jenso1608 | 17.10.2013 20:50 | Whilokii bei windows 8 entfernen Hallo zusammen,
ich würde gerne dieses lästige Programm entfernen.
Ich habe (hoffentlich) die bisherigen Anleitungen befolgt.
Anbei meine Logdatei.
Vielen Dank für eure Hilfe
Jenso
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by SYSTEM on MININT-QFALVEG on 17-10-2013 21:33:07
Running from E:\
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Recovery
The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-10] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212048 2012-06-07] (Realtek Semiconductor)
HKLM\...\Run: [BtPreLoad] - C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [64640 2012-08-10] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Dolby PCEE4\pcee4.exe [508256 2012-04-22] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [LManager] - [x]
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-29] (AVAST Software)
HKU\Default\...\RunOnce: [RegAutoPlay] - C:\Program Files (x86)\Acer\clear.fi Media\RegAutoplay.exe [1845392 2012-08-21] (Acer Incorporated)
HKU\Default User\...\RunOnce: [RegAutoPlay] - C:\Program Files (x86)\Acer\clear.fi Media\RegAutoplay.exe [1845392 2012-08-21] (Acer Incorporated)
HKU\Family\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation)
==================== Services (Whitelisted) =================
S2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-10] (Qualcomm Atheros Commnucations)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-29] (AVAST Software)
S2 BitGuard; C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [2845664 2013-09-23] ()
S2 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-20] (Broadcom Corp.)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-22] (Acer Incorporated)
S3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-22] (Acer Incorporated)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
S2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-22] (NTI Corporation)
S2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-09-26] (Dritek System INC.)
S2 Update Whilokii; C:\Program Files (x86)\Whilokii\updateWhilokii.exe [65304 2013-10-04] (Whilokii)
S2 Util Whilokii; C:\Program Files (x86)\Whilokii\bin\utilWhilokii.exe [65304 2013-10-12] (Whilokii)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-01] (Microsoft Corporation)
S2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [1706064 2013-10-10] (Wsys Co., Ltd.)
S2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe [81536 2012-07-31] (Atheros)
==================== Drivers (Whitelisted) ====================
S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-29] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-29] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-29] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-29] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-29] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-29] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-29] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-29] ()
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-08-10] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-25] (Microsoft Corporation)
S3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-09-26] (Dritek System Inc.)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-17 21:32 - 2013-10-17 21:32 - 00000000 ____D C:\FRST
2013-10-17 11:29 - 2013-10-17 11:29 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard
2013-10-17 11:00 - 2013-10-17 11:00 - 01954124 _____ (Farbar) C:\Users\Family\Downloads\FRST64.exe
2013-10-14 11:00 - 2012-08-30 03:37 - 02213776 _____ (ELAN Microelectronics Corp.) C:\Windows\ETDUninst.dll
2013-10-14 10:05 - 2013-10-14 10:05 - 00000000 _____ C:\autoexec.bat
2013-10-14 10:03 - 2013-10-14 11:00 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-10-14 10:03 - 2013-10-14 10:03 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-10-14 09:58 - 2013-10-14 09:58 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Family\Downloads\SpyHunter-Installer.exe
2013-10-14 05:06 - 2013-10-14 05:06 - 00423696 _____ C:\Windows\System32\FNTCACHE.DAT
2013-10-12 22:12 - 2013-08-28 19:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbser.sys
2013-10-12 22:12 - 2013-07-05 16:15 - 00652288 _____ (Microsoft Corporation) C:\Windows\System32\comctl32.dll
