579BF5-41A2-4528-AAAC-047EF18F15AC}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{10FF4500-C137-4E51-932C-A3C94BB32982}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1233B42F-6683-457D-9290-C9A3A8A7E74B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{13834694-03BB-49F7-878C-AB77E5B68808}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{13CA2F5F-EC22-41D5-8D36-5E53C4776201}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{14AEC8AA-377A-4230-839B-B46542D7DC57}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{152639DD-0FF3-4F4D-BF53-1F64BA344784}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{15948382-87C6-46E9-9AF7-15CE928D26EC}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1596EB92-C099-439A-BFFB-E7B66B7F51AE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{16184A2C-181C-4732-90F4-033F06D08542}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{166A947E-97DD-4EFF-A781-222240A7B20A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{16A7D8DA-7CBC-4687-8A99-5084C09FFEEB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{17C99D51-22DE-4A84-8FF3-4BCF9E2BE46B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{17C9F14A-8013-4AA8-9034-AB300D5C1C88}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{18BD8025-B48F-44E5-AC2E-02BC8669C290}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1A8203E9-0205-427A-9585-0381E001AE53}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1B6E6BDC-E360-410A-BB6F-4B90489FB30C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1C11969D-5965-4F79-B6EE-C88259E0A2D6}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1C3AC2EA-0D55-4F96-B0C3-0592C82E0074}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1D712AE4-D2C2-460C-964D-006D2B4C7980}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1D99DBA6-2EDE-4C80-ACF8-B1CC5EEAA8FE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1E629045-62A7-4452-88F4-6AF93AE33AF2}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1F5F4FA0-4ADD-4FD7-A739-AB4DFCE40B5C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2215024F-2C1D-4C33-AE4F-1B5A4DC00AEF}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{22F145C0-F239-4013-AF72-91CB35566FDE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{23140DDE-2714-400C-AC5B-AF60FC4EFC68}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{240DCD8C-471E-4FAF-A1A0-82C208B88AF9}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2418FBA9-671E-41D8-9C22-EFCCDCA1514C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2463CF50-1AD5-48A8-A44E-1F4540471E0E}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2552EE75-002F-48AA-BD01-6292DE4445CC}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{25C5DE14-6877-45EB-8570-9DCF5CBDF47D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{29687332-8DAC-42CC-94D2-2188CCA85C43}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2BBB07A6-A471-47C6-971C-F946555968CA}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2C571CFD-BFF6-461D-84ED-17969801EFEB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2D62BD86-008A-4A81-8F88-DDF4E0F1E5B7}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2F44D841-D198-4CA6-8D47-350675AA6DC0}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3154D09C-FF74-4949-879F-DB10DEA228BA}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{320C7864-90FF-4365-8A69-FA0CF7FB8EDE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{32BD9E0B-B27B-4DC1-B435-80E53132FD95}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{33B95BBE-6834-40FF-8209-82B56B1C0EF5}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{34166FCC-8A65-4C80-82B6-48D854C6FA3A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3594448E-D3FF-42B1-83F4-93C2DD948ECA}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{36726F9D-763B-45AB-9BC2-105A10236A34}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{371D3A9B-E9AE-4F65-9B97-1E8F66A0B1E0}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{37D3A92F-7824-41A0-8B1D-37FD284615A0}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3A57E227-B546-40C9-B2D3-DED7E049C33A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3CB2F653-C076-464B-A319-E0F04FE22FE3}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3CCD6ABB-727B-42E5-8B58-C5872A8450E5}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3E08B27B-6EF6-48AE-B515-C36124EDCDBA}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3E3F7224-322C-4B91-82F8-0CE6AE973B91}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3E93AEA9-CC2A-488C-942A-0FBE82D962EB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3ED03836-7B5E-47B7-A1B6-F2711B09FD94}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3FF33901-DA5C-4C0B-9932-71C38BA50B04}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4003B4BD-7DB3-4CA4-BD48-E435F77FFAC7}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{400CAEA1-5C4D-44FD-BD4C-11AA13C40447}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{41B7120B-21B7-4760-B956-EDBEDEC200DD}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{42EB5208-6469-4458-94D7-DF94395A5269}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{438B6E86-BD39-42B0-A58B-12AB01806A1F}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4523082B-C738-4CF8-8B6A-50191B5FBCFB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{46626621-0EE2-4598-A3FE-2D8C07F98496}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{46F9B856-87D9-4D8C-BFB0-A78C85203D91}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{47AF3EA7-968E-47F5-B9B6-58F5C3C0EB1A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{481E5860-5E9D-4B7A-AB2F-5683C826DDD3}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{48BD1D50-F291-488D-B64D-586F80FBECBA}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{49474A40-9D65-4EFE-B44E-D23D7CBFB541}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4A027F35-8460-4F39-BFB5-ACEBC1FEAE57}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4BAEE690-9A44-4148-A752-CCC0278E836A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4D788C01-6882-4046-B273-106A0E8EB8C7}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4DD23670-2EDE-49D2-B6B6-C223B27DF9DF}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4E5D583A-BE44-4F4B-8FD2-32F1BDFCCD7B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{521AA4BC-ED5B-4032-99F6-C2A5BBB19A83}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{529D91B9-61EC-4D7D-B93F-734A146CEC1C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{529E9C52-F228-45E8-A194-01754B457819}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5322707D-4658-4B81-A3CF-A816C25BAD17}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{54EF7A75-7D2E-4354-971B-8B81BEA9306D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{554C4003-C023-4D9B-AAB6-49D184101C84}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5721259C-B49B-4AC2-8690-EB45DADC45E7}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{572EC9CA-C513-4825-B288-322BC36067D8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5784899E-DBCE-4675-9175-C3F8B4653375}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{57B906D7-D069-4E00-91A8-1589D3D1BA5B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{590CCCD9-EDDD-4818-9A45-661AB22D51FB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{592360E6-E87F-49B4-A486-35BDEFDB3ACF}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5BF75791-D2F9-4C9A-8333-4BD4AEDB6BBD}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5C0255C6-CF51-4D62-A192-43368ADBC74B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5E145337-25DB-4D0B-8D5A-ECD2AB259872}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5E87AA61-CACA-4926-A18C-2592B2C19B14}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5F7229E3-F0A3-4CC5-9F1D-0638286FF25C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5F730C31-DB67-4923-8974-5CF9C8693DCE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{61524252-FA76-4E43-87E4-9C14DFDA05A4}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6250F42D-BA92-4C39-BD05-95B1A64D3620}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{628F124B-022F-4EA9-978E-7AF33D9733F9}