Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.04.2014
Suchlauf-Zeit: 14:58:39
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.10.04
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: eistee
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 284805
Verstrichene Zeit: 12 Min, 11 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[649c26da10f05aa6cd468b91b252de22]
Ordner: 0
(No malicious items detected)
Dateien: 2
PUP.Optional.Amonetize.A, C:\Users\eistee\Downloads\SciLors Grooveshark__3502_il14843 (1).exe, In Quarantäne, [bb45eb15bd4315ebdb7e300c43bd09f7],
PUP.Optional.Amonetize.A, C:\Users\eistee\Downloads\SciLors Grooveshark__3502_il14843.exe, In Quarantäne, [7f81ba467c84b44c0059a19b669ae51b],
Physische Sektoren: 0
(No malicious items detected)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.023 - Bericht erstellt am 10/04/2014 um 15:09:10
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : eistee - EISTEE-PC
# Gestartet von : C:\Users\eistee\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\eistee\AppData\Local\CrashRpt
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Google Chrome v34.0.1847.116
[ Datei : C:\Users\eistee\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [12344 octets] - [31/03/2014 22:10:44]
AdwCleaner[R1].txt - [4353 octets] - [01/04/2014 22:16:48]
AdwCleaner[R2].txt - [1095 octets] - [10/04/2014 15:06:47]
AdwCleaner[S0].txt - [10393 octets] - [31/03/2014 22:11:46]
AdwCleaner[S1].txt - [2744 octets] - [01/04/2014 22:17:53]
AdwCleaner[S2].txt - [1019 octets] - [10/04/2014 15:09:10]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1079 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x64
Ran by eistee on 10.04.2014 at 15:13:53,35
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2733127231-3189410917-201622006-1000\Software\sweetim
~~~ Files
~~~ Folders
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.04.2014 at 15:23:39,50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 28 days old and could be outdated)
Ran by eistee (administrator) on EISTEE-PC on 10-04-2014 15:26:57
Running from C:\Users\eistee\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(LULU Software) C:\Program Files (x86)\Soda PDF 5\HelperService.exe
(LULU Software) C:\Program Files (x86)\Soda PDF 5\ConversionService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\system32\PrintIsolationHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
() F:\phonostar-Player\phonostarTimer.exe
() C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe
(Apple Inc.) F:\Katrin\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dropbox, Inc.) C:\Users\eistee\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] - F:\Real\RealPlayer\update\realsched.exe [296096 2012-11-28] (RealNetworks, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] - F:\Katrin\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-08] (AVAST Software)
HKU\S-1-5-21-2733127231-3189410917-201622006-1000\...\Run: [phonostar-PlayerTimer] - F:\phonostar-Player\phonostarTimer.exe [41472 2012-04-03] ()
HKU\S-1-5-21-2733127231-3189410917-201622006-1000\...\Run: [Google+ Auto Backup] - C:\Users\eistee\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [3619096 2014-01-06] (Google Inc.)
