Sabine74 | 02.09.2013 20:57 | Windows 7: Häufige Pop-Up Fenster und Virus-Fund: PUP.Optional.OfferMosquito.A Hallo liebes Forum,
seit gestern habe ich dauernd beim Öffnen von Web-Seiten Werbe-Pop-Up-Fenster, die sich durch klicken auf das x-Symbol schließen lassen. Mein McAffee hat keine Meldung gebracht. Malware-Bytes hat jedoch folgende Funde gemacht. Danach habe ich nach Eurer Anleitung diverse Programme heruntergeladen und die Log-Dateien gespeichert - hoffentlich habe ich es richtig gemacht.
Anbei meine Log-Dateien. Ich hoffe Ihr könnt mir helfen! Danke schon einmal!
1) Logfile Malware-Bytes: Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.02.06
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16635
Thomas :: PC-WOHNZIMMER [Administrator]
Schutz: Aktiviert
02.09.2013 19:30:42
MBAM-log-2013-09-02 (21-02-05).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 511838
Laufzeit: 1 Stunde(n), 31 Minute(n),
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|OMESupervisor (PUP.Optional.OfferMosquito.A) -> Daten: C:\Users\Thomas\AppData\Local\omesuperv.exe -> Keine Aktion durchgeführt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 2
C:\Users\Thomas\AppData\Local\omesuperv.exe (PUP.Optional.OfferMosquito.A) -> Keine Aktion durchgeführt.
C:\Users\Thomas\Downloads\SoftonicDownloader_fuer_foxit-pdf-reader.exe (PUP.Optional.Softonic) -> Keine Aktion durchgeführt.
(Ende)
2) Defogger hat keine besondere Meldung gebracht. Kann es sein, dass da kein Log-File gespeichert wurde?
3) FRST.txt Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-09-2013 05
Ran by Thomas (administrator) on PC-WOHNZIMMER on 02-09-2013 21:15:58
Running from C:\Users\Thomas\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(McAfee, Inc.) C:\Windows\system32\mfevtps.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Adobe Systems Incorporated) c:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe
() C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(McAfee, Inc.) c:\PROGRA~1\mcafee.com\agent\mcagent.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [692208 2012-12-21] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-09-06] (IDT, Inc.)
HKLM\...\Run: [QuickSet] - c:\Program Files\Dell\QuickSet\QuickSet.exe [4391072 2012-11-09] (Dell Inc.)
HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4123 2012-05-30] ()
HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [11577216 2012-08-27] (Motorola Solutions, Inc.)
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1
HKCU\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-04-05] (Apple Inc.)
HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-04-05] (Apple Inc.)
HKCU\...\Run: [com.apple.dav.bookmarks.daemon] - C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe [59720 2013-04-05] (Apple Inc.)
HKCU\...\Run: [SSync] - C:\Users\Thomas\AppData\Roaming\SSync\SSync.exe [36864 2013-04-10] ()
HKCU\...\Run: [DataMgr] - C:\Users\Thomas\AppData\Roaming\DataMgr\DataMgr.exe [168848 2013-06-26] (HTTO Group, Ltd.)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1561968 2013-05-23] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup [x]
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1106288 2013-05-23] (Samsung)
HKCU\...\Run: [SCheck] - C:\Users\Thomas\AppData\Roaming\SCheck\SCheck.exe [36864 2013-04-10] ()
HKCU\...\Run: [Snoozer] - C:\Users\Thomas\AppData\Roaming\Snz\Snz.exe [1137764 2013-08-28] ()
HKCU\...\Run: [Intermediate] - C:\Users\Thomas\AppData\Roaming\Intermediate\Intermediate.exe [36864 2013-04-10] ()
HKCU\...\Run: [OMESupervisor] - C:\Users\Thomas\AppData\Local\omesuperv.exe [2218359 2013-08-28] ()
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [102928 2012-10-23] (CyberLink Corp.)
HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [1532992 2013-03-13] (McAfee, Inc.)
HKLM-x32\...\Run: [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-05-23] (Samsung Electronics Co., Ltd.)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [266448 2013-06-21] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [214448 2013-06-21] (NVIDIA Corporation)
Startup: C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.6.lnk
ShortcutTarget: Überwachungstool für die Intel® Turbo-Boost-Technik 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.6.lnk
ShortcutTarget: Überwachungstool für die Intel® Turbo-Boost-Technik 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com
SearchScopes: HKLM - DefaultScope {CE8B75EB-17F6-4674-98BD-489442F37A2F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDCJS
SearchScopes: HKLM - {CE8B75EB-17F6-4674-98BD-489442F37A2F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDCJS
SearchScopes: HKLM-x32 - DefaultScope {CE8B75EB-17F6-4674-98BD-489442F37A2F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDCJS
SearchScopes: HKLM-x32 - {CE8B75EB-17F6-4674-98BD-489442F37A2F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDCJS
SearchScopes: HKCU - DefaultScope {CE8B75EB-17F6-4674-98BD-489442F37A2F} URL =
SearchScopes: HKCU - {CE8B75EB-17F6-4674-98BD-489442F37A2F} URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\4mp0hmty.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor10.0; c:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-14] (Adobe Systems Incorporated)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [138192 2011-02-07] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McAWFwk; c:\PROGRA~1\mcafee\msc\mcawfwk.exe [332080 2012-01-26] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [384048 2013-02-25] (McAfee, Inc.)
S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [241456 2013-02-19] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218760 2013-02-19] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-02-19] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] ()
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1900728 2013-06-09] (Microsoft Corporation)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-25] ()
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [1915480 2013-05-23] (SoftThinks SAS)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [121728 2012-08-27] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [857472 2012-08-29] (Motorola Solutions, Inc.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-02-19] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-25] (OSR Open Systems Resources, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179280 2013-02-19] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309840 2013-02-19] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69168 2013-02-19] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [515968 2013-02-19] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [771536 2013-02-19] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106552 2013-02-19] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340216 2013-02-19] (McAfee, Inc.)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4309032 2012-10-17] (Intel Corporation)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
U3 mfeavfk01; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-02 21:14 - 2013-09-02 21:15 - 01951954 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64.exe
2013-09-02 21:11 - 2013-09-02 21:12 - 00000474 _____ C:\Users\Thomas\Downloads\defogger_disable.log
2013-09-02 21:11 - 2013-09-02 21:11 - 00000000 _____ C:\Users\Thomas\defogger_reenable
2013-09-02 21:10 - 2013-09-02 21:10 - 00050477 _____ C:\Users\Thomas\Downloads\Defogger.exe
2013-09-02 19:28 - 2013-09-02 19:28 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-02 19:28 - 2013-09-02 19:28 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes
2013-09-02 19:28 - 2013-09-02 19:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-02 19:28 - 2013-09-02 19:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-02 19:28 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-02 19:27 - 2013-09-02 19:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-02 19:09 - 2013-09-02 19:12 - 00000000 ____D C:\Windows\system32\MRT
2013-09-01 12:40 - 2013-09-01 12:41 - 00000000 ____D C:\ProgramData\softthinks
2013-09-01 12:40 - 2013-05-24 03:37 - 00000094 ____H C:\DBAR_Ver.txt
2013-09-01 12:30 - 2013-09-01 12:30 - 00329552 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-01 12:30 - 2013-09-01 12:30 - 00003206 _____ C:\Windows\PFRO.log
2013-09-01 12:05 - 2013-09-01 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-01 11:18 - 2013-09-01 11:19 - 04454952 _____ (Piriform Ltd) C:\Users\Thomas\Downloads\ccsetup405(1).exe
2013-09-01 11:18 - 2013-09-01 11:18 - 04454952 _____ (Piriform Ltd) C:\Users\Thomas\Downloads\ccsetup405.exe
2013-09-01 09:27 - 2013-09-01 09:27 - 17737608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-09-01 09:27 - 2013-09-01 09:27 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Snz
2013-08-28 20:46 - 2013-08-28 20:46 - 02218359 _____ C:\Users\Thomas\AppData\Local\omesuperv.exe
==================== One Month Modified Files and Folders =======
2013-09-02 21:15 - 2013-09-02 21:15 - 00000000 ____D C:\FRST
2013-09-02 21:15 - 2013-09-02 21:14 - 01951954 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64.exe
2013-09-02 21:12 - 2013-09-02 21:11 - 00000474 _____ C:\Users\Thomas\Downloads\defogger_disable.log
2013-09-02 21:12 - 2013-04-03 04:14 - 01480569 _____ C:\Windows\WindowsUpdate.log