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{635B5EF3-C35F-42C2-8521-10C9EFD27514}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{635DB9F6-3CB8-4A93-BB9A-119B17141AEA}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{66C42329-6E4A-451E-BEBF-9B7733983EB4}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{66D2124C-D76B-49AF-95E1-ADD45F4EF05C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{67C5301E-61D6-45A8-BC88-EE7AF1A2DE01}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{67FC886C-15BE-4FCA-B6DC-025AC4E6B23C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{698BFEDB-7F27-4231-B387-85636F8F1DB2}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{69B27FBE-984E-4E9E-A7EB-4D4BFCE18CBD}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6A10F672-FA32-49A5-B002-61FCB6C6FFA5}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6A4F3E07-9E43-4E61-9541-95CB50BEB9D3}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6A6854F6-4297-40FC-BDA2-0436CE5C2D26}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6A8A52D0-8C78-479C-BFF5-75615FE1C677}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6B1A79FD-8139-42C0-AF7F-ABE4F0B1289D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6CAC6493-AFF1-4798-BD73-1087AF350DE5}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6D7F568D-1436-42C9-810A-38FB72ACDBBC}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6E24DC49-B1A1-4A59-BB24-FB653F22100D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6ECE3E56-7CBC-41DF-A815-0E1308ABBD84}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6FB9C092-1C68-45AD-9139-44B56A189672}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{704A56BE-3FBE-48C2-B9AB-932C4AD85590}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{708879C7-8E56-4B49-8410-41CD76A636B6}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{714C3802-9A1F-41A2-AFA4-7382B753D659}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{71BE9908-BA2B-48AF-BA79-9A44EAF2598C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7220B662-D000-4E27-9E5B-F3FE7D21362A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7241E997-D3F2-4CC3-BA53-33538380DF07}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{73733C01-91E9-4687-B423-897944142130}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{76F41AB7-C07E-4854-A4BE-D812BF151DDA}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{77B08B2F-09AE-4861-A444-DDD4A5190183}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{77E46581-2940-4848-8073-83FA589F8939}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{77ED0A12-EB8E-4F8C-922D-524C5E929132}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{785D0824-2384-482F-ABBB-B62FEBDC84ED}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{78A81688-37F1-490E-B03E-CA9246A989F9}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7A4352E9-6114-4A61-A498-D7D204683A5F}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7B2634B0-91F8-4E85-908F-41B505A7E34C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7D63BABF-8AF1-4ABA-96B2-AFEC1EC97C30}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7DA4E5C8-F777-4073-9820-374AC559FBCC}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7E579D4B-C2DF-4DB3-8BC9-E6E59C696582}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7E811C44-5F72-424C-A655-B917A6E6F555}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7E9686A4-8429-45A3-BE04-5366934B8C96}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7FC3CF13-BD6E-4E4B-9D6B-6806F6399EB8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{809D6D0A-823A-4B42-9875-D931FAD0014C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8143F5C3-4080-4477-BB76-DA7162407E9C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{82A3EFA3-8756-4863-B153-F3B8EEF2CD6D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{832089FB-F92E-4A2D-ADCB-925725ADE2F6}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{83857151-587C-462D-AEC4-FEA414E20C0B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{83FD7A45-8850-43C2-85A5-088B75F63556}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{84FF0A5D-246E-468F-B898-0DFD9D57563B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{850CFAF8-6377-4756-AC42-90B776FE7F7B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{87FD4072-D6C1-43E8-AC41-602C802119FF}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8888F3EC-9141-405B-BF67-D412A16D74B4}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{88BF4937-9DD4-42EB-A13A-4BF0240C5169}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{88C4B221-A0C7-4491-B119-52699FA44D9F}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8B123261-B006-428A-B545-C941AE0B6F29}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8C5C6119-6F82-4841-B4DC-54B34B77607C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8CC6DA17-D960-4562-A247-29C78917B6EB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8CEF4658-63EB-480E-9420-7186DE8F1033}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8EFF9786-53DB-4F6B-8D23-10A717531C37}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{90337936-711D-4848-9BA9-A67C86CDD570}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{907C7E17-0BA1-485E-85DF-C88986C0A0CA}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{919835E6-46EA-4053-B5E2-458DB270630D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{934EB8CB-9BF9-4CB9-9808-5996B943D163}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{93AF923A-C3C7-4833-AC68-01021D16ECD0}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{93F01C1B-9ABD-4A31-9BF1-624806D4617D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9488362A-0D60-447F-A7F3-DEE012E5C31F}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{94AB8D78-8F01-4FEF-B48B-E93983E9FB72}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{951F128C-24A5-45BD-BB5F-FA50F047F1AD}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{95C53204-5FC2-463F-8D4D-F692477C34F8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{961DA1F0-39FA-4B1E-BB35-5D5AB0643A7A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{96F96DF6-CD70-4930-98BE-EC0A3B903A07}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9751E9E8-40EC-40D5-BE01-FE4EE8E9B109}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{97D396BD-0DD7-49B2-A5B8-40E450A57A31}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{97D59104-3AA7-46F8-A02F-9023CBE193B8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{980285C4-5621-43B2-A461-F1467CB424E4}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{989F9309-BADE-4CF3-A64F-24C743CDC7ED}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9ABEF256-E396-4EA8-9629-D26C5D4A3A51}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9AC5E05F-359A-4D5D-8F6F-40C0C9708C05}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9B683DC0-3B0B-43E8-9575-D66D54F49AB1}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9D1A64F9-27A9-4A4D-8981-EC4177F66291}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9EDDEA89-777F-4029-9F37-E7FCAA2D9EF5}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9F3288FC-07DA-4E9F-8E90-4BA3F98B7F41}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A07906B0-C79C-47D1-981C-6967597C84AF}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A0BD4373-5D50-45AF-AD4C-FE2113C29AAB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A10F0F80-B0F0-4B65-ADDA-DF8A471DF072}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A316777A-E193-433A-92BD-13881CF3EB77}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A35DA85D-ECDE-480C-9BEB-F2A26772EC0E}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A48BED54-3AFD-49B2-82D9-C38DB69408EB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A49AB1EE-B95F-4372-9467-4BAC438A729F}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A4E4D98E-B0DA-48F9-82FB-A07A63F71F8C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A5722E92-17C8-43DA-9038-7F000EA94F52}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A6CDE583-DA03-4F29-82A8-58D31B860147}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A7CE685A-8882-4053-8B98-474BDB50149E}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