|
Log-Analyse und Auswertung: Win 7: Sophos meldet "Troj/Miner-AB"Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
25.06.2015, 15:52 | #1 |
| Win 7: Sophos meldet "Troj/Miner-AB" Hallo Trojaner-Feinde, Gestern Abend fing mein Mauszeiger an langsamer und träge zu werden. Irgendwann meldete Sophos "Troj/Miner-AB" in "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" und verschob diese laut Nachricht in Quarantäne. Unter Maßnahmen zur Bereinigung stand lediglich "Keine Maßnahmen (Neustart erforderlich)", allerdings half der Neustart nicht weiter. Das Problem ist vermutlich durch einen Keygen entstanden, habe versucht ein Spiel zum laufen zu kriegen, bei dem ich leider nur noch die Disk hatte. Die Dateien sollten aber soweit entfernt sein. Ich habe bisher lediglich versucht das Problem mit dem "Sophos Virus Removal Tool" zu beseitigen, jedoch ohne Erfolg. Beim GMER Scan ist dwm.exe regelmäßig abgestürzt (Problemsignatur auch im Anhang). Außerdem habe ich mir erlaubt das Logfile von Sophos zu kürzen, da es sich über 4000 Zeilen ständig nur wiederholt. Gruß und vielen Dank im Voraus, Simon FRST: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015 Ran by SH (administrator) on SH-PC on 25-06-2015 15:18:51 Running from C:\Users\SH\Desktop\trojaner Loaded Profiles: SH (Available Profiles: SH) Platform: Windows 7 Professional N Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (AMD) C:\Windows\System32\atieclxx.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe (Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) F:\Programme\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1240064 2012-07-04] (Marvell Semiconductor, Inc.) HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc) HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1593640 2015-03-04] (Sophos Limited) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-04-20] (Cisco Systems, Inc.) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [Remote Mouse] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe [2050048 2015-01-23] (RemoteMouse.net) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [tsiVideo] => C:\Windows\SysWOW64\rundll32.exe C:\Users\SH\AppData\Local\Temp\\mdi564.dll,asdasd <===== ATTENTION HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\MountPoints2: {3ad94142-678a-11e2-b802-002618879046} - K:\NPSAI.exe AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll [217672 2015-01-14] (Sophos Limited) AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll [275352 2015-01-14] (Sophos Limited) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) SearchScopes: HKU\S-1-5-21-2306031424-1336655547-1434631041-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC8} URL = hxxp://search.icq.com/search/results.php?q=%s&ch_id=hm&search_mode=web BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle Corporation) Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Hosts: 130.83.158.177 vpn.hrz.tu-darmstadt.de ###Cisco AnyConnect VPN client modified this file. Please do not modify contents until this comment is removed. Tcpip\Parameters: [DhcpNameServer] 192.168.192.1 FireFox: ======== FF ProfilePath: C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7B%20var%20lhost%2C%20localIpAddresses%2C%20localDomains%2C%20ipNotation%2C%20i%3B%20function%20isPlainHostNameEx()%20%7B%20return%20!(!!~lhost.indexOf('.')%20%7C%7C%20!!~lhost.indexOf('%3A'))%3B%20%7D%20lhost%20%3D%20host.toLowerCase()%3B%20ipNotation%20%3D%20%2F%5E%5Cd%2B%5C.%5Cd%2B%5C.%5Cd%2B%5C.%5Cd%2B%24%2Fg%3B%20localIpAddresses%20%3D%20%5B'127.0.0.1'%2C'10.*.*.*'%2C'172.1%5B6-9%5D.*.*'%2C'172.2%5B1-9%5D.*.*'%2C'172.3%5B0-1%5D.*.*'%2C'192.168.*.*'%5D%3B%20localDomains%20%3D%20%5B'zeus.pm'%2C'zenguard.biz'%2C'local'%2C'dev'%2C'ip'%2C'box'%2C'lvh.me'%2C'ripe'%2C'invalid'%2C'intra'%2C'intranet'%2C'onion'%2C'vcap.me'%2C'127.0.0.1.xip.io'%2C'smackaho.st'%2C'localtest.me'%2C'site'%5D%3B%20if%20(isPlainHostNameEx())%20%7B%20return%20'DIRECT'%3B%20%7D%20if%20(ipNotation.test(lhost))%20%7B%20for%20(i%20%3D%200%3B%20i%20%3C%20localIpAddresses.length%3B%20i%2B%2B)%20%7B%20if%20(shExpMatch(lhost%2C%20localIpAddresses%5Bi%5D))%20%7B%20return%20'DIRECT'%3B%20%7D%20%7D%20%7D%20for%20(i%20%3D%200%3B%20i%20%3C%20localDomains.length%3B%20i%2B%2B)%20%7B%20if%20(dnsDomainIs(lhost%2C%20localDomains%5Bi%5D))%20%7B%20return%20'DIRECT'%3B%20%7D%20%7D%20return%20'PROXY%20127.0.0.1%3A49186'%3B%20%7D%20%2F*ZenMate*%2F" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-24] () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-24] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> F:\Programme\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> F:\Programme\DivX\DivX Web Player\npdivx32.dll [2014-02-18] (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> F:\Programme\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: @hola.org/vlc,version=1.8.369 -> C:\Users\SH\AppData\Local\Hola\firefox\app\vlc [2015-06-24] () FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\SH\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.) FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: sony.com/MediaGoDetector -> F:\Programme\Media Go\npMediaGoDetector.dll [2013-08-22] (Sony Network Entertainment International LLC) FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-04-23] (Ubisoft) FF Extension: Hola Better Internet - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack [2015-05-27] FF Extension: WOT - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-05-30] FF Extension: ZenMate Security & Privacy VPN - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\firefox@zenmate.com.xpi [2015-05-07] FF Extension: flv movies downloader - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\flvmoviesdownloader@rzll.xpi [2013-10-17] FF Extension: Media Hint - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\mediahint@jetpack.xpi [2014-03-13] FF Extension: Adblock Plus - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-25] StartMenuInternet: FIREFOX.EXE - F:\Programme\Mozilla Firefox\firefox.exe Chrome: ======= CHR Profile: C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-27] CHR Extension: (Google Drive) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-27] CHR Extension: (WOT) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-06-22] CHR Extension: (YouTube) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-27] CHR Extension: (Adblock Plus) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-27] CHR Extension: (Google Search) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-27] CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-11-04] CHR Extension: (Math Anywhere) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebhifiddmaaeecbaiemfpejghjdjmhc [2015-03-12] CHR Extension: (AdBlock) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-27] CHR Extension: (Hola Better Internet) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-01-31] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13] CHR Extension: (Google Wallet) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Enhanced Steam) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2014-06-20] CHR Extension: (Gmail) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-27] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ForceWare Intelligent Application Manager (IAM); F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] () S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed] S3 Media Jukebox 14 Service; F:\Programme\Media Jukebox 14\JRService.exe [379400 2010-07-15] (J. River, Inc.) R2 nSvcIp; F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] () R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [288552 2014-05-23] (Sophos Limited) R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [208168 2014-10-14] (Sophos Limited) R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [340776 2015-03-04] (Sophos Limited) R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [341800 2014-10-14] (Sophos Limited) R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3274536 2015-01-14] (Sophos Limited) S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2065704 2015-01-14] (Sophos Limited) S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) S3 NVENETFD; C:\Windows\System32\DRIVERS\nvm60x64.sys [742696 2009-06-10] (NVIDIA Corporation) S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project) S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [25600 2013-04-19] (Razer USA Ltd) [File not signed] S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [23040 2013-04-19] (Razer USA Ltd) [File not signed] R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [158976 2014-05-23] (Sophos Limited) S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2014-05-23] (Sophos Limited) S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [27904 2014-05-23] (Sophos Limited) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-01-24] (Duplex Secure Ltd.) S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-13] (Anchorfree Inc.) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-25 15:18 - 2015-06-25 15:18 - 00000000 ____D C:\FRST 2015-06-25 15:15 - 2015-04-21 10:55 - 00000845 _____ C:\Windows\system32\Drivers\etc\hosts.ac 2015-06-25 15:13 - 2015-06-25 15:13 - 00000020 _____ C:\Users\SH\defogger_reenable 2015-06-25 15:11 - 2015-06-25 15:18 - 00000000 ____D C:\Users\SH\Desktop\trojaner 2015-06-24 19:50 - 2015-06-24 19:50 - 00002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk 2015-06-24 18:01 - 2015-06-24 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disney Interactive Studios 2015-06-24 16:13 - 2015-06-24 16:13 - 00000000 ____D C:\Users\SH\AppData\Local\Licenses 2015-06-24 15:43 - 2015-06-24 15:43 - 00001112 _____ C:\Users\Public\Desktop\TriDef 3D.lnk 2015-06-24 15:43 - 2015-06-24 15:43 - 00000000 ____D C:\ProgramData\TriDef 3D 2015-06-24 15:42 - 2015-06-24 15:43 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef 2015-06-24 15:41 - 2015-06-24 15:41 - 00000000 ____D C:\ProgramData\DDD 2015-06-17 21:39 - 2015-06-17 21:39 - 00001684 _____ C:\Users\Public\Desktop\roomeon Portal.lnk 2015-06-17 21:39 - 2015-06-17 21:39 - 00001661 _____ C:\Users\Public\Desktop\roomeon 3D-Planer.lnk 2015-06-17 21:39 - 2015-06-17 21:39 - 00000000 ____D C:\Users\SH\AppData\Local\roomeon 2015-06-17 21:28 - 2015-06-17 21:38 - 00000000 ____D C:\Users\SH\AppData\Local\Room Arranger 2015-06-16 16:19 - 2015-06-16 16:19 - 00000000 __SHD C:\Users\SH\AppData\Local\EmieBrowserModeList 2015-06-14 13:54 - 2015-06-14 13:54 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3 Uprising 2015-06-13 14:45 - 2015-06-13 14:45 - 00000040 _____ C:\ProgramData\ra3.ini 2015-06-13 14:45 - 2015-06-13 14:45 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3 2015-06-13 14:06 - 2015-06-13 14:36 - 00000000 ____D C:\Users\SH\AppData\Roaming\Nidhogg 2015-06-13 13:52 - 2015-06-13 13:52 - 00000208 _____ C:\Users\SH\Desktop\Nidhogg.url 2015-06-13 13:36 - 2015-06-13 13:36 - 00000208 _____ C:\Users\SH\Desktop\Command and Conquer Red Alert 3 - Uprising.url 2015-06-13 11:13 - 2015-06-13 11:13 - 00000209 _____ C:\Users\SH\Desktop\Salt Demo.url 2015-06-12 11:08 - 2015-06-12 11:08 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2015-06-11 