2013-09-02 21:11 - 2013-09-02 21:11 - 00000000 _____ C:\Users\Thomas\defogger_reenable
2013-09-02 21:11 - 2013-04-13 20:00 - 00000000 ____D C:\Users\Thomas
2013-09-02 21:10 - 2013-09-02 21:10 - 00050477 _____ C:\Users\Thomas\Downloads\Defogger.exe
2013-09-02 21:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2013-09-02 20:26 - 2013-04-13 22:30 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-02 19:28 - 2013-09-02 19:28 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-02 19:28 - 2013-09-02 19:28 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes
2013-09-02 19:28 - 2013-09-02 19:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-02 19:28 - 2013-09-02 19:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-02 19:27 - 2013-09-02 19:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-02 19:12 - 2013-09-02 19:09 - 00000000 ____D C:\Windows\system32\MRT
2013-09-02 19:09 - 2013-04-17 10:16 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-02 19:09 - 2013-04-13 20:08 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1023412029-2558512523-2891409035-1004
2013-09-02 06:53 - 2013-04-03 04:52 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
2013-09-02 06:50 - 2012-07-26 12:27 - 00754172 _____ C:\Windows\system32\perfh007.dat
2013-09-02 06:50 - 2012-07-26 12:27 - 00156362 _____ C:\Windows\system32\perfc007.dat
2013-09-02 06:50 - 2012-07-26 09:28 - 01748838 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-01 12:41 - 2013-09-01 12:40 - 00000000 ____D C:\ProgramData\softthinks
2013-09-01 12:40 - 2013-04-14 16:05 - 00000000 ____D C:\Users\Thomas\AppData\Local\softthinks
2013-09-01 12:37 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2013-09-01 12:32 - 2013-07-01 11:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-01 12:30 - 2013-09-01 12:30 - 00329552 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-01 12:30 - 2013-09-01 12:30 - 00003206 _____ C:\Windows\PFRO.log
2013-09-01 12:30 - 2013-04-03 04:50 - 00000000 ____D C:\Program Files (x86)\McAfee
2013-09-01 12:30 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-01 12:29 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-09-01 12:29 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2013-09-01 12:16 - 2013-05-22 13:10 - 00000000 ____D C:\Program Files\My Dell
2013-09-01 12:16 - 2013-04-03 04:43 - 00000000 ____D C:\ProgramData\PCDr
2013-09-01 12:05 - 2013-09-01 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-01 12:05 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-09-01 11:22 - 2013-04-29 14:09 - 00000824 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-01 11:22 - 2013-04-29 14:09 - 00000000 ____D C:\Program Files\CCleaner
2013-09-01 11:19 - 2013-09-01 11:18 - 04454952 _____ (Piriform Ltd) C:\Users\Thomas\Downloads\ccsetup405(1).exe
2013-09-01 11:18 - 2013-09-01 11:18 - 04454952 _____ (Piriform Ltd) C:\Users\Thomas\Downloads\ccsetup405.exe
2013-09-01 11:08 - 2013-04-17 08:36 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-09-01 11:04 - 2013-04-26 20:58 - 00000000 ____D C:\Users\Thomas\AppData\Local\Windows Live
2013-09-01 09:28 - 2013-07-03 13:52 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Intermediate
2013-09-01 09:28 - 2013-04-13 22:30 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-01 09:27 - 2013-09-01 09:27 - 17737608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-09-01 09:27 - 2013-09-01 09:27 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Snz
2013-09-01 09:26 - 2013-05-26 14:02 - 00000000 ____D C:\Users\Thomas\AppData\Local\Apple
2013-08-28 20:46 - 2013-08-28 20:46 - 02218359 _____ C:\Users\Thomas\AppData\Local\omesuperv.exe
Files to move or delete:
====================
C:\Users\Thomas\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Thomas\AppData\Local\Temp\nsu3014.tmp\sqlite3.dll
C:\Users\Thomas\AppData\Local\Temp\nsu3014.tmp\uph.dll
C:\Users\Thomas\AppData\Local\Temp\nsu3014.tmp\userid.dll
C:\Users\Thomas\AppData\Local\Temp\nso2E20.tmp\uph.dll
C:\Users\Thomas\AppData\Local\Temp\nslCB1C.tmp\sqlite3.dll
C:\Users\Thomas\AppData\Local\Temp\nslCB1C.tmp\userid.dll
C:\Users\Thomas\AppData\Local\Temp\nsh6BFC.tmp\sqlite3.dll
C:\Users\Thomas\AppData\Local\Temp\nsh6BFC.tmp\userid.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-01 19:07
==================== End Of Log ============================ 4) FRST: Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-09-2013 05
Ran by Thomas at 2013-09-02 21:16:51
Running from C:\Users\Thomas\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe AIR (x32 Version: 2.6.0.19140)
Adobe Community Help (x32 Version: 3.5.23)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Photoshop Elements 10 (x32 Version: 10.0)
Adobe Premiere Elements 10 (Version: 10.0)
Amazon Browser App (x32 Version: 1.0.0.0)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
Bonjour (Version: 3.0.0.10)
Canon Easy-PhotoPrint EX (x32)
Canon Easy-WebPrint EX (x32)
Canon IJ Network Scanner Selector EX (x32)
Canon IJ Network Tool (x32 Version: 3.1.1)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32)
Canon MG5300 series Benutzerregistrierung (x32)
Canon MG5300 series MP Drivers
Canon MG5300 series On-screen Manual (x32)
Canon MP Navigator EX 5.0 (x32)
Canon My Printer (x32)
Canon Solution Menu EX (x32)
CyberLink LabelPrint 2.5 (x32 Version: 2.5.5415)
CyberLink Media Suite 10 (x32 Version: 10.0.1.2417)
CyberLink Media Suite Essentials (x32 Version: 10.0)
CyberLink Power2Go 8 (x32 Version: 8.0.0.2126)
CyberLink PowerDirector 10 (x32 Version: 10.0.1.2413)
CyberLink PowerDVD 10 (x32 Version: 10.0.4828.52)
D3DX10 (x32 Version: 15.4.2368.0902)
Dell Backup and Recovery - Support Software (x32 Version: 1.5.0.0)
Dell Backup and Recovery (x32 Version: 1.5.0.0)
Dell Touchpad (Version: 8.1200.101.217)
eaner (Version: 4.05)
Elements 10 Organizer (x32 Version: 10.0)
Fotogalerie (x32 Version: 16.4.3505.0912)
Foxit Reader (x32 Version: 6.0.5.618)
Free YouTube Download version 3.2.2.422 (x32 Version: 3.2.2.422)
iCloud (Version: 2.1.2.8)
Intel PROSet Wireless
Intel(R) Control Center (x32 Version: 1.2.1.1008)
Intel(R) Management Engine Components (x32 Version: 8.1.0.1252)
Intel(R) Processor Graphics (x32 Version: 9.17.10.2867)
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.5.4.0423)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 2.6.1209.0268)
Intel(R) Rapid Storage Technology (x32 Version: 11.6.0.1030)
Intel(R) WiDi (Version: 3.5.40.0)
Intel® PROSet/Wireless WiFi-Software (Version: 15.05.6000.1620)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
iTunes (Version: 11.0.4.4)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
McAfee SecurityCenter (x32 Version: 11.6.511)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office Home and Student 2013 - de-de (Version: 15.0.4517.1509)
Microsoft SkyDrive (HKCU Version: 16.4.6013.0910)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Movie Maker (x32 Version: 16.4.3505.0912)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
Müller Foto (x32 Version: 5.0.1)
My Dell (Version: 3.3.6280.92)
MyFreeCodec (HKCU)
MyTomTom 3.2.0.906 (x32 Version: 3.2.0.906)
NVIDIA GeForce Experience 1.5 (Version: 1.5)
NVIDIA Grafiktreiber 320.49 (Version: 320.49)
NVIDIA Install Application (Version: 2.1002.124.810)
NVIDIA Optimus 4.11.9 (Version: 4.11.9)
NVIDIA PhysX (x32 Version: 9.13.0604)
NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604)
NVIDIA Systemsteuerung 320.49 (Version: 320.49)
NVIDIA Update 4.11.9 (Version: 4.11.9)
NVIDIA Update Components (Version: 4.11.9)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4517.1509)
Office 15 Click-to-Run Licensing Component (Version: 15.0.4517.1509)
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4517.1509)
Photo Gallery (x32 Version: 16.4.3505.0912)
PRE10STI64Installer (x32 Version: 1.0)
PSE10 STI Installer (x32 Version: 10.0)
Quickset64 (Version: 11.1.37)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.8400.39030)
Samsung Kies (x32 Version: 2.5.3.13052_10)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.24.0)
Shared C Run-time for x64 (Version: 10.0.0)
SmartSound Common Data (x32 Version: 1.1.0)
SmartSound Premiere Elements 10 x64 Plugin (Version: 5.70.0001)
SmartSound Sonicfire Pro 5 (x32 Version: 5.7.1)
Überwachungstool für die Intel® Turbo-Boost-Technik 2.6 (Version: 2.6.2.0)
Visual Studio C++ 10.0 Runtime (x32 Version: 10.0.0)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912)
Windows Live Essentials (x32 Version: 16.4.3505.0912)
Windows Live Installer (x32 Version: 16.4.3505.0912)
Windows Live Photo Common (x32 Version: 16.4.3505.0912)
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912)
Windows Live SOXE (x32 Version: 16.4.3505.0912)
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912)
Windows Live UX Platform (x32 Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912)
==================== Restore Points =========================
10-07-2013 10:58:51 Windows Update
15-07-2013 09:37:31 Windows Update
01-09-2013 07:27:12 Windows Update
==================== Hosts content: ==========================
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {10D85952-E3F6-47A1-96CF-5E1C2D874EA6} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [2012-07-26] (Microsoft Corporation)
Task: {1220E939-99F9-43ED-B0C0-5FDED51ECC9E} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2013-07-18] (PC-Doctor, Inc.)