A8ACD05A-5B3A-48BF-AE80-4896658B37B6}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A92453C1-58D4-4446-9AD3-AA768B42B5D1}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A94C7DE6-E983-4E92-BF3A-57F311F03CEE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AB47EC36-E700-4442-A75E-8D5BD6A9C67C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AD050927-4CA8-4B0D-9E74-3E09764CB655}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AD06BEE4-BB40-4642-9C38-B9EA34E4D932}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AD2C033C-F34A-438C-9C8C-7E1AB9DC104E}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AD52454A-A645-4E72-BD9E-051AFCCFC90A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AFB41E9B-EE88-40DC-8928-5F0DAC9CFE85}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B04466FE-F2C8-4317-8580-0345E7A57277}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B0B68426-A168-47D9-99DF-3673496737B1}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B1110580-B873-4AAE-A6F5-1F7C5AEC6591}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B2D632BB-94D7-473D-9120-1B0CA23B66A8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B34A2F77-7D16-4CA3-826C-8FD4886B36D8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B536A5CA-8A52-4FB2-8557-63FD807B5ACE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B577F428-42E2-4371-A3D6-601176551B85}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B63F125C-74D4-4EF2-A18A-2F1F39048E10}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B7FBBFC2-E237-40F2-B4E2-0C8A1E801D57}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BBA947A5-551A-4736-BF90-DBED7B11E3CB}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BBFBD7EE-A5EF-479B-B516-AA9E5B6F6B2B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BCE5EA73-9027-4F02-97C2-77578362894F}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BD9F495D-713F-49F6-9545-932D709F210C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BE676B08-1388-4DC8-BBB1-71A6FB01F19D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C0F60B30-D716-4452-8B90-3FFD75C1152C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C1BCD1FA-F078-4355-8D3C-F648AE479DF9}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C217BB74-5D34-4443-928A-AB4D0A5B48AC}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C285303F-6A8B-40A4-83FE-9070A1C04792}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C40BCC1F-B789-4F54-B353-00474F6CFFC7}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C4919A7C-2D1A-4CF6-A0F7-89CBE8403890}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C5829563-5B65-402F-AC67-0772F2976FCE}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C59389EA-FB2E-4E72-BE85-E586BE9E6E20}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C5F19DB6-4B0D-4BE2-AD59-95ECDEE8D8D9}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C732E86B-0AE7-49C4-9949-4D842B8A5FBF}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C77AC8CB-B644-410D-81CC-1F894D75D493}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C79ED3A8-BD19-496C-B9C3-C3179977FBB3}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C97E06A0-FEAC-4040-B7CA-31CD9B1C2A41}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CA967193-6809-47B1-BF65-442138185A7A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CB4B801A-FBB7-4208-AECC-0C5F6B452DB3}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CB714EC0-F0CB-43D6-8B1C-77788DFA2763}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CC117AB0-2E58-480B-971C-F8EF01611E27}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CC1DDFFA-9B54-41B7-BC19-9BBF415E8217}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CCE9580B-DFFD-4BD3-9D25-8CA9CFC7A916}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CD8E2581-2395-4448-A5BA-39136B452C7A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CE26D183-D616-4DB4-8898-5BE72E50410D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D1AAF9BB-4554-4C0E-9915-4A10C1C59322}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D30C8EA8-2F82-47CE-8187-C32ABFA8C930}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D39FE9EA-F405-47D7-B707-F9814DE04011}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D3DEA3D0-44EF-46C3-BB89-18510E613C98}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D6611F76-13BA-4903-B7B7-754D1B57843A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D7732F92-CAFD-42A5-995D-FDBE05AEA601}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D80A650B-4320-433F-9792-F10E04C494D3}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D867F407-E793-4F54-AA05-B21ED2931AD8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DA65A950-81BF-414E-9053-43AF4FE847A3}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DB76D859-C906-4A9B-AF22-615594AC1E8F}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DC36058E-E761-4B7B-AD19-AADCFCFA1803}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DE3EF15D-02BF-47E1-BB97-D32C7D82220A}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DF83E91C-549E-42D0-B6CA-75DCA617CE1C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E07664ED-95A2-43C6-A673-50DB7A6D59DD}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E10365DD-38B3-4EFF-8206-99FDB2960230}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E1328159-5BD5-4690-BA6B-C022498D04B5}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E3085623-0C2A-4007-B133-769C5434E0C6}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E4271EAC-4C48-4D8B-97A4-5032D980F6CD}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E54719C8-D211-43A5-99AE-E659129B5A2F}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E57A5E75-22EF-43CB-9074-55B0BABB9D7E}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E59FFA01-3899-4B1D-B0E9-4217EBA96F3B}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E7DA4EB2-104D-4362-AFCE-FCB7A39644B6}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E9EE2942-8172-4D1F-953F-E90AE398CB11}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EA12E7DB-993F-4303-8189-DCCD659719A8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EBB6F81A-96D0-44AD-9DC6-90E74B8B5602}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EC6E2DCF-415F-4F91-9299-02A64ADD6E9E}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EC80ECBB-88DD-4034-A946-C58B5586B3E8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{ED8F9247-E0C2-4424-B567-E04463A45123}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EED4A8A4-0BC2-42AC-8266-932F460FF668}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EF06118D-88E1-4971-9D97-BFF13C3C091C}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EF43DE86-FBD7-4EC0-98C8-BC7E5C1014DC}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F2A77E3C-0E19-4749-A891-03365523D4F0}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F2F3163C-9338-4965-9E6E-96D05749FE1D}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F51A623B-2B6A-4727-96E4-0AC29A1175D9}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F66BACB7-B595-43F7-8179-439413D5F5E8}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F8E5F179-1505-4160-B6D0-9C44BF9BCAC6}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F90CBC14-6AE9-46A6-987B-EDE1F631EBAC}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FA97A7B8-56AF-46CB-A1CB-C9DF10C66401}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FD2E149E-AFFD-46B4-B2A1-3B6BC96ED8C2}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FE53B363-F0D1-4A9E-8EC0-9A1F0EBFF0B7}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FEFEF785-F04E-45A4-9602-BD9667C64ED4}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FFB4C941-4849-4C0D-A76C-73B3F87E57B6}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FFC95BBC-A658-4105-9537-EC5FC1C54017}
Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FFD37BA4-4C01-4FB6-8B29-55FC9CE2D7FC}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 07.01.2014 at 13:15:09,59
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
Code:
ATTFilter
Shortcut Cleaner 1.2.6 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
 hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/