15:28 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-06-11 15:28 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-06-11 15:28 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-06-11 15:28 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-06-11 15:28 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-06-11 15:28 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-06-11 15:28 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-06-11 15:28 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-06-11 15:28 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe 2015-06-11 15:28 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-06-11 15:28 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-06-11 15:28 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-06-11 15:28 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-06-11 15:28 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-06-11 15:28 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-06-11 15:28 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-06-11 15:28 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-06-11 15:28 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-06-11 15:28 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-06-11 15:28 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-06-11 15:28 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-06-11 15:28 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-06-11 15:28 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-06-11 15:28 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-06-11 15:28 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-06-11 15:28 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-06-11 15:28 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-06-11 15:28 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-11 15:28 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2015-06-11 15:28 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-06-11 15:27 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-06-11 15:27 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-06-11 15:27 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-06-11 15:27 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-06-11 15:27 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-06-11 15:27 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-06-11 15:27 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-06-11 15:27 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-06-11 15:27 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-06-11 15:27 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-06-11 15:27 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-06-11 15:27 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-06-11 15:27 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-06-11 15:27 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-06-11 15:27 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-06-11 15:27 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-06-11 15:27 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-06-11 15:27 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-06-11 15:27 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-06-11 15:27 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-06-11 15:27 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-06-11 15:27 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-06-11 15:27 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-06-11 15:27 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-06-11 15:27 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-06-11 15:27 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-06-11 15:27 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-06-11 15:27 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-06-11 15:27 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-06-11 15:27 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-06-11 15:27 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-06-11 15:27 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-06-11 15:27 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-06-11 15:27 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-06-11 15:27 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-06-11 15:27 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-06-11 15:27 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-06-11 15:27 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-06-11 15:27 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-06-11 15:27 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-06-11 15:27 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-06-11 15:27 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-06-11 15:27 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-06-11 15:27 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-06-11 15:27 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-06-11 15:27 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-06-11 15:27 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-11 15:27 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-06-11 15:27 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-11 15:27 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-06-11 15:27 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-06-11 15:27 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-06-11 15:27 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-06-11 15:27 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-06-11 15:27 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-06-11 15:27 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-06-11 15:27 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-06-11 15:27 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-06-11 15:27 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-06-11 15:27 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-06-02 20:16 - 2015-06-02 20:16 - 00000000 ____D C:\Users\SH\AppData\Local\PDF24 2015-06-01 20:27 - 2015-06-01 20:27 - 00000000 ____D C:\Users\SH\AppData\Local\GWX 2015-05-28 22:58 - 2015-05-01 15:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-05-28 22:58 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-05-28 19:09 - 2015-05-28 19:09 - 00000000 ____D C:\Users\SH\Documents\Criterion Games ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-25 15:18 - 2013-01-24 18:29 - 02060153 _____ C:\Windows\WindowsUpdate.log 2015-06-25 15:15 - 2014-07-29 12:52 - 00000000 ____D C:\Users\SH\AppData\Roaming\Raptr 2015-06-25 15:15 - 2013-01-24 19:04 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-06-25 15:15 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-06-25 15:15 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-06-25 15:14 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-06-25 15:14 - 2009-07-14 06:56 - 00121827 _____ C:\Windows\setupact.log 2015-06-25 15:13 - 2013-01-24 19:01 - 00000000 ____D C:\Users\SH 2015-06-25 15:06 - 2013-01-24 19:04 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-06-25 14:35 - 2014-03-08 16:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-06-25 14:26 - 2013-01-26 10:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2015-06-25 14:26 - 2010-11-21 05:47 - 00228388 _____ C:\Windows\PFRO.log 2015-06-25 14:24 - 2014-06-22 17:18 - 00000000 ____D C:\Users\SH\AppData\Local\LOOT 2015-06-25 14:20 - 2013-05-24 12:06 - 00000000 ___RD C:\Users\SH\Desktop\Spiele 2015-06-25 13:10 - 2011-04-12 10:14 - 00713958 _____ C:\Windows\system32\perfh007.dat 2015-06-25 13:10 - 2011-04-12 10:14 - 00154074 _____ C:\Windows\system32\perfc007.dat 2015-06-25 13:10 - 2009-07-14 07:12 - 01648656 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-25 12:43 - 2014-01-22 13:51 - 00000000 ____D C:\Users\SH\AppData\Local\Battle.net 2015-06-25 12:15 - 2013-06-03 12:01 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9941B8CD-7D1F-464E-A428-95CA8D62A133} 2015-06-24 21:10 - 2009-07-14 07:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-06-24 20:57 - 2014-04-04 17:16 - 00001048 _____ C:\Windows\Xbox_360_CC_Driver.log 2015-06-24 20:53 - 2013-05-23 13:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Byte 2015-06-24 19:51 - 2013-01-25 13:08 - 00000000 ____D C:\ProgramData\Sophos 2015-06-24 19:50 - 2014-05-23 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos 2015-06-24 19:50 - 2013-01-25 13:08 - 00000000 ____D C:\Program Files (x86)\Sophos 2015-06-24 19:25 - 2014-08-28 11:32 - 00000000 ____D C:\Users\SH\AppData\Local\CrashDumps 2015-06-24 18:50 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-06-24 17:08 - 2013-01-30 00:09 - 00649191 _____ C:\Windows\DirectX.log 2015-06-24 14:19 - 2015-01-10 16:37 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-06-24 11:35 - 2014-03-08 16:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-06-24 11:35 - 2014-03-08 16:32 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-06-24 11:35 - 2014-03-08 16:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-06-21 14:19 - 2013-01-30 09:33 - 00000000 ____D C:\Users\SH\AppData\Roaming\vlc 2015-06-19 10:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2015-06-19 09:17 - 2009-07-14 06:50 - 00320184 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-19 09:15 - 2015-04-21 10:42 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-19 09:15 - 2014-05-19 12:34 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-06-19 09:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2015-06-19 04:26 - 2013-02-25 13:03 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-06-19 04:25 - 2013-07-12 23:23 - 00000000 ____D C:\Windows\system32\MRT 2015-06-19 04:19 - 2013-01-24 19:47 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-06-17 21:38 - 2013-07-08 17:10 - 00000000 ____D C:\Users\SH\AppData\Local\Downloaded Installations 2015-06-16 18:15 - 2015-05-06 10:39 - 00007601 _____ C:\Users\SH\AppData\Local\Resmon.ResmonCfg 2015-06-16 16:18 - 2015-05-05 10:24 - 00000000 ____D C:\Users\SH\Desktop\SS 15 2015-06-12 11:08 - 2013-01-24 19:04 - 00000000 ____D C:\Program Files (x86)\Google 2015-06-02 11:26 - 2013-01-24 19:04 - 00066648 _____ C:\Users\SH\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\system32\GWX 2015-05-29 16:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers 2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2015-05-28 22:58 - 2013-01-30 00:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight ==================== Files in the root of some directories ======= 2015-01-28 13:58 - 2015-01-28 13:59 - 0009918 _____ () C:\Users\SH\AppData\Local\CleanupUninstall.txt 2013-06-04 22:44 - 2013-06-04 22:44 - 0003072 _____ () C:\Users\SH\AppData\Local\file__0.localstorage 2015-05-06 10:39 - 2015-06-16 18:15 - 0007601 _____ () C:\Users\SH\AppData\Local\Resmon.ResmonCfg 2013-01-29 16:21 - 2013-01-29 16:21 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt 2015-06-13 14:45 - 2015-06-13 14:45 - 0000040 _____ () C:\ProgramData\ra3.ini Some files in TEMP: ==================== C:\Users\SH\AppData\Local\Temp\amazonicon_v10.exe C:\Users\SH\AppData\Local\Temp\amazoninstallernircmdc.exe C:\Users\SH\AppData\Local\Temp\drm_dyndata_7410004.dll C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.919.