2013-10-12 22:12 - 2013-07-03 18:13 - 00541696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-12 22:11 - 2013-09-22 15:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-12 22:11 - 2013-09-22 15:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-12 22:11 - 2013-09-22 15:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-12 22:11 - 2013-09-22 15:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-12 22:11 - 2013-09-22 15:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-12 22:11 - 2013-09-22 15:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-12 22:11 - 2013-09-22 15:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-12 22:11 - 2013-09-22 15:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-12 22:11 - 2013-09-22 14:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-10-12 22:11 - 2013-09-22 14:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-10-12 22:11 - 2013-09-22 14:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-10-12 22:11 - 2013-09-22 14:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-10-12 22:11 - 2013-09-22 14:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-10-12 22:11 - 2013-09-22 14:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-10-12 22:11 - 2013-09-22 14:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-10-12 22:11 - 2013-09-22 14:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-10-12 22:11 - 2013-09-22 14:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-10-12 22:10 - 2013-07-05 14:02 - 00099328 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbcir.sys
2013-10-12 22:10 - 2013-07-05 14:01 - 00210560 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbvideo.sys
2013-10-12 22:10 - 2013-07-01 14:14 - 00025600 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbprint.sys
2013-10-12 22:10 - 2013-06-28 19:08 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidparse.sys
2013-10-12 22:10 - 2013-06-28 19:07 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-10-12 22:10 - 2013-06-21 21:45 - 00785624 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys
2013-10-12 22:10 - 2013-06-21 21:45 - 00054488 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\WdfLdr.sys
2013-10-12 22:09 - 2013-08-22 21:11 - 04040192 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-10-12 22:09 - 2013-07-19 14:13 - 00124112 _____ (Microsoft Corporation) C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2013-10-12 22:09 - 2013-07-19 14:13 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-12 22:09 - 2013-07-01 17:41 - 00447320 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\USBHUB3.SYS
2013-10-12 22:09 - 2013-07-01 17:41 - 00337752 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\USBXHCI.SYS
2013-10-12 22:09 - 2013-07-01 17:41 - 00213336 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\UCX01000.SYS
2013-10-12 22:09 - 2013-06-30 17:42 - 00623448 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys
2013-10-12 22:09 - 2013-06-30 17:42 - 00498008 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys
2013-10-12 22:09 - 2013-06-30 17:42 - 00079192 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys
2013-10-12 22:09 - 2013-06-30 17:42 - 00021848 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys
2013-10-12 22:09 - 2013-06-28 19:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys
2013-10-12 22:09 - 2013-06-28 19:06 - 00120832 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbccgp.sys
2013-10-12 22:09 - 2013-05-26 15:17 - 00035328 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-12 22:09 - 2013-05-26 14:59 - 00046080 _____ (Adobe Systems) C:\Windows\System32\atmlib.dll
2013-10-12 22:09 - 2013-05-24 19:15 - 00362496 _____ (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2013-10-12 22:09 - 2013-05-24 18:32 - 00300032 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-12 22:08 - 2013-08-09 21:21 - 00448512 _____ (Microsoft Corporation) C:\Windows\System32\SettingSync.dll
2013-10-12 22:08 - 2013-08-09 21:21 - 00128512 _____ (Microsoft Corporation) C:\Windows\System32\SettingSyncInfo.dll
2013-10-12 22:08 - 2013-08-09 19:58 - 00356352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2013-10-12 22:08 - 2013-08-02 22:40 - 01374208 _____ (Microsoft Corporation) C:\Windows\System32\wdc.dll