Windows Version: Windows 7 Home Premium Service Pack 1
Program started at: 01/07/2014 01:16:53 PM.

Scanning for registry hijacks:

 * No issues found in the Registry.

Searching for Hijacked Shortcuts:

Searching C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\

Searching C:\ProgramData\Microsoft\Windows\Start Menu\

Searching C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\

Searching C:\Users\Public\Desktop\

Searching C:\Users\Ozoma\Desktop


0 bad shortcuts found.

Program finished at: 01/07/2014 01:16:59 PM
Execution time: 0 hours(s), 0 minute(s), and 5 seconds(s)
         
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014
Ran by Ozoma (administrator) on OZOMA-PC on 07-01-2014 13:17:48
Running from C:\Users\Ozoma\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.)
HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"

FireFox:
========
FF ProfilePath: C:\Users\Ozoma\AppData\Roaming\Mozilla\Firefox\Profiles\xf4j3rjr.default-1389032603445
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afurladvisor@anchorfree.com
FF StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome: 
=======
CHR Extension: (Adblock Plus) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0
CHR Extension: (AdBlock) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (Google Wallet) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1
CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Ozoma\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-07-12] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-31] (DT Soft Ltd)
S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-07-24] (AnchorFree Inc.)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-07 13:16 - 2014-01-07 13:16 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Ozoma\Desktop\sc-cleaner.exe
2014-01-07 13:16 - 2014-01-07 13:16 - 00001796 _____ C:\sc-cleaner.txt
2014-01-07 13:15 - 2014-01-07 13:15 - 00032162 _____ C:\Users\Ozoma\Desktop\JRT.txt
2014-01-07 13:10 - 2014-01-07 13:10 - 00000000 ____D C:\Windows\ERUNT
2014-01-07 13:09 - 2014-01-07 13:10 - 01036305 _____ (Thisisu) C:\Users\Ozoma\Desktop\JRT.exe
2014-01-07 13:08 - 2014-01-07 13:08 - 00003993 _____ C:\Users\Ozoma\Desktop\ADWCleanerscan.txt
2014-01-07 12:58 - 2014-01-07 12:58 - 01233962 _____ C:\Users\Ozoma\Desktop\adwcleaner (1).exe
2014-01-07 12:48 - 2014-01-07 12:48 - 00000000 ____D C:\Users\Ozoma\Desktop\Malwarebytes' Anti-Malware
2014-01-07 12:47 - 2014-01-07 12:48 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Ozoma\Desktop\mbam-setup-1.75.0.1300 (1).exe
2014-01-06 19:47 - 2014-01-07 13:17 - 00011895 _____ C:\Users\Ozoma\Downloads\FRST.txt
2014-01-06 19:47 - 2014-01-06 19:47 - 01931762 _____ (Farbar) C:\Users\Ozoma\Desktop\FRST64.exe
2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt
2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat
2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group
2014-01-06 19:12 - 2014-01-06 19:13 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP
2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe
2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-01-06 15:17 - 2014-01-06 15:18 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt
2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url
2014-01-05 16:01 - 2014-01-05 16:02 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar
2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip
2014-01-05 12:47 - 2014-01-05 12:48 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar
2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer
2014-01-02 20:13 - 2014-01-02 20:14 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip
2014-01-02 18:52 - 2014-01-02 20:42 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt
2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip
2014-01-02 14:50 - 2013-11-15 04:48 - 00336896 _____ C:\Users\Ozoma\Desktop\WSplit.exe
2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip
2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url
2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip
2013-12-31 15:19 - 2013-12-31 15:20 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip
2013-12-31 14:41 - 2013-12-31 14:42 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar
2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip
2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url
2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url
2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV
2013-12-21 22:10 - 2013-12-31 04:08 - 00000050 _____ C:\Users\Ozoma\Desktop\save1
2013-12-21 22:09 - 2013-12-31 04:12 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime
2013-12-21 22:09 - 2013-11-23 09:22 - 147172145 _____ () C:\Users\Ozoma\Desktop\I wanna go the Parallel World.exe
2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4
2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url
2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg
2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg
2013-12-18 21:50 - 2013-12-31 00:35 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1
2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip
2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url
2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk
2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe
2013-12-14 22:12 - 2013-12-14 23:26 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip
2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar
2013-12-12 03:01 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 03:01 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 03:01 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 03:01 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 03:00 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 03:00 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 03:00 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:00 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 03:00 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 03:00 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:00 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 03:00 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 03:00 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 03:00 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 03:00 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 03:00 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 03:00 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:00 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 03:00 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 03:00 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 03:00 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 03:00 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 03:00 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 03:00 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 03:00 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 03:00 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 03:00 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 03:00 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 03:00 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 03:00 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 03:00 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 03:00 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 03:00 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 03:00 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 03:00 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 15:28 - 2013-12-11 16:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 12:45 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 12:45 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 12:45 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 12:45 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 12:45 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 12:45 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 12:45 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 12:45 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 12:45 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 12:45 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 12:45 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 12:45 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 12:45 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 12:45 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 12:45 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 12:45 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 12:45 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 12:45 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 12:45 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 03:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-11 02:59 - 2013-12-11 03:03 - 00010277 _____ C:\Windows\IE11_main.log
2013-12-08 00:51 - 2014-01-04 23:15 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update
2013-12-08 00:50 - 2013-12-31 14:52 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode

==================== One Month Modified Files and Folders =======

2014-01-07 13:18 - 2014-01-06 19:47 - 00011895 _____ C:\Users\Ozoma\Downloads\FRST.txt
2014-01-07 13:16 - 2014-01-07 13:16 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Ozoma\Desktop\sc-cleaner.exe
2014-01-07 13:16 - 2014-01-07 13:16 - 00001796 _____ C:\sc-cleaner.txt
2014-01-07 13:15 - 2014-01-07 13:15 - 00032162 _____ C:\Users\Ozoma\Desktop\JRT.txt
2014-01-07 13:14 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-07 13:14 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-07 13:10 - 2014-01-07 13:10 - 00000000 ____D C:\Windows\ERUNT
2014-01-07 13:10 - 2014-01-07 13:09 - 01036305 _____ (Thisisu) C:\Users\Ozoma\Desktop\JRT.exe
2014-01-07 13:10 - 2012-04-24 07:18 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Skype
2014-01-07 13:08 - 2014-01-07 13:08 - 00003993 _____ C:\Users\Ozoma\Desktop\ADWCleanerscan.txt
2014-01-07 13:08 - 2013-05-11 13:54 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-07 13:08 - 2013-04-29 19:53 - 00000000 ____D C:\Users\Ozoma\AppData\Local\LogMeIn Hamachi
2014-01-07 13:07 - 2012-04-18 06:46 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-07 13:07 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-07 13:07 - 2009-07-14 05:51 - 00876670 _____ C:\Windows\setupact.log
2014-01-07 13:06 - 2013-11-25 15:24 - 00000000 ____D C:\AdwCleaner
2014-01-07 13:06 - 2013-05-11 13:54 - 00001284 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-07 13:06 - 2013-03-02 11:33 - 00001055 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-01-07 13:06 - 2012-04-20 22:45 - 00001001 _____ C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-07 13:06 - 2012-04-20 22:40 - 01358085 _____ C:\Windows\WindowsUpdate.log
2014-01-07 12:58 - 2014-01-07 12:58 - 01233962 _____ C:\Users\Ozoma\Desktop\adwcleaner (1).exe
2014-01-07 12:48 - 2014-01-07 12:48 - 00000000 ____D C:\Users\Ozoma\Desktop\Malwarebytes' Anti-Malware
2014-01-07 12:48 - 2014-01-07 12:47 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Ozoma\Desktop\mbam-setup-1.75.0.1300 (1).exe
2014-01-07 12:48 - 2013-11-25 16:42 - 00000791 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-07 00:53 - 2012-04-20 22:59 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\TS3Client
2014-01-07 00:28 - 2013-01-03 23:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-07 00:21 - 2013-05-11 13:54 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-06 19:47 - 2014-01-06 19:47 - 01931762 _____ (Farbar) C:\Users\Ozoma\Desktop\FRST64.exe
2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt
2014-01-06 19:42 - 2012-07-31 10:22 - 00000000 ____D C:\Qoobox
2014-01-06 19:40 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat
2014-01-06 19:16 - 2013-11-25 15:28 - 05160001 ____R (Swearware) C:\Users\Ozoma\Downloads\ComboFix.exe
2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group
2014-01-06 19:13 - 2014-01-06 19:12 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP
2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe
2014-01-06 19:03 - 2010-11-21 04:47 - 00907684 _____ C:\Windows\PFRO.log
2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-01-06 15:30 - 2013-11-25 16:34 - 00000000 ____D C:\ProgramData\AVAST Software
2014-01-06 15:27 - 2012-04-20 22:45 - 00000000 ___RD C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-06 15:24 - 2013-01-20 02:32 - 00000000 ____D C:\Program Files (x86)\Sony
2014-01-06 15:18 - 2014-01-06 15:17 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt
2014-01-06 14:46 - 2012-04-20 22:45 - 00000000 ____D C:\Users\Ozoma
2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-06 13:46 - 2012-08-16 23:56 - 00029696 _____ C:\Users\Ozoma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-06 12:42 - 2012-04-21 10:44 - 00000000 ____D C:\Users\Ozoma\Desktop\Let's plays und fails
2014-01-05 21:18 - 2013-08-15 19:52 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Mumble
2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url
2014-01-05 16:02 - 2014-01-05 16:01 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar
2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip
2014-01-05 12:49 - 2012-10-01 16:39 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Paint.NET
2014-01-05 12:48 - 2014-01-05 12:47 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar
2014-01-04 23:15 - 2013-12-08 00:51 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update
2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer
2014-01-02 20:42 - 2014-01-02 18:52 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt
2014-01-02 20:14 - 2014-01-02 20:13 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip
2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip
2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip
2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url
2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip
2013-12-31 15:20 - 2013-12-31 15:19 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip
2013-12-31 14:52 - 2013-12-08 00:50 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode
2013-12-31 14:42 - 2013-12-31 14:41 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar
2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip
2013-12-31 04:12 - 2013-12-21 22:09 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime
2013-12-31 04:08 - 2013-12-21 22:10 - 00000050 _____ C:\Users\Ozoma\Desktop\save1
2013-12-31 00:35 - 2013-12-18 21:50 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1
2013-12-30 10:21 - 2013-11-11 06:09 - 00001945 _____ C:\Users\Ozoma\Desktop\Warp 9,975.txt
2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url
2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url
2013-12-23 04:55 - 2013-06-27 19:58 - 00000000 ____D C:\Users\Ozoma\Desktop\JoyToKey_en
2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV
2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4
2013-12-21 04:20 - 2012-05-11 14:51 - 00000000 ____D C:\Users\Ozoma\Documents\StarCraft II
2013-12-20 21:16 - 2012-04-20 22:44 - 00407840 _____ C:\Windows\DirectX.log
2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url
2013-12-20 07:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-19 15:42 - 2012-05-23 10:35 - 00002884 _____ C:\Users\Ozoma\Desktop\Tag.txt
2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg
2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg
2013-12-18 21:50 - 2013-08-15 19:51 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplit
2013-12-18 18:58 - 2013-11-25 15:29 - 00001467 _____ C:\Users\Ozoma\Desktop\ComboFix - Verknüpfung.lnk
2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip
2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url
2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk
2013-12-15 22:49 - 2012-04-18 06:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe
2013-12-14 23:26 - 2013-12-14 22:12 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip
2013-12-14 18:43 - 2012-07-08 22:49 - 00007601 _____ C:\Users\Ozoma\AppData\Local\Resmon.ResmonCfg
2013-12-14 03:02 - 2013-09-06 00:05 - 00000000 ____D C:\Windows\system32\MRT
2013-12-14 03:00 - 2012-07-23 16:49 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-13 14:56 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar
2013-12-12 14:02 - 2011-04-12 08:43 - 05873572 _____ C:\Windows\system32\perfh007.dat
2013-12-12 14:02 - 2011-04-12 08:43 - 01756324 _____ C:\Windows\system32\perfc007.dat
2013-12-12 14:02 - 2009-07-14 06:13 - 00005884 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-12 13:56 - 2009-07-14 05:45 - 04918320 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-11 16:28 - 2013-12-11 15:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 16:28 - 2013-01-03 23:39 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 16:28 - 2012-04-21 18:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 12:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-11 03:03 - 2013-12-11 02:59 - 00010277 _____ C:\Windows\IE11_main.log
2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe

Files to move or delete:
====================
C:\Users\Ozoma\AppData\Roaming\Camdata.ini
C:\Users\Ozoma\AppData\Roaming\CamLayout.ini
C:\Users\Ozoma\AppData\Roaming\CamShapes.ini
C:\Users\Ozoma\AppData\Roaming\CamStudio.Producer.Data.ini


Some content of TEMP:
====================
C:\Users\Ozoma\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-31 15:55

==================== End Of Log ============================
         
--- --- ---
__________________

Alt 08.01.2014, 07:31   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten - Standard

Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.01.2014, 14:01   #5
Heradi
 
Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten - Standard

Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten



Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=12
esets_scanner_update returned -1 esets_gle=12
esets_scanner_update returned -1 esets_gle=12
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=f5c96da94935ef42b00bb4b6d20c77d4
# engine=16559
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-08 01:32:32
# local_time=2014-01-08 02:32:32 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1023 16777215 0 0 0 0 0 0
# compatibility_mode=5893 16776573 100 94 68312 140817802 0 0
# scanned=486697
# found=61
# cleaned=0
# scan_time=8980
sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Doiwneload keepeeRa\2TW6QpDS.dll.vir"
sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Downllooad keeper\bOdeIA2.dll.vir"
sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\DownloAud. kkEeper\O612R0Wa.dll.vir"
sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\DowNNlooad keepper\oOqvgRBUz4.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Savensharee a\UBU6gV_BMo.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\sAvEnshhare u\XlxJ.dll.vir"
sh=6C5F221B49AD2693D21EE0528FE6286A410D7517 ft=1 fh=fdf8e68f729f4ef4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\cconttiNiUUetoosaavee\51890f78706ce.dll.vir"
sh=6C5F221B49AD2693D21EE0528FE6286A410D7517 ft=1 fh=fdf8e68f729f4ef4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\conetinuetioSaVaee\5189151046e35.dll.vir"
sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\DownlOaad keeper\ct.dll.vir"
sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Download keeper\V.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saavenshare\v1MKeDC4i.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Saavenshaure!\4rFWvTdOyc.dll.vir"
sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\sAfe save\IVx_.dll.vir"
sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Safe savee\GIXbk1.dll.vir"
sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\safe suaveo\knDMXJW8FJ.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saffE save\51cd8a0c24fc5.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saffE save\51cd8e76413d4.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saffE save\51cd9d4110dc1.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saffee Savoe\51cd671634e49.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\C9pNbcMIma.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\iqqe.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\K3Fw1No8nE.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\KobvF.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\wt2wpcGR.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SaVensharei\JhowIhcU.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\savoenshaRe\aqo982hBl2.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\savveNSharE\Grk0gv3w.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\sayfE  savee\51e646373678e.dll.vir"
sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SeaaRCh-NewTaB\lQ8yX.dll.vir"
sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Searceh-NeawTiab\VhW_.dll.vir"
sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearcH-NEwwTabo\psIP.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\4v.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51c3211fa3b49.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51c323b1267e7.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd671d72a13.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd7ec006cb0.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd7ed4c2630.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd7ee448708.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd8e7c5d2ff.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd921990a5f.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51e6464288497.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\7U82.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\bU.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\gPzTF.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\I.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\jy.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\kpyb5m6kg.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\Mm1F.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\ObQBXt0WAL.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\rihb1QfH.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\rr.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\SyUR7.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\wm.dll.vir"
sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Seariceh--NewTab\vMGawD6.dll.vir"
sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\seavensharei\Jt.dll.vir"
sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SEearcch-NewTaab\dejw9mQdHP.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\soafuE sauve\51c323ab2aeb7.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SSaafe save\51c3211bd4b7e.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SSafe savvee\51cd7eb9837d6.dll.vir"
sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SSafe savvee\51cd7ecdeffbc.dll.vir"
sh=1BE8D19F044D98320BBB7A0942924735233BCD26 ft=1 fh=1a64171e126b0516 vn="Win64/Agent.BA trojan" ac=I fn="C:\Qoobox\Quarantine\C\Windows\Installer\{52d7caf4-d0aa-4ad1-625a-8ff9241a22be}\U\00000008.@.vir"
         
