Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Nach dem Booten bekomme ich einenweißen Bildschirm (https://www.trojaner-board.de/137647-booten-bekomme-einenweissen-bildschirm.html)

AdITa 03.07.2013 19:35

Nach dem Booten bekomme ich einenweißen Bildschirm
 
Hallo erstmal,
ich möchte zunächst einmal sagen, dass ich euren Einsatz und euer Engargement echt klasse finde!
Daumen hoch, dass ihr in eurer Freizeit die Geduld aufbring so vielen Leuten gutes zu tun.
:applaus: :applaus::applaus:


Nunja jetzt habe ich, wie ihr euch sicher denken könnt, ein Problemchen.
Es handelt sich um einen Win7-Rechner, der den weißen Bildschirm nach dem Booten anzeigt.
Wollte schon mal ein Log für euch erstellen. Leider bekomme ich beim Starten des Reatogon-X-PE einen Bluescreen
0x0000007B (0xF78DA528, 0xC0000034, 0x00000000, 0x00000000) wenn das hilft.
Ich hoffe, ich stelle mich nicht übermäßig blöd an.

Vielen Dank schon mal im Voraus für die Zeit und Hilfe!
Gruß AdITa

schrauber 03.07.2013 19:49

hi,



Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Yes und klicke Scan
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).

AdITa 03.07.2013 21:35


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-07-2013 02
Ran by SYSTEM on 04-07-2013 01:29:50
Running from G:\
Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11101800 2010-07-28] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [325120 2009-10-22] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [lxdimon.exe] "C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe" [434856 2009-04-27] ()
HKLM\...\Run: [lxdiamon] "C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe" [25256 2009-04-27] ()
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-08-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: []  [x]
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [240112 2009-07-23] (Sonic Solutions)
HKLM-x32\...\Run: [starter4g] C:\Windows\starter4g.exe [160424 2010-04-30] (4G Systems GmbH & Co. KG)
HKU\Carina\...\Run: [Yontoo Desktop] "C:\Users\Carina\AppData\Roaming\Yontoo\YontooDesktop.exe" [47392 2013-05-17] (Yontoo LLC)
HKU\Carina\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-11-09] (Google Inc.)
HKU\Carina\...\Winlogon: [Shell] C:\Users\Carina\AppData\Roaming\dbu32.ocx,explorer.exe <==== ATTENTION
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-14] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-14] ()
AppInit_DLLs-x32: c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll  [2521552 2013-06-03] ()
Startup: C:\ProgramData\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

==================== Services (Whitelisted) =================

S2 BrowserProtect; C:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [3085264 2013-06-03] ()
S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-01-13] ()
S2 lxdi_device; C:\Windows\system32\lxdicoms.exe [876976 2007-06-11] ( )
S2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-05-29] (TuneUp Software)
S2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [329168 2010-04-12] ()
S2 XS Stick Service; C:\Windows\service4g.exe [145064 2010-04-30] (4G Systems GmbH & Co. KG)
S2 Yontoo Desktop Updater; C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [23552 2013-05-17] (Microsoft)
S4 bkybkergvqia; "C:\Users\Carina\AppData\Local\Temp\DAT9A5C.tmp.exe" --SERVICE [x]

==================== Drivers (Whitelisted) ====================

S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-01-28] (Mobile Connector)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S2 Sentinel; C:\Windows\SysWow64\Drivers\SENTINEL.SYS [73728 2001-06-21] (Rainbow Technologies, Inc.)
S3 Sntnlusb; C:\Windows\SysWow64\DRIVERS\SNTNLUSB.SYS [20032 2001-06-21] (Rainbow Technologies Inc.)
S3 SynUSB64; C:\Windows\System32\DRIVERS\SynUSB64.sys [29432 2007-10-24] (SIA Syncrosoft)
S3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-11-24] (TuneUp Software)
S2 Sentinel; \SystemRoot\System32\Drivers\SENTINEL.SYS [x]
S3 Sntnlusb; system32\DRIVERS\SNTNLUSB.SYS [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-04 01:29 - 2013-07-04 01:29 - 00000000 ____D C:\FRST
2013-07-01 14:44 - 2013-07-01 14:44 - 00002317 ____A C:\Users\Carina\Desktop\clamav_report_010713_224342.txt
2013-06-29 03:20 - 2013-06-29 03:20 - 00000000 ____D C:\Windows\pss
2013-06-11 15:00 - 2013-06-11 15:00 - 00172024 ____A (Hilgraeve, Inc.) C:\Users\Carina\Desktop\agpc.tmp
2013-06-11 14:14 - 2013-06-11 14:14 - 00121271 ____A C:\Users\Carina\Desktop\HC3A11~12
2013-06-11 14:13 - 2013-06-11 14:13 - 00456935 ____A C:\Users\Carina\Desktop\1
2013-06-11 05:34 - 2013-06-11 05:34 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (4)
2013-06-11 05:34 - 2013-06-11 05:34 - 00000000 ____D C:\Users\Carina\Desktop\Hochzeitshooting Ideen und Motive
2013-06-10 08:50 - 2013-06-11 12:22 - 00000000 ____D C:\Users\Carina\Desktop\J und D bearbeitet
2013-06-10 06:54 - 2013-06-11 06:36 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (3)
2013-06-09 10:28 - 2013-06-09 10:28 - 00009495 ____A C:\Users\Carina\Desktop\Mappe1.xlsx
2013-06-08 07:59 - 2013-06-11 05:10 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (2)
2013-06-08 07:27 - 2013-06-08 08:33 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner
2013-06-08 01:24 - 2013-06-10 09:03 - 00000000 ____D C:\Users\Carina\Desktop\Jenny und Dami 7.6.13
2013-06-04 06:02 - 2013-06-04 06:13 - 00000000 ____D C:\Users\Carina\Desktop\BWL KOPIE

==================== One Month Modified Files and Folders =======

2013-07-04 01:29 - 2013-07-04 01:29 - 00000000 ____D C:\FRST
2013-07-01 14:44 - 2013-07-01 14:44 - 00002317 ____A C:\Users\Carina\Desktop\clamav_report_010713_224342.txt
2013-07-01 10:02 - 2011-01-13 07:12 - 00029566 ____A C:\Windows\PFRO.log
2013-07-01 10:00 - 2012-11-14 10:47 - 00000910 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000Core.job
2013-07-01 09:52 - 2012-11-14 10:47 - 00000932 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000UA.job
2013-07-01 09:50 - 2011-11-09 10:08 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-01 09:50 - 2011-11-09 10:08 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-01 09:15 - 2012-04-05 06:28 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-01 08:25 - 2009-07-13 20:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-01 08:25 - 2009-07-13 20:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-01 08:22 - 2010-10-08 12:06 - 00659238 ____A C:\Windows\System32\perfh007.dat
2013-07-01 08:22 - 2010-10-08 12:06 - 00132776 ____A C:\Windows\System32\perfc007.dat
2013-07-01 08:22 - 2009-07-13 21:13 - 01512244 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-01 08:17 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-01 08:16 - 2009-07-13 20:51 - 00155713 ____A C:\Windows\setupact.log
2013-06-29 03:20 - 2013-06-29 03:20 - 00000000 ____D C:\Windows\pss
2013-06-29 03:14 - 2012-07-31 08:17 - 00000000 ____D C:\Users\Carina\AppData\Roaming\BrowserCompanion
2013-06-11 16:10 - 2013-05-19 09:34 - 00000000 ____D C:\Users\Carina\AppData\Roaming\player
2013-06-11 16:10 - 2013-05-19 09:32 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Yontoo
2013-06-11 16:10 - 2013-05-19 09:32 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Delta
2013-06-11 16:10 - 2013-05-19 09:32 - 00000000 ____D C:\Users\Carina\AppData\Roaming\BabSolution
2013-06-11 16:10 - 2013-05-19 09:32 - 00000000 ____D C:\Program Files (x86)\Yontoo
2013-06-11 16:10 - 2013-05-19 09:32 - 00000000 ____D C:\Program Files (x86)\Delta
2013-06-11 16:10 - 2013-05-13 08:12 - 00000000 ____D C:\Users\Carina\Desktop\Neu neu
2013-06-11 16:10 - 2013-04-28 03:10 - 00000000 ____D C:\ProgramData\Protexis
2013-06-11 16:10 - 2011-12-05 01:13 - 00000000 ____D C:\Windows\System32\Macromed
2013-06-11 16:10 - 2011-01-20 07:05 - 00000000 ____D C:\Users\Carina\Desktop\Mobile Partner
2013-06-11 16:10 - 2011-01-13 06:52 - 00000000 ____D C:\users\Carina
2013-06-11 16:10 - 2010-09-15 15:32 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-06-11 16:10 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-11 16:10 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2013-06-11 16:10 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\AppCompat
2013-06-11 15:53 - 2010-10-08 02:16 - 01945334 ____A C:\Windows\WindowsUpdate.log
2013-06-11 15:02 - 2013-04-08 01:18 - 00000000 ____D C:\ProgramData\dvjl
2013-06-11 15:00 - 2013-06-11 15:00 - 00172024 ____A (Hilgraeve, Inc.) C:\Users\Carina\Desktop\agpc.tmp
2013-06-11 14:14 - 2013-06-11 14:14 - 00121271 ____A C:\Users\Carina\Desktop\HC3A11~12
2013-06-11 14:13 - 2013-06-11 14:13 - 00456935 ____A C:\Users\Carina\Desktop\1
2013-06-11 12:48 - 2013-04-28 03:12 - 00000000 ____D C:\Users\Carina\AppData\Local\CrashDumps
2013-06-11 12:22 - 2013-06-10 08:50 - 00000000 ____D C:\Users\Carina\Desktop\J und D bearbeitet
2013-06-11 06:36 - 2013-06-10 06:54 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (3)
2013-06-11 05:34 - 2013-06-11 05:34 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (4)
2013-06-11 05:34 - 2013-06-11 05:34 - 00000000 ____D C:\Users\Carina\Desktop\Hochzeitshooting Ideen und Motive
2013-06-11 05:10 - 2013-06-08 07:59 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (2)
2013-06-10 09:03 - 2013-06-08 01:24 - 00000000 ____D C:\Users\Carina\Desktop\Jenny und Dami 7.6.13
2013-06-09 23:18 - 2011-01-13 09:04 - 00000000 ____D C:\ProgramData\Sonic
2013-06-09 10:28 - 2013-06-09 10:28 - 00009495 ____A C:\Users\Carina\Desktop\Mappe1.xlsx
2013-06-08 08:51 - 2012-08-24 03:22 - 00002187 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-08 08:33 - 2013-06-08 07:27 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner
2013-06-05 07:12 - 2013-05-05 23:42 - 00000000 ____D C:\Users\Carina\Desktop\musik
2013-06-04 06:13 - 2013-06-04 06:02 - 00000000 ____D C:\Users\Carina\Desktop\BWL KOPIE
2013-06-04 03:47 - 2013-05-19 09:32 - 00000000 ____D C:\ProgramData\BrowserProtect

ZeroAccess:
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\@
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\L
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\00000001.@
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\80000000.@
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\800000cb.@

ZeroAccess:
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\@
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\L
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\00000001.@
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\80000000.@
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\800000cb.@

Files to move or delete:
====================
C:\ProgramData\FullRemove.exe

==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

Restore point made on: 2013-05-06 01:41:43
Restore point made on: 2013-05-18 01:57:18
Restore point made on: 2013-05-26 04:38:41
Restore point made on: 2013-06-09 03:12:01
Restore point made on: 2013-07-01 08:54:52

==================== Memory info ===========================

Percentage of memory in use: 18%
Total physical RAM: 3956.5 MB
Available physical RAM: 3210.84 MB
Total Pagefile: 3954.64 MB
Available Pagefile: 3204.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:452.48 GB) (Free:165.89 GB) NTFS (Disk=0 Partition=3)
Drive e: (PQSERVICE) (Fixed) (Total:13.18 GB) (Free:1.92 GB) NTFS (Disk=0 Partition=1)
Drive g: (PLATINUM) (Removable) (Total:1.87 GB) (Free:1.87 GB) FAT32 (Disk=1 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9EFE9EFE)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=452 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 2 GB) (Disk ID: C3F7D2FB)
Partition 1: (Not Active) - (Size=2 GB) - (Type=0B)


LastRegBack: 2013-07-01 08:46

==================== End Of Log ============================

--- --- ---

schrauber 04.07.2013 06:54

Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

HKU\Carina\...\Winlogon: [Shell] C:\Users\Carina\AppData\Roaming\dbu32.ocx,explorer.exe <==== ATTENTION
ZeroAccess:
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\@
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\L
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\00000001.@
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\80000000.@
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\800000cb.@

ZeroAccess:
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\@
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\L
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\00000001.@
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\80000000.@
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\800000cb.@
C:\Users\Carina\AppData\Roaming\dbu32.ocx

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Fix Button.
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

AdITa 04.07.2013 09:22

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-07-2013
Ran by SYSTEM at 2013-07-04 13:19:36 Run:1
Running from G:\
Boot Mode: Recovery
==============================================

HKU\Carina\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully.
C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2} => Moved successfully.
"C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\@" => File/Directory not found.
"C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\L" => File/Directory not found.
"C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n" => File/Directory not found.
"C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U" => File/Directory not found.
"C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\00000001.@" => File/Directory not found.
"C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\80000000.@" => File/Directory not found.
"C:\Windows\Installer\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\800000cb.@" => File/Directory not found.
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2} => Moved successfully.
"C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\@" => File/Directory not found.
"C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\L" => File/Directory not found.
"C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n" => File/Directory not found.
"C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U" => File/Directory not found.
"C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\00000001.@" => File/Directory not found.
"C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\80000000.@" => File/Directory not found.
"C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\800000cb.@" => File/Directory not found.
C:\Users\Carina\AppData\Roaming\dbu32.ocx => Moved successfully.

==== End of Fixlo


schrauber 04.07.2013 10:52

Neu booten? :)

AdITa 04.07.2013 12:23

Ist erledigt.

Soweit ich das sehen kann, läuft er wieder normal.

Muss ich noch was nacharbeiten?

Gruß
AdITa

schrauber 04.07.2013 12:44

Auf jeden Fall :). ab jetzt alles im normalen Windows:

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


Systemscan mit FRST
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Scan.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

AdITa 04.07.2013 13:21

So, hier die Logs

Code:

# AdwCleaner v2.304 - Datei am 04/07/2013 um 16:59:48 erstellt
# Aktualisiert am 03/07/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium  (64 bits)
# Benutzer : Carina - CARINA-NOTEBOOK
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Carina\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : BrowserProtect
Gestoppt & Gelöscht : Yontoo Desktop Updater

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Gelöscht mit Neustart : C:\ProgramData\BrowserProtect
Ordner Gelöscht : C:\Program Files (x86)\BrowserCompanion
Ordner Gelöscht : C:\Program Files (x86)\Delta
Ordner Gelöscht : C:\Program Files (x86)\Yontoo
Ordner Gelöscht : C:\Program Files\DomaIQ Uninstaller
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\boost_interprocess
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf
Ordner Gelöscht : C:\Users\Carina\AppData\LocalLow\bbrs_002.tb
Ordner Gelöscht : C:\Users\Carina\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Carina\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Carina\AppData\Roaming\BrowserCompanion
Ordner Gelöscht : C:\Users\Carina\AppData\Roaming\Delta
Ordner Gelöscht : C:\Users\Carina\AppData\Roaming\Yontoo
Ordner Gelöscht : C:\Windows\Installer\{EBE677C0-CBCB-4EBF-8098-E27E1B5271CF}

***** [Registrierungsdatenbank] *****

Daten Gelöscht : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\Blabbers
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\5d53dc8ab06fec47
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9}
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\BrowserCompanion
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\base64
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\chrome
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\prox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\tdataprotocol.CTData
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\tdataprotocol.CTData.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\updatebho.TimerBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\updatebho.TimerBHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wit4ie.WitBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wit4ie.WitBHO.2
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\5d53dc8ab06fec47
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bodddioamolcibagionmmobehnbhiakf
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EBE677C0-CBCB-4EBF-8098-E27E1B5271CF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DomaIQ Uninstaller
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Tarma Installer
Schlüssel Gelöscht : HKU\S-1-5-21-4174051618-920821422-2312507155-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Yontoo Desktop]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16447

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v27.0.1453.110

Datei : C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [13648 octets] - [04/07/2013 16:59:48]

########## EOF - C:\AdwCleaner[S1].txt - [13709 octets] ##########

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by Carina on 04.07.2013 at 17:06:09,12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.07.2013 at 17:10:41,53
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013
Ran by Carina (administrator) on 04-07-2013 17:11:49
Running from C:\Users\Carina\Desktop
Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
() C:\Windows\SysWOW64\srvany.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Windows\KMService.exe
(Lexmark International, Inc.) C:\Windows\system32\spool\DRIVERS\x64\3\lxdiserv.exe
( ) C:\Windows\system32\lxdicoms.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(4G Systems GmbH & Co. KG) C:\Windows\starter4g.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
() C:\Program Files (x86)\XSManager\WTGService.exe
(4G Systems GmbH & Co. KG) C:\Windows\service4g.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11101800 2010-07-29] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [325120 2009-10-22] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [lxdimon.exe] "C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe" [434856 2009-04-27] ()
HKLM\...\Run: [lxdiamon] "C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe" [25256 2009-04-27] ()
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-11-09] (Google Inc.)
HKCR\...0c966feabec1\InprocServer32: [Default-shell32] C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n. ATTENTION! ====> ZeroAccess?
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
MountPoints2: E - E:\AutoRun.exe
MountPoints2: {2b5e3296-2b04-11e0-9212-207c8f26f449} - E:\autorun.exe
MountPoints2: {2be3a3dc-471f-11e0-83d7-207c8f26f449} - E:\AutoRun.exe
MountPoints2: {46948402-2c65-11e0-a066-206a8a1b5d89} - E:\AutoRun.exe
MountPoints2: {5da13dc4-2408-11e1-8665-806e6f6e6963} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\index.html
MountPoints2: {64514d76-2e51-11e1-b91e-207c8f26f449} - E:\DPFMate.exe
MountPoints2: {cec3c9ab-dba2-11e1-aa93-207c8f26f449} - E:\AutoRun.exe
MountPoints2: {de3c8749-2493-11e0-8379-207c8f26f449} - E:\AutoRun.exe
MountPoints2: {de3c8756-2493-11e0-8379-207c8f26f449} - E:\AutoRun.exe
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-08-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-11] (Dritek System Inc.)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: []  [x]
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [240112 2009-07-24] (Sonic Solutions)
HKLM-x32\...\Run: [starter4g] C:\Windows\starter4g.exe [160424 2010-04-30] (4G Systems GmbH & Co. KG)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
Startup: C:\ProgramData\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {581B6F77-9558-4CD8-880F-5BCEF1186E2A} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {B5272B94-79F4-4A6C-B1E9-E5E9E993295A} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADFA_deDE457
SearchScopes: HKCU - {BF101066-1C31-455C-8FA3-948602990DBC} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {D8AF42D8-1CBB-4BB4-A870-CEC55BD53C0C} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
SearchScopes: HKCU - {F22CD882-23AF-44F1-B657-0946862985AA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: pdfMachine - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\Windows\SysWow64\bgstb.dll (Broadgun Software)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL (Microsoft Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - pdfMachine - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\Windows\SysWow64\bgstb.dll (Broadgun Software)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {56CF4856-ECB4-4E46-A897-A378821F97B9} -  No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} -  No File
DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.6.0/jinstall-6-windows-i586.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~4\Office12\GRA32A~1.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation)
Tcpip\..\Interfaces\{33C17895-EFE6-4203-8BB0-7676BD32652D}: [NameServer]212.23.115.148 212.23.115.132
Tcpip\..\Interfaces\{449021CE-CD4F-45F0-B8B7-9BD01ADFF7F0}: [NameServer]212.23.115.148 212.23.115.132
Tcpip\..\Interfaces\{C6073CA8-2E01-4250-8473-B4B2FC1859E1}: [NameServer]212.23.115.132 212.23.115.148

Chrome:
=======
CHR Extension: (YouTube) - C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Gmail) - C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

==================== Services (Whitelisted) =================

R2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-01-13] ()
R2 lxdi_device; C:\Windows\system32\lxdicoms.exe [876976 2007-06-11] ( )
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-05-29] (TuneUp Software)
R2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [329168 2010-04-12] ()
R2 XS Stick Service; C:\Windows\service4g.exe [145064 2010-04-30] (4G Systems GmbH & Co. KG)
S4 bkybkergvqia; "C:\Users\Carina\AppData\Local\Temp\DAT9A5C.tmp.exe" --SERVICE [x]