Task: {13A2AC02-B682-48CC-9155-2E2673580117} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
Task: {17644F17-DC4C-4AC8-9444-7AAA52EB5CDC} - System32\Tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler
Task: {18317699-33F7-485A-8668-F822ECF4E4E1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\System32\sysmain.dll [2013-05-04] (Microsoft Corporation)
Task: {1DB7C2F1-876C-4F24-AD17-8428211113F9} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
Task: {214B24F4-FEB4-4C59-AF1F-70136065199C} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance
Task: {23700E5C-0E77-499D-908A-415D5C6252F4} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => C:\Windows\System32\WSClient.dll [2012-09-20] (Microsoft Corporation)
Task: {2C6B9EA8-7F5A-4ABA-BF96-8D352D02A743} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh
Task: {2E030FA7-3D7C-4E1D-8CFE-56ADB26FD402} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks
Task: {2F48A043-F0F8-4AB1-9199-99D7987A4B83} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2012-12-03] (CyberLink Corp.)
Task: {3054485A-F517-4E95-9977-4DD827B1E9B3} - System32\Tasks\Microsoft\Windows\WS\Badge Update
Task: {33D5C311-61EF-43E5-9DDF-8657E2792D47} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-06-09] (Microsoft Corporation)
Task: {378401BA-A703-444A-A79C-3C47AD2DC5B6} - System32\Tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator
Task: {3AADC153-47C1-430D-AA20-FECAC8086674} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2013-05-07] (PC-Doctor, Inc.)
Task: {3AE164E7-30CD-40BC-9422-3EC7A5618965} - System32\Tasks\Microsoft\Windows\WS\WSTask
Task: {3C490ABD-D849-41AF-9AC4-87DD759B0996} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
Task: {4073C1B3-6E16-4AA8-B7F3-C6A6D35D5071} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance
Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage
Task: {483A8F5C-5D26-44B5-B49E-AF6741D1BBEB} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [2012-07-26] (Microsoft Corporation)
Task: {4B952129-9AE9-41A3-BE2B-8AD2E06F66B6} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
Task: {549A9AF3-D709-485E-A6CE-075793B05157} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall
Task: {5755E746-D7ED-4C20-A472-66C11834CDE4} - System32\Tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance
Task: {5C4EFB77-EFA6-45DF-A373-D795C0725BFF} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required
Task: {627441F3-8526-4B62-BF9A-1A3EA414E71A} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [2012-07-26] (Microsoft Corporation)
Task: {6AFE5F5B-06A1-412A-B171-1BD6783BFD4C} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1023412029-2558512523-2891409035-1002
Task: {6E9DE125-5583-4031-B572-FEE48F25CFFF} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [2012-09-20] (Microsoft Corporation)
Task: {6EF000A9-5DE6-4691-AAD2-13EDF60D011F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-01] (Adobe Systems Incorporated)
Task: {6FDDEA7C-6310-428D-AEB2-54FFC72811EF} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
Task: {74096F94-B654-4DB0-96F5-3C3408B92FE3} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update
Task: {7D9A9A1C-499C-40A6-8F8A-5BCC4CC9A87C} - System32\Tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance
Task: {845CB020-68B5-4C6B-9876-7BEC7B3E27AC} - System32\Tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance
Task: {87354DAA-66DF-4B41-9346-15958D96E1D2} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode)
Task: {8E02D795-4FE3-4AC6-85FF-3B1CF10CAAD4} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1023412029-2558512523-2891409035-1002 => C:\Windows\System32\portabledeviceapi.dll [2012-07-26] (Microsoft Corporation)
Task: {921A1D4E-32FB-46D7-B6C0-6F467884074D} - System32\Tasks\Microsoft\Windows\WS\Sync Licenses
Task: {9479EF8E-11D4-41B3-9783-CC65070D592D} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
Task: {94DCF254-64FB-4C4E-8E12-5F4055C10C2A} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
Task: {96A6335A-38BF-45DB-A74C-2D9CA2909D6A} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup
Task: {989A7C6D-BE82-4C3C-AF96-6116039E336B} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => C:\Windows\System32\WSClient.dll [2012-09-20] (Microsoft Corporation)
Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask
Task: {AB62FA47-2C99-44B1-A5D0-D4161423BE43} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefresh
Task: {AC6259DE-AC59-459E-849E-6ADFFD1ADE63} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask
Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask
Task: {AF549BD8-337C-4BF7-8681-36A182E30507} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan
Task: {B9EDCD64-3BEC-4342-B5BA-8397FB063F42} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1023412029-2558512523-2891409035-1004
Task: {BA750903-D419-481E-8D3B-EEF162C01CF6} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect
Task: {BC76AEF7-2CF0-4EB6-B65B-A8803E0B5E12} - System32\Tasks\Microsoft\Windows\AppID\SmartScreenSpecific
Task: {C1ACCD1E-4385-4FB2-B5E4-7F2A57A626A2} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
Task: {C3B36134-11AA-400A-96E1-A618EC0209A6} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall
Task: {C463FD1E-31C7-4C20-AB65-08E514CA152D} - System32\Tasks\Microsoft\Windows\IME\SQM data sender
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\System32\Windows.Storage.ApplicationData.dll [2012-07-26] (Microsoft Corporation)
Task: {C7AF4EE0-2958-41F0-9520-A601A644EFEC} - System32\Tasks\SystemToolsDailyTest => C:\Windows\System32\uaclauncher.exe No File
Task: {C85AFA53-D3B4-4277-8CD8-6C610768AE55} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-12-03] (CyberLink)
Task: {CD1054FF-8005-4904-8B9C-436EAB1E2021} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
Task: {CF965BC2-23EB-4418-A33C-2A0632AD0A90} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {D64E44A8-7039-4F4F-87AD-DD8A4B9C285F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {DBCF6E1B-CE0A-441E-B7A5-219C8BE50C65} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
Task: {DECE5921-598D-454B-9A04-B2DE95EFC1B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
Task: {E4DFE66F-E089-4CC3-A70F-957223D565F4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
Task: {E8DAA09B-DF2A-4951-9134-6FA9587793F9} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [2012-09-20] (Microsoft Corporation)
Task: {EAD237E7-D276-4257-9F16-51DF41548733} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => start w32time task_started
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\System32\Startupscan.dll [2012-07-26] (Microsoft Corporation)
Task: {ED0C1F69-C3A2-41EA-B8C3-3F0D83A1F6C0} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM
Task: {F106664E-2104-4473-A1A7-5EDB63CEF7DE} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1023412029-2558512523-2891409035-1004 => C:\Windows\System32\portabledeviceapi.dll [2012-07-26] (Microsoft Corporation)
Task: {F52EB4BF-2F73-4782-85C4-CF8B7CDF0526} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => start wuauserv
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2013-04-03 04:25 - 2012-09-20 08:30 - 01743872 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\combase.dll
2013-04-13 20:18 - 2013-02-02 10:23 - 00543232 _____ (Microsoft Corporation) C:\Windows\system32\wlroamextension.dll
2013-04-03 14:03 - 2013-04-03 14:03 - 00590848 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\shcore.dll
2013-05-17 19:51 - 2013-04-09 06:51 - 00765440 _____ (Microsoft Corporation) C:\Windows\winstore\WinStoreUI.dll
2013-04-03 04:25 - 2012-09-20 08:33 - 00177152 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\WSSync.dll
2012-07-26 03:28 - 2012-07-26 05:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\sppcext.dll
2013-06-17 12:42 - 2013-05-04 08:57 - 00389120 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\Bcp47Langs.dll
2012-07-26 04:06 - 2012-07-26 05:07 - 00119296 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\sppc.dll
2013-04-03 14:03 - 2013-04-03 14:03 - 00244736 _____ (Microsoft Corporation) C:\Windows\System32\wpnapps.dll