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.78  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 Malwarebytes Anti-Malware Version 1.75.0.1300  
 JavaFX 2.1.1    
 Java(TM) 7 Update 5  
 Java version out of Date! 
 Adobe Flash Player 11.9.900.170  
 Adobe Reader 9 Adobe Reader out of Date! 
 Mozilla Firefox 21.0 Firefox out of Date!  
 Google Chrome 31.0.1650.57  
 Google Chrome 31.0.1650.63  
````````Process Check: objlist.exe by Laurent````````  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014
Ran by Ozoma (administrator) on OZOMA-PC on 08-01-2014 14:58:57
Running from C:\Users\Ozoma\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
() C:\Users\Ozoma\Desktop\Let's plays und fails\zsnesw.exe
(Microsoft Corporation) C:\Windows\System32\SndVol.exe
(TechSmith Corporation) D:\Camtasia\CamRecorder.exe
(TechSmith Corporation) D:\Camtasia\TscHelp.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.)
HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Ozoma\AppData\Roaming\Mozilla\Firefox\Profiles\xf4j3rjr.default-1389032603445
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afurladvisor@anchorfree.com
FF StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome: 
=======
CHR Extension: (Adblock Plus) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0
CHR Extension: (AdBlock) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (Google Wallet) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1
CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Ozoma\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-07-12] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-31] (DT Soft Ltd)
S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-07-24] (AnchorFree Inc.)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-08 14:58 - 2014-01-08 14:58 - 00000000 ____D C:\Users\Ozoma\Desktop\FRST-OlderVersion
2014-01-08 14:55 - 2014-01-08 14:55 - 00987410 _____ C:\Users\Ozoma\Desktop\SecurityCheck.exe
2014-01-08 11:59 - 2014-01-08 11:59 - 02347384 _____ (ESET) C:\Users\Ozoma\Downloads\esetsmartinstaller_enu (1).exe
2014-01-07 13:16 - 2014-01-07 13:16 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Ozoma\Desktop\sc-cleaner.exe
2014-01-07 13:16 - 2014-01-07 13:16 - 00001796 _____ C:\sc-cleaner.txt
2014-01-07 13:15 - 2014-01-07 13:15 - 00032162 _____ C:\Users\Ozoma\Desktop\JRT.txt
2014-01-07 13:10 - 2014-01-07 13:10 - 00000000 ____D C:\Windows\ERUNT
2014-01-07 13:09 - 2014-01-07 13:10 - 01036305 _____ (Thisisu) C:\Users\Ozoma\Desktop\JRT.exe
2014-01-07 13:08 - 2014-01-07 13:08 - 00003993 _____ C:\Users\Ozoma\Desktop\ADWCleanerscan.txt
2014-01-07 12:58 - 2014-01-07 12:58 - 01233962 _____ C:\Users\Ozoma\Desktop\adwcleaner (1).exe
2014-01-07 12:48 - 2014-01-07 12:48 - 00000000 ____D C:\Users\Ozoma\Desktop\Malwarebytes' Anti-Malware
2014-01-07 12:47 - 2014-01-07 12:48 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Ozoma\Desktop\mbam-setup-1.75.0.1300 (1).exe
2014-01-06 19:47 - 2014-01-08 14:58 - 01932624 _____ (Farbar) C:\Users\Ozoma\Desktop\FRST64.exe
2014-01-06 19:47 - 2014-01-07 13:18 - 00053458 _____ C:\Users\Ozoma\Downloads\FRST.txt
2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt
2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat
2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group
2014-01-06 19:12 - 2014-01-06 19:13 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP
2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe
2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-01-06 15:17 - 2014-01-06 15:18 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt
2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url
2014-01-05 16:01 - 2014-01-05 16:02 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar
2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip
2014-01-05 12:47 - 2014-01-05 12:48 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar
2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer
2014-01-02 20:13 - 2014-01-02 20:14 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip
2014-01-02 18:52 - 2014-01-02 20:42 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt
2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip
2014-01-02 14:50 - 2013-11-15 04:48 - 00336896 _____ C:\Users\Ozoma\Desktop\WSplit.exe
2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip
2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url
2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip
2013-12-31 15:19 - 2013-12-31 15:20 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip
2013-12-31 14:41 - 2013-12-31 14:42 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar
2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip
2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url
2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url
2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV
2013-12-21 22:10 - 2013-12-31 04:08 - 00000050 _____ C:\Users\Ozoma\Desktop\save1
2013-12-21 22:09 - 2013-12-31 04:12 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime
2013-12-21 22:09 - 2013-11-23 09:22 - 147172145 _____ () C:\Users\Ozoma\Desktop\I wanna go the Parallel World.exe
2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4
2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url
2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg
2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg
2013-12-18 21:50 - 2013-12-31 00:35 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1
2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip
2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url
2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk
2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe
2013-12-14 22:12 - 2013-12-14 23:26 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip
2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar
2013-12-12 03:01 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 03:01 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 03:01 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 03:01 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 03:00 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 03:00 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 03:00 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:00 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 03:00 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 03:00 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:00 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 03:00 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 03:00 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 03:00 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 03:00 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 03:00 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 03:00 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:00 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 03:00 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 03:00 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 03:00 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 03:00 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 03:00 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 03:00 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 03:00 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 03:00 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 03:00 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 03:00 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 03:00 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 03:00 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 03:00 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 03:00 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 03:00 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 03:00 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 03:00 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 15:28 - 2013-12-11 16:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 12:45 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 12:45 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 12:45 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 12:45 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 12:45 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 12:45 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 12:45 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 12:45 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 12:45 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 12:45 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 12:45 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 12:45 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 12:45 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 12:45 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 12:45 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 12:45 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 12:45 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 12:45 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 12:45 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 03:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-11 02:59 - 2013-12-11 03:03 - 00010277 _____ C:\Windows\IE11_main.log

==================== One Month Modified Files and Folders =======

2014-01-08 14:58 - 2014-01-08 14:58 - 00000000 ____D C:\Users\Ozoma\Desktop\FRST-OlderVersion
2014-01-08 14:58 - 2014-01-06 19:47 - 01932624 _____ (Farbar) C:\Users\Ozoma\Desktop\FRST64.exe
2014-01-08 14:58 - 2013-11-25 14:51 - 00011487 _____ C:\Users\Ozoma\Desktop\FRST.txt
2014-01-08 14:58 - 2013-11-25 14:51 - 00000000 ____D C:\FRST
2014-01-08 14:58 - 2012-04-24 07:18 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Skype
2014-01-08 14:55 - 2014-01-08 14:55 - 00987410 _____ C:\Users\Ozoma\Desktop\SecurityCheck.exe
2014-01-08 14:51 - 2012-08-16 23:56 - 00029696 _____ C:\Users\Ozoma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-08 14:28 - 2013-01-03 23:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-08 14:21 - 2013-05-11 13:54 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-08 13:31 - 2012-04-20 22:40 - 01399449 _____ C:\Windows\WindowsUpdate.log
2014-01-08 12:00 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-08 12:00 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-08 11:59 - 2014-01-08 11:59 - 02347384 _____ (ESET) C:\Users\Ozoma\Downloads\esetsmartinstaller_enu (1).exe
2014-01-08 11:54 - 2013-04-29 19:53 - 00000000 ____D C:\Users\Ozoma\AppData\Local\LogMeIn Hamachi
2014-01-08 11:53 - 2013-05-11 13:54 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-08 11:53 - 2012-04-18 06:46 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-08 11:53 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-08 11:53 - 2009-07-14 05:51 - 00939670 _____ C:\Windows\setupact.log
2014-01-07 13:31 - 2013-02-19 23:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-07 13:18 - 2014-01-06 19:47 - 00053458 _____ C:\Users\Ozoma\Downloads\FRST.txt
