![]() |
Plagegeister aller Art und deren Bekämpfung: Desktop schwarz und keine Programme gehen mehrWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
| ![]() Desktop schwarz und keine Programme gehen mehr Servus Leute, seit heute spinnt mein PC komplett. Beim Einlogbildschirm ist kein Bild mehr über meinem Namen. Nach dem Login kommt die Meldung, dass meine Windows-Version nicht original ist. Wenn ich diese abbreche, lande ich auf dem Desktop mit schwarzem Hintergrund und dort kommen andauernd Fehler. Wenn ich diese einige Male abbreche kann ich schließlich versuchen irgendetwas zu öffnen, aber bei fast jedem Programm kommt eine Fehlermeldung, dass irgendetwas nicht gefunden wurde. Ich habe dann AdwCleaner drüber laufen lassen und dieser hat ein paar Sachen gefunden, aber leider hat das Nichts gebracht. Wäre sehr dankbar für eure Hilfe, da ich den PC nur ungern neu aufsetzen will MfG Wolf |
![]() | #2 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Desktop schwarz und keine Programme gehen mehr hi,
__________________Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
__________________ |
![]() | #3 |
| ![]() Desktop schwarz und keine Programme gehen mehr Hier die FRST.txt
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-05-2015 Ran by SYSTEM on MININT-3UAEPE4 on 27-05-2015 13:07:57 Running from K:\ Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation) HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" HKLM\...\Run: [Seagull Drivers] => ssdal_nc.exe startup HKLM\...\Run: [ACPW06DE] => "C:\Program Files\ACD Systems\ACDSee Pro\6.0\ACDSeePro6InTouch2.exe" /pid ACPW06DE HKLM-x32\...\Run: [StartCCC] => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun HKLM-x32\...\Run: [ECtiClient] => C:\Program Files (x86)\Aastra\BusinessCTI 3\eCtiClient.exe [19174736 2011-03-23] (ESTOS GmbH) HKLM-x32\...\Run: [ClocX] => C:\Program Files (x86)\ClocX\ClocX.exe [2090496 2013-01-14] (BonSoft) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [728312 2015-05-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DV4TS.EXE] => c:\windows\SysWOW64\DV4TS.EXE [138304 2006-11-19] (Tobit Software) HKLM-x32\...\Run: [Syncios device service] => C:\Program Files (x86)\Syncios\SynciosDeviceService.exe [815104 2015-05-25] () HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3498728 2015-05-01] (Adobe Systems Inc.) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [X] HKU\David\...\Policies\Explorer: [] HKU\david.EDERER\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8204056 2015-04-23] (Piriform Ltd) Startup: C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TCD-TerminWarner.lnk [2013-12-05] ShortcutTarget: TCD-TerminWarner.lnk -> C:\Program Files (x86)\TCD\TCD-Termin\DKTerminWarner.exe (DAKO GmbH, Jena) ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-07] (Advanced Micro Devices, Inc.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [827640 2015-05-05] (Avira Operations GmbH & Co. KG) S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-05-05] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-05-05] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1185584 2015-05-05] (Avira Operations GmbH & Co. KG) S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.) S2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.) S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG) S2 DiagTrack; C:\Windows\system32\diagtrack.dll [1254400 2015-04-27] (Microsoft Corporation) S2 EACUSrv; C:\Windows\system32\EACUSrv.exe [3302728 2011-03-23] (ESTOS GmbH) S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation) S2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) S2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) S2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [X] S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [X] S2 clr_optimization_v4.0.30319_32; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [X] S2 clr_optimization_v4.0.30319_64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [X] S3 FlexNet Licensing Service 64; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe" [X] S3 GSService; "C:\Windows\SysWOW64\GSService.exe" [X] S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S3 