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.974.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.103.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.13.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.131.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.143.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.183.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.188.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.204.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.277.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.28.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.308.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.328.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.369.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.4.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.77.exe C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.89.exe C:\Users\SH\AppData\Local\Temp\i4jdel0.exe C:\Users\SH\AppData\Local\Temp\JExplorer32.2.7.1.dll C:\Users\SH\AppData\Local\Temp\JExplorer32.2.7.1.exe C:\Users\SH\AppData\Local\Temp\JExplorer64.2.7.1.dll C:\Users\SH\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe C:\Users\SH\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe C:\Users\SH\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe C:\Users\SH\AppData\Local\Temp\jre-8u31-windows-au.exe C:\Users\SH\AppData\Local\Temp\mdi064.dll C:\Users\SH\AppData\Local\Temp\mdi164.dll C:\Users\SH\AppData\Local\Temp\mdi264.dll C:\Users\SH\AppData\Local\Temp\mdi364.dll C:\Users\SH\AppData\Local\Temp\mdi464.dll C:\Users\SH\AppData\Local\Temp\mdi564.dll C:\Users\SH\AppData\Local\Temp\MouseKeyboardCenterx64_1031.exe C:\Users\SH\AppData\Local\Temp\ose00000.exe C:\Users\SH\AppData\Local\Temp\raptrpatch.exe C:\Users\SH\AppData\Local\Temp\raptr_stub.exe C:\Users\SH\AppData\Local\Temp\RemoteMouse.exe C:\Users\SH\AppData\Local\Temp\sdan.exe C:\Users\SH\AppData\Local\Temp\sdapk.exe C:\Users\SH\AppData\Local\Temp\sdaspwn.exe C:\Users\SH\AppData\Local\Temp\SiedlerPatch.exe C:\Users\SH\AppData\Local\Temp\tmp539B.exe C:\Users\SH\AppData\Local\Temp\tmp915.exe C:\Users\SH\AppData\Local\Temp\tmpC062.exe C:\Users\SH\AppData\Local\Temp\tmpDBCD.exe C:\Users\SH\AppData\Local\Temp\vcredist_x86.exe C:\Users\SH\AppData\Local\Temp\xruds137.exe C:\Users\SH\AppData\Local\Temp\_isFC8.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-24 11:43 ==================== End of log ============================ Code:
ATTFilter Problemsignatur: Problemereignisname: APPCRASH Anwendungsname: dwm.exe Anwendungsversion: 0.0.0.0 Anwendungszeitstempel: 000e6bfc Fehlermodulname: dwm.exe Fehlermodulversion: 0.0.0.0 Fehlermodulzeitstempel: 000e6bfc Ausnahmecode: c000001d Ausnahmeoffset: 000000000005c0a8 Betriebsystemversion: 6.1.7601.2.1.0.256.49 Gebietsschema-ID: 1031 Zusatzinformation 1: a681 Zusatzinformation 2: a6815bd14801eb6a5d654ae1c7fe8bc1 Zusatzinformation 3: 2769 Zusatzinformation 4: 27699c8391b48bdc18ca43cf2940f9c4 Lesen Sie unsere Datenschutzbestimmungen online: hxxp://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0407 Wenn die Onlinedatenschutzbestimmungen nicht verfügbar sind, lesen Sie unsere Datenschutzbestimmungen offline: C:\Windows\system32\de-DE\erofflps.txt Code:
ATTFilter ****************** Sophos Anti-Virus Protokoll - 25.06.2015 13:30:03 ************** ... 20150625 130017 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 130020 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 130022 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 130022 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131452 Die Erkennungsdatenversion 5.16 (Detection Engine 3.58.3) wird verwendet. Diese Version kann 9404639 Objekte erkennen. 20150625 131453 Benutzer (NT-AUTORITÄT\LOKALER DIENST) hat den On-Access-Scan auf diesem Computer gestartet. 20150625 131512 Virus/Spyware 'Troj/Miner-AB' entfernt. 20150625 131620 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131622 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131622 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131626 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131626 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131628 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131628 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131630 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131631 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131633 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" wurde bereinigt. 20150625 131633 Virus/Spyware 'Troj/Miner-AB' entfernt. 20150625 131633 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131633 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131637 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131637 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131638 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131638 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131647 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131650 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" wurde bereinigt. 20150625 131650 Virus/Spyware 'Troj/Miner-AB' entfernt. 20150625 131901 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131903 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131903 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131907 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131907 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131908 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131908 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131910 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131911 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131913 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" wurde bereinigt. 20150625 131913 Virus/Spyware 'Troj/Miner-AB' entfernt. 20150625 131913 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131913 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131917 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131917 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131919 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131919 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131922 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131923 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131924 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131924 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131926 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" konnte nicht entfernt werden. 20150625 131926 Virus/Spyware 'Troj/Miner-AB' konnte nicht entfernt werden. Es traten Fehler auf. 20150625 131928 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131928 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131929 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131929 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131930 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131933 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131933 Entfernung von Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" wurde verschoben. 20150625 131935 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 131935 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 131935 VEA 'Troj/Miner-AB' erfordert einen Neustart, damit die Bereinigung abgeschlossen werden kann. 20150625 132148 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132150 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132150 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132154 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132155 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132155 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132158 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132201 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132201 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132204 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132206 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132206 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132209 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132211 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132211 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132215 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132216 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132216 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132220 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132222 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132222 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132225 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132227 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132227 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132230 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132232 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132232 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132236 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132236 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132237 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132237 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132241 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132243 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132243 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132247 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132247 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132248 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132248 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132251 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132254 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132254 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132352 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132352 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132353 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132353 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132357 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132359 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132359 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132403 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132403 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132404 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132404 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132408 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132410 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132410 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132413 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132413 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150625 132415 Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'. 20150625 132415 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH (119 Objekte) |
25.06.2015, 16:51 | #2 |
/// the machine /// TB-Ausbilder | Win 7: Sophos meldet "Troj/Miner-AB" Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
25.06.2015, 17:02 | #3 |
| Win 7: Sophos meldet "Troj/Miner-AB" Sorry, ich dachte ich soll direkt anhängen, wenn es zu viel wird.