2013-10-12 22:08 - 2013-08-02 22:40 - 00566784 _____ (Microsoft Corporation) C:\Windows\System32\wvc.dll
2013-10-12 22:08 - 2013-08-02 22:40 - 00462336 _____ (Microsoft Corporation) C:\Windows\System32\sysmon.ocx
2013-10-12 22:08 - 2013-08-02 21:14 - 00399360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2013-10-12 22:08 - 2013-08-02 21:13 - 01245696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2013-10-12 22:08 - 2013-08-02 21:13 - 00437248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2013-10-12 22:08 - 2013-08-01 22:28 - 19758080 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-10-12 22:08 - 2013-08-01 22:28 - 10116608 _____ (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-10-12 22:08 - 2013-08-01 22:28 - 00222208 _____ (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-10-12 22:08 - 2013-08-01 22:26 - 02304512 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-10-12 22:08 - 2013-08-01 21:08 - 17561088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-10-12 22:08 - 2013-08-01 21:08 - 08858112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-10-12 22:08 - 2013-08-01 21:08 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-10-12 22:08 - 2013-08-01 21:06 - 02035712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-10-12 22:08 - 2013-08-01 02:41 - 02233688 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-10-12 22:08 - 2013-07-30 15:30 - 00386923 _____ C:\Windows\System32\ApnDatabase.xml
2013-10-12 22:08 - 2013-07-24 15:10 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mbsmsapi.dll
2013-10-12 22:08 - 2013-07-24 15:06 - 00225280 _____ (Microsoft Corporation) C:\Windows\System32\mbsmsapi.dll
2013-10-12 22:08 - 2013-04-09 15:17 - 01125888 _____ (Microsoft Corporation) C:\Windows\System32\msctf.dll
2013-10-12 22:08 - 2013-04-09 14:29 - 00893952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2013-10-10 11:44 - 2013-10-10 11:44 - 00001926 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-10-10 11:44 - 2013-08-29 23:48 - 00378944 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2013-10-10 11:44 - 2013-08-29 23:48 - 00072016 _____ (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
2013-10-10 11:44 - 2013-08-29 23:48 - 00064288 _____ (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2013-10-10 11:44 - 2013-08-29 23:48 - 00033400 _____ (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2013-10-10 11:43 - 2013-10-17 10:49 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-10 11:43 - 2013-10-10 11:43 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-10 11:43 - 2013-10-10 11:43 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-10 11:43 - 2013-08-29 23:48 - 01030952 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2013-10-10 11:43 - 2013-08-29 23:48 - 00204880 _____ C:\Windows\System32\Drivers\aswVmm.sys
2013-10-10 11:43 - 2013-08-29 23:48 - 00080816 _____ (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2013-10-10 11:43 - 2013-08-29 23:48 - 00065336 _____ C:\Windows\System32\Drivers\aswRvrt.sys
2013-10-10 11:43 - 2013-08-29 23:47 - 00287840 _____ (AVAST Software) C:\Windows\System32\aswBoot.exe
2013-10-10 11:43 - 2013-08-29 23:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-10-10 11:42 - 2013-10-10 11:43 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-10 11:41 - 2013-10-10 11:41 - 131918888 _____ C:\Users\Family\Downloads\avast_free_antivirus_setup.exe
2013-10-10 11:38 - 2013-10-10 11:39 - 05709056 _____ (Systweak Inc ) C:\Users\Family\Downloads\rcpsetup_chip_de_chip_de.exe
2013-10-10 11:27 - 2013-10-15 21:30 - 00000094 _____ C:\Users\Family\AppData\Roaming\WB.CFG
2013-10-10 11:27 - 2013-10-15 21:30 - 00000006 _____ C:\Users\Family\AppData\Roaming\WBPU-TTL.DAT
2013-10-10 11:22 - 2013-10-10 11:22 - 00012784 _____ C:\Users\Family\Downloads\OTL.7z
2013-10-10 10:52 - 2013-10-10 08:19 - 00117428 _____ C:\Users\Family\Downloads\OTL.txt
2013-10-10 10:30 - 2013-10-10 10:30 - 127231689 _____ (Igor Pavlov) C:\Users\Family\Downloads\OTLPENet.exe
2013-10-10 10:28 - 2013-10-10 10:28 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-10-10 10:28 - 2013-10-10 10:28 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-10-10 10:28 - 2013-10-10 10:28 - 00000000 ____D C:\Users\Family\AppData\Local\avgchrome
2013-10-10 10:27 - 2013-10-17 11:27 - 00000000 ____D C:\ProgramData\eSafe