==================== Drivers (Whitelisted) ====================

S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-01-28] (Mobile Connector)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S2 Sentinel; C:\Windows\SysWow64\Drivers\SENTINEL.SYS [73728 2001-06-21] (Rainbow Technologies, Inc.)
S3 Sntnlusb; C:\Windows\SysWow64\DRIVERS\SNTNLUSB.SYS [20032 2001-06-21] (Rainbow Technologies Inc.)
S3 SynUSB64; C:\Windows\System32\DRIVERS\SynUSB64.sys [29432 2007-10-24] (SIA Syncrosoft)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-11-24] (TuneUp Software)
S2 Sentinel; \SystemRoot\System32\Drivers\SENTINEL.SYS [x]
S3 Sntnlusb; system32\DRIVERS\SNTNLUSB.SYS [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-04 17:10 - 2013-07-04 17:10 - 00000755 ____A C:\Users\Carina\Desktop\JRT.txt
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\Windows\ERUNT
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\JRT
2013-07-04 16:59 - 2013-07-04 17:00 - 00013739 ____A C:\AdwCleaner[S1].txt
2013-07-04 13:56 - 2013-07-04 13:56 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Carina\Desktop\JRT.exe
2013-07-04 13:54 - 2013-07-04 13:54 - 00650027 ____A C:\Users\Carina\Desktop\adwcleaner.exe
2013-07-04 11:29 - 2013-07-04 11:29 - 00000000 ____D C:\FRST
2013-07-04 08:40 - 2013-07-04 08:32 - 01934636 ____A (Farbar) C:\Users\Carina\Desktop\FRST64.exe
2013-07-02 00:44 - 2013-07-02 00:44 - 00002317 ____A C:\Users\Carina\Desktop\clamav_report_010713_224342.txt
2013-06-29 13:20 - 2013-06-29 13:20 - 00000000 ____D C:\Windows\pss
2013-06-12 01:00 - 2013-06-12 01:00 - 00172024 ____A (Hilgraeve, Inc.) C:\Users\Carina\Desktop\agpc.tmp
2013-06-12 00:14 - 2013-06-12 00:14 - 00121271 ____A C:\Users\Carina\Desktop\HC3A11~12
2013-06-12 00:13 - 2013-06-12 00:13 - 00456935 ____A C:\Users\Carina\Desktop\1
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (4)
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Hochzeitshooting Ideen und Motive
2013-06-10 18:50 - 2013-06-11 22:22 - 00000000 ____D C:\Users\Carina\Desktop\J und D bearbeitet
2013-06-10 16:54 - 2013-06-11 16:36 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (3)
2013-06-09 20:28 - 2013-06-09 20:28 - 00009495 ____A C:\Users\Carina\Desktop\Mappe1.xlsx
2013-06-08 17:59 - 2013-06-11 15:10 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (2)
2013-06-08 17:27 - 2013-06-08 18:33 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner
2013-06-08 11:24 - 2013-06-10 19:03 - 00000000 ____D C:\Users\Carina\Desktop\Jenny und Dami 7.6.13
2013-06-04 16:02 - 2013-06-04 16:13 - 00000000 ____D C:\Users\Carina\Desktop\BWL KOPIE

==================== One Month Modified Files and Folders =======

2013-07-04 17:10 - 2013-07-04 17:10 - 00000755 ____A C:\Users\Carina\Desktop\JRT.txt
2013-07-04 17:10 - 2010-10-08 22:06 - 00659238 ____A C:\Windows\System32\perfh007.dat
2013-07-04 17:10 - 2010-10-08 22:06 - 00132776 ____A C:\Windows\System32\perfc007.dat
2013-07-04 17:10 - 2009-07-14 07:13 - 01512244 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\Windows\ERUNT
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\JRT
2013-07-04 17:05 - 2011-11-09 20:08 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-04 17:05 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-04 17:05 - 2009-07-14 06:51 - 00156620 ____A C:\Windows\setupact.log
2013-07-04 17:00 - 2013-07-04 16:59 - 00013739 ____A C:\AdwCleaner[S1].txt
2013-07-04 16:52 - 2012-11-14 20:47 - 00000932 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000UA.job
2013-07-04 16:50 - 2011-11-09 20:08 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-04 16:26 - 2009-07-14 06:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-04 16:26 - 2009-07-14 06:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-04 13:56 - 2013-07-04 13:56 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Carina\Desktop\JRT.exe
2013-07-04 13:54 - 2013-07-04 13:54 - 00650027 ____A C:\Users\Carina\Desktop\adwcleaner.exe
2013-07-04 11:29 - 2013-07-04 11:29 - 00000000 ____D C:\FRST
2013-07-04 08:32 - 2013-07-04 08:40 - 01934636 ____A (Farbar) C:\Users\Carina\Desktop\FRST64.exe
2013-07-02 00:44 - 2013-07-02 00:44 - 00002317 ____A C:\Users\Carina\Desktop\clamav_report_010713_224342.txt
2013-07-01 20:02 - 2011-01-13 17:12 - 00029566 ____A C:\Windows\PFRO.log
2013-07-01 20:00 - 2012-11-14 20:47 - 00000910 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000Core.job
2013-07-01 19:15 - 2012-04-05 16:28 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-29 13:20 - 2013-06-29 13:20 - 00000000 ____D C:\Windows\pss
2013-06-12 02:10 - 2013-05-19 19:34 - 00000000 ____D C:\Users\Carina\AppData\Roaming\player
2013-06-12 02:10 - 2013-05-13 18:12 - 00000000 ____D C:\Users\Carina\Desktop\Neu neu
2013-06-12 02:10 - 2013-04-28 13:10 - 00000000 ____D C:\ProgramData\Protexis
2013-06-12 02:10 - 2011-12-05 11:13 - 00000000 ____D C:\Windows\System32\Macromed
2013-06-12 02:10 - 2011-01-20 17:05 - 00000000 ____D C:\Users\Carina\Desktop\Mobile Partner
2013-06-12 02:10 - 2011-01-13 16:52 - 00000000 ____D C:\users\Carina
2013-06-12 02:10 - 2010-09-16 01:32 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-06-12 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-12 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-06-12 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-06-12 01:53 - 2010-10-08 12:16 - 01945334 ____A C:\Windows\WindowsUpdate.log
2013-06-12 01:02 - 2013-04-08 11:18 - 00000000 ____D C:\ProgramData\dvjl
2013-06-12 01:00 - 2013-06-12 01:00 - 00172024 ____A (Hilgraeve, Inc.) C:\Users\Carina\Desktop\agpc.tmp
2013-06-12 00:14 - 2013-06-12 00:14 - 00121271 ____A C:\Users\Carina\Desktop\HC3A11~12
2013-06-12 00:13 - 2013-06-12 00:13 - 00456935 ____A C:\Users\Carina\Desktop\1
2013-06-11 22:48 - 2013-04-28 13:12 - 00000000 ____D C:\Users\Carina\AppData\Local\CrashDumps
2013-06-11 22:22 - 2013-06-10 18:50 - 00000000 ____D C:\Users\Carina\Desktop\J und D bearbeitet
2013-06-11 16:36 - 2013-06-10 16:54 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (3)
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (4)
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Hochzeitshooting Ideen und Motive
2013-06-11 15:10 - 2013-06-08 17:59 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (2)
2013-06-10 19:03 - 2013-06-08 11:24 - 00000000 ____D C:\Users\Carina\Desktop\Jenny und Dami 7.6.13
2013-06-10 09:18 - 2011-01-13 19:04 - 00000000 ____D C:\ProgramData\Sonic
2013-06-09 20:28 - 2013-06-09 20:28 - 00009495 ____A C:\Users\Carina\Desktop\Mappe1.xlsx
2013-06-08 18:51 - 2012-08-24 13:22 - 00002187 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-08 18:33 - 2013-06-08 17:27 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner
2013-06-05 17:12 - 2013-05-06 09:42 - 00000000 ____D C:\Users\Carina\Desktop\musik
2013-06-04 16:13 - 2013-06-04 16:02 - 00000000 ____D C:\Users\Carina\Desktop\BWL KOPIE

Files to move or delete:
====================
C:\ProgramData\FullRemove.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-01 18:46

==================== End Of Log ============================

--- --- ---




Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2013
Ran by Carina at 2013-07-04 17:12:46
Running from C:\Users\Carina\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Acer Crystal Eye webcam Ver:1.1.192.810 (x32 Version: 1.1.192.810)
Acer ePower Management (x32 Version: 5.00.3005)
Acer eRecovery Management (x32 Version: 4.05.3013)
Acer GameZone Console (x32 Version: 6.1.0.9)
Acer Registration (x32 Version: 1.03.3003)
Acer ScreenSaver (x32 Version: 1.1.0423.2010)
Acer Updater (x32 Version: 1.02.3001)
Acrobat.com (x32 Version: 1.6.65)
Adobe AIR (x32 Version: 1.5.0.7220)
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.202)
Adobe Photoshop 6.0 (x32 Version: 6.0)
Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7)
Airport Mania First Flight (x32)
Alcor Micro USB Card Reader (x32 Version: 1.9.17.06019)
ALPS Touch Pad Driver (Version: 7.105.2015.1107)
Amazonia (x32)
ArCon Eleco +2008 (x32 Version: 1.00.0000)
ATI Catalyst Install Manager (Version: 3.0.778.0)
Broadcom Gigabit NetLink Controller (Version: 14.2.4.2)
BroadGun pdfMachine (x32)
Cake Mania (x32)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0825.2205.37769)
Catalyst Control Center InstallProxy (x32 Version: 2010.0825.2205.37769)
Catalyst Control Center Localization All (x32 Version: 2010.0825.2205.37769)
CCC Help Chinese Standard (x32 Version: 2010.0825.2204.37769)
CCC Help Chinese Traditional (x32 Version: 2010.0825.2204.37769)
CCC Help Czech (x32 Version: 2010.0825.2204.37769)
CCC Help Danish (x32 Version: 2010.0825.2204.37769)
CCC Help Dutch (x32 Version: 2010.0825.2204.37769)
CCC Help English (x32 Version: 2010.0825.2204.37769)
CCC Help Finnish (x32 Version: 2010.0825.2204.37769)
CCC Help French (x32 Version: 2010.0825.2204.37769)
CCC Help German (x32 Version: 2010.0825.2204.37769)
CCC Help Greek (x32 Version: 2010.0825.2204.37769)
CCC Help Hungarian (x32 Version: 2010.0825.2204.37769)
CCC Help Italian (x32 Version: 2010.0825.2204.37769)
CCC Help Japanese (x32 Version: 2010.0825.2204.37769)
CCC Help Korean (x32 Version: 2010.0825.2204.37769)
CCC Help Norwegian (x32 Version: 2010.0825.2204.37769)
CCC Help Polish (x32 Version: 2010.0825.2204.37769)
CCC Help Portuguese (x32 Version: 2010.0825.2204.37769)
CCC Help Russian (x32 Version: 2010.0825.2204.37769)
CCC Help Spanish (x32 Version: 2010.0825.2204.37769)
CCC Help Swedish (x32 Version: 2010.0825.2204.37769)
CCC Help Thai (x32 Version: 2010.0825.2204.37769)
CCC Help Turkish (x32 Version: 2010.0825.2204.37769)
ccc-core-static (x32 Version: 2010.0825.2205.37769)
ccc-utility64 (Version: 2010.0825.2205.37769)
Corel Graphics - Windows Shell Extension (x32 Version: 15.1.0.588)
Corel Graphics - Windows Shell Extension (x32 Version: 15.1.588)
Corel PaintShop Pro X5 (x32 Version: 15.0.0.183)
Corel PaintShop Pro X5 (x32 Version: 15.1.0.10)
CorelDRAW Graphics Suite X5 - Capture (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - Common (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - Connect (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - Custom Data (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - DE (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - Draw (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - Filters (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - FontNav (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - IPM (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - PHOTO-PAINT (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - Photozoom Plugin (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Redist (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Setup Files (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - VBA (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - VideoBrowser (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - VSTA (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit (Version: 15.1.588)
CorelDRAW Graphics Suite X5 - WT (x32 Version: 15.1)
CorelDRAW Graphics Suite X5 (x32 Version: 15.1)
CorelDRAW(R) Graphics Suite X5 (x32 Version: 15.1.0.588)
CyberLink PowerDVD 9 (x32 Version: 9.0.3216.50)
DirectX 9 Runtime (x32 Version: 1.00.0000)
dm-Fotowelt (x32 Version: 5.0.1)
Dream Day First Home (x32)
DWGExport (x32 Version: 1.3.0.1)
eSobi v2 (x32 Version: 2.0.4.000274)
Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287)
Farm Frenzy 2 (x32)
Galapago (x32)
Google Chrome (x32 Version: 27.0.1453.110)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Toolbar for Internet Explorer (x32 Version: 7.4.3607.2246)
Google Update Helper (x32 Version: 1.3.21.145)
Heroes of Hellas (x32)
Hotfix für Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (x32 Version: 1)
ICA (x32 Version: 15.0.0.183)
ICQ 7.2 Build #3525 Banner Remover 1.0 (x32)
ICQ7.2 (x32 Version: 7.2)
Identity Card (x32 Version: 1.00.3003)
Intel(R) Management Engine Components (x32 Version: 6.0.0.1179)
Intel(R) Rapid Storage Technology (x32 Version: 9.6.0.1014)
IPM_PSP_COM (x32 Version: 15.0.0.183)
Java Auto Updater (x32 Version: 2.0.4.1)
Java(TM) 6 Update 25 (x32 Version: 6.0.250)
JNLP (HKCU)
Junk Mail filter update (x32 Version: 14.0.8117.416)
Launch Manager (x32 Version: 4.0.14)
Lernstudio Polnisch 3.1 (x32)
Lexmark 3500-4500 Series
Merriam Websters Spell Jam (x32)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Choice Guard (x32 Version: 2.0.48.0)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.4518.1014)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Standard 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Silverlight (x32 Version: 4.0.50401.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (x32 Version: 9.0.30729)
Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU (x32 Version: 9.0.30729)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (x32 Version: 9.0.30729)
Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU (x32 Version: 9.0.30729)
Mobile Partner (x32 Version: 16.001.06.03.52)
Mobipocket Reader 6.2 (x32 Version: 6.2.608)
Mozilla Thunderbird (3.1.12) (x32 Version: 3.1.12 (de))
MSVCRT (x32 Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Nero 7 Premium (x32 Version: 7.01.0728)
Poker Pop (x32)
Portrait Professional 10.8 (x32 Version: 10.8)
PSPPContent (x32 Version: 15.1.0.9)
PSPPHelp (x32 Version: 15.0.0.183)
PSPPro64 (Version: 15.0.0.183)
PX Profile Update (x32 Version: 1.00.1.)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6167)
Roxio Activation Module (x32 Version: 1.0)
Roxio BackOnTrack (x32 Version: 1.3.1)
Roxio Burn (x32 Version: 1.0.0)
Roxio CinePlayer (x32 Version: 5.3)
Roxio CinePlayer Decoder Pack (x32 Version: 4.3.0)
Roxio File Backup (Version: 1.3.0)
Roxio Video Capture USB (x32 Version: 1.22.0000)
Roxio WinOnCD 2010 (x32 Version: 1.2.193)
Roxio WinOnCD 2010 (x32 Version: 12.0)
Roxio WinOnCD 2010 (x32 Version: 5.0.0)
Sentinel System Driver (x32)
Setup (x32 Version: 15.0.0.183)
SmartSound Quicktracks Plugin (x32 Version: 3.0.8.0)
Spin & Win (x32)
StairCon (x32)
Syncrosoft Lizenz Kontrolle (x32)
TeamViewer 4 (x32)
Total Immersion D'Fusion @Home Web Plug-In (x32)
TuneUp Utilities 2012 (x32 Version: 12.0.3600.73)
TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.73)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
VD64Inst (Version: 1.00.0000)
Visual Basic for Applications (R) Core - English (x32 Version: 6.4.99.69)
Visual Basic for Applications (R) Core - German (x32 Version: 6.4.99.69)
Visual Basic for Applications (R) Core (x32 Version: 6.4.99.69)
WEB.DE Softwareaktualisierung (x32 Version: 3.0.0.1)
Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5)
Windows Live Call (x32 Version: 14.0.8117.0416)
Windows Live Communications Platform (x32 Version: 14.0.8117.416)
Windows Live Essentials (x32 Version: 14.0.8117.0416)
Windows Live Essentials (x32 Version: 14.0.8117.416)
Windows Live Fotogalerie (x32 Version: 14.0.8117.416)
Windows Live Mail (x32 Version: 14.0.8117.0416)
Windows Live Messenger (x32 Version: 14.0.8117.0416)
Windows Live Movie Maker (x32 Version: 14.0.8117.0416)
Windows Live Sync (x32 Version: 14.0.8117.416)
Windows Live Writer (x32 Version: 14.0.8117.0416)
Windows Live-Uploadtool (x32 Version: 14.0.8014.1029)
WinRAR
XSManager (x32 Version: 3.0)

==================== Restore Points  =========================

06-05-2013 09:41:22 Geplanter Prüfpunkt
18-05-2013 09:57:03 Geplanter Prüfpunkt
26-05-2013 12:38:27 Geplanter Prüfpunkt
09-06-2013 11:11:46 Geplanter Prüfpunkt
01-07-2013 16:53:48 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {1B319143-EF05-4EB4-966A-B71621830590} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-01-07] (Sun Microsystems, Inc.)
Task: {1B545604-3728-4742-9E4D-48A125D359A8} - System32\Tasks\EPUpdater => C:\Users\Carina\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe No File
Task: {20519D81-7432-49C9-A465-9E1AB8F973F9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-15] (Adobe Systems Incorporated)
Task: {285015EB-BD8A-4FBE-AC9B-7C95BB37B269} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {3EBD55F6-851C-48F1-B412-7BFD3E33FF93} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-09] (Google Inc.)
Task: {52C52EB3-E4F0-4910-A540-84A659340BCC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-09] (Google Inc.)
Task: {557119C5-FEB4-4262-B298-C6EDC88B266F} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-05-29] (TuneUp Software)
Task: {66C3E364-E5F9-4569-BC5D-04C416491E4E} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {674E627F-21F4-4167-BAF4-3853335923F6} - System32\Tasks\{17032792-D804-44FE-A2C1-7F817E3E3286} => C:\Users\Carina\Desktop\Mobile Partner\Mobile Partner.exe [2009-12-15] ()
Task: {6DCD3806-52E0-4303-8E4A-4B78547963C1} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000UA => C:\Users\Carina\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-14] (Facebook Inc.)
Task: {8610A7C2-146C-423A-848F-88396FD0CC88} - System32\Tasks\Registration 1und1 Task => C:\Program Files (x86)\1und1Softwareaktualisierung\cdsupdclient.exe [2013-01-29] (1&1 Mail & Media GmbH)
Task: {B363A21D-4F8E-425D-A909-59BA99C2AB5D} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000Core => C:\Users\Carina\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-14] (Facebook Inc.)
Task: {F42E686A-C5EE-4B09-A3FC-FD4467F2D0C4} - System32\Tasks\User_Feed_Synchronization-{B09687A1-C61D-4E39-82F7-5E7A87F4643E} => C:\Windows\system32\msfeedssync.exe [2012-02-24] (Microsoft Corporation)
Task: {FDCC614F-7E95-41AD-A566-C31903F752B8} - System32\Tasks\BrowserProtect => C:\Windows\system32\sc.exe [2009-07-14] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000Core.job => C:\Users\Carina\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000UA.job => C:\Users\Carina\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============

Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Percentage of memory in use: 27%
Total physical RAM: 3956.5 MB
Available physical RAM: 2869.48 MB
Total Pagefile: 7911.14 MB
Available Pagefile: 6684.68 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:452.48 GB) (Free:165.62 GB) NTFS (Disk=0 Partition=3)
Drive e: (KINGSTON) (Removable) (Total:3.72 GB) (Free:3.72 GB) FAT32 (Disk=1 Partition=1)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9EFE9EFE)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=452 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=4 GB) - (Type=0B)

==================== End Of Log ============================

Gruß
AdITa

schrauber 04.07.2013 14:14


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST Log bitte. Noch Probleme? :)

AdITa 04.07.2013 19:28

Code:

ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=fe658724a6b35f4685858992fadfca2a
# engine=14268
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-04 05:11:01
# local_time=2013-07-04 07:11:01 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=5893 16776574 66 94 30341238 124587711 0 0
# scanned=332219
# found=17
# cleaned=0
# scan_time=224248700
sh=D6D04E1EB74702E69704622DD109972ECF0B25B3 ft=1 fh=5240ac6d7b311971 vn="a variant of Win32/Kryptik.BDSJ trojan" ac=I fn="C:\FRST\Quarantine\dbu32.ocx"
sh=199B79852882DAC6A6E2AC202D64A01A88CCFDDB ft=1 fh=fa2c5781ae458497 vn="Win64/Sirefef.W trojan" ac=I fn="C:\FRST\Quarantine\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n"
sh=0CF03F6DA9D5780F4A50E8DA795BA305B2E2FD6D ft=1 fh=2bf4e2b747dd3741 vn="Win64/Sirefef.AL trojan" ac=I fn="C:\FRST\Quarantine\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\80000000.@"
sh=54D538485EDA63CB816D8BEB41B9A0C8B5BDF831 ft=1 fh=8a67face120d9525 vn="Win64/Sirefef.AH trojan" ac=I fn="C:\FRST\Quarantine\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\800000cb.@"
sh=199B79852882DAC6A6E2AC202D64A01A88CCFDDB ft=1 fh=fa2c5781ae458497 vn="Win64/Sirefef.W trojan" ac=I fn="C:\FRST\Quarantine\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n"
sh=0CF03F6DA9D5780F4A50E8DA795BA305B2E2FD6D ft=1 fh=2bf4e2b747dd3741 vn="Win64/Sirefef.AL trojan" ac=I fn="C:\FRST\Quarantine\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\80000000.@"
sh=54D538485EDA63CB816D8BEB41B9A0C8B5BDF831 ft=1 fh=8a67face120d9525 vn="Win64/Sirefef.AH trojan" ac=I fn="C:\FRST\Quarantine\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\U\800000cb.@"
sh=A9F71A9262305B42586484605D47501EE5AE0DEA ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.OOC trojan" ac=I fn="C:\Users\Carina\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\53d90297-4a543b26"
sh=A9F71A9262305B42586484605D47501EE5AE0DEA ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.OOC trojan" ac=I fn="C:\Users\Carina\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\53d90297-64fc39b6"
sh=73AF035DFACF92C281388AE69D564E3ECB21A0A0 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NQS trojan" ac=I fn="C:\Users\Carina\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\cb37ca9-7cb9adc2"
sh=514A4E72BFAF56D0F2F6672445BF7177A08DE1CB ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2012-1723.R trojan" ac=I fn="C:\Users\Carina\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\2f66a0ee-1f20357c"
sh=AD7F135E31D6AED3ED71BCBA3C921643FB574B93 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2012-1723.R trojan" ac=I fn="C:\Users\Carina\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\50ecb030-6ee88339"
sh=52946B9893766C669DC3DE92FA1643CE89ACBC49 ft=1 fh=5919f471372cbd39 vn="a variant of Win32/Kryptik.BDHW trojan" ac=I fn="C:\Users\Carina\Desktop\agpc.tmp"
sh=E98B4E02F9A17DF9A6BE647F72FF1BCBA8FE4F07 ft=1 fh=4851af2b72ab6ea4 vn="a variant of Win32/Injector.AEYB trojan" ac=I fn="C:\Users\Carina\Desktop\Externe Festplatte\Neu\Diplomarbeit\lijb.tmp"
sh=9310A9E2B49B16D2EBCDF9E3C924B66CD8E0BCAA ft=1 fh=671dce8643508eaf vn="Win32/TrojanProxy.Hioles.AB trojan" ac=I fn="C:\Windows\System32\EcyeqhovYetd.dll"
sh=9310A9E2B49B16D2EBCDF9E3C924B66CD8E0BCAA ft=1 fh=671dce8643508eaf vn="Win32/TrojanProxy.Hioles.AB trojan" ac=I fn="C:\Windows\SysWOW64\EcyeqhovYetd.dll"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/TrojanProxy.Hioles.AA trojan" ac=I fn="${Memory}"

Code:

Results of screen317's Security Check version 0.99.68 
 Windows 7  x64 (UAC is disabled!) 
 Out of date service pack!!
 Internet Explorer 10 
``````````````Antivirus/Firewall Check:``````````````
 Windows Security Center service is not running! This report may not be accurate!
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 TuneUp Utilities 2012 
 TuneUp Utilities Language Pack (de-DE)
 Java(TM) 6 Update 25 
 Java version out of Date!
 Adobe Reader 10.1.7 Adobe Reader out of Date! 
 Mozilla Thunderbird (3.1.12) Thunderbird out of Date! 
 Google Chrome 27.0.1453.110 
 Google Chrome 27.0.1453.116 
````````Process Check: objlist.exe by Laurent```````` 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````


schrauber 04.07.2013 20:01

Java, Adobe und Thunderbird updaten.

Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop.
Schließe nun alle offenen Programme und trenne Dich von dem Internet.
Doppelklick auf die TFC.exe und drücke auf Start.
Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen.


Fix mit FRST
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

C:\Users\Carina\Desktop\agpc.tmp
C:\Users\Carina\Desktop\Externe Festplatte\Neu\Diplomarbeit\lijb.tmp
C:\Windows\System32\EcyeqhovYetd.dll
C:\Windows\SysWOW64\EcyeqhovYetd.dll

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Fix Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Downloade dir bitte Farbar Service Scanner Farbar Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.

Poste bitte den Inhalt hier.



AdITa 05.07.2013 07:57

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-07-2013
Ran by Carina at 2013-07-05 08:52:45 Run:2
Running from C:\Users\Carina\Desktop
Boot Mode: Normal
==============================================

C:\Users\Carina\Desktop\agpc.tmp => Moved successfully.
C:\Users\Carina\Desktop\Externe Festplatte\Neu\Diplomarbeit\lijb.tmp => Moved successfully.
"C:\Windows\System32\EcyeqhovYetd.dll" => File/Directory not found.
C:\Windows\SysWOW64\EcyeqhovYetd.dll => Moved successfully.

==== End of Fixlog ====

Code:

Farbar Service Scanner Version: 27-06-2013
Ran by Carina (administrator) on 05-07-2013 at 08:54:44
Running from "C:\Users\Carina\Desktop"
Microsoft Windows 7 Home Premium  (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Attempt to access Google IP returned error.
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.

Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.

BITS Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.


Other Services:
==============
Checking Start type of SharedAccess: ATTENTION!=====> Unable to retrieve start type of SharedAccess. The value does not exist.
Checking ImagePath of SharedAccess: ATTENTION!=====> Unable to retrieve ImagePath of SharedAccess. The value does not exist.
Checking ServiceDll of SharedAccess: ATTENTION!=====> Unable to open SharedAccess registry key. The service key does not exist.
Checking Start type of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.
Checking ImagePath of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.
Checking ServiceDll of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll
[2012-06-13 21:04] - [2012-04-24 07:59] - 0182272 ____A (Microsoft Corporation) F02786B66375292E58C8777082D4396D

C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****


schrauber 05.07.2013 09:35

Windows Repair (All In One) - Download - Filepony

laden und installieren. Alle Schritte machen, am Schluss alle Kästchen anhaken und laufen lassen.

reboot und frisches FSS log bitte.

AdITa 06.07.2013 08:31

Morgen,
ich wollte grad anfangen die Schritte abzuarbeiten. Malwarebytes zeigt mir 8 gefundene Bedrohungen.

Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.07.06.02

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Carina :: CARINA-NOTEBOOK [Administrator]

06.07.2013 09:15:32
MBAM-log-2013-07-06 (09-27-25).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 213253
Laufzeit: 4 Minute(n), 33 Sekunde(n)

Infizierte Speicherprozesse: 1
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> 1016 -> Keine Aktion durchgeführt.

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 2
C:\Windows\System32\config\systemprofile\AppData\LocalLow\bbrs_002.tb (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\bbrs_002.tb\content (PUP.Blabbers) -> Keine Aktion durchgeführt.

Infizierte Dateien: 3
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> Keine Aktion durchgeführt.
C:\Windows\System32\drivers\str.sys (Rootkit.Agent) -> Keine Aktion durchgeführt.
C:\Windows\SysWOW64\drivers\str.sys (Rootkit.Agent) -> Keine Aktion durchgeführt.

(Ende)

Soll ich die einfach über das Programm entfernen und weitermachen?

Gruß
AdITa

schrauber 06.07.2013 09:07

Genau, dann das Löschlogfile posten und All in One repair laufen lassen.

AdITa 06.07.2013 09:16

Hier schon mal das Logfile
Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.07.06.02

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Carina :: CARINA-NOTEBOOK [Administrator]

06.07.2013 09:15:32
mbam-log-2013-07-06 (09-15-32).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 213253
Laufzeit: 4 Minute(n), 33 Sekunde(n)

Infizierte Speicherprozesse: 1
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> 1016 -> Löschen bei Neustart.

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 2
C:\Windows\System32\config\systemprofile\AppData\LocalLow\bbrs_002.tb (PUP.Blabbers) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\bbrs_002.tb\content (PUP.Blabbers) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 3
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> Löschen bei Neustart.
C:\Windows\System32\drivers\str.sys (Rootkit.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\SysWOW64\drivers\str.sys (Rootkit.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


schrauber 06.07.2013 10:22

Dann jetzt all in one und ein frisches FRST log bitte.

AdITa 06.07.2013 13:08


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013
Ran by Carina (administrator) on 06-07-2013 14:03:45
Running from C:\Users\Carina\Desktop
Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(4G Systems GmbH & Co. KG) C:\Windows\starter4g.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Lexmark International, Inc.) C:\Windows\system32\spool\DRIVERS\x64\3\lxdiserv.exe
( ) C:\Windows\system32\lxdicoms.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
() C:\Program Files (x86)\XSManager\WTGService.exe
(4G Systems GmbH & Co. KG) C:\Windows\service4g.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11101800 2010-07-29] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [325120 2009-10-22] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [lxdimon.exe] "C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe" [434856 2009-04-27] ()
HKLM\...\Run: [lxdiamon] "C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe" [25256 2009-04-27] ()
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-11-09] (Google Inc.)
HKCR\...0c966feabec1\InprocServer32: [Default-shell32] C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n. ATTENTION! ====> ZeroAccess?
MountPoints2: E - E:\AutoRun.exe
MountPoints2: {2b5e3296-2b04-11e0-9212-207c8f26f449} - E:\autorun.exe
MountPoints2: {2be3a3dc-471f-11e0-83d7-207c8f26f449} - E:\AutoRun.exe
MountPoints2: {46948402-2c65-11e0-a066-206a8a1b5d89} - E:\AutoRun.exe
MountPoints2: {5da13dc4-2408-11e1-8665-806e6f6e6963} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\index.html
MountPoints2: {64514d76-2e51-11e1-b91e-207c8f26f449} - E:\DPFMate.exe
MountPoints2: {cec3c9ab-dba2-11e1-aa93-207c8f26f449} - E:\AutoRun.exe
MountPoints2: {de3c8749-2493-11e0-8379-207c8f26f449} - E:\AutoRun.exe
MountPoints2: {de3c8756-2493-11e0-8379-207c8f26f449} - E:\AutoRun.exe
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-08-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-11] (Dritek System Inc.)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: []  [x]
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [240112 2009-07-24] (Sonic Solutions)
HKLM-x32\...\Run: [starter4g] C:\Windows\starter4g.exe [160424 2010-04-30] (4G Systems GmbH & Co. KG)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
Startup: C:\ProgramData\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKCU SearchScopes: DefaultScope {581B6F77-9558-4CD8-880F-5BCEF1186E2A} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {581B6F77-9558-4CD8-880F-5BCEF1186E2A} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {B5272B94-79F4-4A6C-B1E9-E5E9E993295A} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADFA_deDE457
SearchScopes: HKCU - {BF101066-1C31-455C-8FA3-948602990DBC} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {D8AF42D8-1CBB-4BB4-A870-CEC55BD53C0C} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
SearchScopes: HKCU - {F22CD882-23AF-44F1-B657-0946862985AA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: pdfMachine - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\Windows\SysWow64\bgstb.dll (Broadgun Software)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL (Microsoft Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - pdfMachine - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\Windows\SysWow64\bgstb.dll (Broadgun Software)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {56CF4856-ECB4-4E46-A897-A378821F97B9} -  No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} -  No File
DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.6.0/jinstall-6-windows-i586.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~4\Office12\GRA32A~1.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{33C17895-EFE6-4203-8BB0-7676BD32652D}: [NameServer]212.23.115.148 212.23.115.132
Tcpip\..\Interfaces\{449021CE-CD4F-45F0-B8B7-9BD01ADFF7F0}: [NameServer]212.23.115.148 212.23.115.132
Tcpip\..\Interfaces\{C6073CA8-2E01-4250-8473-B4B2FC1859E1}: [NameServer]212.23.115.132 212.23.115.148

Chrome:
=======
CHR Extension: (YouTube) - C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Gmail) - C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

==================== Services (Whitelisted) =================

S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-01-13] ()
R2 lxdi_device; C:\Windows\system32\lxdicoms.exe [876976 2007-06-11] ( )
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-05-29] (TuneUp Software)
R2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [329168 2010-04-12] ()
R2 XS Stick Service; C:\Windows\service4g.exe [145064 2010-04-30] (4G Systems GmbH & Co. KG)
S4 bkybkergvqia; "C:\Users\Carina\AppData\Local\Temp\DAT9A5C.tmp.exe" --SERVICE [x]

==================== Drivers (Whitelisted) ====================

S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-01-28] (Mobile Connector)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S2 Sentinel; C:\Windows\SysWow64\Drivers\SENTINEL.SYS [73728 2001-06-21] (Rainbow Technologies, Inc.)
S3 Sntnlusb; C:\Windows\SysWow64\DRIVERS\SNTNLUSB.SYS [20032 2001-06-21] (Rainbow Technologies Inc.)
S3 SynUSB64; C:\Windows\System32\DRIVERS\SynUSB64.sys [29432 2007-10-24] (SIA Syncrosoft)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-11-24] (TuneUp Software)
S2 Sentinel; \SystemRoot\System32\Drivers\SENTINEL.SYS [x]
S3 Sntnlusb; system32\DRIVERS\SNTNLUSB.SYS [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-06 11:57 - 2013-07-06 11:57 - 00000207 ____A C:\Windows\tweaking.com-regbackup-CARINA-NOTEBOOK-Microsoft-Windows-7-Home-Premium-(64-Bit).dat
2013-07-06 11:55 - 2013-07-06 11:55 - 00000000 ____D C:\RegBackup
2013-07-06 10:37 - 2013-07-06 13:55 - 00181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-07-06 10:24 - 2013-07-06 10:24 - 00000000 __SHD C:\found.000
2013-07-06 09:14 - 2013-07-06 09:14 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Malwarebytes
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-06 09:14 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-07-05 08:54 - 2013-07-05 08:54 - 00005636 ____A C:\Users\Carina\Desktop\FSS.txt
2013-07-05 08:53 - 2013-07-05 08:02 - 00356397 ____A (Farbar) C:\Users\Carina\Desktop\FSS.exe
2013-07-05 08:12 - 2013-07-06 09:13 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-07-05 08:12 - 2013-07-05 08:02 - 00448512 ____A (OldTimer Tools) C:\Users\Carina\Desktop\TFC.exe
2013-07-04 20:20 - 2013-07-04 15:31 - 00890988 ____A C:\Users\Carina\Desktop\SecurityCheck.exe
2013-07-04 17:12 - 2013-07-04 17:12 - 00016977 ____A C:\Users\Carina\Desktop\Addition.txt
2013-07-04 17:10 - 2013-07-04 17:10 - 00000755 ____A C:\Users\Carina\Desktop\JRT.txt
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\Windows\ERUNT
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\JRT
2013-07-04 16:59 - 2013-07-04 17:00 - 00013739 ____A C:\AdwCleaner[S1].txt
2013-07-04 13:56 - 2013-07-04 13:56 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Carina\Desktop\JRT.exe
2013-07-04 13:54 - 2013-07-04 13:54 - 00650027 ____A C:\Users\Carina\Desktop\adwcleaner.exe
2013-07-04 11:29 - 2013-07-04 11:29 - 00000000 ____D C:\FRST
2013-07-04 08:40 - 2013-07-04 08:32 - 01934636 ____A (Farbar) C:\Users\Carina\Desktop\FRST64.exe
2013-07-02 00:44 - 2013-07-02 00:44 - 00002317 ____A C:\Users\Carina\Desktop\clamav_report_010713_224342.txt
2013-06-29 13:20 - 2013-06-29 13:20 - 00000000 ____D C:\Windows\pss
2013-06-12 00:14 - 2013-06-12 00:14 - 00121271 ____A C:\Users\Carina\Desktop\HC3A11~12
2013-06-12 00:13 - 2013-06-12 00:13 - 00456935 ____A C:\Users\Carina\Desktop\1
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (4)
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Hochzeitshooting Ideen und Motive
2013-06-10 18:50 - 2013-06-11 22:22 - 00000000 ____D C:\Users\Carina\Desktop\J und D bearbeitet
2013-06-10 16:54 - 2013-06-11 16:36 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (3)
2013-06-09 20:28 - 2013-06-09 20:28 - 00009495 ____A C:\Users\Carina\Desktop\Mappe1.xlsx
2013-06-08 17:59 - 2013-06-11 15:10 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (2)
2013-06-08 17:27 - 2013-06-08 18:33 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner
2013-06-08 11:24 - 2013-06-10 19:03 - 00000000 ____D C:\Users\Carina\Desktop\Jenny und Dami 7.6.13

==================== One Month Modified Files and Folders =======

2013-07-06 14:05 - 2010-10-08 22:06 - 00659238 ____A C:\Windows\System32\perfh007.dat
2013-07-06 14:05 - 2010-10-08 22:06 - 00132776 ____A C:\Windows\System32\perfc007.dat
2013-07-06 14:05 - 2009-07-14 07:13 - 01512418 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-06 13:57 - 2011-11-09 20:08 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-06 13:57 - 2011-01-13 17:12 - 00031824 ____A C:\Windows\PFRO.log
2013-07-06 13:57 - 2011-01-13 16:53 - 00133040 ____A C:\Users\Carina\AppData\Local\GDIPFONTCACHEV1.DAT
2013-07-06 13:57 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-06 13:57 - 2009-07-14 06:51 - 00157124 ____A C:\Windows\setupact.log
2013-07-06 13:57 - 2009-07-14 06:45 - 00474776 ____A C:\Windows\System32\FNTCACHE.DAT
2013-07-06 13:55 - 2013-07-06 10:37 - 00181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-07-06 13:52 - 2012-11-14 20:47 - 00000932 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000UA.job
2013-07-06 13:50 - 2011-11-09 20:08 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-06 13:48 - 2009-07-14 04:34 - 00000514 ____A C:\Windows\win.ini
2013-07-06 13:46 - 2013-04-28 13:12 - 00000000 ____D C:\Users\Carina\AppData\Local\CrashDumps
2013-07-06 13:15 - 2012-04-05 16:28 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-06 12:01 - 2009-07-14 06:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-06 12:01 - 2009-07-14 06:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-06 11:57 - 2013-07-06 11:57 - 00000207 ____A C:\Windows\tweaking.com-regbackup-CARINA-NOTEBOOK-Microsoft-Windows-7-Home-Premium-(64-Bit).dat
2013-07-06 11:55 - 2013-07-06 11:55 - 00000000 ____D C:\RegBackup
2013-07-06 10:24 - 2013-07-06 10:24 - 00000000 __SHD C:\found.000
2013-07-06 09:14 - 2013-07-06 09:14 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Malwarebytes
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-06 09:13 - 2013-07-05 08:12 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-07-06 09:13 - 2011-01-13 19:04 - 00000000 ____D C:\ProgramData\Sonic
2013-07-05 08:54 - 2013-07-05 08:54 - 00005636 ____A C:\Users\Carina\Desktop\FSS.txt
2013-07-05 08:02 - 2013-07-05 08:53 - 00356397 ____A (Farbar) C:\Users\Carina\Desktop\FSS.exe
2013-07-05 08:02 - 2013-07-05 08:12 - 00448512 ____A (OldTimer Tools) C:\Users\Carina\Desktop\TFC.exe
2013-07-04 20:25 - 2011-11-09 16:14 - 00000000 ____D C:\Users\Carina\AppData\Local\Google
2013-07-04 20:07 - 2012-08-24 13:22 - 00002187 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-04 19:57 - 2012-11-14 20:47 - 00000910 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000Core.job
2013-07-04 17:15 - 2012-04-05 16:28 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-04 17:15 - 2011-06-15 12:54 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-04 17:12 - 2013-07-04 17:12 - 00016977 ____A C:\Users\Carina\Desktop\Addition.txt
2013-07-04 17:10 - 2013-07-04 17:10 - 00000755 ____A C:\Users\Carina\Desktop\JRT.txt
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\Windows\ERUNT
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\JRT
2013-07-04 17:00 - 2013-07-04 16:59 - 00013739 ____A C:\AdwCleaner[S1].txt
2013-07-04 15:31 - 2013-07-04 20:20 - 00890988 ____A C:\Users\Carina\Desktop\SecurityCheck.exe
2013-07-04 13:56 - 2013-07-04 13:56 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Carina\Desktop\JRT.exe
2013-07-04 13:54 - 2013-07-04 13:54 - 00650027 ____A C:\Users\Carina\Desktop\adwcleaner.exe
2013-07-04 11:29 - 2013-07-04 11:29 - 00000000 ____D C:\FRST
2013-07-04 08:32 - 2013-07-04 08:40 - 01934636 ____A (Farbar) C:\Users\Carina\Desktop\FRST64.exe
2013-07-02 00:44 - 2013-07-02 00:44 - 00002317 ____A C:\Users\Carina\Desktop\clamav_report_010713_224342.txt
2013-06-29 13:20 - 2013-06-29 13:20 - 00000000 ____D C:\Windows\pss
2013-06-12 02:10 - 2013-05-19 19:34 - 00000000 ____D C:\Users\Carina\AppData\Roaming\player
2013-06-12 02:10 - 2013-05-13 18:12 - 00000000 ____D C:\Users\Carina\Desktop\Neu neu
2013-06-12 02:10 - 2013-04-28 13:10 - 00000000 ____D C:\ProgramData\Protexis
2013-06-12 02:10 - 2011-12-05 11:13 - 00000000 ____D C:\Windows\System32\Macromed
2013-06-12 02:10 - 2011-01-20 17:05 - 00000000 ____D C:\Users\Carina\Desktop\Mobile Partner
2013-06-12 02:10 - 2011-01-13 16:52 - 00000000 ____D C:\users\Carina
2013-06-12 02:10 - 2010-09-16 01:32 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-06-12 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-12 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-06-12 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-06-12 01:53 - 2010-10-08 12:16 - 01953943 ____A C:\Windows\WindowsUpdate.log
2013-06-12 01:02 - 2013-04-08 11:18 - 00000000 ____D C:\ProgramData\dvjl
2013-06-12 00:14 - 2013-06-12 00:14 - 00121271 ____A C:\Users\Carina\Desktop\HC3A11~12
2013-06-12 00:13 - 2013-06-12 00:13 - 00456935 ____A C:\Users\Carina\Desktop\1
2013-06-11 22:22 - 2013-06-10 18:50 - 00000000 ____D C:\Users\Carina\Desktop\J und D bearbeitet
2013-06-11 16:36 - 2013-06-10 16:54 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (3)
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (4)
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Hochzeitshooting Ideen und Motive
2013-06-11 15:10 - 2013-06-08 17:59 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (2)
2013-06-10 19:03 - 2013-06-08 11:24 - 00000000 ____D C:\Users\Carina\Desktop\Jenny und Dami 7.6.13
2013-06-09 20:28 - 2013-06-09 20:28 - 00009495 ____A C:\Users\Carina\Desktop\Mappe1.xlsx
2013-06-08 18:33 - 2013-06-08 17:27 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner

Files to move or delete:
====================
C:\ProgramData\FullRemove.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-06 09:49

==================== End Of Log ============================

--- --- ---

schrauber 06.07.2013 17:15

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKCR\...0c966feabec1\InprocServer32: [Default-shell32] C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n. ATTENTION! ====> ZeroAccess?
S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-01-13] ()
R2 lxdi_device; C:\Windows\system32\lxdicoms.exe [876976 2007-06-11] ( )
S4 bkybkergvqia; "C:\Users\Carina\AppData\Local\Temp\DAT9A5C.tmp.exe" --SERVICE [x]
C:\ProgramData\FullRemove.exe
C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n
C:\Windows\SysWow64\srvany.exe
C:\Windows\system32\lxdicoms.exe
C:\Users\Carina\AppData\Local\Temp\DAT9A5C.tmp.exe


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


AdITa 06.07.2013 19:30

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-07-2013
Ran by Carina at 2013-07-06 20:29:20 Run:3
Running from C:\Users\Carina\Desktop
Boot Mode: Normal
==============================================

HKCU\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} => Key deleted successfully.
KMService => Service deleted successfully.
lxdi_device => Service deleted successfully.
bkybkergvqia => Service deleted successfully.
C:\ProgramData\FullRemove.exe => Moved successfully.
"C:\Users\Carina\AppData\Local\{d072f7c8-52ba-5570-4a89-7f1eacd287e2}\n" => File/Directory not found.
C:\Windows\SysWow64\srvany.exe => Moved successfully.
C:\Windows\system32\lxdicoms.exe => Moved successfully.
"C:\Users\Carina\AppData\Local\Temp\DAT9A5C.tmp.exe" => File/Directory not found.


The system needs a manual reboot.

==== End of Fixlog ====

Reboot ist auch gemacht

schrauber 07.07.2013 06:30

Ok, bitte ein frischen Quickscan mit MBAM und ein frisches FRST Log. Noch Probleme?

AdITa 07.07.2013 10:48

Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.07.06.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Carina :: CARINA-NOTEBOOK [Administrator]

07.07.2013 11:17:20
mbam-log-2013-07-07 (11-17-20).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 213498
Laufzeit: 8 Minute(n), 14 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013
Ran by Carina (administrator) on 07-07-2013 11:41:55
Running from C:\Users\Carina\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Lexmark International, Inc.) C:\Windows\system32\spool\DRIVERS\x64\3\lxdiserv.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
() C:\Program Files (x86)\XSManager\WTGService.exe
(4G Systems GmbH & Co. KG) C:\Windows\service4g.exe
(AMD) C:\Windows\system32\atieclxx.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(4G Systems GmbH & Co. KG) C:\Windows\starter4g.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11101800 2010-07-29] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [325120 2009-10-22] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [lxdimon.exe] "C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe" [434856 2009-04-27] ()
HKLM\...\Run: [lxdiamon] "C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe" [25256 2009-04-27] ()
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-11-09] (Google Inc.)
MountPoints2: E - E:\AutoRun.exe
MountPoints2: {2b5e3296-2b04-11e0-9212-207c8f26f449} - E:\autorun.exe
MountPoints2: {2be3a3dc-471f-11e0-83d7-207c8f26f449} - E:\AutoRun.exe
MountPoints2: {46948402-2c65-11e0-a066-206a8a1b5d89} - E:\AutoRun.exe
MountPoints2: {5da13dc4-2408-11e1-8665-806e6f6e6963} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\index.html
MountPoints2: {64514d76-2e51-11e1-b91e-207c8f26f449} - E:\DPFMate.exe
MountPoints2: {cec3c9ab-dba2-11e1-aa93-207c8f26f449} - E:\AutoRun.exe
MountPoints2: {de3c8749-2493-11e0-8379-207c8f26f449} - E:\AutoRun.exe
MountPoints2: {de3c8756-2493-11e0-8379-207c8f26f449} - E:\AutoRun.exe
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-08-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-11] (Dritek System Inc.)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: []  [x]
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [240112 2009-07-24] (Sonic Solutions)
HKLM-x32\...\Run: [starter4g] C:\Windows\starter4g.exe [160424 2010-04-30] (4G Systems GmbH & Co. KG)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
Startup: C:\ProgramData\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKCU SearchScopes: DefaultScope {581B6F77-9558-4CD8-880F-5BCEF1186E2A} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {581B6F77-9558-4CD8-880F-5BCEF1186E2A} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {B5272B94-79F4-4A6C-B1E9-E5E9E993295A} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADFA_deDE457
SearchScopes: HKCU - {BF101066-1C31-455C-8FA3-948602990DBC} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {D8AF42D8-1CBB-4BB4-A870-CEC55BD53C0C} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
SearchScopes: HKCU - {F22CD882-23AF-44F1-B657-0946862985AA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: pdfMachine - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\Windows\SysWow64\bgstb.dll (Broadgun Software)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL (Microsoft Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - pdfMachine - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\Windows\SysWow64\bgstb.dll (Broadgun Software)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {56CF4856-ECB4-4E46-A897-A378821F97B9} -  No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} -  No File
DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.6.0/jinstall-6-windows-i586.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~4\Office12\GRA32A~1.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{33C17895-EFE6-4203-8BB0-7676BD32652D}: [NameServer]212.23.115.148 212.23.115.132
Tcpip\..\Interfaces\{449021CE-CD4F-45F0-B8B7-9BD01ADFF7F0}: [NameServer]212.23.115.148 212.23.115.132
Tcpip\..\Interfaces\{C6073CA8-2E01-4250-8473-B4B2FC1859E1}: [NameServer]212.23.115.132 212.23.115.148

Chrome:
=======
CHR Extension: (YouTube) - C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Gmail) - C:\Users\Carina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

==================== Services (Whitelisted) =================

R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-05-29] (TuneUp Software)
R2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [329168 2010-04-12] ()
R2 XS Stick Service; C:\Windows\service4g.exe [145064 2010-04-30] (4G Systems GmbH & Co. KG)