LBTServ; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [X] S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.8.150\McCHSvc.exe" [X] S3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [X] S4 NetMsmqActivator; "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator [X] S4 NetPipeActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [X] S4 NetTcpActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [X] S4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [X] S3 ose; "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE" [X] S3 osppsvc; "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" [X] S3 SwitchBoard; "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [152744 2015-05-05] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-05-05] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-07-23] (Avira Operations GmbH & Co. KG) S2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-03-03] (Avira Operations GmbH & Co. KG) S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation) S2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-06-21] (Anchorfree Inc.) S2 AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X] S2 UltraMonUtility; \??\C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-27 13:07 - 2015-05-27 13:07 - 00000000 ____D () C:\FRST 2015-05-27 11:59 - 2015-05-27 11:52 - 02108928 _____ (Farbar) C:\Users\david.EDERER\Desktop\FRST64.exe 2015-05-27 11:17 - 2015-05-27 11:17 - 00602112 _____ (OldTimer Tools) C:\Users\david.EDERER\Downloads\OTL.exe 2015-05-27 10:58 - 2015-05-27 10:58 - 05437024 _____ (TeamViewer) C:\Users\david.EDERER\Downloads\TeamViewerQS_de.exe 2015-05-27 10:50 - 2015-05-27 10:53 - 00000000 ____D () C:\AdwCleaner 2015-05-27 10:50 - 2015-05-27 10:50 - 02209792 _____ () C:\Users\david.EDERER\Downloads\adwcleaner_4.205.exe 2015-05-27 10:47 - 2015-01-10 14:20 - 04071281 _____ () C:\Users\david.EDERER\Desktop\Windows Loader 2.2.2.zip 2015-05-27 10:21 - 2015-05-27 10:21 - 00000389 _____ () C:\Windows\SysWOW64\EACUSrv.log 2015-05-27 10:21 - 2011-03-23 05:41 - 00888320 _____ (Aastra) C:\Windows\System32\edial.tsp 2015-05-27 10:21 - 2011-03-23 05:41 - 00872448 _____ (Aastra) C:\Windows\SysWOW64\edial.tsp 2015-05-27 10:20 - 2015-05-27 11:57 - 00000504 _____ () C:\Windows\setupact.log 2015-05-27 10:20 - 2015-05-27 11:57 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-05-27 10:20 - 2015-05-27 10:20 - 00000000 ____D () C:\usr 2015-05-27 10:20 - 2015-05-27 10:20 - 00000000 ____D () C:\ProgramData\GroupPolicy 2015-05-27 10:20 - 2015-05-27 10:20 - 00000000 ____D () C:\ProgramData\Apple 2015-05-27 10:20 - 2015-05-27 10:20 - 00000000 ____D () C:\Program Files\Windows Small Business Server 2015-05-27 10:20 - 2015-05-27 10:20 - 00000000 ____D () C:\Program Files (x86)\Windows Small Business Server 2015-05-27 10:20 - 2015-05-27 10:20 - 00000000 _____ () C:\Windows\setuperr.log 2015-05-27 10:20 - 2015-05-27 10:20 - 00000000 _____ () C:\Windows\ativpsrm.bin 2015-05-27 06:42 - 2015-05-27 06:43 - 00000000 ____D () C:\Users\david.EDERER\Desktop\Wallpaper PC 2015-05-27 06:38 - 2015-05-27 06:41 - 00000000 ____D () C:\Users\david.EDERER\Desktop\cleo wattenström 2015-05-27 06:38 - 2015-05-27 06:38 - 00000000 ____D () C:\Users\david.EDERER\Desktop\Neuer Ordner (2) 2015-05-26 15:48 - 2015-05-26 15:48 - 00000991 _____ () C:\Users\Public\Desktop\Syncios.lnk 2015-05-26 15:45 - 2015-05-26 15:49 - 00000000 ____D () C:\Users\david.EDERER\Desktop\Neuer Ordner 2015-05-18 16:49 - 2015-05-18 16:51 - 00000000 ____D () C:\Users\david.EDERER\Desktop\Tat 2015-05-18 06:43 - 2015-05-18 06:44 - 00000000 ____D () C:\Users\david.EDERER\Desktop\Koi 2015-05-13 17:19 - 2015-05-01 14:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll 2015-05-13 17:19 - 2015-05-01 14:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-05-13 06:28 - 2015-05-05 02:29 - 00342016 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll 2015-05-13 06:28 - 2015-05-05 02:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-05-13 06:28 - 2015-04-22 03:28 - 00389840 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2015-05-13 06:28 - 2015-04-22 02:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-05-13 06:28 - 2015-04-21 18:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2015-05-13 06:28 - 2015-04-21 18:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2015-05-13 06:28 - 2015-04-21 18:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2015-05-13 06:28 - 2015-04-21 17:51 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2015-05-13 06:28 - 2015-04-21 17:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2015-05-13 06:28 - 2015-04-21 17:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec 2015-05-13 06:28 - 2015-04-21 17:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2015-05-13 06:28 - 2015-04-21 17:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2015-05-13 06:28 - 2015-04-21 17:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2015-05-13 06:28 - 2015-04-21 17:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2015-05-13 06:28 - 2015-04-21 17:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2015-05-13 06:28 - 2015-04-21 17:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2015-05-13 06:28 - 2015-04-21 17:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2015-05-13 06:28 - 2015-04-21 17:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2015-05-13 06:28 - 2015-04-21 17:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2015-05-13 06:28 - 2015-04-21 17:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2015-05-13 06:28 - 2015-04-21 17:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2015-05-13 06:28 - 2015-04-21 17:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2015-05-13 06:28 - 2015-04-21 17:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-05-13 06:28 - 2015-04-21 17:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-05-13 06:28 - 2015-04-21 17:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2015-05-13 06:28 - 2015-04-21 17:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2015-05-13 06:28 - 2015-04-21 17:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-05-13 06:28 - 2015-04-21 17:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-05-13 06:28 - 2015-04-21 17:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-05-13 06:28 - 2015-04-21 17:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-05-13 06:28 - 2015-04-21 17:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2015-05-13 06:28 - 2015-04-21 17:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2015-05-13 06:28 - 2015-04-21 17:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-05-13 06:28 - 2015-04-21 17:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2015-05-13 06:28 - 2015-04-21 17:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-05-13 06:28 - 2015-04-21 17:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-05-13 06:28 - 2015-04-21 17:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-05-13 06:28 - 2015-04-21 17:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-05-13 06:28 - 2015-04-21 16:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-05-13 06:28 - 2015-04-21 16:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-05-13 06:28 - 2015-04-21 16:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-05-13 06:28 - 2015-04-21 16:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2015-05-13 06:28 - 2015-04-21 16:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2015-05-13 06:28 - 2015-04-21 16:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-05-13 06:28 - 2015-04-21 16:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2015-05-13 06:28 - 2015-04-21 16:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2015-05-13 06:28 - 2015-04-21 16:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-05-13 06:28 - 2015-04-21 16:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2015-05-13 06:28 - 2015-04-21 16:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-05-13 06:28 - 2015-04-21 16:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-05-13 06:28 - 2015-04-21 16:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-05-13 06:28 - 2015-04-21 16:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-05-13 06:28 - 2015-04-21 16:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2015-05-13 06:28 - 2015-04-21 16:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-05-13 06:28 - 2015-04-21 16:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-05-13 06:28 - 2015-04-21 16:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-05-13 06:28 - 2015-04-21 16:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-05-13 06:28 - 2015-04-21 16:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2015-05-13 06:28 - 2015-04-21 16:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2015-05-13 06:28 - 2015-04-21 16:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-05-13 06:28 - 2015-04-21 15:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-05-13 06:28 - 2015-04-21 15:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-05-13 06:28 - 2015-04-18 04:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll 2015-05-13 06:28 - 2015-04-18 03:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2015-05-13 06:27 - 2015-04-27 20:28 - 05569984 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2015-05-13 06:27 - 2015-04-27 20:28 - 00155584 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2015-05-13 06:27 - 2015-04-27 20:28 - 00095680 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2015-05-13 06:27 - 2015-04-27 20:26 - 01728960 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 01461760 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 01254400 _____ (Microsoft Corporation) C:\Windows\System32\diagtrack.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 01162752 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\System32\tdh.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00728064 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00314880 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00309760 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00215040 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00210944 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00136192 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00113664 _____ (Microsoft Corporation) C:\Windows\System32\sechost.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00029184 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll 2015-05-13 06:27 - 2015-04-27 20:23 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll 2015-05-13 06:27 - 2015-04-27 20:22 - 00404992 _____ (Microsoft Corporation) C:\Windows\System32\tracerpt.exe 2015-05-13 06:27 - 2015-04-27 20:22 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe 2015-05-13 06:27 - 2015-04-27 20:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe 2015-05-13 06:27 - 2015-04-27 20:22 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe 2015-05-13 06:27 - 2015-04-27 20:22 - 00104448 _____ (Microsoft Corporation) C:\Windows\System32\logman.exe 2015-05-13 06:27 - 2015-04-27 20:22 - 00047104 _____ (Microsoft Corporation) C:\Windows\System32\typeperf.exe 2015-05-13 06:27 - 2015-04-27 20:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\relog.exe 2015-05-13 06:27 - 2015-04-27 20:22 - 00031232 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe 2015-05-13 06:27 - 2015-04-27 20:22 - 00019456 _____ (Microsoft Corporation) C:\Windows\System32\diskperf.exe 2015-05-13 06:27 - 2015-04-27 20:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe 2015-05-13 06:27 - 2015-04-27 20:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll 2015-05-13 06:27 - 2015-04-27 20:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00686080 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 20:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-05-13 06:27 - 2015-04-27 20:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-05-13 06:27 - 2015-04-27 20:08 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-05-13 06:27 - 2015-04-27 20:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2015-05-13 06:27 - 2015-04-27 20:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-05-13 06:27 - 2015-04-27 20:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-05-13 06:27 - 2015-04-27 20:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-05-13 06:27 - 2015-04-27 20:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2015-05-13 06:27 - 2015-04-27 20:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-05-13 06:27 - 2015-04-27 20:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-05-13 06:27 - 2015-04-27 20:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-05-13 06:27 - 2015-04-27 20:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-05-13 06:27 - 2015-04-27 20:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2015-05-13 06:27 - 2015-04-27 20:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-05-13 