2013-10-10 10:27 - 2013-10-16 21:29 - 00000306 _____ C:\Windows\Tasks\DigitalSite.job
2013-10-10 10:27 - 2013-10-14 10:59 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-10-10 10:27 - 2013-10-12 22:04 - 00000000 ____D C:\Program Files (x86)\Whilokii
2013-10-10 10:27 - 2013-10-10 10:27 - 00002644 _____ C:\Windows\System32\Tasks\DigitalSite
2013-10-10 10:27 - 2013-10-10 10:27 - 00001078 _____ C:\Users\Public\Desktop\Open It!.lnk
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\Users\Family\AppData\Roaming\DigitalSite
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\Users\Family\AppData\Local\BonanzaDealsLive
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\ProgramData\BitGuard
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\ProgramData\Babylon
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-10-02 23:46 - 2013-10-02 23:46 - 00000000 ___RD C:\Users\Family\AppData\Roaming\Brother
2013-09-26 00:26 - 2013-10-04 22:21 - 00024064 _____ C:\Users\Family\Downloads\08-Sp13-14.xls
2013-09-26 00:26 - 2013-09-27 23:38 - 00025088 _____ C:\Users\Family\Downloads\07-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00031232 _____ C:\Users\Family\Downloads\13-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00031232 _____ C:\Users\Family\Downloads\12-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00031232 _____ C:\Users\Family\Downloads\11-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00031232 _____ C:\Users\Family\Downloads\10-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00030720 _____ C:\Users\Family\Downloads\14-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00025088 _____ C:\Users\Family\Downloads\09-Sp13-14.xls
2013-09-22 09:31 - 2013-08-15 21:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dam.sys
2013-09-22 09:31 - 2013-08-15 21:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\System32\WSService.dll
2013-09-22 09:31 - 2013-08-15 21:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2013-09-22 09:31 - 2013-08-15 21:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\System32\NotificationUI.exe
2013-09-22 09:31 - 2013-08-15 21:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\System32\sppsvc.exe
2013-09-22 09:31 - 2013-08-15 21:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2013-09-22 09:31 - 2013-08-15 21:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\System32\sppobjs.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\System32\WSShared.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\System32\sppwinob.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\System32\WUSettingsProvider.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\System32\WSClient.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.Store.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\System32\WSSync.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\System32\storewuauth.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\System32\sppc.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\System32\setupcln.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2013-09-22 09:31 - 2013-08-15 21:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
2013-09-22 09:31 - 2013-08-15 21:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll
2013-09-22 09:31 - 2013-08-15 14:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-09-22 09:31 - 2013-08-15 14:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2013-09-22 09:31 - 2013-08-15 14:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2013-09-22 09:31 - 2013-08-15 14:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll
2013-09-22 09:28 - 2013-07-09 00:04 - 00120144 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\msgpioclx.sys
2013-09-22 09:28 - 2013-07-08 22:18 - 00439488 _____ (Microsoft Corporation) C:\Windows\System32\WerFault.exe
2013-09-22 09:28 - 2013-07-08 20:25 - 00385768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2013-09-22 09:28 - 2013-07-08 19:57 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2013-09-22 09:28 - 2013-07-08 14:46 - 00543744 _____ (Microsoft Corporation) C:\Windows\System32\wwanmm.dll
2013-09-22 09:28 - 2013-07-08 14:46 - 00414208 _____ (Microsoft Corporation) C:\Windows\System32\wwanconn.dll
2013-09-22 09:28 - 2013-07-08 14:46 - 00370688 _____ (Microsoft Corporation) C:\Windows\System32\Wwanadvui.dll