2014-01-07 13:16 - 2014-01-07 13:16 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Ozoma\Desktop\sc-cleaner.exe
2014-01-07 13:16 - 2014-01-07 13:16 - 00001796 _____ C:\sc-cleaner.txt
2014-01-07 13:15 - 2014-01-07 13:15 - 00032162 _____ C:\Users\Ozoma\Desktop\JRT.txt
2014-01-07 13:10 - 2014-01-07 13:10 - 00000000 ____D C:\Windows\ERUNT
2014-01-07 13:10 - 2014-01-07 13:09 - 01036305 _____ (Thisisu) C:\Users\Ozoma\Desktop\JRT.exe
2014-01-07 13:08 - 2014-01-07 13:08 - 00003993 _____ C:\Users\Ozoma\Desktop\ADWCleanerscan.txt
2014-01-07 13:06 - 2013-11-25 15:24 - 00000000 ____D C:\AdwCleaner
2014-01-07 13:06 - 2013-05-11 13:54 - 00001284 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-07 13:06 - 2013-03-02 11:33 - 00001055 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-01-07 13:06 - 2012-04-20 22:45 - 00001001 _____ C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-07 12:58 - 2014-01-07 12:58 - 01233962 _____ C:\Users\Ozoma\Desktop\adwcleaner (1).exe
2014-01-07 12:48 - 2014-01-07 12:48 - 00000000 ____D C:\Users\Ozoma\Desktop\Malwarebytes' Anti-Malware
2014-01-07 12:48 - 2014-01-07 12:47 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Ozoma\Desktop\mbam-setup-1.75.0.1300 (1).exe
2014-01-07 12:48 - 2013-11-25 16:42 - 00000791 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-07 00:53 - 2012-04-20 22:59 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\TS3Client
2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt
2014-01-06 19:42 - 2012-07-31 10:22 - 00000000 ____D C:\Qoobox
2014-01-06 19:40 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat
2014-01-06 19:16 - 2013-11-25 15:28 - 05160001 ____R (Swearware) C:\Users\Ozoma\Downloads\ComboFix.exe
2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr
2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group
2014-01-06 19:13 - 2014-01-06 19:12 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP
2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe
2014-01-06 19:03 - 2010-11-21 04:47 - 00907684 _____ C:\Windows\PFRO.log
2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-01-06 15:30 - 2013-11-25 16:34 - 00000000 ____D C:\ProgramData\AVAST Software
2014-01-06 15:27 - 2012-04-20 22:45 - 00000000 ___RD C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-06 15:24 - 2013-01-20 02:32 - 00000000 ____D C:\Program Files (x86)\Sony
2014-01-06 15:18 - 2014-01-06 15:17 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android
2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt
2014-01-06 14:46 - 2012-04-20 22:45 - 00000000 ____D C:\Users\Ozoma
2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-06 12:42 - 2012-04-21 10:44 - 00000000 ____D C:\Users\Ozoma\Desktop\Let's plays und fails
2014-01-05 21:18 - 2013-08-15 19:52 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Mumble
2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url
2014-01-05 16:02 - 2014-01-05 16:01 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar
2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip
2014-01-05 12:49 - 2012-10-01 16:39 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Paint.NET
2014-01-05 12:48 - 2014-01-05 12:47 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar
2014-01-04 23:15 - 2013-12-08 00:51 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update
2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer
2014-01-02 20:42 - 2014-01-02 18:52 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt
2014-01-02 20:14 - 2014-01-02 20:13 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip
2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip
2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip
2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url
2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip
2013-12-31 15:20 - 2013-12-31 15:19 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip
2013-12-31 14:52 - 2013-12-08 00:50 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode
2013-12-31 14:42 - 2013-12-31 14:41 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar
2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip
2013-12-31 04:12 - 2013-12-21 22:09 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime
2013-12-31 04:08 - 2013-12-21 22:10 - 00000050 _____ C:\Users\Ozoma\Desktop\save1
2013-12-31 00:35 - 2013-12-18 21:50 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1
2013-12-30 10:21 - 2013-11-11 06:09 - 00001945 _____ C:\Users\Ozoma\Desktop\Warp 9,975.txt
2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url
2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url
2013-12-23 04:55 - 2013-06-27 19:58 - 00000000 ____D C:\Users\Ozoma\Desktop\JoyToKey_en
2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV
2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4
2013-12-21 04:20 - 2012-05-11 14:51 - 00000000 ____D C:\Users\Ozoma\Documents\StarCraft II
2013-12-20 21:16 - 2012-04-20 22:44 - 00407840 _____ C:\Windows\DirectX.log
2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url
2013-12-20 07:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-19 15:42 - 2012-05-23 10:35 - 00002884 _____ C:\Users\Ozoma\Desktop\Tag.txt
2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg
2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg
2013-12-18 21:50 - 2013-08-15 19:51 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplit
2013-12-18 18:58 - 2013-11-25 15:29 - 00001467 _____ C:\Users\Ozoma\Desktop\ComboFix - Verknüpfung.lnk
2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip
2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url
2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk
2013-12-15 22:49 - 2012-04-18 06:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe
2013-12-14 23:26 - 2013-12-14 22:12 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip
2013-12-14 18:43 - 2012-07-08 22:49 - 00007601 _____ C:\Users\Ozoma\AppData\Local\Resmon.ResmonCfg
2013-12-14 03:02 - 2013-09-06 00:05 - 00000000 ____D C:\Windows\system32\MRT
2013-12-14 03:00 - 2012-07-23 16:49 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-13 14:56 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar
2013-12-12 14:02 - 2011-04-12 08:43 - 05873572 _____ C:\Windows\system32\perfh007.dat
2013-12-12 14:02 - 2011-04-12 08:43 - 01756324 _____ C:\Windows\system32\perfc007.dat
2013-12-12 14:02 - 2009-07-14 06:13 - 00005884 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-12 13:56 - 2009-07-14 05:45 - 04918320 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-11 16:28 - 2013-12-11 15:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 16:28 - 2013-01-03 23:39 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 16:28 - 2012-04-21 18:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 12:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-11 03:03 - 2013-12-11 02:59 - 00010277 _____ C:\Windows\IE11_main.log
2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe

Files to move or delete:
====================
C:\Users\Ozoma\AppData\Roaming\Camdata.ini
C:\Users\Ozoma\AppData\Roaming\CamLayout.ini
C:\Users\Ozoma\AppData\Roaming\CamShapes.ini
C:\Users\Ozoma\AppData\Roaming\CamStudio.Producer.Data.ini


Some content of TEMP:
====================
C:\Users\Ozoma\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-31 15:55

==================== End Of Log ============================
         
--- --- ---


Hier die verlangten Logs was Nation Zoom angeht: Beim Starten meiner Internet Browser ist die seite bisher nicht wieder aufgetaucht ich denke das ist ein gutes Zeichen
Aber ihr seit der Fachmann ist mein Pc wieder sauber nach den Logs zu urteilen?


Alt 09.01.2014, 10:02   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten - Standard

Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten



Java, Adobe und Firefox updaten.

Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
--> Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten

Antwort

Themen zu Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten
adblock, administrator, antivirus, combofix, desktop, firefox, flash player, helper, hotspot, installation, internet browser, mobogenie, mobogenie entfernen, nation zoom, nation zoom entfernen, nationzoom, nationzoom entfernen, registry, services.exe, software, spyhunter, spyhunter entfernen, svchost.exe, win32/adware.multiplug.i, win32/adware.multiplug.n, win64/agent.ba, winlogon.exe



Ähnliche Themen: Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten


  1. IE und Google Chrome öffnen beim anklicken ständig zusätzlich andere Seiten
    Plagegeister aller Art und deren Bekämpfung - 08.06.2015 (7)
  2. Werbungen und andere Seiten öffnen sich, obwohl ich Adblock installiert habe/Google Chrome
    Log-Analyse und Auswertung - 03.06.2015 (10)
  3. Firefox & Chrome öffnen automatisch Seiten mit Werbung
    Plagegeister aller Art und deren Bekämpfung - 01.11.2014 (7)
  4. Google Chrome: Seiten öffnen sich unerwünscht
    Plagegeister aller Art und deren Bekämpfung - 06.06.2014 (31)
  5. Nach der Installation von Windows 7 öffnen sich immer öfters popups erst in chrome nun auch in firefox
    Plagegeister aller Art und deren Bekämpfung - 04.06.2014 (19)
  6. [Google Chrome]Neue Seiten öffnen sich automatisch ( Werbung ) zufällige wörter jeder Internet seiten sind mit URL's verseht
    Plagegeister aller Art und deren Bekämpfung - 01.04.2014 (5)
  7. Nation Zoom erscheint beim Öffnen von Int. Explorer und Firefox, Windows 7
    Plagegeister aller Art und deren Bekämpfung - 04.03.2014 (55)
  8. Nation Zoom - ADWCleaner hängt sich auf
    Plagegeister aller Art und deren Bekämpfung - 04.02.2014 (13)
  9. Win7 , 64 bit -- (Firefox) Nation-zoom Befall.
    Log-Analyse und Auswertung - 12.01.2014 (7)
  10. Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern
    Log-Analyse und Auswertung - 07.01.2014 (14)
  11. Nation Zoom öffnet sich ungefragt in allen Browsern
    Plagegeister aller Art und deren Bekämpfung - 04.01.2014 (12)
  12. nation zoom lässt sich nicht löschen
    Plagegeister aller Art und deren Bekämpfung - 03.01.2014 (5)
  13. Nation zoom und andere sich plötzlich öffnende Tabs
    Log-Analyse und Auswertung - 25.12.2013 (15)
  14. Windows 7: Nation Zoom läßt sich nicht entfernen
    Log-Analyse und Auswertung - 21.12.2013 (19)
  15. Windows 7 Firefox zeigt immer Nation Zoom als Startseite
    Log-Analyse und Auswertung - 18.12.2013 (12)
  16. Ich habe das Problem das ich Nation Zoom nicht mehr aus Firefox herausbekomme!!
    Log-Analyse und Auswertung - 17.12.2013 (13)
  17. Google leitet auf andere Seiten um, Seiten wollen sich ungefragt öffnen. Gelöst(?) Sicher?
    Plagegeister aller Art und deren Bekämpfung - 26.07.2010 (8)

Zum Thema Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten - Guten Tag liebe TrojanerBoard Helfer, ich habe heute ein paar Videos geschaut und bei einem ist ein Download gestartet den ich noch abbrechen wollte aber ohne Erfolg. Danach habe ich - Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten...
Archiv
Du betrachtest: Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.