06:27 - 2015-04-27 20:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe 2015-05-13 06:27 - 2015-04-27 20:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe 2015-05-13 06:27 - 2015-04-27 20:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe 2015-05-13 06:27 - 2015-04-27 20:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe 2015-05-13 06:27 - 2015-04-27 20:04 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-05-13 06:27 - 2015-04-27 20:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-05-13 06:27 - 2015-04-27 20:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-05-13 06:27 - 2015-04-27 20:03 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-05-13 06:27 - 2015-04-27 20:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-05-13 06:27 - 2015-04-27 20:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-05-13 06:27 - 2015-04-27 20:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe 2015-05-13 06:27 - 2015-04-27 20:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-05-13 06:27 - 2015-04-27 20:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-05-13 06:27 - 2015-04-27 20:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 19:06 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\UtcResources.dll 2015-05-13 06:27 - 2015-04-27 18:57 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-05-13 06:27 - 2015-04-27 18:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-05-13 06:27 - 2015-04-27 18:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 18:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 18:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-05-13 06:27 - 2015-04-27 18:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-05-13 06:27 - 2015-04-13 04:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\System32\services.exe 2015-05-13 06:26 - 2015-04-20 04:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2015-05-13 06:26 - 2015-04-20 04:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2015-05-13 06:26 - 2015-04-20 03:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2015-05-13 06:26 - 2015-04-20 03:11 - 03204608 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2015-05-13 06:26 - 2015-04-08 04:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\System32\InkEd.dll 2015-05-13 06:26 - 2015-04-08 04:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2015-05-13 06:26 - 2015-03-04 05:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\System32\apphelp.dll 2015-05-13 06:26 - 2015-03-04 05:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\System32\aelupsvc.dll 2015-05-13 06:26 - 2015-03-04 05:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\System32\sdbinst.exe 2015-05-13 06:26 - 2015-03-04 05:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\shimeng.dll 2015-05-13 06:26 - 2015-03-04 05:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll 2015-05-13 06:26 - 2015-03-04 05:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2015-05-13 06:26 - 2015-03-04 05:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe 2015-05-13 06:26 - 2015-02-18 08:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2015-05-13 06:26 - 2015-02-18 08:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\System32\poqexec.exe 2015-05-13 06:26 - 2015-01-29 04:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\System32\wpdshext.dll 2015-05-13 06:26 - 2015-01-29 04:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll 2015-05-08 10:55 - 2015-05-27 10:14 - 00000000 ____D () C:\Program Files\CCleaner 2015-05-08 10:55 - 2015-05-08 10:55 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-05-08 10:55 - 2015-05-08 10:55 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-05-08 10:54 - 2015-05-08 10:54 - 05248848 _____ (Piriform Ltd) C:\Users\david.EDERER\Downloads\ccsetup505_slim.exe 2015-04-29 11:33 - 2015-05-27 08:41 - 00011538 _____ () C:\Users\david.EDERER\Desktop\Mauerstein Lieferung von Borowskie.xlsx ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-27 12:00 - 2013-08-28 23:34 - 01372878 _____ () C:\Windows\WindowsUpdate.log 2015-05-27 12:00 - 2011-04-12 08:43 - 00700470 _____ () C:\Windows\System32\perfh007.dat 2015-05-27 12:00 - 2011-04-12 08:43 - 00149210 _____ () C:\Windows\System32\perfc007.dat 2015-05-27 12:00 - 2009-07-14 06:13 - 