==================== Drivers (Whitelisted) ====================

S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-01-28] (Mobile Connector)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S2 Sentinel; C:\Windows\SysWow64\Drivers\SENTINEL.SYS [73728 2001-06-21] (Rainbow Technologies, Inc.)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 Sntnlusb; C:\Windows\SysWow64\DRIVERS\SNTNLUSB.SYS [20032 2001-06-21] (Rainbow Technologies Inc.)
S3 SynUSB64; C:\Windows\System32\DRIVERS\SynUSB64.sys [29432 2007-10-24] (SIA Syncrosoft)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-11-24] (TuneUp Software)
S2 Sentinel; \SystemRoot\System32\Drivers\SENTINEL.SYS [x]
S3 Sntnlusb; system32\DRIVERS\SNTNLUSB.SYS [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-06 16:35 - 2012-07-26 06:55 - 00785512 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys
2013-07-06 16:35 - 2012-07-26 06:55 - 00054376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WdfLdr.sys
2013-07-06 16:35 - 2012-07-26 04:36 - 00009728 ____A (Microsoft Corporation) C:\Windows\System32\Wdfres.dll
2013-07-06 16:35 - 2012-06-02 16:35 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2013-07-06 16:20 - 2013-07-06 16:20 - 00000000 ____D C:\Windows\System32\SPReview
2013-07-06 16:19 - 2013-07-06 16:19 - 00000000 ____D C:\Windows\System32\EventProviders
2013-07-06 16:18 - 2013-02-22 08:57 - 17817088 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-07-06 16:18 - 2013-02-22 08:29 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-07-06 16:18 - 2013-02-22 08:27 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-07-06 16:18 - 2013-02-22 08:21 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-07-06 16:18 - 2013-02-22 08:20 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-07-06 16:18 - 2013-02-22 08:19 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-07-06 16:18 - 2013-02-22 08:18 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-07-06 16:18 - 2013-02-22 08:17 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-07-06 16:18 - 2013-02-22 08:15 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-07-06 16:18 - 2013-02-22 08:15 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-07-06 16:18 - 2013-02-22 08:15 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-07-06 16:18 - 2013-02-22 08:14 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-07-06 16:18 - 2013-02-22 08:13 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-07-06 16:18 - 2013-02-22 08:13 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-07-06 16:18 - 2013-02-22 08:12 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-07-06 16:18 - 2013-02-22 08:09 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-07-06 16:18 - 2013-02-22 06:05 - 12324352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-06 16:18 - 2013-02-22 05:47 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-06 16:18 - 2013-02-22 05:46 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-06 16:18 - 2013-02-22 05:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-06 16:18 - 2013-02-22 05:38 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-06 16:18 - 2013-02-22 05:37 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-07-06 16:18 - 2013-02-22 05:36 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-07-06 16:18 - 2013-02-22 05:35 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-06 16:18 - 2013-02-22 05:34 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-06 16:18 - 2013-02-22 05:34 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-07-06 16:18 - 2013-02-22 05:34 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-07-06 16:18 - 2013-02-22 05:33 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-06 16:18 - 2013-02-22 05:32 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-06 16:18 - 2013-02-22 05:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-06 16:18 - 2013-02-22 05:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-07-06 16:18 - 2013-02-22 05:28 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-06 16:17 - 2012-12-16 19:11 - 00046080 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2013-07-06 16:17 - 2012-12-16 16:45 - 00367616 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2013-07-06 16:17 - 2012-12-16 16:13 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-07-06 16:17 - 2012-12-16 16:13 - 00034304 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-07-06 16:16 - 2012-07-26 05:08 - 00744448 ____A (Microsoft Corporation) C:\Windows\System32\WUDFx.dll
2013-07-06 16:16 - 2012-07-26 05:08 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\WUDFHost.exe
2013-07-06 16:16 - 2012-07-26 05:08 - 00194048 ____A (Microsoft Corporation) C:\Windows\System32\WUDFPlatform.dll
2013-07-06 16:16 - 2012-07-26 05:08 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\WUDFSvc.dll
2013-07-06 16:16 - 2012-07-26 05:08 - 00045056 ____A (Microsoft Corporation) C:\Windows\System32\WUDFCoinstaller.dll
2013-07-06 16:16 - 2012-07-26 04:26 - 00198656 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFRd.sys
2013-07-06 16:16 - 2012-07-26 04:26 - 00087040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFPf.sys
2013-07-06 16:16 - 2012-06-02 16:57 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2013-07-06 14:51 - 2010-11-20 15:33 - 00299392 ____A (Microsoft Corporation) C:\Windows\System32\mcupdate_GenuineIntel.dll
2013-07-06 14:51 - 2010-11-20 15:33 - 00273792 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\msiscsi.sys
2013-07-06 14:51 - 2010-11-20 15:27 - 14633472 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 03860992 ____A (Microsoft Corporation) C:\Windows\System32\UIRibbon.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 03650560 ____A (Microsoft Corporation) C:\Windows\System32\MSVidCtl.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 03008000 ____A (Microsoft Corporation) C:\Windows\System32\xpsservices.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 02086912 ____A (Microsoft Corporation) C:\Windows\System32\ole32.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 01753088 ____A (Microsoft Corporation) C:\Windows\System32\vssapi.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 01743360 ____A (Microsoft Corporation) C:\Windows\System32\sysmain.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 01646080 ____A (Microsoft Corporation) C:\Windows\System32\wevtsvc.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 01556992 ____A (Microsoft Corporation) C:\Windows\System32\RacEngn.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 01326080 ____A (Microsoft Corporation) C:\Windows\System32\NaturalLanguage6.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 01219584 ____A (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 01197056 ____A (Microsoft Corporation) C:\Windows\System32\taskschd.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 01110016 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 00488448 ____A (Microsoft Corporation) C:\Windows\System32\secproc.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 00485888 ____A (Microsoft Corporation) C:\Windows\System32\secproc_isv.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 00263168 ____A (Microsoft Corporation) C:\Windows\System32\spwizui.dll
2013-07-06 14:51 - 2010-11-20 15:27 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2013-07-06 14:51 - 2010-11-20 15:26 - 04120064 ____A (Microsoft Corporation) C:\Windows\System32\mf.dll
2013-07-06 14:51 - 2010-11-20 15:26 - 03205120 ____A (Microsoft Corporation) C:\Windows\System32\mmcndmgr.dll
2013-07-06 14:51 - 2010-11-20 15:26 - 01866240 ____A (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll
2013-07-06 14:51 - 2010-11-20 15:26 - 01838080 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll
2013-07-06 14:51 - 2010-11-20 15:26 - 01340416 ____A (Microsoft Corporation) C:\Windows\System32\diagperf.dll
2013-07-06 14:51 - 2010-11-20 15:25 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\RMActivate_isv.exe
2013-07-06 14:51 - 2010-11-20 15:25 - 00359424 ____A (Microsoft Corporation) C:\Windows\System32\RMActivate.exe
2013-07-06 14:51 - 2010-11-20 14:21 - 11410432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-07-06 14:51 - 2010-11-20 14:21 - 00423936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2013-07-06 14:51 - 2010-11-20 14:20 - 00428032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2013-07-06 14:51 - 2010-11-20 14:19 - 03207680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2013-07-06 14:51 - 2010-11-20 14:19 - 00954752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll
2013-07-06 14:51 - 2010-11-20 14:19 - 00954288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll
2013-07-06 14:51 - 2010-11-20 14:18 - 01334272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2013-07-06 14:51 - 2010-11-20 14:18 - 01171456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-07-06 14:51 - 2010-11-20 14:17 - 00327168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2013-07-06 14:51 - 2010-11-20 14:17 - 00322048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2013-07-06 14:51 - 2010-11-20 13:07 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys
2013-07-06 14:51 - 2010-11-05 03:58 - 01130824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2013-07-06 14:51 - 2010-11-05 03:58 - 00297808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll
2013-07-06 14:51 - 2010-11-05 03:57 - 01942856 ____A (Microsoft Corporation) C:\Windows\System32\dfshim.dll
2013-07-06 14:51 - 2010-11-05 03:57 - 00444752 ____A (Microsoft Corporation) C:\Windows\System32\mscoree.dll
2013-07-06 14:51 - 2010-11-05 03:57 - 00048976 ____A (Microsoft Corporation) C:\Windows\System32\netfxperf.dll
2013-07-06 14:50 - 2010-11-20 15:44 - 01077248 ____A (Microsoft Corporation) C:\Windows\System32\Narrator.exe
2013-07-06 14:50 - 2010-11-20 15:39 - 05066752 ____A (Microsoft Corporation) C:\Windows\System32\AuthFWSnapin.dll
2013-07-06 14:50 - 2010-11-20 15:34 - 00295808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volsnap.sys
2013-07-06 14:50 - 2010-11-20 15:34 - 00215936 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\vhdmp.sys
2013-07-06 14:50 - 2010-11-20 15:34 - 00071552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volmgr.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00982912 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00951680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00366976 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\msrpc.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00289664 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fltMgr.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00263040 ____A (Microsoft Corporation) C:\Windows\System32\hal.dll
2013-07-06 14:50 - 2010-11-20 15:33 - 00184704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pci.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00140672 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\msdsm.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00103808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\sbp2port.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00078720 ____A (Hewlett-Packard Company) C:\Windows\System32\Drivers\HpSAMD.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00063360 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\termdd.sys
2013-07-06 14:50 - 2010-11-20 15:33 - 00031104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\msahci.sys
2013-07-06 14:50 - 2010-11-20 15:32 - 00334208 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\acpi.sys
2013-07-06 14:50 - 2010-11-20 15:32 - 00179072 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Classpnp.sys
2013-07-06 14:50 - 2010-11-20 15:32 - 00112000 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-07-06 14:50 - 2010-11-20 15:29 - 00345600 ____A (Microsoft Corporation) C:\Windows\System32\fveapi.dll
2013-07-06 14:50 - 2010-11-20 15:28 - 00780008 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-07-06 14:50 - 2010-11-20 15:28 - 00298104 ____A (Microsoft Corporation) C:\Windows\System32\bcryptprimitives.dll
2013-07-06 14:50 - 2010-11-20 15:28 - 00166784 ____A (Microsoft Corporation) C:\Windows\System32\basecsp.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 03027968 ____A (Microsoft Corporation) C:\Windows\System32\WMVCORE.DLL
2013-07-06 14:50 - 2010-11-20 15:27 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\themeui.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 02652160 ____A (Microsoft Corporation) C:\Windows\System32\netshell.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 02543616 ____A (Microsoft Corporation) C:\Windows\System32\wpdshext.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 02262528 ____A (Microsoft Corporation) C:\Windows\System32\SyncCenter.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 02250752 ____A (Microsoft Corporation) C:\Windows\System32\SensorsCpl.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 02193920 ____A (Microsoft Corporation) C:\Windows\System32\themecpl.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 02072576 ____A (Microsoft Corporation) C:\Windows\System32\WMPEncEn.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 02055680 ____A (Microsoft Corporation) C:\Windows\System32\Query.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 02018304 ____A (Microsoft Corporation) C:\Windows\System32\WsmSvc.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01900544 ____A (Microsoft Corporation) C:\Windows\System32\setupapi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01888256 ____A (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL
2013-07-06 14:50 - 2010-11-20 15:27 - 01808384 ____A (Microsoft Corporation) C:\Windows\System32\pnidui.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01689600 ____A (Microsoft Corporation) C:\Windows\System32\netcenter.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01509888 ____A (Microsoft Corporation) C:\Windows\System32\msdtctm.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01441280 ____A (Microsoft Corporation) C:\Windows\System32\wlanpref.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01389056 ____A (Microsoft Corporation) C:\Windows\System32\pla.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01363968 ____A (Microsoft Corporation) C:\Windows\System32\wdc.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01281024 ____A (Microsoft Corporation) C:\Windows\System32\werconcpl.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01243136 ____A (Microsoft Corporation) C:\Windows\System32\WMNetMgr.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01212416 ____A (Microsoft Corporation) C:\Windows\System32\propsys.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01190400 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01160192 ____A (Microsoft Corporation) C:\Windows\System32\MSMPEG2ENC.DLL
2013-07-06 14:50 - 2010-11-20 15:27 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\webservices.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01120768 ____A (Microsoft Corporation) C:\Windows\System32\sdengin2.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01098240 ____A (Microsoft Corporation) C:\Windows\System32\Vault.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01082880 ____A (Microsoft Corporation) C:\Windows\System32\sppobjs.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01050624 ____A (Microsoft Corporation) C:\Windows\System32\printui.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01024512 ____A (Microsoft Corporation) C:\Windows\System32\wmpmde.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 01008128 ____A (Microsoft Corporation) C:\Windows\System32\user32.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00933888 ____A (Microsoft Corporation) C:\Windows\System32\sqlsrv32.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00867840 ____A (Microsoft Corporation) C:\Windows\System32\SearchFolder.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00849920 ____A (Microsoft Corporation) C:\Windows\System32\qmgr.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00799744 ____A (Microsoft Corporation) C:\Windows\System32\msftedit.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00758784 ____A (Microsoft Corporation) C:\Windows\System32\samsrv.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00758272 ____A (Microsoft Corporation) C:\Windows\System32\PortableDeviceApi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00750080 ____A (Microsoft Corporation) C:\Windows\System32\TSWorkspace.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00720896 ____A (Microsoft Corporation) C:\Windows\System32\odbc32.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00695808 ____A (Microsoft Corporation) C:\Windows\System32\netlogon.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00691200 ____A (Microsoft Corporation) C:\Windows\System32\VAN.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00680960 ____A (Microsoft Corporation) C:\Windows\System32\termsrv.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00658432 ____A (Microsoft Corporation) C:\Windows\System32\PerfCenterCPL.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00633344 ____A (Microsoft Corporation) C:\Windows\System32\riched20.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00625664 ____A (Microsoft Corporation) C:\Windows\System32\mscms.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00605696 ____A (Microsoft Corporation) C:\Windows\System32\wmpeffects.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00582656 ____A (Microsoft Corporation) C:\Windows\System32\sxs.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00580096 ____A (Microsoft Corporation) C:\Windows\System32\wiaservc.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00577536 ____A (Microsoft Corporation) C:\Windows\System32\WSDApi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00571904 ____A (Microsoft Corporation) C:\Windows\System32\mspbda.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\msdri.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00519680 ____A (Microsoft Corporation) C:\Windows\System32\netcfgx.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00512000 ____A (Microsoft Corporation) C:\Windows\System32\rpcss.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00501248 ____A (Microsoft Corporation) C:\Windows\System32\WinSATAPI.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00486400 ____A (Microsoft Corporation) C:\Windows\System32\powercpl.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00483840 ____A (Microsoft Corporation) C:\Windows\System32\StructuredQuery.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00481280 ____A (Microsoft Corporation) C:\Windows\System32\wmpps.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00476160 ____A (Microsoft Corporation) C:\Windows\System32\QAGENTRT.DLL
2013-07-06 14:50 - 2010-11-20 15:27 - 00475136 ____A (Microsoft Corporation) C:\Windows\System32\wlangpui.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00473600 ____A (Microsoft Corporation) C:\Windows\System32\taskcomp.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00462336 ____A (Microsoft Corporation) C:\Windows\System32\wiadefui.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00457216 ____A (Microsoft Corporation) C:\Windows\System32\msdrm.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\shlwapi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00444416 ____A (Microsoft Corporation) C:\Windows\System32\winhttp.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00429568 ____A (Microsoft Corporation) C:\Windows\System32\puiobj.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00424448 ____A (Microsoft Corporation) C:\Windows\System32\rastls.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00418816 ____A (Microsoft Corporation) C:\Windows\System32\sppwinob.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00409600 ____A (Microsoft Corporation) C:\Windows\System32\photowiz.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00406016 ____A (Microsoft Corporation) C:\Windows\System32\scesrv.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00372736 ____A (Microsoft Corporation) C:\Windows\System32\mtxclu.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00370688 ____A (Microsoft Corporation) C:\Windows\System32\shsvcs.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00367104 ____A (Microsoft Corporation) C:\Windows\System32\wcncsvc.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00357888 ____A (Microsoft Corporation) C:\Windows\System32\sharemediacpl.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00344064 ____A (Microsoft Corporation) C:\Windows\System32\rasmans.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\srchadmin.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00326144 ____A (Microsoft Corporation) C:\Windows\System32\mswsock.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00324096 ____A (Microsoft Corporation) C:\Windows\System32\netdiagfx.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00316928 ____A (Microsoft Corporation) C:\Windows\System32\tapisrv.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00312832 ____A (Microsoft Corporation) C:\Windows\System32\Wldap32.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00312320 ____A (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00303616 ____A (Microsoft Corporation) C:\Windows\System32\scansetting.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00303616 ____A (Microsoft Corporation) C:\Windows\System32\nlasvc.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00299520 ____A (Microsoft Corporation) C:\Windows\System32\tsmf.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00297984 ____A (Microsoft Corporation) C:\Windows\System32\ws2_32.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00266240 ____A (Microsoft Corporation) C:\Windows\System32\QAGENT.DLL
2013-07-06 14:50 - 2010-11-20 15:27 - 00264192 ____A (Microsoft Corporation) C:\Windows\System32\upnp.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00263168 ____A (Microsoft Corporation) C:\Windows\System32\vpnike.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00258560 ____A (Microsoft Corporation) C:\Windows\System32\WebClnt.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00257024 ____A (Microsoft Corporation) C:\Windows\System32\stobject.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00253440 ____A (Microsoft Corporation) C:\Windows\System32\tcpipcfg.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00244224 ____A (Microsoft Corporation) C:\Windows\System32\spp.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00236032 ____A (Microsoft Corporation) C:\Windows\System32\srvsvc.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00235520 ____A (Microsoft Corporation) C:\Windows\System32\onex.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\winsta.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00232960 ____A (Microsoft Corporation) C:\Windows\System32\scecli.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00232448 ____A (Microsoft Corporation) C:\Windows\System32\sppcomapi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\XpsRasterService.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00223232 ____A (Microsoft Corporation) C:\Windows\System32\QSHVHOST.DLL
2013-07-06 14:50 - 2010-11-20 15:27 - 00215552 ____A (Microsoft Corporation) C:\Windows\System32\netiohlp.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\ncsi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00188928 ____A (Microsoft Corporation) C:\Windows\System32\netjoin.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00187904 ____A (Microsoft Corporation) C:\Windows\System32\rpchttp.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\prncache.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00165376 ____A (Microsoft Corporation) C:\Windows\System32\netid.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\ocsetapi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00148992 ____A (Microsoft Corporation) C:\Windows\System32\t2embed.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00146944 ____A (Microsoft Corporation) C:\Windows\System32\scavengeui.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00121856 ____A (Microsoft Corporation) C:\Windows\System32\SessEnv.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00118784 ____A (Microsoft Corporation) C:\Windows\System32\wkssvc.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00117248 ____A (Microsoft Corporation) C:\Windows\System32\wpdbusenum.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00112640 ____A (Microsoft Corporation) C:\Windows\System32\thumbcache.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00109056 ____A (Microsoft Corporation) C:\Windows\System32\userenv.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00107520 ____A (Microsoft Corporation) C:\Windows\System32\QUTIL.DLL
2013-07-06 14:50 - 2010-11-20 15:27 - 00095232 ____A (Microsoft Corporation) C:\Windows\System32\regapi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00092672 ____A (Microsoft Corporation) C:\Windows\System32\TabSvc.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00090112 ____A (Microsoft Corporation) C:\Windows\System32\nci.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\nlaapi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00067584 ____A (Microsoft Corporation) C:\Windows\System32\samcli.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00065536 ____A (Microsoft Corporation) C:\Windows\System32\RpcRtRemote.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00063488 ____A (Microsoft Corporation) C:\Windows\System32\wscapi.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00046592 ____A (Microsoft Corporation) C:\Windows\System32\msasn1.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00040960 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll
2013-07-06 14:50 - 2010-11-20 15:27 - 00038912 ____A (Microsoft Corporation) C:\Windows\System32\vpnikeapi.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 03391488 ____A (Microsoft Corporation) C:\Windows\System32\dbgeng.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 02067456 ____A (Microsoft Corporation) C:\Windows\System32\d3d9.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 01632256 ____A (Microsoft Corporation) C:\Windows\System32\dwmcore.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 01457664 ____A (Microsoft Corporation) C:\Windows\System32\DxpTaskSync.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 01244160 ____A (Microsoft Corporation) C:\Windows\System32\imapi2fs.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 01009152 ____A (Microsoft Corporation) C:\Windows\System32\mcmde.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00934912 ____A (Microsoft Corporation) C:\Windows\System32\FirewallControlPanel.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00853504 ____A (Microsoft Corporation) C:\Windows\System32\IKEEXT.DLL
2013-07-06 14:50 - 2010-11-20 15:26 - 00828416 ____A (Microsoft Corporation) C:\Windows\System32\MPSSVC.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00787968 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00777728 ____A (Microsoft Corporation) C:\Windows\System32\gpsvc.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00675328 ____A (Microsoft Corporation) C:\Windows\System32\DXPTaskRingtone.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00658944 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00630272 ____A (Microsoft Corporation) C:\Windows\System32\evr.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00584192 ____A (Microsoft Corporation) C:\Windows\System32\ipsmsnap.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00569344 ____A (Microsoft Corporation) C:\Windows\System32\iphlpsvc.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00551936 ____A (Microsoft Corporation) C:\Windows\System32\localsec.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00503296 ____A (Microsoft Corporation) C:\Windows\System32\imapi2.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00501248 ____A (Microsoft Corporation) C:\Windows\System32\IPSECSVC.DLL
2013-07-06 14:50 - 2010-11-20 15:26 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\DXP.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00403968 ____A (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00381440 ____A (Microsoft Corporation) C:\Windows\System32\mfds.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00355328 ____A (Microsoft Corporation) C:\Windows\System32\Faultrep.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00348160 ____A (Microsoft Corporation) C:\Windows\System32\eapp3hst.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00332288 ____A (Microsoft Corporation) C:\Windows\System32\hgcpl.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00317952 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcore.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00303616 ____A (Microsoft Corporation) C:\Windows\System32\eapphost.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00295936 ____A (Microsoft Corporation) C:\Windows\System32\framedynos.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00281600 ____A (Microsoft) C:\Windows\System32\DShowRdpFilter.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00279040 ____A (Microsoft Corporation) C:\Windows\System32\framedyn.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00257024 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00239616 ____A (Microsoft Corporation) C:\Windows\System32\dskquoui.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\hgprint.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00232448 ____A (Microsoft Corporation) C:\Windows\System32\ListSvc.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\mprapi.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00217088 ____A (Microsoft Corporation) C:\Windows\System32\iasrad.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00186880 ____A (Microsoft Corporation) C:\Windows\System32\logoncli.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00171520 ____A (Microsoft Corporation) C:\Windows\System32\fde.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00166912 ____A (Microsoft Corporation) C:\Windows\System32\inetpp.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\IPHLPAPI.DLL
2013-07-06 14:50 - 2010-11-20 15:26 - 00128512 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00118272 ____A (Microsoft Corporation) C:\Windows\System32\dnscmmc.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00100864 ____A (Microsoft Corporation) C:\Windows\System32\iasacct.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00100864 ____A (Microsoft Corporation) C:\Windows\System32\davclnt.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\dot3api.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\fdeploy.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\lsmproxy.dll
2013-07-06 14:50 - 2010-11-20 15:26 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\mimefilt.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 03957760 ____A (Microsoft Corporation) C:\Windows\System32\WinSAT.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 01975296 ____A (Microsoft Corporation) C:\Windows\System32\CertEnroll.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 01927680 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\certmgr.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 01600512 ____A (Microsoft Corporation) C:\Windows\System32\VSSVC.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 01504256 ____A (Microsoft Corporation) C:\Windows\System32\wbengine.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 01116672 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00958464 ____A (Microsoft Corporation) C:\Windows\System32\actxprxy.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00897536 ____A (Microsoft Corporation) C:\Windows\System32\azroles.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00726528 ____A (Microsoft Corporation) C:\Windows\System32\AuxiliaryDisplayCpl.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00705024 ____A (Microsoft Corporation) C:\Windows\System32\BFE.DLL
2013-07-06 14:50 - 2010-11-20 15:25 - 00679424 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00633856 ____A (Microsoft Corporation) C:\Windows\System32\comctl32.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00598016 ____A (Microsoft Corporation) C:\Windows\System32\spinstall.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00594432 ____A (Microsoft Corporation) C:\Windows\System32\comdlg32.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00533504 ____A (Microsoft Corporation) C:\Windows\System32\vds.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00504320 ____A (Microsoft Corporation) C:\Windows\System32\biocpl.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00464384 ____A (Microsoft Corporation) C:\Windows\System32\taskeng.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00412160 ____A (Microsoft Corporation) C:\Windows\System32\aepdu.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00405504 ____A (Microsoft Corporation) C:\Windows\System32\wisptis.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00390656 ____A (Microsoft Corporation) C:\Windows\System32\winlogon.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00342016 ____A (Microsoft Corporation) C:\Windows\System32\apphelp.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00314368 ____A (Microsoft Corporation) C:\Windows\System32\clusapi.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\wusa.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00301568 ____A (Microsoft Corporation) C:\Windows\System32\spreview.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00296448 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00285696 ____A (Microsoft Corporation) C:\Windows\System32\schtasks.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00273920 ____A (Microsoft Corporation) C:\Windows\System32\SndVol.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\credui.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00186368 ____A (Microsoft Corporation) C:\Windows\System32\ocsetup.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00139264 ____A (Microsoft Corporation) C:\Windows\System32\cabview.dll