HKU\S-1-5-21-2733127231-3189410917-201622006-1000\...\Run: [AudialsNotifier] - C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe [473352 2014-02-18] ()
Startup: C:\Users\eistee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\eistee\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Soda PDF 5 IE Helper - {C737F472-1193-4281-BF53-A00B67AB3E19} - C:\Program Files (x86)\Soda PDF 5\PDFIEHelper.dll (LULU Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ChromeFrame BHO - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files (x86)\Google\Chrome Frame\Application\32.0.1700.107\npchrome_frame.dll (Google Inc.)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - No File
Handler-x32: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files (x86)\Google\Chrome Frame\Application\32.0.1700.107\npchrome_frame.dll (Google Inc.)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\eistee\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-01]
CHR Extension: (Google Drive) - C:\Users\eistee\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-01]
CHR Extension: (YouTube) - C:\Users\eistee\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-01]
CHR Extension: (Google-Suche) - C:\Users\eistee\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01]
CHR Extension: (avast! Online Security) - C:\Users\eistee\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-04-01]
CHR Extension: (Google Wallet) - C:\Users\eistee\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-01]
CHR Extension: (Google Mail) - C:\Users\eistee\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-01]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-04-08]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-08] (AVAST Software)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\RpcAgentSrv.exe [68760 2009-06-13] (SiSoftware)
R2 Soda PDF 5 Helper Service; C:\Program Files (x86)\Soda PDF 5\HelperService.exe [1069408 2013-01-29] (LULU Software)
R2 Soda PDF 5 Service; C:\Program Files (x86)\Soda PDF 5\ConversionService.exe [794464 2013-01-29] (LULU Software)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-08] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-08] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-08] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-08] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-08] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-04-08] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-04-08] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-10] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-02-18] (Audials AG)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-10 15:26 - 2014-04-10 15:26 - 00011504 _____ () C:\Users\eistee\Desktop\FRST.txt
2014-04-10 15:24 - 2014-04-10 15:24 - 00000933 _____ () C:\Users\eistee\Desktop\JRT1.txt
2014-04-10 15:13 - 2014-04-10 15:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-10 15:11 - 2014-04-10 15:25 - 00000000 ____D () C:\Users\eistee\Desktop\Neuer Ordner
2014-04-10 15:11 - 2014-04-10 15:11 - 00001159 _____ () C:\Users\eistee\Desktop\AdwCleaner[S2].txt
2014-04-10 15:11 - 2014-04-10 15:11 - 00000000 ____D () C:\Users\eistee\AppData\Local\CrashRpt
2014-04-10 15:03 - 2014-04-10 15:03 - 00001649 _____ () C:\Users\eistee\Desktop\mbam.txt
2014-04-10 14:44 - 2014-04-10 15:11 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-10 14:44 - 2014-04-10 14:44 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-10 14:44 - 2014-04-10 14:44 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-10 14:44 - 2014-04-10 14:44 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-10 14:44 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-10 14:44 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-10 14:44 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-10 14:40 - 2014-04-10 14:40 - 01016261 _____ (Thisisu) C:\Users\eistee\Desktop\JRT.exe
2014-04-10 14:39 - 2014-04-10 14:39 - 01426178 _____ () C:\Users\eistee\Desktop\adwcleaner.exe
2014-04-09 16:07 - 2014-04-09 16:07 - 00018645 _____ () C:\ComboFix.txt
2014-04-09 15:55 - 2014-04-09 15:55 - 05196025 ____R (Swearware) C:\Users\eistee\Desktop\ComboFix.exe
2014-04-09 15:10 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-09 15:10 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-09 15:10 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-09 15:10 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-09 15:10 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-09 15:10 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-09 15:10 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-09 15:10 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-09 15:07 - 2014-04-09 16:07 - 00000000 ____D () C:\Qoobox