2012-07-26 02:00 - 2012-07-26 05:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\TaskSchdPS.dll
2012-07-26 02:33 - 2012-07-26 05:05 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2012-07-26 02:12 - 2012-07-26 06:55 - 01326784 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2012-07-26 02:08 - 2012-07-26 05:06 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\NTASN1.dll
2011-08-30 23:05 - 2011-08-30 23:05 - 00132968 _____ (Apple Inc.) C:\Program Files\Bonjour\mdnsNSP.dll
2013-04-13 20:23 - 2013-03-02 04:44 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncInfo.dll
2012-07-26 01:55 - 2012-07-26 05:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\System32\DeviceSetupManagerAPI.dll
2013-04-03 14:04 - 2013-04-03 14:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2013-04-03 14:03 - 2013-04-03 14:03 - 00590848 _____ (Microsoft Corporation) C:\Windows\system32\SHCORE.dll
2012-07-26 01:55 - 2012-07-26 05:07 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\WINMMBASE.dll
2012-07-26 01:31 - 2012-07-26 05:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\profext.dll
2013-04-03 14:03 - 2013-04-03 14:03 - 00590848 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\SHCORE.dll
2013-04-03 14:03 - 2013-04-03 14:03 - 01395712 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Immersive.dll
2013-04-03 04:25 - 2012-09-20 08:33 - 00699392 _____ (Microsoft Corporation) C:\Windows\System32\twinapi.dll
2013-06-17 12:42 - 2013-05-04 08:58 - 10116096 _____ (Microsoft Corporation) C:\Windows\System32\twinui.dll
2012-07-26 01:33 - 2012-07-26 05:07 - 00069632 _____ (Microsoft Corporation) C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
2012-07-26 01:54 - 2012-07-26 05:05 - 00171008 _____ (Microsoft Corporation) C:\Windows\System32\IDStore.dll
2013-05-17 19:51 - 2013-04-09 06:51 - 00456704 _____ (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-04-03 13:31 - 2013-06-21 14:06 - 01059560 _____ (NVIDIA Corporation) C:\Windows\SYSTEM32\nvumdshimx.dll
2013-04-03 13:31 - 2013-06-21 14:06 - 00266448 _____ (NVIDIA Corporation) C:\Windows\SYSTEM32\nvinitx.dll
2013-04-03 13:30 - 2012-10-26 20:39 - 12836864 _____ (Intel Corporation) C:\Windows\System32\igd10umd64.dll
2012-07-26 02:05 - 2012-07-26 05:05 - 00192000 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\dcomp.dll
2012-07-26 01:31 - 2012-07-26 05:08 - 00343552 _____ (Microsoft Corporation) C:\Windows\System32\wlidprov.dll
2012-07-26 01:24 - 2012-07-26 05:05 - 00186368 _____ (Microsoft Corporation) C:\Windows\System32\InputSwitch.dll
2012-07-26 01:55 - 2012-07-26 05:07 - 01161216 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\UIAutomationCore.dll
2012-07-26 02:04 - 2012-07-26 05:07 - 00046592 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\windows.globalization.fontgroups.dll
2013-04-13 20:18 - 2013-02-02 10:23 - 00293376 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Networking.Connectivity.dll
2012-07-26 02:05 - 2012-07-26 05:07 - 00029184 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\wcmapi.dll
2012-07-26 04:09 - 2012-07-26 05:07 - 00044544 _____ (Microsoft Corporation) C:\Windows\System32\qmgrprxy.dll
2012-07-26 03:37 - 2012-07-26 05:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\NcaApi.dll
2012-07-26 01:33 - 2012-07-26 05:06 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\NetworkStatus.dll
2012-07-26 01:54 - 2012-07-26 05:05 - 00101888 _____ (Microsoft Corporation) C:\Windows\System32\BluetoothApis.dll
2012-07-26 02:51 - 2012-07-26 05:05 - 00123904 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\apprepapi.dll
2012-07-26 04:19 - 2012-07-26 05:06 - 00023040 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\pcacli.dll
2013-04-17 08:40 - 2013-04-17 08:40 - 00244696 _____ (Microsoft Corporation) C:\Users\Thomas\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
2013-04-17 08:40 - 2013-04-17 08:40 - 00661448 _____ (Microsoft Corporation) C:\Users\Thomas\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\MSVCP110.dll
2013-04-17 08:40 - 2013-04-17 08:40 - 00828872 _____ (Microsoft Corporation) C:\Users\Thomas\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\MSVCR110.dll
2013-09-01 11:06 - 2013-09-01 11:06 - 02328776 _____ (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
2013-04-17 08:38 - 2013-04-17 08:38 - 00158536 _____ (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ATL100.DLL
2013-09-01 11:06 - 2013-09-01 11:06 - 08922840 _____ (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1031\GrooveIntlResource.dll
2012-07-26 02:12 - 2012-07-26 06:55 - 01326784 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\webservices.dll
2013-04-03 04:19 - 2013-06-21 12:23 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-04-03 13:30 - 2012-10-26 20:39 - 00386048 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll
2013-04-03 13:30 - 2012-10-26 20:38 - 00110592 _____ (Intel Corporation) C:\Windows\system32\hccutils.DLL
2013-04-03 13:30 - 2012-10-26 20:39 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrDEU.lrc
2013-04-03 13:30 - 2012-10-26 20:39 - 00063488 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll
2012-07-26 04:09 - 2012-07-26 05:05 - 00014848 _____ (Microsoft Corporation) C:\Windows\System32\bitsprx7.dll
2012-07-26 04:09 - 2012-07-26 05:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\System32\bitsprx5.dll
2012-07-26 04:09 - 2012-07-26 05:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\bitsprx3.dll
2012-07-26 04:09 - 2012-07-26 05:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\bitsprx2.dll
2012-07-26 04:09 - 2012-07-26 05:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\bitsprx6.dll
2013-04-15 09:32 - 2012-09-10 12:33 - 00238360 _____ (McAfee, Inc.) C:\Program Files\Common Files\McAfee\MSC\McRtMui.dll
2013-04-15 09:32 - 2012-09-10 12:17 - 00167832 _____ (McAfee, Inc.) C:\Program Files\Common Files\McAfee\MSC\LangSel.dll
2013-04-15 09:33 - 2012-09-10 23:35 - 00193576 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\mqs\shredext.dll
2013-04-15 09:33 - 2012-09-10 23:35 - 00227584 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\mqs\shrcore.dll
2013-04-15 09:32 - 2012-08-31 13:00 - 00054056 _____ (McAfee, Inc.) c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll
2013-04-15 09:33 - 2012-09-10 23:35 - 00170928 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\mqs\shredshm.dll
2012-07-26 02:08 - 2012-07-26 05:06 - 00205312 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\NTASN1.dll
2013-04-03 13:30 - 2013-06-21 14:06 - 02936208 _____ (NVIDIA Corporation) C:\Windows\SYSTEM32\nvapi64.dll
2013-04-03 04:19 - 2013-06-21 12:23 - 00067072 _____ (NVIDIA Corporation) C:\Windows\SYSTEM32\Nv3DAppShExtR.dll
2013-04-13 20:23 - 2013-03-02 04:45 - 00951808 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Globalization.dll
2012-07-26 02:35 - 2012-07-26 05:07 - 04243456 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2012-07-26 04:33 - 2012-07-26 04:33 - 00629760 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\UIRibbonRes.dll
2012-07-26 01:55 - 2012-07-26 05:07 - 00180224 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\WINMMBASE.dll
2013-04-05 12:58 - 2013-04-05 12:58 - 00954696 _____ () C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll
2012-07-26 02:59 - 2012-07-26 05:05 - 00465408 _____ (Microsoft Corporation) C:\Windows\System32\dlnashext.dll
2013-04-03 04:25 - 2012-09-20 08:33 - 01304064 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Streaming.dll
2013-04-13 20:23 - 2013-03-02 04:44 - 00049152 _____ (Microsoft Corporation) C:\Windows\System32\DevDispItemProvider.dll
2012-07-26 02:33 - 2012-07-26 05:07 - 00285696 _____ (Microsoft Corporation) C:\Windows\System32\systemcpl.dll
2012-07-26 02:03 - 2012-07-26 05:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\WINBRAND.dll
2013-04-03 13:20 - 2013-02-05 22:48 - 00849360 _____ (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\MSVCR110.dll
2013-04-03 13:27 - 2013-01-03 00:54 - 00054176 _____ (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\wllog.dll
2013-04-03 13:27 - 2013-01-03 00:55 - 03429792 _____ (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Service.dll