2013-07-06 14:50 - 2010-11-20 15:25 - 00128000 ____A (Microsoft) C:\Windows\System32\Robocopy.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\setupcl.exe
2013-07-06 14:50 - 2010-11-20 15:25 - 00069120 ____A (Microsoft Corporation) C:\Windows\System32\taskhost.exe
2013-07-06 14:50 - 2010-11-20 15:24 - 00850944 ____A (Microsoft Corporation) C:\Windows\System32\mmsys.cpl
2013-07-06 14:50 - 2010-11-20 15:24 - 00726528 ____A (Microsoft Corporation) C:\Windows\System32\appwiz.cpl
2013-07-06 14:50 - 2010-11-20 15:24 - 00689152 ____A (Microsoft Corporation) C:\Windows\System32\FXSSVC.exe
2013-07-06 14:50 - 2010-11-20 15:24 - 00684032 ____A (Microsoft Corporation) C:\Windows\System32\TabletPC.cpl
2013-07-06 14:50 - 2010-11-20 15:24 - 00653312 ____A (Microsoft Corporation) C:\Windows\System32\lpksetup.exe
2013-07-06 14:50 - 2010-11-20 15:24 - 00477696 ____A (Microsoft Corporation) C:\Windows\System32\PhotoScreensaver.scr
2013-07-06 14:50 - 2010-11-20 15:24 - 00442368 ____A (Microsoft Corporation) C:\Windows\System32\winspool.drv
2013-07-06 14:50 - 2010-11-20 15:24 - 00378880 ____A (Microsoft Corporation) C:\Windows\System32\msinfo32.exe
2013-07-06 14:50 - 2010-11-20 15:24 - 00359936 ____A (Microsoft Corporation) C:\Windows\System32\eudcedit.exe
2013-07-06 14:50 - 2010-11-20 15:24 - 00345088 ____A (Microsoft Corporation) C:\Windows\System32\cmd.exe
2013-07-06 14:50 - 2010-11-20 15:24 - 00343040 ____A (Microsoft Corporation) C:\Windows\System32\lsm.exe
2013-07-06 14:50 - 2010-11-20 15:24 - 00300032 ____A (Microsoft Corporation) C:\Windows\System32\msconfig.exe
2013-07-06 14:50 - 2010-11-20 15:24 - 00272896 ____A (Microsoft Corporation) C:\Windows\System32\mcbuilder.exe
2013-07-06 14:50 - 2010-11-20 15:24 - 00217088 ____A (Microsoft Corporation) C:\Windows\System32\wdmaud.drv
2013-07-06 14:50 - 2010-11-20 15:24 - 00122880 ____A (Microsoft Corporation) C:\Windows\System32\aitagent.exe
2013-07-06 14:50 - 2010-11-20 14:55 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
2013-07-06 14:50 - 2010-11-20 14:51 - 00424448 ____A (Microsoft Corporation) C:\Windows\System32\aeinv.dll
2013-07-06 14:50 - 2010-11-20 14:32 - 05066752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AuthFWSnapin.dll
2013-07-06 14:50 - 2010-11-20 14:23 - 00144768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 02983424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 02755072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 02311168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 02146304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SyncCenter.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 01712640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xpsservices.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 01667584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 01624064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPEncEn.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 01619456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-06 14:50 - 2010-11-20 14:21 - 01363456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 01175040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 01128448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vssapi.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 01115136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RacEngn.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 01010688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00782336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00778240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sqlsrv32.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00646144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00597504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00560128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00505856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00458752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WSDApi.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00411648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlangpui.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00381440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00380416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sxs.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00352256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmpeffects.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00351232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00350208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shlwapi.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00335872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WinSATAPI.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00328192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shsvcs.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00305152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00270848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00269824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00246272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\scansetting.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00228352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\upnp.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00194048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00172544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\spp.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00156672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00139264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00134656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00113664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SessEnv.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00081920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\userenv.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00051712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-07-06 14:50 - 2010-11-20 14:21 - 00051200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\samcli.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 02504192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMVCORE.DLL
2013-07-06 14:50 - 2010-11-20 14:20 - 02494464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 01750528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pnidui.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 01508864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 01414144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00988160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00932352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\printui.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00801280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\NaturalLanguage6.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00573440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00563712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00547840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PortableDeviceApi.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00406528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netcfgx.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00225792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netdiagfx.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\onex.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00167936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\QSHVHOST.DLL
2013-07-06 14:50 - 2010-11-20 14:20 - 00166400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netiohlp.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2013-07-06 14:50 - 2010-11-20 14:20 - 00116736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\prncache.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 02291712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 02151936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 01493504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00830464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2013-07-06 14:50 - 2010-11-20 14:19 - 00732160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imapi2fs.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00488448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00392192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imapi2.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00341504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00296448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00257024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00232448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00213504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00206336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\framedynos.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00196608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00124416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fde.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IPHLPAPI.DLL
2013-07-06 14:50 - 2010-11-20 14:19 - 00066560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\hbaapi.dll
2013-07-06 14:50 - 2010-11-20 14:19 - 00034304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msasn1.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 02522624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 01828352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 01792000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 01555456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certmgr.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 01371136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00854016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00762880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\azroles.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00640512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00630784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00530432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00522752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00508416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00485888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00342016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00295936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00254464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00252928 ____A (Microsoft) C:\Windows\SysWOW64\DShowRdpFilter.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00168960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00091136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dot3api.dll
2013-07-06 14:50 - 2010-11-20 14:18 - 00080384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-07-06 14:50 - 2010-11-20 14:17 - 01049600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-07-06 14:50 - 2010-11-20 14:17 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
2013-07-06 14:50 - 2010-11-20 14:17 - 00220672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mcbuilder.exe
2013-07-06 14:50 - 2010-11-20 14:17 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2013-07-06 14:50 - 2010-11-20 14:17 - 00142336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\net1.exe
2013-07-06 14:50 - 2010-11-20 14:17 - 00028672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\proquota.exe
2013-07-06 14:50 - 2010-11-20 14:16 - 00776192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe
2013-07-06 14:50 - 2010-11-20 14:16 - 00668160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2013-07-06 14:50 - 2010-11-20 14:16 - 00658944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2013-07-06 14:50 - 2010-11-20 14:16 - 00320000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2013-07-06 14:50 - 2010-11-20 14:08 - 00833024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2013-07-06 14:50 - 2010-11-20 14:08 - 00311296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-07-06 14:50 - 2010-11-20 13:05 - 00274944 ____A (Microsoft Corporation) C:\Windows\System32\rdpdd.dll
2013-07-06 14:50 - 2010-11-20 13:04 - 00248832 ____A (Microsoft Corporation) C:\Windows\System32\wksprt.exe
2013-07-06 14:50 - 2010-11-20 12:52 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndiswan.sys
2013-07-06 14:50 - 2010-11-20 12:52 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rasl2tp.sys
2013-07-06 14:50 - 2010-11-20 12:52 - 00111104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\raspptp.sys
2013-07-06 14:50 - 2010-11-20 12:52 - 00082944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ipfltdrv.sys
2013-07-06 14:50 - 2010-11-20 12:44 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\1394ohci.sys
2013-07-06 14:50 - 2010-11-20 12:33 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ks.sys
2013-07-06 14:50 - 2010-11-20 11:27 - 00309248 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdbss.sys
2013-07-06 14:50 - 2010-11-20 11:26 - 00328192 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\udfs.sys
2013-07-06 14:50 - 2010-11-20 11:26 - 00140800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys
2013-07-06 14:50 - 2010-11-20 11:25 - 00753664 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-07-06 14:50 - 2010-11-20 11:23 - 00261632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netbt.sys
2013-07-06 14:50 - 2010-11-20 11:21 - 00119296 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdx.sys
2013-07-06 14:50 - 2010-11-05 04:20 - 00347904 ____A C:\Windows\System32\systemsf.ebd
2013-07-06 14:50 - 2010-11-05 03:58 - 00049488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll
2013-07-06 14:50 - 2010-11-05 03:53 - 00320352 ____A (Microsoft Corporation) C:\Windows\System32\PresentationHost.exe
2013-07-06 14:50 - 2010-11-05 03:53 - 00295264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe
2013-07-06 14:50 - 2010-11-05 03:53 - 00109928 ____A (Microsoft Corporation) C:\Windows\System32\PresentationHostProxy.dll
2013-07-06 14:50 - 2010-11-05 03:53 - 00099176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll
2013-07-06 14:50 - 2009-07-14 03:16 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tcpmonui.dll
2013-07-06 14:49 - 2010-11-20 15:44 - 00133632 ____A (Microsoft Corporation) C:\Windows\System32\NAPHLPR.DLL
2013-07-06 14:49 - 2010-11-20 15:44 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\NAPCRYPT.DLL
2013-07-06 14:49 - 2010-11-20 15:34 - 00363392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volmgrx.sys
2013-07-06 14:49 - 2010-11-20 15:33 - 00213888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdyboost.sys
2013-07-06 14:49 - 2010-11-20 15:33 - 00171392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\scsiport.sys
2013-07-06 14:49 - 2010-11-20 15:33 - 00155008 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mpio.sys
2013-07-06 14:49 - 2010-11-20 15:33 - 00094592 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mountmgr.sys
2013-07-06 14:49 - 2010-11-20 15:33 - 00014720 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hwpolicy.sys
2013-07-06 14:49 - 2010-11-20 15:32 - 02217856 ____A (Microsoft Corporation) C:\Windows\System32\bootres.dll
2013-07-06 14:49 - 2010-11-20 15:32 - 00155520 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ataport.sys
2013-07-06 14:49 - 2010-11-20 15:27 - 02146816 ____A (Microsoft Corporation) C:\Windows\System32\networkmap.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 01911808 ____A (Microsoft Corporation) C:\Windows\System32\OpcServices.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 01672704 ____A (Microsoft Corporation) C:\Windows\System32\networkexplorer.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 01232896 ____A (Microsoft Corporation) C:\Windows\System32\WMADMOD.DLL
2013-07-06 14:49 - 2010-11-20 15:27 - 01080320 ____A (Microsoft Corporation) C:\Windows\System32\onexui.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00978944 ____A (Microsoft Corporation) C:\Windows\System32\WMSPDMOD.DLL
2013-07-06 14:49 - 2010-11-20 15:27 - 00898560 ____A (Microsoft Corporation) C:\Windows\System32\OobeFldr.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00812032 ____A (Microsoft Corporation) C:\Windows\System32\wpccpl.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00781312 ____A (Microsoft Corporation) C:\Windows\System32\wmdrmsdk.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00769536 ____A (Microsoft Corporation) C:\Windows\System32\sud.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\sdcpl.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00666112 ____A (Microsoft Corporation) C:\Windows\System32\WMVSDECD.DLL
2013-07-06 14:49 - 2010-11-20 15:27 - 00641024 ____A (Microsoft Corporation) C:\Windows\System32\msscp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00636416 ____A (Microsoft Corporation) C:\Windows\System32\wmdrmdev.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00625664 ____A (Microsoft Corporation) C:\Windows\System32\usercpl.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00624128 ____A (Microsoft Corporation) C:\Windows\System32\qedit.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00611840 ____A (Microsoft Corporation) C:\Windows\System32\wpd_ci.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00594432 ____A (Microsoft Corporation) C:\Windows\System32\wvc.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00527872 ____A (Microsoft Corporation) C:\Windows\System32\wmdrmnet.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00455168 ____A (Microsoft Corporation) C:\Windows\System32\nshipsec.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00451072 ____A (Microsoft Corporation) C:\Windows\System32\shwebsvc.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00446976 ____A (Microsoft Corporation) C:\Windows\System32\sqlcese30.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00445952 ____A (Microsoft Corporation) C:\Windows\System32\spwizeng.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00435712 ____A (Microsoft Corporation) C:\Windows\System32\PortableDeviceStatus.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00431104 ____A (Microsoft Corporation) C:\Windows\System32\WPDSp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00421888 ____A (Microsoft Corporation) C:\Windows\System32\termmgr.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\systemcpl.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00416256 ____A (Microsoft Corporation) C:\Windows\System32\prnfldr.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\wlanmsm.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00414208 ____A (Microsoft Corporation) C:\Windows\System32\wlanui.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00403968 ____A (Microsoft Corporation) C:\Windows\System32\untfs.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00392192 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00366080 ____A (Microsoft Corporation) C:\Windows\System32\zipfldr.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00358400 ____A (Microsoft Corporation) C:\Windows\System32\wmpdxm.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00344576 ____A (Microsoft Corporation) C:\Windows\System32\ntprint.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00337920 ____A (Microsoft Corporation) C:\Windows\System32\raschap.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00335360 ____A (Microsoft Corporation) C:\Windows\System32\msieftp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00325632 ____A (Microsoft Corporation) C:\Windows\System32\msnetobj.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00313856 ____A (Microsoft Corporation) C:\Windows\System32\ReAgent.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00300032 ____A (Microsoft Corporation) C:\Windows\System32\pdh.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\srrstr.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00268288 ____A (Microsoft Corporation) C:\Windows\System32\MSAC3ENC.DLL
2013-07-06 14:49 - 2010-11-20 15:27 - 00255488 ____A (Microsoft Corporation) C:\Windows\System32\wavemsp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\qasf.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00250880 ____A (Microsoft Corporation) C:\Windows\System32\qdv.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\taskbarcpl.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00238080 ____A (Microsoft Corporation) C:\Windows\System32\mstask.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\SndVolSSO.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00224256 ____A (Microsoft Corporation) C:\Windows\System32\PortableDeviceSyncProvider.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00223232 ____A (Microsoft Corporation) C:\Windows\System32\wmpsrcwp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00222720 ____A (Microsoft Corporation) C:\Windows\System32\wwanconn.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\rdpencom.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00221696 ____A (Microsoft Corporation) C:\Windows\System32\OnLineIDCpl.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00217600 ____A (Microsoft Corporation) C:\Windows\System32\WinSCard.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\wpdwcn.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00211456 ____A (Microsoft Corporation) C:\Windows\System32\rasppp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00207360 ____A (Microsoft Corporation) C:\Windows\System32\sysclass.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00200192 ____A (Microsoft Corporation) C:\Windows\System32\syncui.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00196608 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00193024 ____A (Microsoft Corporation) C:\Windows\System32\netplwiz.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00190976 ____A (Microsoft Corporation) C:\Windows\System32\vdsbas.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00189952 ____A (Microsoft Corporation) C:\Windows\System32\SmartcardCredentialProvider.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00187904 ____A (Microsoft Corporation) C:\Windows\System32\provsvc.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00185856 ____A (Microsoft Corporation) C:\Windows\System32\vdsutil.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00181248 ____A (Microsoft Corporation) C:\Windows\System32\qcap.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\twext.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00170496 ____A (Microsoft Corporation) C:\Windows\System32\sdrsvc.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00156160 ____A (Microsoft Corporation) C:\Windows\System32\prntvpt.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00154624 ____A (Microsoft Corporation) C:\Windows\System32\uxlib.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00153088 ____A (Microsoft Corporation) C:\Windows\System32\remotepg.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00146944 ____A (Microsoft Corporation) C:\Windows\System32\recovery.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\sppc.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00143360 ____A (Microsoft Corporation) C:\Windows\System32\mydocs.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\shacct.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00132608 ____A (Microsoft Corporation) C:\Windows\System32\wmpshell.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00130048 ____A (Microsoft Corporation) C:\Windows\System32\shsetup.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\ntlanman.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00128000 ____A (Microsoft Corporation) C:\Windows\System32\srvcli.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00124928 ____A (Microsoft Corporation) C:\Windows\System32\wiavideo.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00124416 ____A (Microsoft Corporation) C:\Windows\System32\QSVRMGMT.DLL
2013-07-06 14:49 - 2010-11-20 15:27 - 00121856 ____A (Microsoft Corporation) C:\Windows\System32\secproc_ssp_isv.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00121856 ____A (Microsoft Corporation) C:\Windows\System32\secproc_ssp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00115200 ____A (Microsoft Corporation) C:\Windows\System32\WPDShServiceObj.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00102400 ____A (Microsoft Corporation) C:\Windows\System32\sppnp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00086016 ____A (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00084480 ____A (Microsoft Corporation) C:\Windows\System32\UserAccountControlSettings.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00079872 ____A (Microsoft Corporation) C:\Windows\System32\QCLIPROV.DLL
2013-07-06 14:49 - 2010-11-20 15:27 - 00078848 ____A (Microsoft Corporation) C:\Windows\System32\spbcd.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00073728 ____A (Microsoft Corporation) C:\Windows\System32\tlscsp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\unimdmat.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\napdsnap.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\wkscli.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\vfwwdm32.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\rdpd3d.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\wsnmp32.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00066048 ____A (Microsoft Corporation) C:\Windows\System32\ncryptui.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00061952 ____A (Microsoft Corporation) C:\Windows\System32\WavDest.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00061952 ____A (Microsoft Corporation) C:\Windows\System32\vss_ps.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00059904 ____A (Microsoft Corporation) C:\Windows\System32\umb.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\odbcconf.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\rtutils.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\PrintIsolationProxy.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00047104 ____A (Microsoft Corporation) C:\Windows\System32\wshbth.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00038912 ____A (Microsoft Corporation) C:\Windows\System32\msvidc32.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\shimgvw.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00036352 ____A (Microsoft Corporation) C:\Windows\System32\wdiasqmmodule.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00035840 ____A (Microsoft Corporation) C:\Windows\System32\msdmo.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\seclogon.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00029184 ____A (Microsoft Corporation) C:\Windows\System32\netutils.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00028160 ____A (Microsoft Corporation) C:\Windows\System32\shgina.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00026112 ____A (Microsoft Corporation) C:\Windows\System32\wsdchngr.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00025600 ____A (Microsoft Corporation) C:\Windows\System32\msyuv.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00024064 ____A (Microsoft Corporation) C:\Windows\System32\sisbkup.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00024064 ____A (Microsoft Corporation) C:\Windows\System32\schedcli.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00023040 ____A (Microsoft Corporation) C:\Windows\System32\rdprefdrvapi.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00021504 ____A (Microsoft Corporation) C:\Windows\System32\TRAPI.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00018944 ____A (Microsoft Corporation) C:\Windows\System32\spopk.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00017408 ____A (Microsoft Corporation) C:\Windows\System32\syssetup.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00016896 ____A (Microsoft Corporation) C:\Windows\System32\muifontsetup.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\msrle32.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\slwga.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\nrpsrv.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00014848 ____A (Microsoft Corporation) C:\Windows\System32\tsbyuv.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\wshirda.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\sscore.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00011264 ____A (Microsoft Corporation) C:\Windows\System32\shunimpl.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\riched32.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00010240 ____A (Microsoft Corporation) C:\Windows\System32\rdpcfgex.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00009728 ____A (Microsoft Corporation) C:\Windows\System32\spwmp.dll
2013-07-06 14:49 - 2010-11-20 15:27 - 00005120 ____A (Microsoft Corporation) C:\Windows\System32\msdxm.ocx
2013-07-06 14:49 - 2010-11-20 15:27 - 00005120 ____A (Microsoft Corporation) C:\Windows\System32\dxmasf.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 01202176 ____A (Microsoft Corporation) C:\Windows\System32\DiagCpl.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 01087488 ____A (Microsoft Corporation) C:\Windows\System32\dbghelp.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 01066496 ____A (Microsoft Corporation) C:\Windows\System32\Display.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\fontext.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00701440 ____A (Microsoft Corporation) C:\Windows\System32\dsuiext.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\FXSAPI.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00508928 ____A (Microsoft Corporation) C:\Windows\System32\DeviceCenter.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00495104 ____A (Microsoft Corporation) C:\Windows\System32\drmmgrtn.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00434688 ____A (Microsoft Corporation) C:\Windows\System32\FXSTIFF.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00345600 ____A (Microsoft Corporation) C:\Windows\System32\MediaMetadataHandler.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00313344 ____A (Microsoft Corporation) C:\Windows\System32\dot3ui.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00304128 ____A (Microsoft Corporation) C:\Windows\System32\efscore.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00282624 ____A (Microsoft Corporation) C:\Windows\System32\iTVData.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\iprtrmgr.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\dxdiagn.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\dot3svc.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00240640 ____A (Microsoft Corporation) C:\Windows\System32\MFPlay.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00233984 ____A (Microsoft Corporation) C:\Windows\System32\defaultlocationcpl.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\DevicePairingFolder.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00211456 ____A (Microsoft Corporation) C:\Windows\System32\mprddm.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00206848 ____A (Microsoft Corporation) C:\Windows\System32\mfps.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00198656 ____A (Microsoft Corporation) C:\Windows\System32\iasrecst.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00194048 ____A (Microsoft Corporation) C:\Windows\System32\itircl.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\ifsutil.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\dps.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\EhStorAPI.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00121344 ____A (Microsoft Corporation) C:\Windows\System32\fphc.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00116224 ____A (Windows (R) Codename Longhorn DDK provider) C:\Windows\System32\fms.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\eappgnui.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\dot3msm.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\mapistub.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\mapi32.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00090624 ____A (Microsoft Corporation) C:\Windows\System32\KMSVC.DLL
2013-07-06 14:49 - 2010-11-20 15:26 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\Mcx2Svc.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00078848 ____A (Microsoft Corporation) C:\Windows\System32\hbaapi.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00074240 ____A (Microsoft Corporation) C:\Windows\System32\fdProxy.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00069120 ____A (Microsoft Corporation) C:\Windows\System32\dot3cfg.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00065536 ____A (Microsoft Corporation) C:\Windows\System32\inetmib1.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\iyuv_32.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\luainstall.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00045056 ____A (Microsoft Corporation) C:\Windows\System32\httpapi.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\FXSMON.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\mciqtz32.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\iscsium.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\dsauth.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00027136 ____A (Microsoft Corporation) C:\Windows\System32\HotStartUserAgent.dll
2013-07-06 14:49 - 2010-11-20 15:26 - 00025600 ____A (Microsoft Corporation) C:\Windows\System32\elsTrans.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 03745792 ____A (Microsoft Corporation) C:\Windows\System32\accessibilitycpl.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 03524608 ____A (Microsoft Corporation) C:\Windows\System32\sppsvc.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 01264640 ____A (Microsoft Corporation) C:\Windows\System32\sdclt.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 01065984 ____A (Microsoft Corporation) C:\Windows\System32\cryptui.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00840192 ____A (Microsoft Corporation) C:\Windows\System32\blackbox.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00780800 ____A (Microsoft Corporation) C:\Windows\System32\ActionCenter.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00749568 ____A (Microsoft Corporation) C:\Windows\System32\batmeter.dll