2014-04-09 15:06 - 2014-04-09 15:35 - 00000000 ____D () C:\Windows\erdnt
2014-04-09 15:06 - 2014-04-09 15:06 - 05196025 ____R (Swearware) C:\Users\eistee\Downloads\ComboFix.exe
2014-04-09 15:04 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-09 15:04 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-09 15:04 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-09 15:04 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-09 15:04 - 2014-03-04 13:08 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 15:04 - 2014-03-04 13:08 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-04-09 15:04 - 2014-03-04 13:08 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 15:04 - 2014-03-04 13:08 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 15:04 - 2014-03-04 13:08 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-04-09 15:04 - 2014-03-04 13:08 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 15:04 - 2014-03-04 13:08 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 15:04 - 2014-03-04 13:07 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-04-09 15:04 - 2014-03-04 13:03 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:39 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 15:04 - 2014-03-04 12:38 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 15:04 - 2014-03-04 12:38 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-04-09 15:04 - 2014-03-04 12:38 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 15:04 - 2014-03-04 12:38 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 11:33 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 15:04 - 2014-03-04 11:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 15:04 - 2014-03-04 11:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 11:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 11:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-04-09 15:04 - 2014-03-04 11:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-04-09 15:04 - 2014-02-04 04:37 - 00191424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 15:04 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 15:04 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 15:04 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 15:04 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 15:04 - 2014-01-24 04:40 - 01684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-08 21:03 - 2014-04-08 21:03 - 00110592 _____ () C:\Users\eistee\Downloads\image.jpeg
2014-04-08 20:51 - 2014-04-08 20:51 - 00000000 ____D () C:\Users\eistee\Downloads\krolopgerst_lightroom_looks_v1
2014-04-08 20:50 - 2014-04-08 20:50 - 00021205 _____ () C:\Users\eistee\Downloads\krolopgerst_lightroom_looks_v1.zip
2014-04-08 18:29 - 2014-04-08 18:32 - 00030967 _____ () C:\Users\eistee\Downloads\FRST.txt
2014-04-08 18:29 - 2014-04-08 18:32 - 00028504 _____ () C:\Users\eistee\Downloads\Addition.txt
2014-04-08 18:28 - 2014-04-10 15:26 - 00000000 ____D () C:\FRST
2014-04-08 18:27 - 2014-04-08 18:27 - 02157056 _____ (Farbar) C:\Users\eistee\Desktop\FRST64.exe
2014-04-08 17:17 - 2014-04-08 17:17 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-04-08 17:17 - 2014-04-08 17:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-04-08 17:17 - 2014-04-08 17:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-04-08 17:17 - 2014-04-08 17:17 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-04-08 17:14 - 2014-04-08 17:15 - 30796712 _____ (Oracle Corporation) C:\Users\eistee\Downloads\jre-7u51-windows-x64.exe
2014-04-08 16:59 - 2014-04-08 16:59 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-01 22:53 - 2014-04-08 20:07 - 00000106 _____ () C:\Windows\Podcasts.INI
2014-04-01 22:40 - 2014-04-01 22:40 - 00000950 _____ () C:\Users\Public\Desktop\Audials 11.lnk
2014-04-01 22:40 - 2014-04-01 22:40 - 00000000 ____D () C:\Program Files (x86)\Audials
2014-04-01 22:39 - 2014-04-01 22:39 - 54041344 _____ () C:\Users\eistee\Downloads\Audials_One-Setup.exe
2014-04-01 22:22 - 2014-04-10 14:35 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-31 22:10 - 2014-04-10 15:09 - 00000000 ____D () C:\AdwCleaner
2014-03-31 22:10 - 2014-03-31 22:10 - 01950720 _____ () C:\Users\eistee\Downloads\adwcleaner_3.022 (1).exe
2014-03-31 22:06 - 2014-03-31 22:06 - 00000000 ____D () C:\ProgramData\PDF Architect
2014-03-31 21:53 - 2014-03-31 22:00 - 00000000 ____D () C:\Program Files (x86)\SciLor's grooveshark(tm).com Downloader
2014-03-31 21:52 - 2014-03-31 21:52 - 00689856 _____ () C:\Users\eistee\Downloads\SciLors_Grooveshark(tm)_DownloaderSetup.exe
2014-03-31 21:28 - 2014-03-31 21:33 - 00000444 __RSH () C:\ProgramData\ntuser.pol
2014-03-31 21:17 - 2014-04-01 22:40 - 00000000 ____D () C:\ProgramData\RapidSolution