2013-09-22 09:28 - 2013-07-08 14:45 - 00312832 _____ (Microsoft Corporation) C:\Windows\System32\LocationApi.dll
2013-09-22 09:28 - 2013-07-05 16:16 - 01025024 _____ (Microsoft Corporation) C:\Windows\System32\localspl.dll
2013-09-22 09:28 - 2013-07-02 16:23 - 00778752 _____ (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
2013-09-22 09:28 - 2013-07-02 16:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-09-22 09:28 - 2013-07-02 16:22 - 02839552 _____ (Microsoft Corporation) C:\Windows\System32\msftedit.dll
2013-09-22 09:28 - 2013-07-02 16:22 - 01300480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2013-09-22 09:28 - 2013-07-02 16:11 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2013-09-22 09:28 - 2013-07-02 16:11 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-09-22 09:28 - 2013-07-02 16:10 - 02273792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2013-09-22 09:28 - 2013-06-30 14:30 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\openfiles.exe
2013-09-22 09:28 - 2013-06-30 14:29 - 00077312 _____ (Microsoft Corporation) C:\Windows\System32\openfiles.exe
2013-09-22 09:28 - 2013-06-28 22:15 - 00195416 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\sdbus.sys
2013-09-22 09:28 - 2013-06-28 22:15 - 00125784 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dumpsd.sys
2013-09-22 09:28 - 2013-06-28 21:43 - 00327512 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\Classpnp.sys
2013-09-22 09:28 - 2013-06-28 17:12 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-09-22 09:28 - 2013-06-25 19:01 - 00321536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\udfs.sys
2013-09-22 09:28 - 2013-06-25 18:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\HdAudio.sys
2013-09-22 09:28 - 2013-06-24 14:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-09-22 09:28 - 2013-06-24 14:54 - 00263680 _____ (Microsoft Corporation) C:\Windows\System32\wcmsvc.dll
2013-09-22 09:28 - 2013-06-24 14:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\System32\wcmcsp.dll
2013-09-22 09:28 - 2013-06-18 21:36 - 00183808 _____ (Microsoft Corporation) C:\Windows\System32\winmmbase.dll
2013-09-22 09:28 - 2013-06-18 21:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\System32\winmm.dll
2013-09-22 09:28 - 2013-06-18 14:38 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll
2013-09-22 09:28 - 2013-06-18 14:38 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2013-09-22 09:28 - 2013-06-11 15:43 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2013-09-22 09:28 - 2013-06-11 15:26 - 00230912 _____ (Microsoft Corporation) C:\Windows\System32\WinSCard.dll
2013-09-22 09:28 - 2013-06-10 13:17 - 00096512 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\wfplwfs.sys
2013-09-22 09:28 - 2013-06-10 11:16 - 00888832 _____ (Microsoft Corporation) C:\Windows\System32\nshwfp.dll
2013-09-22 09:28 - 2013-06-10 11:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\System32\IKEEXT.DLL
2013-09-22 09:28 - 2013-06-10 11:15 - 00723968 _____ (Microsoft Corporation) C:\Windows\System32\BFE.DLL
2013-09-22 09:28 - 2013-06-10 11:15 - 00381952 _____ (Microsoft Corporation) C:\Windows\System32\FWPUCLNT.DLL
2013-09-22 09:28 - 2013-06-10 11:10 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-09-22 09:28 - 2013-06-10 11:10 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-09-22 09:28 - 2013-06-06 00:03 - 00119040 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\USBSTOR.SYS
2013-09-22 09:26 - 2013-08-06 21:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\System32\tssdisai.dll
==================== One Month Modified Files and Folders =======
2013-10-17 21:32 - 2013-10-17 21:32 - 00000000 ____D C:\FRST
2013-10-17 11:29 - 2013-10-17 11:29 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard
2013-10-17 11:27 - 2013-10-10 10:27 - 00000000 ____D C:\ProgramData\eSafe
2013-10-17 11:27 - 2013-01-01 06:55 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-17 11:27 - 2012-07-25 23:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-17 11:17 - 2012-09-26 15:38 - 00753134 _____ C:\Windows\System32\perfh007.dat
2013-10-17 11:17 - 2012-09-26 15:38 - 00155826 _____ C:\Windows\System32\perfc007.dat
2013-10-17 11:17 - 2012-07-25 23:28 - 01745416 _____ C:\Windows\System32\PerfStringBackup.INI