AdITa 07.07.2013 10:53

Code:

2013-07-06 14:49 - 2010-11-20 15:25 - 00549888 ____A (Microsoft Corporation) C:\Windows\System32\ActionCenterCPL.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00472064 ____A (Microsoft Corporation) C:\Windows\System32\azroleui.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00460800 ____A (Microsoft Corporation) C:\Windows\System32\certcli.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00395776 ____A (Microsoft Corporation) C:\Windows\System32\nltest.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00349696 ____A (Microsoft Corporation) C:\Windows\System32\slui.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00306688 ____A (Microsoft Corporation) C:\Windows\System32\RMActivate_ssp.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00305152 ____A (Microsoft Corporation) C:\Windows\System32\RMActivate_ssp_isv.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00294912 ____A (Microsoft Corporation) C:\Windows\System32\WindowsAnytimeUpgradeResults.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00293888 ____A (Microsoft Corporation) C:\Windows\System32\wsqmcons.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00279040 ____A (Microsoft Corporation) C:\Windows\System32\sethc.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00257024 ____A (Microsoft Corporation) C:\Windows\System32\taskmgr.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00238080 ____A (Microsoft Corporation) C:\Windows\System32\recdisc.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00213504 ____A (Microsoft Corporation) C:\Windows\System32\ActionQueue.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\perfmon.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00168448 ____A (Microsoft Corporation) C:\Windows\System32\bcdsrv.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00155136 ____A (Microsoft Corporation) C:\Windows\System32\autoplay.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00152064 ____A (Microsoft Corporation) C:\Windows\System32\net1.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\AuxiliaryDisplayServices.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00114688 ____A (Microsoft Corporation) C:\Windows\System32\AxInstSv.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00109568 ____A (Microsoft Corporation) C:\Windows\System32\nslookup.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00095232 ____A (Microsoft Corporation) C:\Windows\System32\cca.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00094720 ____A (Microsoft Corporation) C:\Windows\System32\cabinet.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\amstream.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\asycfilt.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00080384 ____A (Microsoft Corporation) C:\Windows\System32\certprop.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00078848 ____A (Microsoft Corporation) C:\Windows\System32\tabcal.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\CertPolEng.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00063488 ____A (Microsoft Corporation) C:\Windows\System32\takeown.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\PnPUnattend.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00058368 ____A (Microsoft Corporation) C:\Windows\System32\tzutil.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\runonce.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\acppage.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\repair-bde.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\MultiDigiMon.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00046080 ____A (Microsoft Corporation) C:\Windows\System32\cscapi.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00043008 ____A (Microsoft Corporation) C:\Windows\System32\relog.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\proquota.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\AzSqlExt.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\userinit.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00030208 ____A (Microsoft Corporation) C:\Windows\System32\cscdll.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00026112 ____A (Microsoft Corporation) C:\Windows\System32\WerFaultSecure.exe
2013-07-06 14:49 - 2010-11-20 15:25 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\bitsperf.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00022016 ____A (Microsoft Corporation) C:\Windows\System32\credssp.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00014848 ____A (Microsoft Corporation) C:\Windows\System32\BWUnpairElevated.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00014336 ____A (Microsoft Corporation) C:\Windows\System32\browseui.dll
2013-07-06 14:49 - 2010-11-20 15:25 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\C_ISCII.DLL
2013-07-06 14:49 - 2010-11-20 15:25 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00957440 ____A (Microsoft Corporation) C:\Windows\System32\mblctr.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00899584 ____A (Microsoft Corporation) C:\Windows\System32\Bubbles.scr
2013-07-06 14:49 - 2010-11-20 15:24 - 00793088 ____A (Microsoft Corporation) C:\Windows\System32\autoconv.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00777728 ____A (Microsoft Corporation) C:\Windows\System32\autochk.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00763904 ____A (Microsoft Corporation) C:\Windows\System32\autofmt.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00721408 ____A (Microsoft Corporation) C:\Windows\System32\bthprops.cpl
2013-07-06 14:49 - 2010-11-20 15:24 - 00606208 ____A (Microsoft Corporation) C:\Windows\System32\dfrgui.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00497664 ____A (Microsoft Corporation) C:\Windows\System32\main.cpl
2013-07-06 14:49 - 2010-11-20 15:24 - 00474112 ____A (Microsoft Corporation) C:\Windows\System32\sysmon.ocx
2013-07-06 14:49 - 2010-11-20 15:24 - 00373248 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-07-06 14:49 - 2010-11-20 15:24 - 00363520 ____A (Microsoft Corporation) C:\Windows\System32\diskraid.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00352768 ____A (Microsoft Corporation) C:\Windows\System32\sysdm.cpl
2013-07-06 14:49 - 2010-11-20 15:24 - 00346112 ____A (Microsoft Corporation) C:\Windows\System32\bcdedit.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00333824 ____A (Microsoft Corporation) C:\Windows\System32\ssText3d.scr
2013-07-06 14:49 - 2010-11-20 15:24 - 00321536 ____A (Microsoft Corporation) C:\Windows\System32\unimdm.tsp
2013-07-06 14:49 - 2010-11-20 15:24 - 00250880 ____A (Microsoft Corporation) C:\Windows\System32\ksproxy.ax
2013-07-06 14:49 - 2010-11-20 15:24 - 00242688 ____A (Microsoft Corporation) C:\Windows\System32\Mystify.scr
2013-07-06 14:49 - 2010-11-20 15:24 - 00241664 ____A (Microsoft Corporation) C:\Windows\System32\Ribbons.scr
2013-07-06 14:49 - 2010-11-20 15:24 - 00232448 ____A (Microsoft Corporation) C:\Windows\System32\bitsadmin.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\VBICodec.ax
2013-07-06 14:49 - 2010-11-20 15:24 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\bcdboot.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\powercfg.cpl
2013-07-06 14:49 - 2010-11-20 15:24 - 00166400 ____A (Microsoft Corporation) C:\Windows\System32\diskpart.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00152064 ____A (Microsoft Corporation) C:\Windows\System32\iscsicli.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00146944 ____A (Microsoft Corporation) C:\Windows\System32\MdSched.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\Kswdmcap.ax
2013-07-06 14:49 - 2010-11-20 15:24 - 00130048 ____A (Microsoft Corporation) C:\Windows\System32\desk.cpl
2013-07-06 14:49 - 2010-11-20 15:24 - 00128000 ____A (Microsoft Corporation) C:\Windows\System32\msiexec.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00104448 ____A (Microsoft Corporation) C:\Windows\System32\logman.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\kstvtune.ax
2013-07-06 14:49 - 2010-11-20 15:24 - 00102400 ____A (Microsoft Corporation) C:\Windows\System32\mobsync.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\WSTPager.ax
2013-07-06 14:49 - 2010-11-20 15:24 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\cmstp.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\isoburn.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00079872 ____A (Microsoft Corporation) C:\Windows\System32\manage-bde.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00071168 ____A (Microsoft Corporation) C:\Windows\System32\findstr.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00071168 ____A (Microsoft Corporation) C:\Windows\bfsvc.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00066048 ____A (Microsoft Corporation) C:\Windows\System32\ksxbar.ax
2013-07-06 14:49 - 2010-11-20 15:24 - 00061440 ____A (Microsoft Corporation) C:\Windows\System32\djoin.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\g711codc.ax
2013-07-06 14:49 - 2010-11-20 15:24 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\ftp.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\vbisurf.ax
2013-07-06 14:49 - 2010-11-20 15:24 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\choice.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\LogonUI.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00018432 ____A (Microsoft Corporation) C:\Windows\System32\FXSUNATD.exe
2013-07-06 14:49 - 2010-11-20 15:24 - 00017920 ____A (Microsoft Corporation) C:\Windows\System32\fixmapi.exe
2013-07-06 14:49 - 2010-11-20 15:15 - 01164800 ____A (Microsoft Corporation) C:\Windows\System32\UIRibbonRes.dll
2013-07-06 14:49 - 2010-11-20 15:13 - 00147456 ____A (Microsoft Corporation) C:\Windows\System32\RDPENCDD.dll
2013-07-06 14:49 - 2010-11-20 15:02 - 01148416 ____A (Microsoft Corporation) C:\Windows\System32\IMJP10.IME
2013-07-06 14:49 - 2010-11-20 15:02 - 00457216 ____A (Microsoft Corporation) C:\Windows\System32\imkr80.ime
2013-07-06 14:49 - 2010-11-20 15:02 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\KBDTUQ.DLL
2013-07-06 14:49 - 2010-11-20 15:02 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\KBDTUF.DLL
2013-07-06 14:49 - 2010-11-20 15:02 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\KBDSG.DLL
2013-07-06 14:49 - 2010-11-20 15:02 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\kbdlk41a.dll
2013-07-06 14:49 - 2010-11-20 15:02 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\KBDGKL.DLL
2013-07-06 14:49 - 2010-11-20 15:02 - 00007680 ____A (Microsoft Corporation) C:\Windows\System32\KBDSF.DLL
2013-07-06 14:49 - 2010-11-20 15:02 - 00007680 ____A (Microsoft Corporation) C:\Windows\System32\KBDPO.DLL
2013-07-06 14:49 - 2010-11-20 15:02 - 00007680 ____A (Microsoft Corporation) C:\Windows\System32\KBDNEPR.DLL
2013-07-06 14:49 - 2010-11-20 15:02 - 00007680 ____A (Microsoft Corporation) C:\Windows\System32\KBDINTAM.DLL
2013-07-06 14:49 - 2010-11-20 15:02 - 00007680 ____A (Microsoft Corporation) C:\Windows\System32\KBDINBEN.DLL
2013-07-06 14:49 - 2010-11-20 15:02 - 00007680 ____A (Microsoft Corporation) C:\Windows\System32\KBDGR1.DLL
2013-07-06 14:49 - 2010-11-20 14:51 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-ums-l1-1-0.dll
2013-07-06 14:49 - 2010-11-20 14:36 - 00107008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\NAPHLPR.DLL
2013-07-06 14:49 - 2010-11-20 14:36 - 00046080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\NAPCRYPT.DLL
2013-07-06 14:49 - 2010-11-20 14:21 - 02202624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SensorsCpl.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 02157568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\themecpl.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 01326592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlanpref.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 01227776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 01003008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMNetMgr.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00933376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Vault.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00902656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2013-07-06 14:49 - 2010-11-20 14:21 - 00755200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sud.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00739328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2013-07-06 14:49 - 2010-11-20 14:21 - 00738816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00638976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\VAN.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00616960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00600064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00541184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
2013-07-06 14:49 - 2010-11-20 14:21 - 00507392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmdev.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00473600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\riched20.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00444928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00436736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmnet.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00428544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shwebsvc.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00428032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00416768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wiadefui.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00410624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\systemcpl.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00410112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlanui.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00406528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00372224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00363520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00352768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\termmgr.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00352768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\spwizeng.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00350720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WPDSp.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00346624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00327680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00318976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\raschap.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00318464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00309760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sqlcese30.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00307712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00301568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srchadmin.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00299520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmpdxm.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00276992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00247808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00242176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tapisrv.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00222208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wavemsp.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SndVolSSO.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00198144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wpdwcn.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00193536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sppcomapi.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00186368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00182272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmpsrcwp.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00181760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tcpipcfg.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00179712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rasppp.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00175616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\scecli.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00160256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vdsbas.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00159232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\syncui.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00146944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\remotepg.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00146432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twext.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00144384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmpps.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00135168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\uxlib.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00115712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00111104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shsetup.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00109568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wiavideo.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00108032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WPDShServiceObj.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00105472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmpshell.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00100864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sppinst.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00090112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srvcli.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00087552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00085504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00085504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00082944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00080896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\QUTIL.DLL
2013-07-06 14:49 - 2010-11-20 14:21 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UserAccountControlSettings.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00072192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\regapi.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00071168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00069632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tlscsp.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00069632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rastapi.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\spbcd.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00059392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\unimdmat.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00056832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vfwwdm32.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00052224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpd3d.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00051712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wsnmp32.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00051200 ____A (Twain Working Group) C:\Windows\twain_32.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00047104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wkscli.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00046080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RpcRtRemote.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00040448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wtsapi32.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00037376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rtutils.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00036352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wshbth.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shimgvw.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\utildll.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00027648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vpnikeapi.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00021504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wsdchngr.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00021504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\TRAPI.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00021504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdprefdrvapi.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00020992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shgina.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00019968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\spopk.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00019456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sisbkup.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00017408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schedcli.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00014848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\syssetup.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00012288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsbyuv.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00011264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wshirda.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shunimpl.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00009728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00008704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\riched32.dll
2013-07-06 14:49 - 2010-11-20 14:21 - 00004096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2013-07-06 14:49 - 2010-11-20 14:21 - 00004096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 02130944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\networkmap.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 01661440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\networkexplorer.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 01644032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netcenter.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 01111552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\onexui.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00859648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\OobeFldr.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00656384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00600576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PerfCenterCPL.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00509440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00441856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\powercpl.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00427520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PortableDeviceStatus.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00395264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\prnfldr.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00346112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nshipsec.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00324608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00297472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00295424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00283136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdv.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00236544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00218112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\OnLineIDCpl.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00190976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qcap.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00183296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PortableDeviceSyncProvider.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00175616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netplwiz.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00174592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ocsetapi.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00171520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\QAGENT.DLL
2013-07-06 14:49 - 2010-11-20 14:20 - 00165376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\provsvc.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netjoin.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00136192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mydocs.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00121344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00120320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\prntvpt.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netid.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00099328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\QSVRMGMT.DLL
2013-07-06 14:49 - 2010-11-20 14:20 - 00090112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nci.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00077824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\olethk32.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\QCLIPROV.DLL
2013-07-06 14:49 - 2010-11-20 14:20 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntlanman.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00068096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\napdsnap.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00060928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncryptui.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00052224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00046592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00040960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00022528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netutils.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00017408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\perfts.dll
2013-07-06 14:49 - 2010-11-20 14:20 - 00008192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00856576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\FirewallControlPanel.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00828928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fontext.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00592384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00504320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00481792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00429056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\localsec.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00400896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ipsmsnap.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00337408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00320512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mtxclu.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00320512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00312832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\hgcpl.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00301568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00271360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mprddm.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00266752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MediaMetadataHandler.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00265216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00226304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAC3ENC.DLL
2013-07-06 14:49 - 2010-11-20 14:19 - 00219648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iTVData.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00216576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-07-06 14:49 - 2010-11-20 14:19 - 00209920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstask.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00202752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\framedyn.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00202240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00176128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00176128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00172032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iasrad.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00167936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msutb.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mprapi.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00148992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ifsutil.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00127488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\logoncli.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00122880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iasrecst.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00120320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvfw32.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\migisol.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fphc.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00093696 ____A (Windows (R) Codename Longhorn DDK provider) C:\Windows\SysWOW64\fms.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00084480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mciavi32.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00082944 ____A (Radius Inc.) C:\Windows\SysWOW64\iccvid.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iasacct.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00059904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fdeploy.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00052736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetmib1.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00050176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iyuv_32.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00042496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mimefilt.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\luainstall.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00036352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mciqtz32.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00034816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\httpapi.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvidc32.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00030720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msdmo.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00028672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iscsium.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00022528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msyuv.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00021504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\lsmproxy.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\muifontsetup.dll
2013-07-06 14:49 - 2010-11-20 14:19 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrle32.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 03727872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\accessibilitycpl.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 01400320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DxpTaskSync.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 01040384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 01003520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00744448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ActionCenter.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00743424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00740864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\batmeter.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00685056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dsuiext.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00665600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AuxiliaryDisplayCpl.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00537600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ActionCenterCPL.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00484864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DeviceCenter.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00402944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00333824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dot3ui.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00314368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\azroleui.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00309760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00243712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\audiodev.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00242176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00230912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00222208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00220672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\defaultlocationcpl.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00211456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairingFolder.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00210432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxdiagn.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00205312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\efscore.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00202752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\activeds.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00196608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dskquoui.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00195584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\adsldp.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00146944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\autoplay.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00132608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cabview.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00128512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\EhStorAPI.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00115200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dot3msm.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnscmmc.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00094208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00091648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\avifil32.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dot3cfg.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cabinet.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00070656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\amstream.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00066560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cca.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\CertPolEng.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00045568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\acppage.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00034816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cscapi.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00030208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dsauth.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00028160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AzSqlExt.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cscdll.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00022528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elsTrans.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00019456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\bitsperf.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00017408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2013-07-06 14:49 - 2010-11-20 14:18 - 00011264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\C_ISCII.DLL
2013-07-06 14:49 - 2010-11-20 14:18 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browseui.dll
2013-07-06 14:49 - 2010-11-20 14:17 - 00586752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dfrgui.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00327680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wimserv.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00314880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00314368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SndVol.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00303104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00288256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\eudcedit.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00280064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00278016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00276480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\diskraid.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00270336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sethc.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00227328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskmgr.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00197632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ocsetup.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00179712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00157184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\perfmon.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00144896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iscsicli.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\diskpart.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00113152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setupugc.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00101376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mobsync.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00098816 ____A (Microsoft) C:\Windows\SysWOW64\Robocopy.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nslookup.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00095232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\logagent.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\isoburn.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00084992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cmstp.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00082944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00070656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MuiUnattend.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\w32tm.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00062976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\findstr.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00051200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\takeown.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00050688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\runonce.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00047616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzutil.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00042496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftp.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00037888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00034304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\unlodctr.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00028672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00026624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\userinit.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netiougc.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00024064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2013-07-06 14:49 - 2010-11-20 14:17 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ReAgentc.exe
2013-07-06 14:49 - 2010-11-20 14:16 - 00905216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mmsys.cpl
2013-07-06 14:49 - 2010-11-20 14:16 - 00878592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Bubbles.scr
2013-07-06 14:49 - 2010-11-20 14:16 - 00692736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl
2013-07-06 14:49 - 2010-11-20 14:16 - 00679424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2013-07-06 14:49 - 2010-11-20 14:16 - 00649216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl
2013-07-06 14:49 - 2010-11-20 14:16 - 00516096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\main.cpl
2013-07-06 14:49 - 2010-11-20 14:16 - 00413696 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PhotoScreensaver.scr
2013-07-06 14:49 - 2010-11-20 14:16 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2013-07-06 14:49 - 2010-11-20 14:16 - 00345088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-07-06 14:49 - 2010-11-20 14:16 - 00326656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sysdm.cpl
2013-07-06 14:49 - 2010-11-20 14:16 - 00293888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ssText3d.scr
2013-07-06 14:49 - 2010-11-20 14:16 - 00281088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\unimdm.tsp
2013-07-06 14:49 - 2010-11-20 14:16 - 00221184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Mystify.scr
2013-07-06 14:49 - 2010-11-20 14:16 - 00220672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Ribbons.scr
2013-07-06 14:49 - 2010-11-20 14:16 - 00193536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2013-07-06 14:49 - 2010-11-20 14:16 - 00186368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\bitsadmin.exe
2013-07-06 14:49 - 2010-11-20 14:16 - 00172032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wdmaud.drv
2013-07-06 14:49 - 2010-11-20 14:16 - 00153600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\VBICodec.ax
2013-07-06 14:49 - 2010-11-20 14:16 - 00142336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\powercfg.cpl
2013-07-06 14:49 - 2010-11-20 14:16 - 00128000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\desk.cpl
2013-07-06 14:49 - 2010-11-20 14:16 - 00107008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Kswdmcap.ax
2013-07-06 14:49 - 2010-11-20 14:16 - 00084480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kstvtune.ax
2013-07-06 14:49 - 2010-11-20 14:16 - 00068608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WSTPager.ax
2013-07-06 14:49 - 2010-11-20 14:16 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ksxbar.ax
2013-07-06 14:49 - 2010-11-20 14:16 - 00045568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\g711codc.ax
2013-07-06 14:49 - 2010-11-20 14:16 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbisurf.ax
2013-07-06 14:49 - 2010-11-20 14:08 - 12625408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-07-06 14:49 - 2010-11-20 14:08 - 00663040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-07-06 14:49 - 2010-11-20 14:08 - 00119808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imm32.dll
2013-07-06 14:49 - 2010-11-20 14:08 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDTUQ.DLL
2013-07-06 14:49 - 2010-11-20 14:08 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDTUF.DLL
2013-07-06 14:49 - 2010-11-20 14:08 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDSG.DLL
2013-07-06 14:49 - 2010-11-20 14:08 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kbdlk41a.dll
2013-07-06 14:49 - 2010-11-20 14:08 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDGR1.DLL
2013-07-06 14:49 - 2010-11-20 14:08 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDGKL.DLL
2013-07-06 14:49 - 2010-11-20 14:07 - 01164800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2013-07-06 14:49 - 2010-11-20 14:00 - 01027584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2013-07-06 14:49 - 2010-11-20 14:00 - 00430080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2013-07-06 14:49 - 2010-11-20 13:37 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbrpm.sys
2013-07-06 14:49 - 2010-11-20 13:04 - 00039424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys
2013-07-06 14:49 - 2010-11-20 12:52 - 00131584 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pacer.sys
2013-07-06 14:49 - 2010-11-20 12:52 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-07-06 14:49 - 2010-11-20 12:52 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-07-06 14:49 - 2010-11-20 12:51 - 00125440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tunnel.sys
2013-07-06 14:49 - 2010-11-20 12:51 - 00045056 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2013-07-06 14:49 - 2010-11-20 12:50 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndisuio.sys
2013-07-06 14:49 - 2010-11-20 12:49 - 00146432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rmcast.sys
2013-07-06 14:49 - 2010-11-20 12:44 - 00350208 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\HdAudio.sys
2013-07-06 14:49 - 2010-11-20 12:44 - 00184960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbvideo.sys
2013-07-06 14:49 - 2010-11-20 12:44 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\umbus.sys
2013-07-06 14:49 - 2010-11-20 12:44 - 00032896 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\USBCAMD2.sys
2013-07-06 14:49 - 2010-11-20 12:43 - 00122368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hdaudbus.sys
2013-07-06 14:49 - 2010-11-20 12:43 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-07-06 14:49 - 2010-11-20 12:43 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\winusb.sys
2013-07-06 14:49 - 2010-11-20 12:43 - 00030208 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-07-06 14:49 - 2010-11-20 12:34 - 00014336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\sffp_sd.sys
2013-07-06 14:49 - 2010-11-20 12:33 - 00038912 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\CompositeBus.sys
2013-07-06 14:49 - 2010-11-20 12:33 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\kbdhid.sys
2013-07-06 14:49 - 2010-11-20 12:14 - 00061440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\appid.sys
2013-07-06 14:49 - 2010-11-20 12:09 - 00029696 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\scfilter.sys
2013-07-06 14:49 - 2010-11-20 12:04 - 00078848 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\IPMIDrv.sys
2013-07-06 14:49 - 2010-11-20 11:49 - 00258048 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-07-06 14:49 - 2010-11-20 11:30 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\acpipmi.sys
2013-07-06 14:49 - 2010-11-20 11:26 - 00102400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dfsc.sys
2013-07-06 14:49 - 2010-11-20 11:22 - 00026624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdi.sys
2013-07-06 14:49 - 2010-11-20 11:19 - 00147456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cdrom.sys
2013-07-06 14:49 - 2010-11-10 03:48 - 00010429 ____A C:\Windows\System32\ScavengeSpace.xml
2013-07-06 14:49 - 2010-11-05 04:11 - 00433512 ____A (Microsoft Corporation) C:\Windows\System32\MCEWMDRMNDBootstrap.dll
2013-07-06 14:49 - 2010-11-05 04:11 - 00312168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MCEWMDRMNDBootstrap.dll
2013-07-06 14:49 - 2010-11-05 03:58 - 00155472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2013-07-06 14:49 - 2010-11-05 03:58 - 00080720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2013-07-06 14:49 - 2010-11-05 03:57 - 00154960 ____A (Microsoft Corporation) C:\Windows\System32\mscorier.dll
2013-07-06 14:48 - 2010-11-20 15:16 - 12625920 ____A (Microsoft Corporation) C:\Windows\System32\wmploc.DLL
2013-07-06 14:48 - 2010-11-20 15:14 - 00007680 ____A (Microsoft Corporation) C:\Windows\System32\spwizres.dll
2013-07-06 14:48 - 2010-11-20 15:13 - 00069120 ____A (Microsoft Corporation) C:\Windows\System32\nlsbres.dll
2013-07-06 14:48 - 2010-11-20 15:12 - 00035328 ____A (Microsoft Corporation) C:\Windows\System32\pifmgr.dll
2013-07-06 14:48 - 2010-11-20 15:02 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\KBDCZ1.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDUS.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDUGHR1.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDTURME.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDTAJIK.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDMON.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDMAORI.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDLT1.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDINTEL.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDINORI.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDINMAR.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDINKAN.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDINHIN.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDBULG.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDBLR.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDBASH.DLL
2013-07-06 14:48 - 2010-11-20 15:02 - 00006656 ____A (Microsoft Corporation) C:\Windows\System32\KBDGEO.DLL
2013-07-06 14:48 - 2010-11-20 14:54 - 00052736 ____A (Microsoft Corporation) C:\Windows\System32\BlbEvents.dll
2013-07-06 14:48 - 2010-11-20 14:21 - 00363008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wbemcomn.dll
2013-07-06 14:48 - 2010-11-20 14:21 - 00189952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wdscore.dll
2013-07-06 14:48 - 2010-11-20 14:21 - 00189952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sqmapi.dll
2013-07-06 14:48 - 2010-11-20 14:18 - 00323072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\drvstore.dll
2013-07-06 14:48 - 2010-11-20 14:18 - 00257024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dpx.dll
2013-07-06 14:48 - 2010-11-20 14:17 - 00209920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PkgMgr.exe
2013-07-06 14:48 - 2010-11-20 14:08 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDCZ1.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDSF.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDPO.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDNEPR.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTAM.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDINORI.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDINMAR.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDINKAN.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDINHIN.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBEN.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDUS.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDUGHR1.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDTURME.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAJIK.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDMON.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDMAORI.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDLT1.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTEL.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDGEO.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDBULG.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDBLR.DLL
2013-07-06 14:48 - 2010-11-20 14:08 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2013-07-06 14:48 - 2010-11-20 14:07 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\spwizres.dll
2013-07-06 14:48 - 2010-11-20 14:06 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2013-07-06 14:48 - 2010-11-20 14:05 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pifmgr.dll
2013-07-06 14:48 - 2010-11-05 04:20 - 00105559 ____A C:\Windows\SysWOW64\RacRules.xml
2013-07-06 14:48 - 2010-11-05 04:20 - 00105559 ____A C:\Windows\System32\RacRules.xml
2013-07-06 14:48 - 2009-06-10 23:39 - 00001041 ____A C:\Windows\SysWOW64\tcpbidi.xml
2013-07-06 14:46 - 2010-11-20 15:27 - 00933376 ____A (Microsoft Corporation) C:\Windows\System32\SmiEngine.dll
2013-07-06 14:46 - 2010-11-20 15:27 - 00529408 ____A (Microsoft Corporation) C:\Windows\System32\wbemcomn.dll
2013-07-06 14:46 - 2010-11-20 15:27 - 00524288 ____A (Microsoft Corporation) C:\Windows\System32\wmicmiplugin.dll
2013-07-06 14:46 - 2010-11-20 15:27 - 00244736 ____A (Microsoft Corporation) C:\Windows\System32\sqmapi.dll
2013-07-06 14:45 - 2010-11-20 15:26 - 00422912 ____A (Microsoft Corporation) C:\Windows\System32\drvstore.dll
2013-07-06 14:45 - 2010-11-20 15:26 - 00399872 ____A (Microsoft Corporation) C:\Windows\System32\dpx.dll
2013-07-06 14:45 - 2010-11-20 15:25 - 00199168 ____A (Microsoft Corporation) C:\Windows\System32\PkgMgr.exe
2013-07-06 14:29 - 2013-03-01 05:36 - 03153408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-07-06 14:29 - 2013-02-15 08:08 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2013-07-06 14:29 - 2013-02-15 08:06 - 03717632 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-07-06 14:29 - 2013-02-15 08:02 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll
2013-07-06 14:29 - 2013-02-15 06:37 - 03217408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-07-06 14:29 - 2013-02-15 06:34 - 00131584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-07-06 14:29 - 2013-02-15 05:25 - 00036864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-07-06 14:29 - 2012-11-09 07:45 - 00750592 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-07-06 14:29 - 2012-11-09 07:45 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-07-06 14:29 - 2012-11-09 06:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-07-06 14:29 - 2012-11-09 06:42 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-07-06 14:28 - 2013-04-12 16:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-07-06 14:28 - 2013-02-12 06:12 - 00019968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023x.sys
2013-07-06 14:28 - 2013-02-12 06:12 - 00019968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys
2013-07-06 14:28 - 2012-11-01 07:43 - 02002432 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2013-07-06 14:28 - 2012-11-01 07:43 - 01882624 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2013-07-06 14:28 - 2012-11-01 06:47 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2013-07-06 14:28 - 2012-11-01 06:47 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2013-07-06 14:28 - 2012-08-02 19:58 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2013-07-06 14:28 - 2012-08-02 18:57 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-07-06 14:28 - 2012-07-04 22:26 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rndismpx.sys
2013-07-06 14:27 - 2013-01-04 07:46 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-07-06 14:27 - 2013-01-04 06:51 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-07-06 14:27 - 2013-01-04 04:47 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-07-06 14:27 - 2013-01-04 04:47 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-07-06 14:27 - 2013-01-04 04:47 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-07-06 14:27 - 2013-01-04 04:47 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-07-06 14:27 - 2013-01-03 08:00 - 01913192 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-07-06 14:27 - 2013-01-03 08:00 - 00288088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2013-07-06 14:27 - 2012-12-07 15:20 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\Wpc.dll
2013-07-06 14:27 - 2012-12-07 15:15 - 02746368 ____A (Microsoft Corporation) C:\Windows\System32\gameux.dll
2013-07-06 14:27 - 2012-12-07 14:26 - 00308736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2013-07-06 14:27 - 2012-12-07 14:20 - 02576384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2013-07-06 14:27 - 2012-12-07 13:20 - 00045568 ____A (Microsoft) C:\Windows\System32\oflc-nz.rs
2013-07-06 14:27 - 2012-12-07 13:20 - 00044544 ____A (Microsoft) C:\Windows\System32\pegibbfc.rs
2013-07-06 14:27 - 2012-12-07 13:20 - 00043520 ____A (Microsoft) C:\Windows\System32\csrr.rs
2013-07-06 14:27 - 2012-12-07 13:20 - 00030720 ____A (Microsoft) C:\Windows\System32\usk.rs
2013-07-06 14:27 - 2012-12-07 13:20 - 00023552 ____A (Microsoft) C:\Windows\System32\oflc.rs
2013-07-06 14:27 - 2012-12-07 13:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-pt.rs
2013-07-06 14:27 - 2012-12-07 13:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-fi.rs
2013-07-06 14:27 - 2012-12-07 13:19 - 00055296 ____A (Microsoft) C:\Windows\System32\cero.rs
2013-07-06 14:27 - 2012-12-07 13:19 - 00051712 ____A (Microsoft) C:\Windows\System32\esrb.rs
2013-07-06 14:27 - 2012-12-07 13:19 - 00046592 ____A (Microsoft) C:\Windows\System32\fpb.rs
2013-07-06 14:27 - 2012-12-07 13:19 - 00040960 ____A (Microsoft) C:\Windows\System32\cob-au.rs
2013-07-06 14:27 - 2012-12-07 13:19 - 00021504 ____A (Microsoft) C:\Windows\System32\grb.rs
2013-07-06 14:27 - 2012-12-07 13:19 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi.rs
2013-07-06 14:27 - 2012-12-07 13:19 - 00015360 ____A (Microsoft) C:\Windows\System32\djctq.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00055296 ____A (Microsoft) C:\Windows\SysWOW64\cero.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00051712 ____A (Microsoft) C:\Windows\SysWOW64\esrb.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00046592 ____A (Microsoft) C:\Windows\SysWOW64\fpb.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00045568 ____A (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00044544 ____A (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00043520 ____A (Microsoft) C:\Windows\SysWOW64\csrr.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00040960 ____A (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00030720 ____A (Microsoft) C:\Windows\SysWOW64\usk.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00023552 ____A (Microsoft) C:\Windows\SysWOW64\oflc.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00021504 ____A (Microsoft) C:\Windows\SysWOW64\grb.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi.rs
2013-07-06 14:27 - 2012-12-07 12:46 - 00015360 ____A (Microsoft) C:\Windows\SysWOW64\djctq.rs
2013-07-06 14:27 - 2012-11-22 07:44 - 00800768 ____A (Microsoft Corporation) C:\Windows\System32\usp10.dll
2013-07-06 14:27 - 2012-11-22 06:45 - 00626688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2013-07-06 14:27 - 2012-11-20 07:48 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2013-07-06 14:27 - 2012-11-20 06:51 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-07-06 14:27 - 2012-11-02 07:59 - 00478208 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
2013-07-06 14:27 - 2012-11-02 07:11 - 00376832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2013-07-06 14:27 - 2012-08-24 20:05 - 00220160 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2013-07-06 14:27 - 2012-08-24 18:57 - 00172544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-07-06 14:27 - 2012-08-22 20:12 - 00376688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2013-07-06 14:27 - 2010-11-20 14:58 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\dpnaddr.dll
2013-07-06 14:27 - 2010-11-20 13:57 - 00002560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dpnaddr.dll
2013-07-06 14:26 - 2012-11-30 07:45 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2013-07-06 14:26 - 2012-11-30 07:45 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll
2013-07-06 14:26 - 2012-11-30 07:45 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2013-07-06 14:26 - 2012-11-30 07:43 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2013-07-06 14:26 - 2012-11-30 07:41 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-07-06 14:26 - 2012-11-30 07:41 - 00424448 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 07:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:53 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-07-06 14:26 - 2012-11-30 06:53 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 06:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 05:23 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-07-06 14:26 - 2012-11-30 04:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 04:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 04:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 04:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-07-06 14:26 - 2012-11-30 01:17 - 00420064 ____A C:\Windows\SysWOW64\locale.nls
2013-07-06 14:26 - 2012-11-30 01:15 - 00420064 ____A C:\Windows\System32\locale.nls
2013-07-06 14:26 - 2012-08-11 02:56 - 00715776 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-07-06 14:26 - 2012-08-11 01:56 - 00542208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-07-06 14:25 - 2013-03-19 08:04 - 05550424 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-07-06 14:25 - 2013-03-19 07:46 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2013-07-06 14:25 - 2013-03-19 07:04 - 03968856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-07-06 14:25 - 2013-03-19 07:04 - 03913560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-07-06 14:25 - 2013-03-19 06:47 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-07-06 14:25 - 2013-03-19 05:06 - 00112640 ____A (Microsoft Corporation) C:\Windows\System32\smss.exe
2013-07-06 14:25 - 2013-01-24 08:01 - 00223752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys
2013-07-06 14:25 - 2012-09-26 00:47 - 00078336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2013-07-06 14:25 - 2012-09-26 00:46 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\synceng.dll
2013-07-06 14:25 - 2012-07-05 00:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2013-07-06 14:25 - 2012-07-05 00:13 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2013-07-06 14:25 - 2012-07-05 00:13 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2013-07-06 14:25 - 2012-07-04 23:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2013-07-06 14:25 - 2012-07-04 23:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2013-07-06 14:25 - 2012-05-14 07:26 - 00956928 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2013-07-06 14:25 - 2012-05-05 10:36 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2013-07-06 14:25 - 2012-05-05 09:46 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2013-07-06 14:25 - 2012-02-11 08:36 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2013-07-06 14:25 - 2012-02-11 08:36 - 00067072 ____A (Microsoft Corporation) C:\Windows\splwow64.exe
2013-07-06 14:25 - 2010-11-20 15:25 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2013-07-06 14:24 - 2012-06-02 07:41 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-07-06 14:24 - 2012-06-02 07:41 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-07-06 14:24 - 2012-06-02 07:41 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-07-06 14:24 - 2012-06-02 06:36 - 01159680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-07-06 14:24 - 2012-06-02 06:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-07-06 14:24 - 2012-06-02 06:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-07-06 11:57 - 2013-07-06 11:57 - 00000207 ____A C:\Windows\tweaking.com-regbackup-CARINA-NOTEBOOK-Microsoft-Windows-7-Home-Premium-(64-Bit).dat
2013-07-06 11:55 - 2013-07-06 11:55 - 00000000 ____D C:\RegBackup
2013-07-06 10:37 - 2013-07-06 13:55 - 00181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-07-06 10:24 - 2013-07-06 10:24 - 00000000 __SHD C:\found.000
2013-07-06 09:14 - 2013-07-06 09:14 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Malwarebytes
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-06 09:14 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-07-05 08:54 - 2013-07-05 08:54 - 00005636 ____A C:\Users\Carina\Desktop\FSS.txt
2013-07-05 08:53 - 2013-07-05 08:02 - 00356397 ____A (Farbar) C:\Users\Carina\Desktop\FSS.exe
2013-07-05 08:12 - 2013-07-06 09:13 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-07-05 08:12 - 2013-07-05 08:02 - 00448512 ____A (OldTimer Tools) C:\Users\Carina\Desktop\TFC.exe
2013-07-04 20:20 - 2013-07-04 15:31 - 00890988 ____A C:\Users\Carina\Desktop\SecurityCheck.exe
2013-07-04 17:12 - 2013-07-04 17:12 - 00016977 ____A C:\Users\Carina\Desktop\Addition.txt
2013-07-04 17:10 - 2013-07-04 17:10 - 00000755 ____A C:\Users\Carina\Desktop\JRT.txt
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\Windows\ERUNT
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\JRT
2013-07-04 16:59 - 2013-07-04 17:00 - 00013739 ____A C:\AdwCleaner[S1].txt
2013-07-04 13:56 - 2013-07-04 13:56 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Carina\Desktop\JRT.exe
2013-07-04 13:54 - 2013-07-04 13:54 - 00650027 ____A C:\Users\Carina\Desktop\adwcleaner.exe
2013-07-04 11:29 - 2013-07-06 20:29 - 00000000 ____D C:\FRST
2013-07-04 08:40 - 2013-07-04 08:32 - 01934636 ____A (Farbar) C:\Users\Carina\Desktop\FRST64.exe
2013-07-02 00:44 - 2013-07-02 00:44 - 00002317 ____A C:\Users\Carina\Desktop\clamav_report_010713_224342.txt
2013-06-29 13:20 - 2013-06-29 13:20 - 00000000 ____D C:\Windows\pss
2013-06-12 00:14 - 2013-06-12 00:14 - 00121271 ____A C:\Users\Carina\Desktop\HC3A11~12
2013-06-12 00:13 - 2013-06-12 00:13 - 00456935 ____A C:\Users\Carina\Desktop\1
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (4)
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Hochzeitshooting Ideen und Motive
2013-06-10 18:50 - 2013-06-11 22:22 - 00000000 ____D C:\Users\Carina\Desktop\J und D bearbeitet
2013-06-10 16:54 - 2013-06-11 16:36 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (3)
2013-06-09 20:28 - 2013-06-09 20:28 - 00009495 ____A C:\Users\Carina\Desktop\Mappe1.xlsx
2013-06-08 17:59 - 2013-06-11 15:10 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (2)
2013-06-08 17:27 - 2013-06-08 18:33 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner
2013-06-08 11:24 - 2013-06-10 19:03 - 00000000 ____D C:\Users\Carina\Desktop\Jenny und Dami 7.6.13