2014-03-31 21:17 - 2014-03-31 21:17 - 00000550 _____ () C:\Users\Public\Desktop\AudialsOne 4.lnk
2014-03-31 21:16 - 2014-04-01 22:39 - 00000000 ____D () C:\Users\eistee\AppData\Local\RapidSolution
2014-03-28 13:36 - 2014-03-28 13:36 - 00000000 ____D () C:\Users\eistee\AppData\Roaming\DropboxMaster
2014-03-16 19:39 - 2014-03-19 00:08 - 00005632 _____ () C:\Users\eistee\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-12 18:23 - 2014-03-12 18:23 - 05777288 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-03-12 16:48 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 16:48 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 16:48 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 16:48 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 16:48 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-12 16:48 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-12 16:48 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-12 16:48 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-12 16:48 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-12 16:48 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 16:48 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-12 16:48 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-12 16:48 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-12 16:48 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-12 16:48 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-12 16:48 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 16:48 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-12 16:48 - 2014-02-07 03:25 - 03159552 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 16:48 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 16:48 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-12 16:48 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-12 16:47 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 16:47 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 16:47 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 16:47 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 16:47 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 16:47 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 16:47 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 16:47 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 16:47 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 16:47 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 16:47 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-12 16:47 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 16:47 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 16:47 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-12 16:47 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-12 16:47 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 16:47 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-12 16:47 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 16:47 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-12 16:47 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 16:47 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 16:47 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-12 16:47 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
==================== One Month Modified Files and Folders =======
2014-04-10 15:27 - 2014-04-10 15:26 - 00011504 _____ () C:\Users\eistee\Desktop\FRST.txt
2014-04-10 15:26 - 2014-04-08 18:28 - 00000000 ____D () C:\FRST
2014-04-10 15:25 - 2014-04-10 15:11 - 00000000 ____D () C:\Users\eistee\Desktop\Neuer Ordner
2014-04-10 15:24 - 2014-04-10 15:24 - 00000933 _____ () C:\Users\eistee\Desktop\JRT1.txt
2014-04-10 15:23 - 2013-06-23 21:37 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-10 15:17 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-10 15:17 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-10 15:13 - 2014-04-10 15:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-10 15:13 - 2012-07-19 15:29 - 01269301 _____ () C:\Windows\WindowsUpdate.log
2014-04-10 15:11 - 2014-04-10 15:11 - 00001159 _____ () C:\Users\eistee\Desktop\AdwCleaner[S2].txt
2014-04-10 15:11 - 2014-04-10 15:11 - 00000000 ____D () C:\Users\eistee\AppData\Local\CrashRpt
2014-04-10 15:11 - 2014-04-10 14:44 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-10 15:11 - 2013-01-31 23:24 - 00000000 ___RD () C:\Users\eistee\Dropbox
2014-04-10 15:11 - 2013-01-31 23:21 - 00000000 ____D () C:\Users\eistee\AppData\Roaming\Dropbox
2014-04-10 15:10 - 2013-08-25 14:03 - 00071599 _____ () C:\Windows\setupact.log