2012-07-26 01:33 - 2012-07-26 05:07 - 00175616 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Storage.ApplicationData.dll
2013-04-03 04:25 - 2012-09-20 08:33 - 00699392 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\twinapi.dll
2013-04-03 04:25 - 2012-09-20 08:33 - 00866304 _____ (Microsoft Corporation) C:\Windows\System32\WinTypes.dll
2013-04-03 13:27 - 2013-01-03 00:54 - 00229792 _____ (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\shared\bici.dll
2012-07-26 01:59 - 2012-07-26 05:07 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\threadpoolwinrt.dll
2013-06-17 12:42 - 2013-05-04 08:57 - 00122368 _____ (Microsoft Corporation) C:\Windows\System32\biwinrt.dll
2013-04-03 13:27 - 2013-01-03 00:55 - 01938328 _____ (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.dll
2012-07-26 04:01 - 2012-07-26 05:07 - 00056320 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.dll
2013-04-13 20:23 - 2013-03-02 04:45 - 00645120 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll
2013-05-17 19:51 - 2013-04-09 06:51 - 00391168 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2012-07-26 02:06 - 2012-07-26 05:07 - 00015360 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll
2013-04-03 14:03 - 2013-04-03 14:03 - 00757760 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\FirewallAPI.dll
2013-04-03 13:27 - 2013-01-03 00:55 - 00175008 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2013-04-03 04:19 - 2013-06-21 12:23 - 04528416 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvUI.dll
2013-04-03 14:03 - 2013-04-03 14:03 - 00590848 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\SHCORE.DLL
2013-04-03 04:19 - 2013-05-16 16:39 - 01225504 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Common\easyDaemonAPIU64.DLL
2013-04-03 04:19 - 2013-05-16 16:39 - 04843296 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Common\NvUpdt.dll
2013-04-03 04:19 - 2013-05-16 16:39 - 01649440 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Common\NVUPDTR.DLL
2012-07-26 01:58 - 2012-07-26 05:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2013-04-03 13:30 - 2012-12-21 01:17 - 01816560 _____ (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.dll
2013-04-03 13:30 - 2012-11-29 23:09 - 00113560 _____ (Alps Electric Co., Ltd.) C:\Windows\SYSTEM32\Vxdif.dll
2013-04-03 13:30 - 2010-06-01 08:23 - 00039792 _____ (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\EzAuto.dll
2012-07-26 03:39 - 2012-07-26 05:06 - 00757248 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\ODBC32.dll
2013-04-03 13:31 - 2012-09-06 12:10 - 00672256 ____N (IDT, Inc.) C:\Windows\system32\stapi64.dll
2013-04-03 13:30 - 2012-10-26 20:38 - 00110592 _____ (Intel Corporation) C:\Windows\System32\hccutils.DLL
2013-04-03 14:03 - 2013-04-03 14:03 - 00590848 _____ (Microsoft Corporation) C:\Windows\System32\SHCORE.dll
2013-04-03 13:30 - 2012-10-26 20:39 - 09007616 _____ (Intel Corporation) C:\Windows\System32\igfxress.dll
2013-04-03 13:30 - 2012-11-29 23:09 - 00113560 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\VXDIF.DLL
2013-04-03 13:30 - 2012-12-21 01:17 - 01816560 _____ (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.DLL
2013-04-03 13:30 - 2012-10-26 20:38 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-04-03 13:30 - 2012-10-26 20:39 - 00028672 _____ (Intel Corporation) C:\Windows\system32\IGFXEXPS.DLL
2013-07-10 12:30 - 2013-04-23 00:08 - 10004120 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
2013-07-12 17:19 - 2013-07-12 17:19 - 15577088 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\a77d877c214d5c7b4adbe2b8a9da3cf2\mscorlib.ni.dll
2013-07-12 17:20 - 2013-07-12 17:20 - 10656256 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System\572cf15f1c03f8129ef4af72c248a8ae\System.ni.dll
2013-07-13 13:17 - 2013-07-13 13:17 - 02173440 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\23718d30efe2e39a1745de518983bf11\Microsoft.VisualBasic.ni.dll
2013-04-13 20:22 - 2012-10-09 05:09 - 01574496 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
2012-05-30 13:11 - 2012-05-30 13:11 - 00019496 _____ (Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandCommon.dll
2013-07-12 17:21 - 2013-07-12 17:21 - 02320384 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\aad149aedd73b35bee3208b976f1edf6\System.Drawing.ni.dll
2013-07-12 17:21 - 2013-07-12 17:21 - 17387008 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\417bfcb305172fd47dc89df26eb16f4a\System.Windows.Forms.ni.dll
2013-07-13 13:18 - 2013-07-13 13:18 - 01022976 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\17a505bef019e046f4b10c0575c858a6\System.Runtime.Remoting.ni.dll
2013-07-13 13:18 - 2013-07-13 13:18 - 01320448 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\d71b7bb54e4d6b831557c1636a169741\System.Configuration.ni.dll
2013-07-12 17:21 - 2013-07-12 17:21 - 06964736 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\c05ddfb7d5242800072f6cefa2ea8dd7\System.Xml.ni.dll
2013-07-12 17:20 - 2013-07-12 17:20 - 04965376 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\eb29d3616d48c736a09d75eca128ee85\WindowsBase.ni.dll
2013-07-12 17:20 - 2013-07-12 17:20 - 16545280 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\4207102628e254fdd36e64d7b31abe04\PresentationCore.ni.dll
2013-07-12 17:20 - 2013-07-12 17:20 - 19202560 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\e78df0b284876803ede0f141e3a0b40c\PresentationFramework.ni.dll
2013-07-10 12:32 - 2013-04-20 00:05 - 02256032 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\wpfgfx_v0300.dll
2013-04-03 14:03 - 2013-04-03 14:03 - 00315392 _____ (Microsoft Corporation) C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
2012-05-30 13:15 - 2012-05-30 13:15 - 00404008 _____ () C:\Program Files\Intel\TurboBoost\de\SignalIslandUi.resources.dll
2008-05-08 14:37 - 2008-05-08 14:37 - 00070720 _____ (Microsoft Corporation) C:\Program Files\Intel\TurboBoost\Microsoft.Practices.Unity.dll
2008-05-08 14:37 - 2008-05-08 14:37 - 00070720 _____ (Microsoft Corporation) C:\Program Files\Intel\TurboBoost\Microsoft.Practices.ObjectBuilder2.dll
2009-09-23 11:51 - 2009-09-23 11:51 - 00012288 _____ ( ) C:\Program Files\Intel\TurboBoost\DHLogInterfaces.Interop.dll
2013-07-13 13:17 - 2013-07-13 13:17 - 03315712 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\5130256280b786789954a4daf6e3b0ba\System.Core.ni.dll
2013-04-03 04:21 - 2012-07-26 15:53 - 00797776 ____R (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\diasymreader.dll
2013-07-03 10:40 - 2013-06-21 14:06 - 01059560 _____ (NVIDIA Corporation) C:\Windows\system32\NV\nvumdshimx.dll
2013-04-03 13:31 - 2013-01-11 15:45 - 00004096 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2013-05-26 11:36 - 2013-06-21 14:06 - 00330344 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\CoProcManager\nvd3d9wrapx.dll
2013-05-26 11:36 - 2013-06-21 14:06 - 00229392 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\CoProcManager\nvdxgiwrapx.dll
2013-04-03 13:30 - 2012-10-26 20:39 - 12604416 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll
2013-07-12 17:20 - 2013-07-12 17:20 - 00463360 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\29a215774deeb61579578d43862c2d94\PresentationFramework.Aero.ni.dll
2013-04-03 04:21 - 2012-07-26 15:53 - 01166440 ____R (Microsoft Corporation) C:\Windows\SYSTEM32\PresentationNative_v0300.dll
2012-07-26 04:07 - 2012-07-26 05:06 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\msctfui.dll
2013-04-26 14:35 - 2013-04-26 14:35 - 00546976 _____ (Microsoft) C:\Windows\assembly\GAC_MSIL\Microsoft.WindowsAPICodePack.Shell\1.1.0.0__31bf3856ad364e35\Microsoft.WindowsAPICodePack.Shell.dll
2013-04-26 14:35 - 2013-04-26 14:35 - 00110240 _____ (Microsoft) C:\Windows\assembly\GAC_MSIL\Microsoft.WindowsAPICodePack\1.1.0.0__31bf3856ad364e35\Microsoft.WindowsAPICodePack.dll
2013-07-10 12:32 - 2013-04-23 00:08 - 09808440 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
2012-07-25 22:13 - 2012-07-12 04:01 - 00856016 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\MSVCR110_CLR0400.dll
2013-07-12 17:16 - 2013-07-12 17:16 - 22589440 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\ab0a8fc3d086a3aaf942f366a12a9185\mscorlib.ni.dll