2013-10-17 11:00 - 2013-10-17 11:00 - 01954124 _____ (Farbar) C:\Users\Family\Downloads\FRST64.exe
2013-10-17 11:00 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\System32\sru
2013-10-17 10:51 - 2013-01-01 11:49 - 00000000 ____D C:\Users\Family\Documents\Ausgaben
2013-10-17 10:49 - 2013-10-10 11:43 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-17 10:48 - 2013-01-01 06:54 - 00000000 ____D C:\Users\Family\AppData\Local\Deployment
2013-10-16 21:29 - 2013-10-10 10:27 - 00000306 _____ C:\Windows\Tasks\DigitalSite.job
2013-10-16 21:21 - 2013-01-01 06:55 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-15 21:30 - 2013-10-10 11:27 - 00000094 _____ C:\Users\Family\AppData\Roaming\WB.CFG
2013-10-15 21:30 - 2013-10-10 11:27 - 00000006 _____ C:\Users\Family\AppData\Roaming\WBPU-TTL.DAT
2013-10-15 21:29 - 2013-01-01 06:16 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2665461011-2761154639-2427061440-1002
2013-10-14 11:32 - 2013-10-10 10:27 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-10-14 11:00 - 2013-10-14 10:03 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-10-14 10:59 - 2013-10-10 10:27 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-10-14 10:17 - 2013-01-01 06:10 - 01885156 _____ C:\Windows\WindowsUpdate.log
2013-10-14 10:05 - 2013-10-14 10:05 - 00000000 _____ C:\autoexec.bat
2013-10-14 10:03 - 2013-10-14 10:03 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-10-14 09:58 - 2013-10-14 09:58 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Family\Downloads\SpyHunter-Installer.exe
2013-10-14 05:22 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-10-14 05:06 - 2013-10-14 05:06 - 00423696 _____ C:\Windows\System32\FNTCACHE.DAT
2013-10-12 22:24 - 2012-07-26 00:12 - 00000000 ___RD C:\Windows\ToastData
2013-10-12 22:24 - 2012-07-25 21:26 - 00262144 ___SH C:\Windows\System32\config\BBI
2013-10-12 22:20 - 2013-01-01 07:53 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-12 22:19 - 2013-07-26 11:31 - 00000000 ____D C:\Windows\System32\MRT
2013-10-12 22:18 - 2013-01-01 14:25 - 80541720 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-10-12 22:16 - 2013-01-01 06:55 - 00004092 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-12 22:16 - 2013-01-01 06:55 - 00003856 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-12 22:04 - 2013-10-10 10:27 - 00000000 ____D C:\Program Files (x86)\Whilokii
2013-10-12 21:59 - 2012-09-03 02:56 - 00019758 _____ C:\Windows\PFRO.log
2013-10-10 12:03 - 2013-01-01 06:56 - 00002223 _____ C:\Users\Family\Desktop\Google Chrome.lnk
2013-10-10 11:44 - 2013-10-10 11:44 - 00001926 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-10-10 11:43 - 2013-10-10 11:43 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-10 11:43 - 2013-10-10 11:43 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-10 11:43 - 2013-10-10 11:42 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-10 11:41 - 2013-10-10 11:41 - 131918888 _____ C:\Users\Family\Downloads\avast_free_antivirus_setup.exe
2013-10-10 11:39 - 2013-10-10 11:38 - 05709056 _____ (Systweak Inc ) C:\Users\Family\Downloads\rcpsetup_chip_de_chip_de.exe
2013-10-10 11:22 - 2013-10-10 11:22 - 00012784 _____ C:\Users\Family\Downloads\OTL.7z
2013-10-10 10:30 - 2013-10-10 10:30 - 127231689 _____ (Igor Pavlov) C:\Users\Family\Downloads\OTLPENet.exe
2013-10-10 10:28 - 2013-10-10 10:28 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-10-10 10:28 - 2013-10-10 10:28 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-10-10 10:28 - 2013-10-10 10:28 - 00000000 ____D C:\Users\Family\AppData\Local\avgchrome
2013-10-10 10:27 - 2013-10-10 10:27 - 00002644 _____ C:\Windows\System32\Tasks\DigitalSite
2013-10-10 10:27 - 2013-10-10 10:27 - 00001078 _____ C:\Users\Public\Desktop\Open It!.lnk
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\Users\Family\AppData\Roaming\DigitalSite
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\Users\Family\AppData\Local\BonanzaDealsLive
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\ProgramData\BitGuard
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\ProgramData\Babylon
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-10-10 10:27 - 2013-10-10 10:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-10 08:19 - 2013-10-10 10:52 - 00117428 _____ C:\Users\Family\Downloads\OTL.txt