2014-04-10 15:10 - 2013-01-11 17:32 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-10 15:10 - 2012-07-19 15:53 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-04-10 15:10 - 2012-07-19 15:45 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-04-10 15:10 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-10 15:09 - 2014-03-31 22:10 - 00000000 ____D () C:\AdwCleaner
2014-04-10 15:03 - 2014-04-10 15:03 - 00001649 _____ () C:\Users\eistee\Desktop\mbam.txt
2014-04-10 14:59 - 2013-08-25 14:56 - 00266114 _____ () C:\Windows\PFRO.log
2014-04-10 14:44 - 2014-04-10 14:44 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-10 14:44 - 2014-04-10 14:44 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-10 14:44 - 2014-04-10 14:44 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-10 14:40 - 2014-04-10 14:40 - 01016261 _____ (Thisisu) C:\Users\eistee\Desktop\JRT.exe
2014-04-10 14:39 - 2014-04-10 14:39 - 01426178 _____ () C:\Users\eistee\Desktop\adwcleaner.exe
2014-04-10 14:35 - 2014-04-01 22:22 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-10 14:35 - 2013-01-11 17:32 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-10 00:04 - 2009-07-14 04:34 - 00000539 _____ () C:\Windows\win.ini
2014-04-10 00:02 - 2013-08-21 22:59 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 00:02 - 2012-07-19 15:48 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-09 16:07 - 2014-04-09 16:07 - 00018645 _____ () C:\ComboFix.txt
2014-04-09 16:07 - 2014-04-09 15:07 - 00000000 ____D () C:\Qoobox
2014-04-09 16:05 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-09 15:55 - 2014-04-09 15:55 - 05196025 ____R (Swearware) C:\Users\eistee\Desktop\ComboFix.exe
2014-04-09 15:36 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-04-09 15:35 - 2014-04-09 15:06 - 00000000 ____D () C:\Windows\erdnt
2014-04-09 15:34 - 2012-07-19 15:33 - 00000000 ____D () C:\Users\eistee
2014-04-09 15:06 - 2014-04-09 15:06 - 05196025 ____R (Swearware) C:\Users\eistee\Downloads\ComboFix.exe
2014-04-08 21:03 - 2014-04-08 21:03 - 00110592 _____ () C:\Users\eistee\Downloads\image.jpeg
2014-04-08 20:51 - 2014-04-08 20:51 - 00000000 ____D () C:\Users\eistee\Downloads\krolopgerst_lightroom_looks_v1
2014-04-08 20:50 - 2014-04-08 20:50 - 00021205 _____ () C:\Users\eistee\Downloads\krolopgerst_lightroom_looks_v1.zip
2014-04-08 20:16 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-04-08 20:16 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-04-08 20:16 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-08 20:07 - 2014-04-01 22:53 - 00000106 _____ () C:\Windows\Podcasts.INI
2014-04-08 18:32 - 2014-04-08 18:29 - 00030967 _____ () C:\Users\eistee\Downloads\FRST.txt
2014-04-08 18:32 - 2014-04-08 18:29 - 00028504 _____ () C:\Users\eistee\Downloads\Addition.txt
2014-04-08 18:27 - 2014-04-08 18:27 - 02157056 _____ (Farbar) C:\Users\eistee\Desktop\FRST64.exe
2014-04-08 17:17 - 2014-04-08 17:17 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-04-08 17:17 - 2014-04-08 17:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-04-08 17:17 - 2014-04-08 17:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-04-08 17:17 - 2014-04-08 17:17 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-04-08 17:15 - 2014-04-08 17:14 - 30796712 _____ (Oracle Corporation) C:\Users\eistee\Downloads\jre-7u51-windows-x64.exe
2014-04-08 16:59 - 2014-04-08 16:59 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-08 16:59 - 2014-03-10 16:06 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-04-08 16:59 - 2013-03-27 14:28 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-08 16:59 - 2013-03-27 14:28 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-08 16:59 - 2012-07-19 15:53 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-04-08 16:59 - 2012-07-19 15:53 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-04-08 16:59 - 2012-07-19 15:53 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-08 16:59 - 2012-07-19 15:53 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-08 16:59 - 2012-07-19 15:53 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-08 16:59 - 2012-07-19 15:53 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-04-03 09:51 - 2014-04-10 14:44 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-10 14:44 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-10 14:44 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-01 22:40 - 2014-04-01 22:40 - 00000950 _____ () C:\Users\Public\Desktop\Audials 11.lnk
2014-04-01 22:40 - 2014-04-01 22:40 - 00000000 ____D () C:\Program Files (x86)\Audials
2014-04-01 22:40 - 2014-03-31 21:17 - 00000000 ____D () C:\ProgramData\RapidSolution
2014-04-01 22:39 - 2014-04-01 22:39 - 54041344 _____ () C:\Users\eistee\Downloads\Audials_One-Setup.exe
2014-04-01 22:39 - 2014-03-31 21:16 - 00000000 ____D () C:\Users\eistee\AppData\Local\RapidSolution