2013-06-04 22:24 - 2013-04-02 00:06 - 01237024 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
2013-07-12 17:17 - 2013-07-12 17:17 - 13227520 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_64\System\a868e6efe8abc696ec355ae5721a066a\System.ni.dll
2013-07-12 17:17 - 2013-07-12 17:17 - 10137600 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\b0c762ba51fa367fc98f795307a56402\System.Core.ni.dll
2013-07-06 18:09 - 2013-04-20 00:52 - 00293664 _____ (The Apache Software Foundation) C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\log4net.dll
2013-07-12 17:18 - 2013-07-12 17:18 - 01259008 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\b4cc2c6435aff36f374e0b84e73c923e\System.Configuration.ni.dll
2013-07-12 17:19 - 2013-07-12 17:19 - 10137088 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\ece05aeeb68c0c14dec2136e8e176f0c\System.Xml.ni.dll
2013-07-06 18:09 - 2013-04-20 00:52 - 00049440 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\STCommonShellIntegration.dll
2013-07-06 18:09 - 2013-04-20 00:53 - 00198432 _____ (hxxp://system.data.sqlite.org/) C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\System.Data.SQLite.dll
2013-07-12 17:18 - 2013-07-12 17:18 - 09212928 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data\ee1059437a6914b1e8c16b11ccd8fae7\System.Data.ni.dll
2013-06-04 22:24 - 2013-04-02 00:06 - 03203632 _____ (Microsoft Corporation) C:\Windows\Microsoft.Net\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
2013-07-12 17:19 - 2013-07-12 17:19 - 00900096 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\1e50de1d1c39a3a5c471c96c6a397ddf\System.Transactions.ni.dll
2012-07-25 22:12 - 2012-07-12 04:01 - 00288216 _____ (Microsoft Corporation) C:\Windows\Microsoft.Net\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
2013-07-06 18:09 - 2013-04-20 00:53 - 01019168 _____ (Robert Simpson, et al.) C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\SQLite.Interop.dll
2012-07-25 22:12 - 2012-07-12 04:01 - 00247792 _____ (Microsoft Corporation) C:\Windows\Microsoft.Net\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
2012-07-25 22:12 - 2012-07-12 04:01 - 00129024 _____ (Microsoft Corporation) C:\Windows\Microsoft.Net\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
2013-04-03 04:25 - 2012-08-31 02:52 - 00994312 _____ (Microsoft Corporation) C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources\v4.0_4.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
2012-07-26 02:52 - 2012-07-26 05:07 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\SyncInfrastructure.dll
2011-06-11 01:15 - 2011-06-11 01:15 - 00829264 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\MSVCR100.dll
2011-06-11 01:15 - 2011-06-11 01:15 - 00608080 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\MSVCP100.dll
2011-06-11 01:15 - 2011-06-11 01:15 - 00158536 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\ATL100.DLL
2013-03-12 22:04 - 2013-03-12 22:04 - 00394896 _____ (McAfee, Inc.) c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\11_6_2~1\McUtil.dll
2012-06-21 21:49 - 2012-06-22 22:31 - 00270952 _____ (McAfee, Inc.) C:\Program Files\McAfee\MSC\McOemRes.dll
2012-06-21 21:49 - 2012-06-22 22:31 - 00036968 _____ (McAfee, Inc.) C:\Program Files\McAfee\MSC\OemUI.dll
2013-05-29 20:40 - 2013-05-08 04:31 - 05470664 _____ (McAfee, Inc.) C:\Program Files\McAfee\MSC\mcprlres.dll
2013-05-29 20:40 - 2013-03-13 18:46 - 00874864 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\msc\mcmscshm.dll
2013-05-29 20:40 - 2013-03-13 18:45 - 00146112 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\msc\McMscHlp.dll
2013-05-29 20:40 - 2013-03-12 22:03 - 00557088 _____ (McAfee, Inc.) C:\PROGRA~1\COMMON~1\McAfee\MSC\McBrwsr2.dll
2013-05-29 20:40 - 2013-03-13 18:47 - 00130144 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\msc\mcupdshm.dll
2013-05-29 20:40 - 2013-03-13 18:46 - 00045720 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\msc\mcuicfg.dll
2013-03-13 18:46 - 2013-03-13 18:46 - 00655968 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\msc\mcsubmgr\11_6_5~1\mcsubmgr.dll
2013-05-29 20:40 - 2013-03-13 18:45 - 00161056 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\msc\mcmispps.dll
2013-05-29 20:40 - 2013-05-08 04:31 - 03969960 _____ (McAfee, Inc.) C:\Program Files\McAfee\MSC\mscjsres.dll
2013-04-03 14:03 - 2013-04-03 14:03 - 00757760 _____ (Microsoft Corporation) C:\Windows\System32\FirewallAPI.dll
2013-04-15 09:33 - 2012-10-06 15:02 - 00371736 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\mpf\mpfshm.dll
2013-04-15 09:33 - 2012-09-10 23:41 - 00444896 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\msk\mskcshim.dll
2013-05-29 20:40 - 2013-05-08 04:31 - 00411816 _____ (McAfee, Inc.) c:\progra~1\mcafee\msc\mscuild.dll
2013-04-15 09:32 - 2013-02-25 23:05 - 00352648 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\VIRUSS~1\mcoasshm.dll
2012-06-21 21:49 - 2012-06-22 22:31 - 00007784 _____ (McAfee, Inc.) c:\progra~1\mcafee\msc\oemuild.dll
2013-04-03 04:25 - 2012-09-20 08:30 - 02219008 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\d3d10warp.dll
2013-07-10 12:31 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-26 02:10 - 2012-07-26 05:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\DPAPI.DLL
2013-05-29 20:40 - 2013-03-13 18:45 - 00154352 _____ (McAfee, Inc.) C:\PROGRA~1\McAfee\MSC\McLWAPI.DLL
2012-07-26 03:56 - 2012-07-26 05:07 - 00593408 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-04-15 09:32 - 2012-09-10 17:50 - 01022232 _____ (McAfee, Inc.) c:\PROGRA~1\COMMON~1\mcafee\msc\mcdspwrp.dll
2013-04-15 09:32 - 2013-02-25 23:05 - 01597864 _____ (McAfee, Inc.) C:\PROGRA~1\McAfee\VIRUSS~1\VsoRes.Dll
2013-05-29 20:40 - 2013-03-13 18:46 - 00212544 _____ (McAfee, Inc.) C:\PROGRA~1\McAfee\MSC\mcprlalt.dll
2013-04-15 09:33 - 2012-09-10 23:35 - 00042208 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\mqs\QCPROG~1.DLL
2013-05-29 20:40 - 2013-03-13 18:45 - 00272832 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\msc\mciptshm.dll
2013-04-15 09:33 - 2012-09-10 15:21 - 00311496 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\mps\mpsmisp.dll
2013-04-15 09:33 - 2012-09-10 15:21 - 00495872 _____ (McAfee, Inc.) c:\PROGRA~1\mcafee\mps\mpscfg.dll
2011-08-30 23:05 - 2011-08-30 23:05 - 00121704 _____ (Apple Inc.) C:\Program Files (x86)\Bonjour\mdnsNSP.dll
2013-04-21 21:43 - 2013-04-21 21:43 - 00017296 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\AppleVersions.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00039240 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\YSCrashDump.DLL
2013-04-21 21:43 - 2013-04-21 21:43 - 01079624 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreFoundation.dll
2013-04-21 21:43 - 2013-04-21 21:43 - 00075664 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\ASL.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00053648 _____ (Open Source Software community project) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\pthreadVC2.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00124816 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\objc.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00043408 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libdispatch.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 01292136 _____ (The ICU Project) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libicuin.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00923496 _____ (The ICU Project) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libicuuc.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 16303976 _____ (The ICU Project) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\icudt46.dll
2013-04-05 12:59 - 2013-04-05 12:59 - 00178504 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices_main.dll
2013-04-05 12:56 - 2013-04-05 12:56 - 00141640 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AOSKit.dll