01622204 _____ () C:\Windows\System32\PerfStringBackup.INI 2015-05-27 12:00 - 2009-07-14 05:45 - 00031280 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-27 12:00 - 2009-07-14 05:45 - 00031280 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-27 11:57 - 2013-09-04 14:25 - 00000120 _____ () C:\Windows\System32\config\netlogon.ftl 2015-05-27 11:51 - 2013-09-04 14:28 - 00030104 _____ () C:\Users\david.EDERER\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-27 11:42 - 2009-07-14 05:45 - 00695256 _____ () C:\Windows\System32\FNTCACHE.DAT 2015-05-27 10:57 - 2013-09-13 09:07 - 00000000 ____D () C:\Users\david.EDERER\AppData\Roaming\TeamViewer 2015-05-27 10:19 - 2014-08-01 17:03 - 00000000 ____D () C:\ProgramData\Avira 2015-05-27 10:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup 2015-05-27 10:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe 2015-05-27 10:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2015-05-27 10:16 - 2015-01-22 09:38 - 00000000 ____D () C:\Program Files (x86)\Syncios 2015-05-27 10:16 - 2013-10-12 09:58 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar 2015-05-27 10:16 - 2013-09-16 08:20 - 00000000 ____D () C:\Program Files (x86)\Tobit InfoCenter 2015-05-27 10:16 - 2013-09-16 05:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2015-05-27 10:16 - 2013-09-16 04:39 - 00000000 ____D () C:\users\Administrator 2015-05-27 10:16 - 2013-09-05 10:18 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2015-05-27 10:16 - 2013-09-04 14:30 - 00000000 ____D () C:\Program Files (x86)\SelectLineSQL 2015-05-27 10:16 - 2013-09-04 11:31 - 00000000 ____D () C:\Program Files (x86)\TCD 2015-05-27 10:16 - 2013-09-02 10:35 - 00000000 ____D () C:\ProgramData\Autodesk 2015-05-27 10:16 - 2013-09-02 10:19 - 00000000 ____D () C:\ProgramData\Protexis64 2015-05-27 10:16 - 2013-09-02 10:06 - 00000000 ____D () C:\ProgramData\Corel 2015-05-27 10:16 - 2013-08-28 23:39 - 00000000 ____D () C:\Program Files (x86)\Realtek 2015-05-27 10:16 - 2013-08-28 21:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2015-05-27 10:16 - 2013-08-28 20:36 - 00000000 ____D () C:\ProgramData\Adobe 2015-05-27 10:16 - 2013-08-28 17:44 - 00000000 ____D () C:\ProgramData\AMD 2015-05-27 10:16 - 2009-07-14 04:20 - 00000000 __RSD () C:\Windows\Media 2015-05-27 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\com 2015-05-27 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Resources 2015-05-27 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PLA 2015-05-27 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\IME 2015-05-27 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help 2015-05-27 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2015-05-27 10:15 - 2015-04-10 06:30 - 00000000 ____D () C:\Program Files\iTunes 2015-05-27 10:15 - 2015-04-10 06:30 - 00000000 ____D () C:\Program Files\iPod 2015-05-27 10:15 - 2014-06-20 06:22 - 00000000 ____D () C:\Program Files (x86)\McAfee Security Scan 2015-05-27 10:15 - 2013-10-12 09:58 - 00000000 ____D () C:\Program Files\Windows Sidebar 2015-05-27 10:15 - 2013-09-05 09:25 - 00000000 ____D () C:\Program Files (x86)\ClocX 2015-05-27 10:15 - 2013-09-05 09:18 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2015-05-27 10:15 - 2013-09-05 08:33 - 00000000 ____D () C:\Program Files\Common Files\LogiShrd 2015-05-27 10:15 - 2013-09-02 09:53 - 00000000 ____D () C:\Program Files\UltraMon 2015-05-27 10:15 - 2013-09-02 07:20 - 00000000 ____D () C:\Program Files\Microsoft Office 2015-05-27 10:15 - 2013-08-28 23:37 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2015-05-27 10:15 - 2013-08-28 21:15 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2015-05-27 10:15 - 2013-08-28 20:41 - 00000000 ____D () C:\Program Files\Java 2015-05-27 10:15 - 2013-08-28 20:36 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-05-27 10:15 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2015-05-27 10:14 - 2015-02-10 14:48 - 00000000 ____D () C:\a18731d7fb7c7cc22445 2015-05-27 10:14 - 2014-10-09 06:47 - 00000000 ____D () C:\Program Files\7-Zip 2015-05-27 10:14 - 2013-09-05 09:18 - 00000000 ____D () C:\Program Files\Bonjour 2015-05-27 10:14 - 2013-09-02 10:33 - 00000000 ____D () C:\Program Files\Autodesk 2015-05-27 09:29 - 2013-09-04 14:50 - 00000000 ____D () C:\Users\david.EDERER\Desktop\gemailte PDF Dokumente 2015-05-27 06:12 - 2014-08-26 06:22 - 00000000 ____D () C:\Users\david.EDERER\AppData\Local\Adobe 2015-05-26 17:05 - 2013-09-04 14:37 - 00000000 ____D () C:\Users\david.EDERER\Desktop\diverse Bilder 2015-05-22 15:11 - 2013-09-04 14:47 - 00000000 ____D () C:\Users\david.EDERER\Desktop\diverses 2015-05-22 08:11 - 2013-10-01 06:25 - 00000000 ___HD () C:\Users\david.EDERER\Desktop\[Originaldateien] 2015-05-20 17:00 - 2015-04-04 12:03 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-05-20 17:00 - 2015-04-04 12:03 - 00000000 ___SD () C:\Windows\System32\GWX 2015-05-18 11:02 - 2013-09-04 14:37 - 00000000 ____D () C:\Users\david.EDERER\Documents\DVDVideoSoft 2015-05-15 06:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\System32\AdvancedInstallers 2015-05-13 17:28 - 2013-09-02 10:52 - 00000000 ____D () C:\Windows\System32\MRT 2015-05-13 17:26 - 2013-09-02 10:52 - 140425016 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2015-05-08 13:56 - 2015-01-13 09:38 - 00000000 ____D () C:\Users\david.EDERER\Desktop\Gloria 2015-05-08 10:56 - 2014-11-20 09:46 - 00000000 ____D () C:\Users\david.EDERER\AppData\Roaming\XnView 2015-05-05 10:03 - 2014-08-01 17:03 - 00152744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avgntflt.sys 2015-05-05 10:03 - 2014-08-01 17:03 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avipbb.sys 2015-04-30 06:31 - 2013-09-04 15:03 - 00021504 _____ () C:\Users\david.EDERER\Desktop\verschiedens.xlsx 2015-04-29 15:17 - 2014-05-09 08:39 - 00000000 ____D () C:\Users\david.EDERER\Desktop\Lieferschein - Mauersteine 2015-04-27 12:43 - 2013-09-04 15:02 - 00000000 ____D () C:\Users\david.EDERER\Desktop\Schriften Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.5808.dll C:\Users\Public\AlexaNSISPlugin.7024.dll Some files in TEMP: ==================== C:\Users\David\AppData\Local\Temp\AcDeltree.exe C:\Users\David\AppData\Local\Temp\juKkqAPOWrFvXhhHVjsP.DLL C:\Users\David\AppData\Local\Temp\kmpd51e5.dlL C:\Users\David\AppData\Local\Temp\NcxFUPPTlZJzSuvKkZvy.DLL C:\Users\David\AppData\Local\Temp\oedpCMnYUUPoTZQYRgoM.DLL C:\Users\David\AppData\Local\Temp\ose00000.exe C:\Users\David\AppData\Local\Temp\qCwlyrzcojJWSPtgLmkM.DLL C:\Users\David\AppData\Local\Temp\QyPqBVsHVsErDezokGJA.DLL C:\Users\David\AppData\Local\Temp\xmlUpdater.exe C:\Users\david.EDERER\AppData\Local\Temp\avgnt.exe C:\Users\david.EDERER\AppData\Local\Temp\SynciosDeviceService.exe ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe [2015-05-13 06:27] - [2015-04-13 04:28] - 0328704 ____A (Microsoft Corporation) 71C85477DF9347FE8E7BC55768473FCA C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2015-05-27 11:19:57 Restore point made on: 2015-05-27 11:23:43 ==================== Memory info =========================== Percentage of memory in use: 11% Total physical RAM: 7629.76 MB Available physical RAM: 6757.37 MB Total Pagefile: 7627.96 MB Available Pagefile: 6773.9 MB Total Virtual: 8192 MB Available Virtual: 8191.87 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:33.2 GB) NTFS Drive f: (MULTIBOOT) (Removable) (Total:14.61 GB) (Free:11.54 GB) FAT32 Drive k: () (Removable) (Total:7.66 GB) (Free:1.61 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: FD3E961D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 14.6 GB) (Disk ID: 00013757) Partition 1: (Active) - (Size=14.6 GB) - (Type=0C) ======================================================== Disk: 6 (Size: 7.7 GB) (Disk ID: FA4F0335) Partition 1: (Not Active) - (Size=7.7 GB) - (Type=0B) LastRegBack: 2015-05-26 09:35 ==================== End of log ============================ |
![]() | #4 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Desktop schwarz und keine Programme gehen mehr Drücke bitte die ![]() Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\David\...\Policies\Explorer: []
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. Bitte mal FRST im normalen Modus scannen lassen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
Themen zu Desktop schwarz und keine Programme gehen mehr |
andauernd, aufsetzen, dauernd, desktop, fehlermeldung, heute, hintergrund, irgendetwas, laufen, leute, login, meldung, neu, nichts, original, programm, programme, sache, sachen, schwarz, servus, spinn, spinnt, versuche, öffnen |