2014-04-01 22:23 - 2013-01-11 16:47 - 00001124 _____ () C:\Users\eistee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2014-04-01 22:22 - 2012-07-19 15:53 - 00000000 ____D () C:\Users\eistee\AppData\Local\Google
2014-04-01 22:22 - 2012-07-19 15:53 - 00000000 ____D () C:\Program Files (x86)\Google
2014-04-01 22:17 - 2013-11-19 20:37 - 00000997 _____ () C:\Users\eistee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-01 22:17 - 2012-07-19 15:36 - 00000967 _____ () C:\Users\eistee\Desktop\Internet Explorer.lnk
2014-03-31 22:11 - 2013-07-31 13:59 - 00000000 ____D () C:\Users\eistee\AppData\Roaming\Common
2014-03-31 22:10 - 2014-03-31 22:10 - 01950720 _____ () C:\Users\eistee\Downloads\adwcleaner_3.022 (1).exe
2014-03-31 22:06 - 2014-03-31 22:06 - 00000000 ____D () C:\ProgramData\PDF Architect
2014-03-31 22:02 - 2014-03-08 19:28 - 00000000 ____D () C:\Program Files (x86)\Nikon
2014-03-31 22:01 - 2012-07-19 15:36 - 00000000 ___RD () C:\Users\eistee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-31 22:00 - 2014-03-31 21:53 - 00000000 ____D () C:\Program Files (x86)\SciLor's grooveshark(tm).com Downloader
2014-03-31 21:52 - 2014-03-31 21:52 - 00689856 _____ () C:\Users\eistee\Downloads\SciLors_Grooveshark(tm)_DownloaderSetup.exe
2014-03-31 21:33 - 2014-03-31 21:28 - 00000444 __RSH () C:\ProgramData\ntuser.pol
2014-03-31 21:28 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-03-31 21:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-03-31 21:17 - 2014-03-31 21:17 - 00000550 _____ () C:\Users\Public\Desktop\AudialsOne 4.lnk
2014-03-31 03:16 - 2014-04-09 15:04 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 15:04 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-28 13:36 - 2014-03-28 13:36 - 00000000 ____D () C:\Users\eistee\AppData\Roaming\DropboxMaster
2014-03-28 13:36 - 2013-01-31 23:24 - 00001021 _____ () C:\Users\eistee\Desktop\Dropbox.lnk
2014-03-28 13:36 - 2013-01-31 23:22 - 00000000 ____D () C:\Users\eistee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-03-27 23:48 - 2012-07-19 15:42 - 00000000 ____D () C:\Users\eistee\AppData\Roaming\Adobe
2014-03-26 22:27 - 2013-01-11 17:32 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-26 22:27 - 2013-01-11 17:32 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-24 21:42 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-22 16:53 - 2014-03-08 19:31 - 00000000 ____D () C:\Users\eistee\AppData\Roaming\Nikon
2014-03-22 16:53 - 2014-03-08 19:28 - 00000020 ____H () C:\ProgramData\PKP_DLev.DAT
2014-03-22 16:52 - 2014-03-08 19:28 - 00000020 ____H () C:\ProgramData\PKP_DLet.DAT
2014-03-19 00:08 - 2014-03-16 19:39 - 00005632 _____ () C:\Users\eistee\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-12 20:53 - 2009-07-14 06:45 - 00553984 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-12 20:51 - 2013-07-14 16:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-12 18:23 - 2014-03-12 18:23 - 05777288 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-03-12 18:23 - 2013-06-23 21:37 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-12 18:23 - 2012-07-19 15:34 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 18:23 - 2012-07-19 15:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
Files to move or delete:
====================
C:\ProgramData\PKP_DLeo.DAT
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLev.DAT
Some content of TEMP:
====================
C:\Users\eistee\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9t9zhv.dll
C:\Users\eistee\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe
[2012-05-09 19:32] - [2012-05-09 19:32] - 0391168 ____A (Microsoft Corporation) EC5BD25A41E9B633CB39120DBB0939DC
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2012-05-09 20:12] - [2012-05-09 20:12] - 2872320 ____A (Microsoft Corporation) A27FB0CA2971BEC02595902A9FD35D6D
C:\Windows\SysWOW64\explorer.exe
[2012-05-09 20:12] - [2012-05-09 20:12] - 2616320 ____A (Microsoft Corporation) 82B49E32080BF5C469BF877C473B15EB
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll
[2012-05-09 19:42] - [2012-05-09 19:42] - 1008128 ____A (Microsoft Corporation) 7FB4D54B502C6CF2E35B8188FA4CC08C
C:\Windows\SysWOW64\User32.dll
[2012-05-09 19:42] - [2012-05-09 19:42] - 0833024 ____A (Microsoft Corporation) 9B836EE76E3A99052EF6DEA52B41D1BE
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2012-05-09 20:09] - [2012-05-09 20:09] - 0512512 ____A (Microsoft Corporation) 29AC62409BF4939EE14D70EC07CA12BB
ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\Windows\System32\Drivers\volsnap.sys
[2012-05-09 19:43] - [2012-05-09 19:43] - 0296816 ____A (Microsoft Corporation) ABFECA99D72CE81E5C3612861F03B0CA
LastRegBack: 2014-04-09 16:25
==================== End Of Log ============================
--- --- ---
--- --- ---