2013-04-21 21:43 - 2013-04-21 21:43 - 02464072 _____ (Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CFNetwork.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 01833288 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\Foundation.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00456592 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\SQLite3.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00329616 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libtidy.dll
2013-04-05 12:58 - 2013-04-05 12:58 - 00256328 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client_main.dll
2013-04-05 12:58 - 2013-04-05 12:58 - 00518472 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\CoreDAV.dll
2013-04-21 21:43 - 2013-04-21 21:43 - 00046736 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\ApplePushService.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00017224 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\YSUtilities.dll
2013-04-05 12:58 - 2013-04-05 12:58 - 00203080 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\LibRainfall.dll
2012-07-26 02:10 - 2012-07-26 05:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\DPAPI.dll
2013-04-05 12:58 - 2013-04-05 12:58 - 00227656 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\InternetExplorerBookmarkDAV.dll
2012-04-19 18:12 - 2012-04-19 18:12 - 00078312 ____N (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\CLRCEngine3.dll
2013-04-03 04:48 - 2013-04-03 04:48 - 00348160 ____N (Microsoft Corporation) C:\Program Files (x86)\CyberLink\PowerDVD10\MSVCR71.dll
2013-04-21 21:43 - 2013-04-21 21:43 - 00682312 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon_main.dll
2013-05-31 11:56 - 2013-05-31 11:56 - 00148808 _____ (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.dll
2013-05-31 12:39 - 2013-05-31 12:39 - 00041800 _____ (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.Resources\de.lproj\iTunesHelperLocalized.DLL
2013-05-31 11:56 - 2013-05-31 11:56 - 00040264 _____ (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.Resources\iTunesHelper.DLL
2012-12-21 16:27 - 2012-12-21 16:27 - 01449648 _____ (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll
2011-08-30 23:05 - 2011-08-30 23:05 - 00085864 _____ (Apple Inc.) C:\Windows\SYSTEM32\dnssd.dll
2013-04-03 04:46 - 2011-03-25 04:06 - 00509224 _____ (Microsoft Corporation) C:\Program Files (x86)\CyberLink\Power2Go8\MSVCP71.dll
2013-04-03 04:46 - 2011-03-25 04:06 - 00353576 _____ (Microsoft Corporation) C:\Program Files (x86)\CyberLink\Power2Go8\MSVCR71.dll
2013-04-03 04:46 - 2012-06-08 05:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2013-05-17 19:51 - 2013-04-09 06:51 - 14267904 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-04-03 04:25 - 2012-09-20 08:12 - 09374208 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.dll
2012-06-08 11:34 - 2012-06-08 11:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2013-04-03 04:25 - 2012-09-20 07:53 - 00311296 _____ (Microsoft Corporation) C:\Windows\AppPatch\AcLayers.DLL
2013-07-10 12:32 - 2013-04-23 00:08 - 06881848 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
2013-07-12 17:14 - 2013-07-12 17:14 - 16547328 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\5e3a9f3d64adfb3c69b49d37368bf454\mscorlib.ni.dll
2013-06-04 22:24 - 2013-04-02 00:06 - 00451608 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
2013-07-12 17:14 - 2013-07-12 17:14 - 09937408 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System\9823be5b56f36a3be7905df81b9c3683\System.ni.dll
2013-07-13 13:15 - 2013-07-13 13:15 - 00366592 _____ (Intel Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorUtil\97e4c0348d2df42b45b64984f6c45ce2\IAStorUtil.ni.dll
2013-07-12 17:15 - 2013-07-12 17:15 - 01631744 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\6a84c818148c37e1585c0422cae02fb0\System.Drawing.ni.dll
2013-07-12 17:15 - 2013-07-12 17:15 - 12698624 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\cae4b27345e2bab9e11b8c9c8ca3fe83\System.Windows.Forms.ni.dll
2013-07-12 17:14 - 2013-07-12 17:14 - 00964096 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\5f9957f3dee5c7bc9f1bef69a923cf9d\System.Configuration.ni.dll
2013-07-12 17:15 - 2013-07-12 17:15 - 07566336 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\a78b71db2984a6ec1cf110e4118603f3\System.Xml.ni.dll
2013-07-13 13:15 - 2013-07-13 13:15 - 00029696 _____ (Microsoft) C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorDataMcfeeca6f#\e95ff740f4c52eca60af5d2a3fd8cf2f\IAStorDataMgrSvcInterfaces.ni.dll
2013-07-12 17:14 - 2013-07-12 17:14 - 06998016 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\2753f437d6e45747bcf7077d338fd8a3\System.Core.ni.dll
2013-07-12 17:15 - 2013-07-12 17:15 - 19537408 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\b6fd410545458d0160528c1b03e88776\System.ServiceModel.ni.dll
2013-07-13 13:15 - 2013-07-13 13:15 - 00121344 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\de1d908e04221344949ab6da55aa4aba\SMDiagnostics.ni.dll
2013-07-13 13:15 - 2013-07-13 13:15 - 00802816 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\7c997aecab8a83df524e081283d66bc6\System.ServiceModel.Internals.ni.dll
2013-07-13 13:15 - 2013-07-13 13:15 - 00026112 _____ (Intel Corp.) C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorCommon\3baf6eefe8ca1de3ae7111a70e477255\IAStorCommon.ni.dll
2013-07-12 17:15 - 2013-07-12 17:15 - 02786816 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\63c905a4148011c72921a8b986ab8526\System.Runtime.Serialization.ni.dll
2013-07-13 13:15 - 2013-07-13 13:15 - 02959872 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\69a399f4391ac030822eec29359156b1\System.IdentityModel.ni.dll
2012-07-26 02:03 - 2012-07-26 05:06 - 00315904 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\msv1_0.DLL
2012-07-26 02:06 - 2012-07-26 05:05 - 00068096 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\cryptdll.dll
2013-07-12 17:14 - 2013-07-12 17:14 - 03910144 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\6531f34b3e528a70be121dee8ee129fa\WindowsBase.ni.dll
2013-07-12 17:14 - 2013-07-12 17:14 - 10926592 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\df2f0c372aad4d363f071625a9df28e7\PresentationCore.ni.dll
2013-07-12 17:14 - 2013-07-12 17:14 - 18545152 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\f7eb12f973b31390974c3858523fd3cb\PresentationFramework.ni.dll
2013-07-12 17:15 - 2013-07-12 17:15 - 01880576 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\05b44a1e63e3783b11917d612cf75d5f\System.Xaml.ni.dll
2013-06-04 22:24 - 2013-04-02 00:06 - 01688632 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll
2012-07-25 22:14 - 2012-07-12 04:02 - 00787952 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNative_v0400.dll
2013-07-13 13:16 - 2013-07-13 13:16 - 00738816 _____ (The Apache Software Foundation) C:\Windows\assembly\NativeImages_v4.0.30319_32\log4net\b0fd1f1ae08426c6f81443343c1001e8\log4net.ni.dll
2012-07-25 22:13 - 2012-07-12 04:01 - 00868288 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll
2013-07-12 17:15 - 2013-07-12 17:15 - 00397312 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\ea416bc5d73e3b06a0f428c74a32337d\System.Xml.Linq.ni.dll
2013-04-03 04:53 - 2012-11-25 22:20 - 03821928 ____N (SoftThinks) C:\Program Files (x86)\Dell Backup and Recovery\Components\PSTImageExt\PhImageBackup.dll
2013-07-12 17:15 - 2013-07-12 17:15 - 01156608 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\cd6b8416903164862eba3d170df40c90\System.Management.ni.dll
2012-07-25 22:13 - 2012-07-12 04:02 - 00041920 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\wminet_utils.dll
2013-07-06 18:09 - 2013-05-03 01:01 - 01813792 _____ () C:\Program Files (x86)\Dell Backup and Recovery\OLCoreWrapper.dll
2013-04-03 13:31 - 2013-01-11 15:45 - 00004096 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2013-05-26 11:36 - 2013-06-21 14:06 - 00289632 _____ (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\nvd3d9wrap.dll
2013-05-26 11:36 - 2013-06-21 14:06 - 00193336 _____ (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\nvdxgiwrap.dll
2013-07-12 17:14 - 2013-07-12 17:14 - 00467456 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\178b22f2da7c2497aa67a36f4edf0674\PresentationFramework.Aero2.ni.dll