__________________Addition: [CODE]Additional FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x64) Version:24-06-2015 Ran by SH at 2015-06-25 15:20:19 Running from C:\Users\SH\Desktop\trojaner Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2306031424-1336655547-1434631041-500 - Administrator - Disabled) Gast (S-1-5-21-2306031424-1336655547-1434631041-501 - Limited - Enabled) HomeGroupUser$ (S-1-5-21-2306031424-1336655547-1434631041-1009 - Limited - Enabled) SH (S-1-5-21-2306031424-1336655547-1434631041-1000 - Administrator - Enabled) => C:\Users\SH SophosSAUSH-PC0 (S-1-5-21-2306031424-1336655547-1434631041-1010 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Sophos Anti-Virus (Enabled - Up to date) {6BABF8F7-3EB6-BD1D-9167-8C5ECA060A29} AS: Sophos Anti-Virus (Enabled - Up to date) {D0CA1913-188C-B293-ABD7-B72CB1814094} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.190 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Anki (HKLM-x32\...\Anki) (Version: - ) ANNO 2070 (HKLM-x32\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft) Antichamber (HKLM-x32\...\Steam App 219890) (Version: - Alexander Bruce) Application Verifier x64 External Package (Version: 8.59.29722 - Microsoft) Hidden Assassins Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version: - Ubisoft) Assassin's Creed Liberation (HKLM-x32\...\Steam App 260210) (Version: - Ubisoft Sofia) Banished (HKLM-x32\...\Steam App 242920) (Version: - Shining Rock Software LLC) Battle Realms (HKLM-x32\...\{9AA761E6-CA51-4FF2-A552-D51638BF0595}) (Version: 0.10.000 - Liquid Entertainment) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Besiege (HKLM-x32\...\Steam App 346010) (Version: - Spiderling Studios) Bridge Constructor (HKLM-x32\...\Steam App 250460) (Version: - ) Bridge Constructor Medieval (HKLM-x32\...\Steam App 319850) (Version: - ClockStone) Bridge Constructor Playground (HKLM-x32\...\Steam App 279990) (Version: - ClockStone) Broforce (HKLM-x32\...\Steam App 274190) (Version: - Free Lives) Bully: Scholarship Edition (HKLM-x32\...\Steam App 12200) (Version: - Rockstar New England) Call of Juarez Gunslinger (HKLM-x32\...\Steam App 204450) (Version: - Techland) Cisco AnyConnect Diagnostics and Reporting Tool (HKLM-x32\...\{9D2D6008-1122-47F3-8322-D6235CD8D1C5}) (Version: 3.1.08009 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.08009 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.08009 - Cisco Systems, Inc.) Hidden Clonk Endeavour 4.95.5 (HKLM-x32\...\Clonk Endeavour) (Version: 4.95.5 - RedWolf Design GmbH) Clonk Planet (HKLM-x32\...\Clonk Planet) (Version: 4.65 - RedWolf Design) Clonk Rage (HKLM-x32\...\Clonk Rage) (Version: - RedWolf Design GmbH) Command & Conquer Alarmstufe Rot 2 (HKLM-x32\...\Red Alert 2) (Version: - ) Command & Conquer(TM) Generäle (HKLM-x32\...\InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}) (Version: 0.50.0000 - Electronic Arts) Command & Conquer(TM) Generäle (x32 Version: 0.50.0000 - Electronic Arts) Hidden Command and Conquer: Red Alert 3 - Uprising (HKLM-x32\...\Steam App 24800) (Version: - EA Los Angeles) Construct 2 Free (HKLM-x32\...\Steam App 227240) (Version: - ) Content Transfer (HKLM-x32\...\{CFADE4AF-C0CF-4A04-A776-741318F1658F}) (Version: 1.3.0.23190 - Sony Corporation) Dark Souls: Prepare to Die Edition (HKLM-x32\...\Steam App 211420) (Version: - FromSoftware) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Die Siedler - Aufbruch der Kulturen (HKLM-x32\...\SADK) (Version: - ) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC) English Country Tune (HKLM-x32\...\Steam App 207570) (Version: - ) ENSLAVED™: Odyssey to the West™ Premium Edition (HKLM-x32\...\Steam App 245280) (Version: - Ninja Theory) EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) FlatOut 2 (HKLM-x32\...\Steam App 2990) (Version: - Bugbear Entertainment) FTL: Faster Than Light (HKLM-x32\...\Steam App 212680) (Version: - Subset Games) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden GTA2 (HKLM-x32\...\{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}) (Version: 1.00.001 - ) Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hotline Miami (HKLM-x32\...\Steam App 219150) (Version: - ) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Kits Configuration Installer (x32 Version: 8.59.25584 - Microsoft) Hidden Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) Left 4 Dead 2 Beta (HKLM-x32\...\Steam App 223530) (Version: - ) Logon Screen (HKLM\...\{1730D13B-7517-4321-A88B-64627CF67CDC}_is1) (Version: - Daniel Rebelo) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) ManiaPlanet (HKLM-x32\...\ManiaPlanet_is1) (Version: - Nadeo) Media Go (HKLM-x32\...\{8D92969D-A6A3-44C8-9D63-D377E94F44B5}) (Version: 2.6.205 - Sony) Media Go Video Playback Engine 2.0.117.09030 (HKLM-x32\...\{49D9CE9D-C8B7-B941-90E1-608044A0FC8D}) (Version: 2.0.117.09030 - Sony) Media Jukebox 14 (HKLM-x32\...\Media Jukebox 14) (Version: 14 - J. River, Inc.) Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft AppLocale (HKLM-x32\...\{394BE3D9-7F57-4638-A8D1-1D88671913B7}) (Version: 1.0.0 - MS) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation) Microsoft LifeCam (HKLM\...\{5CE7E3F5-9803-4F32-AA89-2D8848A80109}) (Version: 3.60.253.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Standard 2007 (HKLM-x32\...\STANDARD) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Windows Application Compatibility Database (HKLM\...\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb) (Version: - ) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Mozilla Firefox 37.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 de)) (Version: 37.0.2 - Mozilla) Mozilla Firefox 38.0.5 (x86 de) (HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) My Game Long Name (HKLM\...\UDK-eeb62aa7-80fe-4449-9b21-540167131065) (Version: - Epic Games, Inc.) Need For Speed - Porsche (HKLM-x32\...\Need For Speed - Porsche) (Version: - ) Next Car Game (HKLM-x32\...\Steam App 228380) (Version: - ) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.50.3 - Black Tree Gaming) Nidhogg (HKLM-x32\...\Steam App 94400) (Version: - Messhof) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.57.35 - NVIDIA Corporation) NVIDIA ForceWare Network Access Manager (HKLM-x32\...\{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version: 1.00.7325.0 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) NWZ-E460 WALKMAN Guide (HKLM-x32\...\{A4D58206-7E8F-41F2-BD94-85009F3AEA28}) (Version: 2.0.2.04130 - Sony Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 9.4.22.2815 - Electronic Arts, Inc.) Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC) PDF24 Creator 5.4.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Plants vs. Zombies: Game of the Year (HKLM-x32\...\Steam App 3590) (Version: - PopCap) Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve) Portal 2 Publishing Tool (HKLM-x32\...\Steam App 644) (Version: - ) QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.) Raptr (HKLM-x32\...\Raptr) (Version: - ) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.) Remote Mouse version 2.70 (HKLM-x32\...\{01E4BC6D-3ACC-45E1-8928-C2FF626F63F3}_is1) (Version: 2.70 - Remote Mouse) Reveal (HKLM\...