2013-10-07 00:39 - 2012-07-25 23:21 - 00043118 _____ C:\Windows\setupact.log
2013-10-06 00:13 - 2013-01-01 06:10 - 00000000 ____D C:\Users\Family\AppData\Local\Packages
2013-10-06 00:11 - 2013-02-15 23:01 - 00000000 ____D C:\Users\Family\AppData\Local\CrashDumps
2013-10-04 22:21 - 2013-09-26 00:26 - 00024064 _____ C:\Users\Family\Downloads\08-Sp13-14.xls
2013-10-02 23:46 - 2013-10-02 23:46 - 00000000 ___RD C:\Users\Family\AppData\Roaming\Brother
2013-10-01 17:38 - 2012-07-26 00:14 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-01 17:38 - 2012-07-26 00:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-27 23:38 - 2013-09-26 00:26 - 00025088 _____ C:\Users\Family\Downloads\07-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00031232 _____ C:\Users\Family\Downloads\13-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00031232 _____ C:\Users\Family\Downloads\12-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00031232 _____ C:\Users\Family\Downloads\11-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00031232 _____ C:\Users\Family\Downloads\10-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00030720 _____ C:\Users\Family\Downloads\14-Sp13-14.xls
2013-09-26 00:26 - 2013-09-26 00:26 - 00025088 _____ C:\Users\Family\Downloads\09-Sp13-14.xls
2013-09-22 15:28 - 2013-10-12 22:11 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-22 15:28 - 2013-10-12 22:11 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-22 15:27 - 2013-10-12 22:11 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-22 15:27 - 2013-10-12 22:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-22 15:27 - 2013-10-12 22:11 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-22 15:27 - 2013-10-12 22:11 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-22 15:27 - 2013-10-12 22:11 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-22 15:27 - 2013-10-12 22:11 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-22 14:55 - 2013-10-12 22:11 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-09-22 14:55 - 2013-10-12 22:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-09-22 14:55 - 2013-10-12 22:11 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-09-22 14:54 - 2013-10-12 22:11 - 19252224 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-09-22 14:54 - 2013-10-12 22:11 - 15404544 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-09-22 14:54 - 2013-10-12 22:11 - 03959296 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-09-22 14:54 - 2013-10-12 22:11 - 02647552 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-09-22 14:54 - 2013-10-12 22:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-09-22 14:54 - 2013-10-12 22:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-09-22 09:59 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\WinStore
2013-09-22 09:59 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-09-22 09:59 - 2012-07-25 21:38 - 00000000 ____D C:\Windows\System32\oobe
2013-09-22 09:52 - 2013-01-01 11:49 - 00000000 ____D C:\Users\Family\Documents\UP
Some content of TEMP:
====================
C:\Users\Family\AppData\Local\Temp\AcerCloudDocsSetup.exe
C:\Users\Family\AppData\Local\Temp\AcerCloudSetup.exe
C:\Users\Family\AppData\Local\Temp\AskSLib.dll
C:\Users\Family\AppData\Local\Temp\ose00000.exe
C:\Users\Family\AppData\Local\Temp\ose00002.exe
C:\Users\Family\AppData\Local\Temp\SHSetup.exe
C:\Users\Family\AppData\Local\Temp\uninst1.exe
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
3
Restore point made on: 2013-09-22 09:32:09
Restore point made on: 2013-10-10 11:43:18
Restore point made on: 2013-10-14 10:03:22
==================== Memory info ===========================
Percentage of memory in use: 10%
Total physical RAM: 8007.27 MB
Available physical RAM: 7183.66 MB
Total Pagefile: 8007.27 MB
Available Pagefile: 7189.14 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:680.19 GB) (Free:635.03 GB) NTFS
Drive e: () (Removable) (Total:3.75 GB) (Free:3.75 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 699 GB) (Disk ID: A139FDE5)
Partition: GPT Partition Type
========================================================
Disk: 1 (Size: 4 GB) (Disk ID: 09ACCA1F)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)
LastRegBack: 2013-10-14 11:43
==================== End Of Log ============================ --- --- --- |