2013-07-12 17:15 - 2013-07-12 17:15 - 00523776 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net.Http\a237f503e206d5c091327b2cdd813629\System.Net.Http.ni.dll
2013-09-01 12:05 - 2013-09-01 12:05 - 03551640 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-04-03 14:04 - 2013-04-03 14:04 - 01526784 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\MFCORE.dll
2013-04-03 14:04 - 2013-04-03 14:04 - 00677888 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\mfnetcore.dll
2012-07-26 01:22 - 2012-07-26 05:06 - 00601600 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\MrmCoreR.dll
2012-07-26 01:55 - 2012-07-26 05:07 - 01161216 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\UIAutomationCore.DLL
2013-09-02 19:28 - 2013-04-04 14:50 - 00527944 _____ (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.dll
2013-09-02 19:28 - 2013-04-04 14:50 - 02191944 _____ (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.dll
2013-09-02 19:28 - 2012-10-25 10:20 - 00074312 _____ (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamtoast.dll
2013-09-02 19:28 - 2013-04-04 14:50 - 00527944 _____ (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.DLL
2012-07-26 03:32 - 2012-07-26 05:05 - 00137728 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\advpack.DLL
2012-07-26 03:57 - 2012-07-26 05:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2013-09-02 19:28 - 2013-04-04 14:50 - 01127496 _____ (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamcore.DLL
2013-09-02 19:28 - 2013-02-16 10:54 - 00914432 _____ (Igor Pavlov) C:\Program Files (x86)\Malwarebytes' Anti-Malware\7z.dll
2013-09-02 19:28 - 2011-06-01 10:16 - 00496976 _____ (vbAccelerator) C:\Program Files (x86)\Malwarebytes' Anti-Malware\vbalsgrid6.ocx
2013-09-02 19:28 - 2012-05-22 17:05 - 00046416 _____ (vbAccelerator) C:\Program Files (x86)\Malwarebytes' Anti-Malware\ssubtmr6.dll
2013-09-02 19:28 - 2013-04-04 14:50 - 02191944 _____ (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.DLL
2012-07-26 02:59 - 2012-07-26 05:05 - 00465408 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\dlnashext.dll
==================== Alternate Data Streams (whitelisted) ==========
AlternateDataStreams: C:\Users\Thomas\Downloads\Thumbs.db:encryptable
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/02/2013 01:19:48 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2547
Error: (09/02/2013 01:19:48 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2547
Error: (09/02/2013 01:19:48 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/02/2013 01:19:47 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1485
Error: (09/02/2013 01:19:47 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1485
Error: (09/02/2013 01:19:47 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2013 06:44:04 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 13507266
Error: (09/01/2013 06:44:04 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 13507266
Error: (09/01/2013 06:44:04 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2013 06:44:02 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 13505094
System errors:
=============
Error: (09/02/2013 06:49:01 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht.
Error: (09/01/2013 00:35:10 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Dell Digital Delivery Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 1000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (09/01/2013 00:29:35 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Error: (09/01/2013 00:29:35 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Error: (09/01/2013 00:28:54 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Error: (09/01/2013 00:28:51 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Error: (09/01/2013 00:28:46 PM) (Source: DCOM) (User: PC-Wohnzimmer)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (09/01/2013 09:26:36 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Error: (09/01/2013 09:26:36 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht.
Error: (09/01/2013 09:25:20 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Microsoft Office Sessions:
=========================
Error: (09/02/2013 01:19:48 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2547
Error: (09/02/2013 01:19:48 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2547
Error: (09/02/2013 01:19:48 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/02/2013 01:19:47 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1485
Error: (09/02/2013 01:19:47 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1485
Error: (09/02/2013 01:19:47 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2013 06:44:04 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 13507266
Error: (09/01/2013 06:44:04 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 13507266
Error: (09/01/2013 06:44:04 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2013 06:44:02 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 13505094
5) GMER.txt Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-09-02 21:31:58
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000003a WDC_WD10JPVT-75A1YT0 rev.01.01A01 931,51GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Thomas\AppData\Local\Temp\awdcypow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\system32\ntoskrnl.exe!KiCpuId + 988 fffff8017785541c 1 byte [31]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1828] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fe8027177a 1 byte [27]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1828] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 308 000007fe8027177c 2 bytes [FE, 07]
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007fe7ead257c 8 bytes JMP 000007ff7e4f03b0
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007fe7ead6b10 9 bytes JMP 000007ff7e4f0308
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\KERNEL32.DLL!K32GetModuleFileNameExW 000007fe7eb55658 7 bytes JMP 000007ff7e4f0260
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007fe7eb55778 7 bytes JMP 000007ff7e4f02d0
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007fe7eb71564 7 bytes JMP 000007ff7e4f0340
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007fe7eb840e4 7 bytes JMP 000007ff7e4f0298
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007fe7eb84178 8 bytes JMP 000007ff7e4f0228
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007fe7eb8479c 8 bytes JMP 000007ff7e4f0378
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\USER32.dll!CreateWindowExW 000007fe7e97c5b0 7 bytes JMP 000007ff7e4f0490
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007fe7e9831f0 9 bytes JMP 000007ff7e4f03e8
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007fe7e9833e0 5 bytes JMP 000007ff7e4f0458
.text C:\Windows\System32\dwm.exe[5404] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007fe7e987160 5 bytes JMP 000007ff7e4f0420
.text C:\Windows\Explorer.EXE[7992] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fe77e61532 4 bytes [E6, 77, FE, 07]
.text C:\Windows\Explorer.EXE[7992] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fe77e6153a 4 bytes [E6, 77, FE, 07]
.text C:\Windows\Explorer.EXE[7992] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fe77e6165a 4 bytes [E6, 77, FE, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5716] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fe77e61532 4 bytes [E6, 77, FE, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5716] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fe77e6153a 4 bytes [E6, 77, FE, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5716] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fe77e6165a 4 bytes [E6, 77, FE, 07]
.text c:\PROGRA~1\mcafee.com\agent\mcagent.exe[5260] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 306 000007fe8027177a 1 byte [27]
.text c:\PROGRA~1\mcafee.com\agent\mcagent.exe[5260] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 308 000007fe8027177c 2 bytes [FE, 07]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [836:7560] fffff960007b25e8
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Ich hoffe, ich habe alles benötigte gepostet.
Freue mich auf Eure Hilfe!!
Viele Grüße, Sabine |