==================== One Month Modified Files and Folders =======

2013-07-07 11:37 - 2010-10-08 22:06 - 00659238 ____A C:\Windows\System32\perfh007.dat
2013-07-07 11:37 - 2010-10-08 22:06 - 00132776 ____A C:\Windows\System32\perfc007.dat
2013-07-07 11:37 - 2009-07-14 07:13 - 01512418 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-07 11:36 - 2009-07-14 06:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-07 11:36 - 2009-07-14 06:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-07 11:34 - 2010-10-08 12:16 - 01763442 ____A C:\Windows\WindowsUpdate.log
2013-07-07 11:31 - 2011-11-09 20:08 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-07 11:30 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-07 11:30 - 2009-07-14 06:51 - 00157516 ____A C:\Windows\setupact.log
2013-07-07 11:30 - 2009-07-14 06:45 - 00476960 ____A C:\Windows\System32\FNTCACHE.DAT
2013-07-07 11:15 - 2012-04-05 16:28 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-07 11:11 - 2011-11-09 20:08 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-06 22:52 - 2012-11-14 20:47 - 00000932 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000UA.job
2013-07-06 22:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-07-06 20:29 - 2013-07-04 11:29 - 00000000 ____D C:\FRST
2013-07-06 19:52 - 2012-11-14 20:47 - 00000910 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4174051618-920821422-2312507155-1000Core.job
2013-07-06 18:57 - 2011-01-13 16:53 - 00133496 ____A C:\Users\Carina\AppData\Local\GDIPFONTCACHEV1.DAT
2013-07-06 18:54 - 2011-01-13 17:12 - 00036752 ____A C:\Windows\PFRO.log
2013-07-06 18:46 - 2010-09-16 02:19 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-06 18:46 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-07-06 18:46 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Portable Devices
2013-07-06 18:46 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-07-06 18:46 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-06 18:46 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker
2013-07-06 18:46 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2013-07-06 18:46 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2013-07-06 18:46 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sppui
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\oobe
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\manifeststore
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\sppui
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\Setup
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\oobe
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\manifeststore
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\AdvancedInstallers
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2013-07-06 18:46 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\System
2013-07-06 18:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\migwiz
2013-07-06 18:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\Dism
2013-07-06 18:41 - 2009-07-14 04:36 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2013-07-06 18:41 - 2009-07-14 04:36 - 00152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2013-07-06 18:31 - 2009-07-14 07:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-06 16:20 - 2013-07-06 16:20 - 00000000 ____D C:\Windows\System32\SPReview
2013-07-06 16:19 - 2013-07-06 16:19 - 00000000 ____D C:\Windows\System32\EventProviders
2013-07-06 13:55 - 2013-07-06 10:37 - 00181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-07-06 13:48 - 2009-07-14 04:34 - 00000514 ____A C:\Windows\win.ini
2013-07-06 13:46 - 2013-04-28 13:12 - 00000000 ____D C:\Users\Carina\AppData\Local\CrashDumps
2013-07-06 11:57 - 2013-07-06 11:57 - 00000207 ____A C:\Windows\tweaking.com-regbackup-CARINA-NOTEBOOK-Microsoft-Windows-7-Home-Premium-(64-Bit).dat
2013-07-06 11:55 - 2013-07-06 11:55 - 00000000 ____D C:\RegBackup
2013-07-06 10:24 - 2013-07-06 10:24 - 00000000 __SHD C:\found.000
2013-07-06 09:14 - 2013-07-06 09:14 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Malwarebytes
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-06 09:14 - 2013-07-06 09:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-06 09:13 - 2013-07-05 08:12 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-07-06 09:13 - 2011-01-13 19:04 - 00000000 ____D C:\ProgramData\Sonic
2013-07-05 08:54 - 2013-07-05 08:54 - 00005636 ____A C:\Users\Carina\Desktop\FSS.txt
2013-07-05 08:02 - 2013-07-05 08:53 - 00356397 ____A (Farbar) C:\Users\Carina\Desktop\FSS.exe
2013-07-05 08:02 - 2013-07-05 08:12 - 00448512 ____A (OldTimer Tools) C:\Users\Carina\Desktop\TFC.exe
2013-07-04 20:25 - 2011-11-09 16:14 - 00000000 ____D C:\Users\Carina\AppData\Local\Google
2013-07-04 20:07 - 2012-08-24 13:22 - 00002187 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-04 17:15 - 2012-04-05 16:28 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-04 17:15 - 2011-06-15 12:54 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-04 17:12 - 2013-07-04 17:12 - 00016977 ____A C:\Users\Carina\Desktop\Addition.txt
2013-07-04 17:10 - 2013-07-04 17:10 - 00000755 ____A C:\Users\Carina\Desktop\JRT.txt
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\Windows\ERUNT
2013-07-04 17:06 - 2013-07-04 17:06 - 00000000 ____D C:\JRT
2013-07-04 17:00 - 2013-07-04 16:59 - 00013739 ____A C:\AdwCleaner[S1].txt
2013-07-04 15:31 - 2013-07-04 20:20 - 00890988 ____A C:\Users\Carina\Desktop\SecurityCheck.exe
2013-07-04 13:56 - 2013-07-04 13:56 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Carina\Desktop\JRT.exe
2013-07-04 13:54 - 2013-07-04 13:54 - 00650027 ____A C:\Users\Carina\Desktop\adwcleaner.exe
2013-07-04 08:32 - 2013-07-04 08:40 - 01934636 ____A (Farbar) C:\Users\Carina\Desktop\FRST64.exe
2013-07-02 00:44 - 2013-07-02 00:44 - 00002317 ____A C:\Users\Carina\Desktop\clamav_report_010713_224342.txt
2013-06-29 13:20 - 2013-06-29 13:20 - 00000000 ____D C:\Windows\pss
2013-06-12 02:10 - 2013-05-19 19:34 - 00000000 ____D C:\Users\Carina\AppData\Roaming\player
2013-06-12 02:10 - 2013-05-13 18:12 - 00000000 ____D C:\Users\Carina\Desktop\Neu neu
2013-06-12 02:10 - 2013-04-28 13:10 - 00000000 ____D C:\ProgramData\Protexis
2013-06-12 02:10 - 2011-12-05 11:13 - 00000000 ____D C:\Windows\System32\Macromed
2013-06-12 02:10 - 2011-01-20 17:05 - 00000000 ____D C:\Users\Carina\Desktop\Mobile Partner
2013-06-12 02:10 - 2011-01-13 16:52 - 00000000 ____D C:\users\Carina
2013-06-12 02:10 - 2010-09-16 01:32 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-06-12 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-12 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-06-12 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-06-12 01:02 - 2013-04-08 11:18 - 00000000 ____D C:\ProgramData\dvjl
2013-06-12 00:14 - 2013-06-12 00:14 - 00121271 ____A C:\Users\Carina\Desktop\HC3A11~12
2013-06-12 00:13 - 2013-06-12 00:13 - 00456935 ____A C:\Users\Carina\Desktop\1
2013-06-11 22:22 - 2013-06-10 18:50 - 00000000 ____D C:\Users\Carina\Desktop\J und D bearbeitet
2013-06-11 16:36 - 2013-06-10 16:54 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (3)
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (4)
2013-06-11 15:34 - 2013-06-11 15:34 - 00000000 ____D C:\Users\Carina\Desktop\Hochzeitshooting Ideen und Motive
2013-06-11 15:10 - 2013-06-08 17:59 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner (2)
2013-06-10 19:03 - 2013-06-08 11:24 - 00000000 ____D C:\Users\Carina\Desktop\Jenny und Dami 7.6.13
2013-06-09 20:28 - 2013-06-09 20:28 - 00009495 ____A C:\Users\Carina\Desktop\Mappe1.xlsx
2013-06-08 18:33 - 2013-06-08 17:27 - 00000000 ____D C:\Users\Carina\Desktop\Neuer Ordner

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-06 09:49


schrauber 07.07.2013 11:20

Noch Probleme? :)

AdITa 07.07.2013 11:27

Sieht alles ganz gut aus. Ist alles sauber?

Sind wir dann durch?

schrauber 07.07.2013 11:30

Ja :)

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

AdITa 07.07.2013 13:53

Alles erledigt.
Ich danke dir sehr für deine Hilfe!! :dankeschoen:

:daumenhoc :applaus:

Gruß
AdITa

schrauber 07.07.2013 14:14

Gern geschehen :)


Alle Zeitangaben in WEZ +1. Es ist jetzt 01:49 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131