\UDK-42ae296b-83a3-4b5f-b34f-2f44d830b3cf) (Version: - Epic Games, Inc.) Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Salt Demo (HKLM-x32\...\Steam App 327870) (Version: - Lavaboots Studios) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_15 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.3.14044_15 - Samsung Electronics Co., Ltd.) Hidden Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14055.3 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.14055.3 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version: - ) Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - ) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.40.0 - SAMSUNG Electronics Co., Ltd.) ScummVM 1.5.0 (HKLM-x32\...\ScummVM_is1) (Version: - The ScummVM Team) SDK Debuggers (x32 Version: 8.59.29746 - Microsoft Corporation) Hidden Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) Slender: The Arrival (HKLM-x32\...\Steam App 252330) (Version: - Blue Isle Studios) Sophos Anti-Virus (HKLM-x32\...\{D929B3B5-56C6-46CC-B3A3-A1A784CBB8E4}) (Version: 10.3.13 - Sophos Limited) Sophos AutoUpdate (HKLM-x32\...\{7CD26A0C-9B59-4E84-B5EE-B386B2F7AA16}) (Version: 4.1.0.273 - Sophos Limited) Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.4 - Sophos Limited) South Park™: The Stick of Truth™ (HKLM-x32\...\Steam App 213670) (Version: - Obsidian Entertainment) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Endless Forest (HKLM-x32\...\The Endless Forest_is1) (Version: - Tale of Tales) The Stanley Parable (HKLM-x32\...\Steam App 221910) (Version: - Galactic Cafe) TmNationsForever (HKLM-x32\...\TmNationsForever_is1) (Version: - Nadeo) Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics) TriDef 3D 6.6 (HKLM-x32\...\essentials-bundle) (Version: 6.6 - Dynamic Digital Depth Australia Pty Ltd) Tropico 5 (HKLM-x32\...\Steam App 245620) (Version: - Haemimont Games) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Ultracopier 1.2.0.2 (HKLM-x32\...\Ultracopier) (Version: 1.2.0.2 - Ultracopier) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_STANDARD_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_STANDARD_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_STANDARD_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_STANDARD_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 4.0 - Ubisoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.0.5 (HKLM-x32\...\VLC media player) (Version: 2.0.5 - VideoLAN) Warcraft III (HKLM-x32\...\Warcraft III) (Version: - Blizzard Entertainment) Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Software Development Kit (HKLM-x32\...\{363a2c1e-637f-45ce-933b-5a5463efd945}) (Version: 8.59.29750 - Microsoft Corporation) WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) WPT Redistributables (x32 Version: 8.59.29750 - Microsoft) Hidden WPTx64 (x32 Version: 8.59.29722 - Microsoft) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 31-05-2015 19:00:37 Windows-Sicherung 08-06-2015 13:27:45 Windows-Sicherung 08-06-2015 13:29:03 Windows Update 13-06-2015 14:39:53 DirectX wurde installiert 14-06-2015 19:00:37 Windows-Sicherung 17-06-2015 21:38:35 roomeon 3D-Planer wurde installiert. 19-06-2015 04:16:31 Windows Update 22-06-2015 09:37:04 Windows-Sicherung 24-06-2015 16:25:08 DirectX wurde installiert 24-06-2015 16:53:49 DirectX wurde installiert 24-06-2015 18:01:31 Installiert Split/Second 24-06-2015 19:40:27 Entfernt Split/Second 24-06-2015 19:50:13 Installed Sophos Virus Removal Tool. 24-06-2015 20:54:39 Removed Guitar Hero III. 24-06-2015 21:01:05 Removed Guitar Hero World Tour. 25-06-2015 00:58:20 Windows Update 25-06-2015 12:55:21 roomeon 3D-Planer wurde entfernt. 25-06-2015 14:22:54 Removed Dual Smart Solution ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2015-06-25 15:15 - 00001001 ____A C:\Windows\system32\Drivers\etc\hosts 130.83.158.177 vpn.hrz.tu-darmstadt.de ###Cisco AnyConnect VPN client modified this file. Please do not modify contents until this comment is removed. ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0AD3C8A4-FC5F-4D51-B2C2-45A9C67E3BE2} - System32\Tasks\{779EC37D-799F-4A57-BAE3-F28F40D31D34} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\3\SSCDUninstall.exe Task: {1A2CB49F-4509-4BA0-9A03-D95D2BC98A7E} - System32\Tasks\{B166BB96-9AE6-4BBE-A6EF-F67E89249AB5} => H:\Setup.exe Task: {1AA6D4D5-982E-4DC8-93FB-F75D65C472CE} - System32\Tasks\{9440065F-91F4-4361-824F-F66FDB50E594} => F:\Programme\OpenVPN\bin\openvpn-gui.exe Task: {1D41D597-5EC0-4A9E-9ACA-7C3F47D404D2} - System32\Tasks\{1BD2999D-1483-4487-B81E-DCDB611CD4E7} => F:\Spiele\Siedler3\s3new160.exe Task: {2ABA1560-E38A-4E97-9DAA-45A6D1D84D3E} - System32\Tasks\{0EB7F8ED-1F7F-43A3-9BC5-0B7705E710F6} => F:\Spiele\Dreamcast\emu\nullDC_Win32_Release-NoTrace.exe Task: {3A2BDED6-1413-4638-98E8-BE643EB339E2} - System32\Tasks\{0ABC3413-E107-4FA4-83FC-1F89A4DAD5C2} => F:\Spiele\Desperados portable\DESPERADOS.exe Task: {423C4B52-065D-4175-B9D0-475946AC6E88} - System32\Tasks\{DC143E6E-E949-4AF7-8EDF-1142EEA4E75D} => C:\Users\SH\Desktop\Daisys Garden\SETUP.EXE Task: {5AEDC82C-41DB-4168-ADA8-25D6E7245795} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {66DAFC3A-12E2-4C39-BFBB-7DAB4BC22406} - System32\Tasks\{0A13E8E8-A30F-4AEA-BF68-D41E2B16944C} => F:\Spiele\Re-Volt\REVOLT.EXE Task: {6855822B-6AC7-4456-8C89-64942C15CA3E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {6B70920D-A199-40FE-B8A4-490D8F85C72C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {6C62208F-3C37-4816-9425-3FE8D5D19786} - System32\Tasks\{5F62F224-F8AE-4AEC-9697-4BA3C6842947} => F:\Spiele\Re-Volt\REVOLT.EXE Task: {6E464BA7-FCED-45D5-AC09-8BBD27C84E46} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2014-11-01] (Microsoft Corporation) Task: {76432D79-BA5E-4708-9049-C2ADE83CA02F} - System32\Tasks\{CF011FBE-9634-4F17-8907-FA7923F15BB7} => E:\Downloads\Zoo Tycoon 2 portable\Zoo Tycoon 2.exe Task: {7C5BE902-191A-4B36-9D63-954264545B71} - System32\Tasks\{6235236C-5FAC-4D95-B4FA-89AE45EF333F} => F:\Spiele\Siedler3\s3.exe Task: {806CACB9-9907-4586-8141-708ECDDAD9C7} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Time-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {807C55E6-025D-458E-9669-4304666E730F} - System32\Tasks\{AEFD3B63-880A-4FED-B867-3FA3283FD068} => H:\Bin\Assetup.exe Task: {83CF2559-908B-4420-B680-85F14AB99EEC} - System32\Tasks\{104CFDDB-9E2D-4220-BA3D-7988D83C9475} => G:\SETUP.EXE Task: {84D02847-BE0C-40EC-8053-5360EF95303C} - System32\Tasks\{D17DD2A7-899F-4A66-8086-D064EFA9AD45} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\6\SSBCUninstall.exe Task: {9027D29F-7717-48E2-A1D0-19354CFD44A4} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {A02D8CF0-FC88-4F88-9B8E-5E129EFE47E6} - System32\Tasks\{C810BC6A-04B8-4620-BCD2-FF0D3A0AE76C} => F:\Spiele\Siedler3\s3.exe Task: {A616CCCE-9739-460D-BF61-1D61445EF1C9} - System32\Tasks\{73626858-316D-461C-B9BF-656D2B494E09} => I:\SETUP.EXE Task: {A6555AD4-7E5E-4841-9010-6A012AE1C07B} - System32\Tasks\{E5FDEE13-FAAC-4FED-ADC9-57E77D2B85B1} => C:\Users\SH\Desktop\Daisys Garden\SETUP.EXE Task: {AAB32953-09E6-4C26-9C6B-B8986F2DFCCC} - System32\Tasks\{F9881EAE-8D85-46DC-8A82-3CF7EBFD7B0F} => F:\Spiele\Battle Realms\Battle_Realms_F.exe [2002-08-29] () Task: {B671DD9A-3497-466D-A9B1-C2B57B8ABA4A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24] (Google Inc.) Task: {BEEB576D-6900-4F49-BC06-62B54B4E8EE8} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {C8755AB7-B150-4928-9C2E-1DE3885A05AF} - System32\Tasks\{8214B320-F092-4CA1-9F00-60004BBB7886} => F:\Spiele\Stronghold Crusader\Stronghold Crusader.exe Task: {D0BD4A0D-16B9-48AE-81F2-AAC146C12367} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {D451D33D-ECFC-416A-9EC3-5EE6897E16FF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24] (Google Inc.) Task: {DD994869-5D1E-45D7-AC8A-1B225FF35B07} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {E34BDEEC-B41B-4172-9AE8-4F1F0B223BBD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {E7D1FA8A-125D-4132-8B5F-B414A746FE20} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated) Task: {E9B983C0-AB48-4288-97C0-4575B5D2A05C} - System32\Tasks\{B5CB0BE8-BCE9-4214-BF8B-F589717B1D18} => F:\Programme\OpenVPN\bin\openvpn-gui.exe Task: {EAE9B20F-EB9D-4A91-A90E-8E3F2D140B47} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-24] (Adobe Systems Incorporated) Task: {ED50CB7B-FE6D-4B37-A286-19A28F2C0867} - System32\Tasks\{36A8A9B0-7B8F-42F9-A36A-E9497174D4F4} => F:\Spiele\AR2\Ra2.exe [2000-09-26] () Task: {EF525288-D933-4223-BA5E-C2D73D4E2728} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {FA210F85-2905-4608-B02F-74CC68B0F194} - System32\Tasks\{D2817F0E-C15B-4836-9384-EE921B14ACD0} => F:\Spiele\Die Siedler - Aufbruch der Kulturen\bin\SADK.exe [2008-08-02] () Task: {FEEC1CC0-E1E4-452B-941D-2342CA6721B3} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2013-01-26 10:00 - 2010-01-21 02:53 - 00496232 _____ () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe 2013-01-26 10:00 - 2010-01-21 02:52 - 00076392 _____ () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll 2013-01-26 10:00 - 2010-01-21 02:53 - 00731752 _____ () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll 2013-01-26 10:00 - 2010-01-21 02:53 - 00209000 _____ () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe 2015-04-20 17:46 - 2015-04-20 17:46 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2014-02-19 22:41 - 2013-11-19 23:34 - 00152576 _____ () C:\Program Files (x86)\Remote Mouse\FileS.dll 2015-06-24 19:25 - 2015-06-24 19:25 - 01478656 _____ () C:\Users\SH\AppData\Local\Temp\mdi564.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SAVService => ""="service" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\SH\AppData\Local\DisplayFusion\Wallpaper_2 DNS Servers: 192.168.192.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: AmazonMP3DownloaderHelper => C:\Users\SH\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe MSCONFIG\startupreg: ContentTransferWMDetector.exe => F:\Programme\Sony\Content Transfer\ContentTransferWMDetector.exe MSCONFIG\startupreg: DAEMON Tools Lite => "F:\Programme\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW MSCONFIG\startupreg: IntelliPoint => "C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe" MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: PDFPrint => F:\Programme\PDF24\pdf24.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [TCP Query User{2C6BE19D-0E58-4CF3-B005-6220A278A365}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe FirewallRules: [UDP Query User{031843FD-4ADA-4FD0-B69F-3DC035CDEF62}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe FirewallRules: [{D8EC7F9A-2C0B-4A43-8EE9-335796C389D6}] => (Allow) F:\Spiele\Steam\Steam.exe FirewallRules: [{1D71F7C7-2A48-4C2D-9324-998923888C84}] => (Allow) F:\Spiele\Steam\Steam.exe FirewallRules: [{59DD7784-CD30-44CE-AD42-A796DAF4D798}] => (Allow) F:\Programme\Skype\Phone\Skype.exe FirewallRules: [{CE4BC92F-D60E-4422-BB9F-812D1EFF6603}] => (Allow) F:\Spiele\Steam\steamapps\common\Plants Vs Zombies\PlantsVsZombies.exe FirewallRules: [{26B43429-3072-4E2C-886B-ED50EC5F1380}] => (Allow) F:\Spiele\Steam\steamapps\common\Plants Vs Zombies\PlantsVsZombies.exe FirewallRules: [{E58FF68A-ED08-46D8-9601-1FF67F6275C4}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe FirewallRules: [{B1BB17BD-FE0C-433D-9658-C326E0C9CD77}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe FirewallRules: [{93B5F8CB-0887-4F04-AB8A-40DF4DE8C970}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\_runA2CO.cmd FirewallRules: [{1D37509C-0346-4930-8D5C-50D6A14A15D8}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\_runA2CO.cmd FirewallRules: [TCP Query User{BC3A705F-913F-4159-BA1C-92108FF713A0}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{EA52438F-5FF5-4C80-8819-4C06F5B54965}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [TCP Query User{3446894D-1667-41A5-8A2E-DB51CF487FEC}F:\spiele\ubisoft\related designs\anno 2070\autopatcher.exe] => (Block) F:\spiele\ubisoft\related designs\anno 2070\autopatcher.exe FirewallRules: [UDP Query User{6EC20222-F622-445D-8700-44E4E433863C}F:\spiele\ubisoft\related designs\anno 2070\autopatcher.exe] => (Block) F:\spiele\ubisoft\related designs\anno 2070\autopatcher.exe FirewallRules: [{AC0E2D0A-4994-4416-AADD-34A69D73760D}] => (Allow) F:\Spiele\Steam\steamapps\common\DmC Devil May Cry\Binaries\Win32\DMC-DevilMayCry.exe FirewallRules: [{81F0C757-7FCC-4BD9-AFDB-2AC4F7E6F3B4}] => (Allow) F:\Spiele\Steam\steamapps\common\DmC Devil May Cry\Binaries\Win32\DMC-DevilMayCry.exe FirewallRules: [{8C641A74-DA57-4BF0-9C66-21326C0DB3F0}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{13FBF50C-3A09-4F8F-8AA4-5A6F6080F6C2}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{88B8F40E-6055-4AB6-98E1-2B9689C0236D}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe FirewallRules: [{7DFE11CA-EADF-491C-8CC0-2505A64AAC70}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe FirewallRules: [{276EBDB5-8508-464B-B174-0323459A605E}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{5A55BECD-CC82-4D25-A2B0-24391E63B7B4}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{E0DEEC64-3D97-4B2B-89E5-8FBF40C9640F}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe FirewallRules: [{9CEF791F-184C-4287-958E-EFF212FAAE64}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe FirewallRules: [{9F9E4530-4EA2-47DC-A523-7FE187FAE15A}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe FirewallRules: [{5FB50D35-4D5C-4A70-9BE5-AD087E5CE162}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe FirewallRules: [TCP Query User{942AF027-F1A3-4A25-8C3D-876AC4DE527C}F:\spiele\farcry 3\bin\farcry3.exe] => (Block) F:\spiele\farcry 3\bin\farcry3.exe FirewallRules: [UDP Query User{DEE31A4C-FDDC-4399-B7CB-CEE8D0DD7DD6}F:\spiele\farcry 3\bin\farcry3.exe] => (Block) F:\spiele\farcry 3\bin\farcry3.exe FirewallRules: [{6B62714C-6366-40FB-89D1-6FAADFF38A35}] => (Allow) F:\Spiele\Steam\steamapps\common\TinyAndBig\tinyandbig.exe FirewallRules: [{1BBE2AA1-CD7A-40D4-BAF7-E7F34BEE87EE}] => (Allow) F:\Spiele\Steam\steamapps\common\TinyAndBig\tinyandbig.exe FirewallRules: [{06B2838C-7296-447B-975A-1563444EDC80}] => (Allow) F:\Spiele\Steam\steamapps\common\English Country Tune\English Country Tune.exe FirewallRules: [{D739DC95-EAA3-4C27-A8B7-CE0175151FBE}] => (Allow) F:\Spiele\Steam\steamapps\common\English Country Tune\English Country Tune.exe FirewallRules: [{BB368750-D952-4687-8BF1-3D48B44F232A}] => (Allow) F:\Spiele\Steam\steamapps\common\Oil Rush\launcher_steam.bat FirewallRules: [{5B5346D6-43F7-4EDE-8B0C-729335463910}] => (Allow) F:\Spiele\Steam\steamapps\common\Oil Rush\launcher_steam.bat FirewallRules: [{7D7822C4-29EF-4283-A43E-29AE4A15910C}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [{94CD086D-601D-4F7C-8EEA-035ACA431F63}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [TCP Query User{77278D68-09CC-4F94-8A29-D4F2E518D61F}F:\spiele\steam\steamapps\common\saints row 2\sr2_pcstart.exe] => (Allow) F:\spiele\steam\steamapps\common\saints row 2\sr2_pcstart.exe FirewallRules: [UDP Query User{26FB494F-75A4-47D6-92FD-C0D6BD1F2805}F:\spiele\steam\steamapps\common\saints row 2\sr2_pcstart.exe] => (Allow) F:\spiele\steam\steamapps\common\saints row 2\sr2_pcstart.exe FirewallRules: [TCP Query User{5EE45DA4-F539-481F-972F-61D75D8B6FF5}F:\spiele\steam\steam.exe] => (Allow) F:\spiele\steam\steam.exe FirewallRules: [UDP Query User{A5424F79-D171-41D4-8A77-6BD6F6D42777}F:\spiele\steam\steam.exe] => (Allow) F:\spiele\steam\steam.exe FirewallRules: [{01E7E936-24EA-480F-9E79-2EF6C6A41C24}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [{82497CF8-B0BB-48C3-A42A-0C8DCCBB4BBA}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [{022BCC5F-073B-4DCE-98A2-058870649A2A}] => (Allow) F:\Spiele\Steam\steamapps\alfonsbauer\source sdk base 2007\hl2.exe FirewallRules: [{00A7551E-A036-4821-8D8D-30C9A3DF29D2}] => (Allow) F:\Spiele\Steam\steamapps\alfonsbauer\source sdk base 2007\hl2.exe FirewallRules: [TCP Query User{B2E05E4B-2B46-4213-9C2C-532FFD5F5D3C}F:\programme\sharekm\sharekm.exe] => (Allow) F:\programme\sharekm\sharekm.exe FirewallRules: [UDP Query User{72A782A5-2930-4248-B7B1-97DB1893267E}F:\programme\sharekm\sharekm.exe] => (Allow) F:\programme\sharekm\sharekm.exe FirewallRules: [{2904C3B5-565E-4BF9-88D3-7E17C8C9608C}] => (Allow) F:\Spiele\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{D3A4C07B-5BE3-43B6-85FA-99D7A8F385BF}] => (Allow) F:\Spiele\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{7172B343-530D-4388-89E7-7D74B80174D4}] => (Allow) F:\Spiele\Steam\steamapps\common\Antichamber\Binaries\Win32\UDK.exe FirewallRules: [{962B7401-1FFB-4908-940B-8521E76C7E9C}] => (Allow) F:\Spiele\Steam\steamapps\common\Antichamber\Binaries\Win32\UDK.exe FirewallRules: [{58AD3F4A-53E4-4A3E-85C2-7AFA0893D50D}] => (Allow) F:\Spiele\Steam\steamapps\common\Construct2\Construct2.exe FirewallRules: [{265C10D1-1274-4A64-96F1-70BE47939109}] => (Allow) F:\Spiele\Steam\steamapps\common\Construct2\Construct2.exe FirewallRules: [{B52FD9C1-D7C7-44A1-ACD6-2B93E243BDB2}] => (Allow) F:\Spiele\Steam\steamapps\common\FlatOut2\FlatOut2.exe FirewallRules: [{964188AE-D332-4B4D-9359-F8636FD7EBC1}] => (Allow) F:\Spiele\Steam\steamapps\common\FlatOut2\FlatOut2.exe FirewallRules: [TCP Query User{1AD91E7C-7376-45FD-8AFE-0DB1B813C40D}F:\spiele\steam\steamapps\common\flatout ultimate carnage\fouc.exe] => (Allow) F:\spiele\steam\steamapps\common\flatout ultimate carnage\fouc.exe FirewallRules: [UDP Query User{2F3DDF7C-B2A8-4FDF-86D3-3DED2976D829}F:\spiele\steam\steamapps\common\flatout ultimate carnage\fouc.exe] => (Allow) F:\spiele\steam\steamapps\common\flatout ultimate carnage\fouc.exe FirewallRules: [{FEFA1B33-BEB0-4345-BA0D-B54D37317B43}] => (Allow) F:\Spiele\Steam\steamapps\common\Oil Rush\launcher_steam.bat FirewallRules: [{1566EE63-81A6-49BE-8C85-F7B95BD64EEA}] => (Allow) F:\Spiele\Steam\steamapps\common\Oil Rush\launcher_steam.bat FirewallRules: [{9253C1F4-BEA3-439A-A413-5BCD6AD9AD3A}] => (Allow) F:\Spiele\Steam\steamapps\common\hotline_miami\HotlineMiami.exe FirewallRules: [{B5A30D86-9A68-4605-A588-B50D3BF98644}] => (Allow) F:\Spiele\Steam\steamapps\common\hotline_miami\HotlineMiami.exe FirewallRules: [{ECA56855-D3CD-439F-A3B0-BDD2BAB5D5EF}] => (Allow) F:\Spiele\ANNO 2070\Anno5.exe FirewallRules: [{FB2424E3-B1B2-4794-921B-6A7C072BDD0C}] => (Allow) F:\Spiele\ANNO 2070\Anno5.exe FirewallRules: [{4AF967B5-631D-4E89-A424-F21C02EDFDBC}] => (Allow) F:\Spiele\ANNO 2070\AutoPatcher.exe FirewallRules: [{0A63D2B5-7532-4102-ABE9-D7140D435729}] => (Allow) F:\Spiele\ANNO 2070\AutoPatcher.exe FirewallRules: [{BB7419C8-C01A-41BE-9E6B-AD03B689D4D8}] => (Allow) F:\Spiele\ANNO 2070\InitEngine.exe FirewallRules: [{9F1FD6D4-858F-4D97-BE43-7A8D5E5DFE47}] => (Allow) F:\Spiele\ANNO 2070\InitEngine.exe FirewallRules: [TCP Query User{5D4D0921-F810-45EF-BCE3-274893E25D0A}F:\spiele\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) F:\spiele\steam\steamapps\common\dark souls prepare to die edition\data\data.exe FirewallRules: [UDP Query User{BC44A9B9-B745-4C56-AA17-3A91559F5CD5}F:\spiele\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) F:\spiele\steam\steamapps\common\dark souls prepare to die edition\data\data.exe FirewallRules: [{89337B81-6AA4-441B-B019-AFC35520EB7B}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal\hl2.exe FirewallRules: [{2C2B7BA7-9034-46CF-9D74-9214F9DB9818}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal\hl2.exe FirewallRules: [TCP Query User{F74E6119-C35A-4DD7-9C4C-BD9D23E46F47}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{B325BB9A-16B9-4252-B55A-737B638D8AF6}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [{12D69903-2EE3-4DD5-8AD5-24AE6B9D4591}] => (Allow) F:\Spiele\Steam\steamapps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat FirewallRules: [{C24C8F33-4DE2-40D3-9F0C-021A7A803614}] => (Allow) F:\Spiele\Steam\steamapps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat FirewallRules: [{15CDA757-8647-477D-AE9B-8A13848C7361}] => (Allow) F:\Spiele\Steam\steamapps\common\Construct2\Construct2.exe FirewallRules: [{E7858CFD-FACC-4B94-A87B-6DC5604E8515}] => (Allow) F:\Spiele\Steam\steamapps\common\Construct2\Construct2.exe FirewallRules: [{D7E45C8E-ABA4-4D87-8263-14FE14A672D5}] => (Allow) F:\Spiele\Steam\steamapps\common\Half-Life 2\hl2.exe FirewallRules: [{927D2BC8-6AF0-4458-B575-FDB0813BCE44}] => (Allow) F:\Spiele\Steam\steamapps\common\Half-Life 2\hl2.exe FirewallRules: [{1CD9155C-D66B-45F9-B24A-0C98D6760659}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{BAB16AD7-D254-42FF-8600-A8FA3D164795}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{2CF0155B-F63C-42CA-A6E5-2A7A3315E161}] => (Allow) F:\Spiele\Steam\steamapps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat FirewallRules: [{A3B332C0-9E46-4846-9D20-029619FA9872}] => (Allow) F:\Spiele\Steam\steamapps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat FirewallRules: [{310DB519-797B-4E17-9EA1-50F952FC4846}] => (Allow) F:\Spiele\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{B73B192C-1973-4309-93C4-9B2B59784BFA}] => (Allow) F:\Spiele\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{BE547D02-320F-4BB2-9467-5B7DDEE788C3}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2 Beta\left4dead2_beta.exe FirewallRules: [{7C24EB07-E89A-46D4-B55F-F6B34AD6EC42}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2 Beta\left4dead2_beta.exe FirewallRules: [{B6834AF7-0382-444E-9D7C-A39F8D4A5B43}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{CC768439-0388-4BD0-9FCE-ED06EC7CFA20}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{452621CA-EE61-436C-A1E9-0EA99A02B4BF}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{35212414-57B3-41E8-BACF-1341BFC08D98}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{A7C577DE-8769-4182-AD9A-82869E47B0BF}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{3FD181C2-632F-4B86-81A4-028B4BF32031}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [TCP Query User{835A04A2-EA55-4497-960A-8B9B21A99B1D}F:\spiele\maniaplanet\maniaplanet.exe] => (Allow) F:\spiele\maniaplanet\maniaplanet.exe FirewallRules: [UDP Query User{6D2909E2-1688-4431-8482-D1063F25E355}F:\spiele\maniaplanet\maniaplanet.exe] => (Allow) F:\spiele\maniaplanet\maniaplanet.exe FirewallRules: [{8C2CA391-70C2-4C05-881A-8B76007B0EC9}] => (Allow) F:\Spiele\Steam\steamapps\common\Bugbear Entertainment\Next Car Game.exe FirewallRules: [{E0E6142A-3BE0-46B4-9C28-33787E69F82A}] => (Allow) F:\Spiele\Steam\steamapps\common\Bugbear Entertainment\Next Car Game.exe FirewallRules: [TCP Query User{CDACFFDA-449A-4BB0-BDA3-B0538313E096}C:\program files (x86)\tale of tales\the endless forest 3\forestviewer.exe] => (Allow) C:\program files (x86)\tale of tales\the endless forest 3\forestviewer.exe FirewallRules: [UDP Query User{E8B277A8-B308-4085-A8DE-6060EA3436FC}C:\program files (x86)\tale of tales\the endless forest 3\forestviewer.exe] => (Allow) C:\program files (x86)\tale of tales\the endless forest 3\forestviewer.exe FirewallRules: [{4CD95332-339F-4B1C-AE13-FF826C158486}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{CAA874F7-94C8-4480-9226-32708B80D708}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{4AB4647A-D046-42E4-B912-02E946B48E09}] => (Allow) F:\Spiele\Blizz\Battle.net\Battle.net.exe FirewallRules: [{E3B8FF95-227D-433E-922D-14C29C8AF006}] => (Allow) F:\Spiele\Blizz\Battle.net\Battle.net.exe FirewallRules: [{68E32DAC-03EF-47FB-BF4C-6B82CD0796C5}] => (Allow) F:\Spiele\Blizz\Diablo III\Diablo III.exe FirewallRules: [{0BF65864-7E8D-4D03-8DB3-D65933DACB33}] => (Allow) F:\Spiele\Blizz\Diablo III\Diablo III.exe FirewallRules: [{7980BD1D-4008-451C-A526-E1CB2285EA4C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{A3A8738E-B81C-4AD2-97D6-6A1EE691AB6E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{822C2752-B4D4-42F6-A54B-06324BC12F14}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe FirewallRules: [{E6572DCD-E3C4-4891-8732-9F53F2DA6D1D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe FirewallRules: [{34C3B52E-ACFD-4D64-8ACF-11ED27CCF393}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe FirewallRules: [{E1B08DCB-7AA5-4F8D-9C95-BF3273F83331}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe FirewallRules: [{6977B532-F320-4368-95EA-59ED582D90B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe FirewallRules: [{9F8F6C0A-ECDD-4750-BCDD-D4EFA36C2DEA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe FirewallRules: [{83C9B81A-AC09-41CC-B3C7-639B73469AA9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe FirewallRules: [{F45323E9-E3C0-48A9-8E5D-E1A54A7EA748}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe FirewallRules: [{7AEF91F2-AF59-479E-9ADF-C7D52E056862}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe FirewallRules: [{83ACBEC3-E604-4BA3-9D52-3664DA8E05D5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe FirewallRules: [{86D791A3-7B1A-4A9C-B586-D4D95E78D764}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe FirewallRules: [{C44977CC-7CBE-448B-9305-1E4C73FA234A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe FirewallRules: [{D9163973-BEA0-4614-99BD-AC674EE5D202}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe FirewallRules: [{36A831EE-3C87-4232-BADB-13BD940BABB9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe FirewallRules: [{AD178CBA-B256-4F4F-A6BD-D0E14793AE95}] => (Allow) F:\Spiele\Blizz\Hearthstone\Hearthstone.exe FirewallRules: [{8E38F59A-9A66-457C-8327-72CFF64A5642}] => (Allow) F:\Spiele\Blizz\Hearthstone\Hearthstone.exe FirewallRules: [{06FB27FD-0BFB-4BF9-A431-F971ABFBFA91}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{F83F8E36-91A1-40A9-90A7-824B38F4C449}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{4509308F-65C3-4CA6-9316-5F33E4934519}] => (Allow) F:\Spiele\Steam\steamapps\common\Banished\Application-steam-x64.exe FirewallRules: [{D7129A8E-03CB-4387-BCE7-5F43EBBBDAF4}] => (Allow) F:\Spiele\Steam\steamapps\common\Banished\Application-steam-x64.exe FirewallRules: [{F16A0A6B-5DB7-43FB-9D6E-85EBEE0B0C98}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{D8F1F1AF-282E-4D2F-A044-FC2FC126FD78}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [TCP Query User{34B1421A-C99C-464F-89B4-D40E58A4E2D6}C:\program files (x86)\remote mouse\remotemouse.exe] => (Allow) C:\program files (x86)\remote mouse\remotemouse.exe FirewallRules: [UDP Query User{45B090D0-6B0F-436A-A634-5DD41FCEAA84}C:\program files (x86)\remote mouse\remotemouse.exe] => (Allow) C:\program files (x86)\remote mouse\remotemouse.exe FirewallRules: [{D9CA769D-2CC1-499D-8CA7-F37B0AE07AA3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{6213593F-AB2D-483B-89B3-251622A63253}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{CAFE9F23-EC99-46EB-B068-1CCC1DD08C44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{6C8D8904-0D5A-4BE9-85A7-8DC71E84A499}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{B76795B7-C827-4F90-8A37-D98FF7CFBCC6}] => (Block) F:\spiele\guitar hero iii\gh3.exe FirewallRules: [{683A0BCE-6EC5-4FAC-9557-4856CCEF29AF}] => (Block) F:\spiele\guitar hero iii\gh3.exe FirewallRules: [{93B9A355-B15F-44C2-9FCF-F3C710EEB9DF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{824E04CC-1EFE-489D-AD70-45B13AA69A95}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{D55E23D3-BACA-4010-86AA-C2130C608AAD}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{B3A8007E-67F9-4BE4-AB2C-74B92922B322}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{9DA23C77-312B-477A-8999-F7184C48F6D7}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{B2BEA770-52AC-4EDD-A755-841333A62011}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{F369FC3F-2ED9-431D-8A9D-2A456439B759}] => (Allow) F:\Spiele\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe FirewallRules: [{024406D0-7077-4A2B-AAC7-22BCF8BEF488}] => (Allow) F:\Spiele\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe FirewallRules: [{56FFC565-6CDF-42EA-AEFD-C64168011B3A}] => (Allow) F:\Spiele\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe FirewallRules: [{ACEEE806-FE56-4DB0-A042-D86BDE93B86B}] => (Allow) F:\Spiele\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe FirewallRules: [{F203C828-AE6B-4A54-925C-BDBD310E6F43}] => (Allow) F:\Spiele\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe FirewallRules: [{EC40F483-557D-4132-99BB-C94F5DA6DFE5}] => (Allow) F:\Spiele\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe FirewallRules: [{EA79F339-3A31-4227-9697-21B7C939B639}] => (Allow) F:\Spiele\Stronghold Crusader\stronghold crusader.exe FirewallRules: [{A3F09705-63EA-4C4C-83EA-E266A70E957D}] => (Allow) F:\Spiele\Steam\steamapps\common\The Stanley Parable\stanley.exe FirewallRules: [{948464A7-3EC1-4D26-A325-6359CF7D60FA}] => (Allow) F:\Spiele\Steam\steamapps\common\The Stanley Parable\stanley.exe FirewallRules: [{268860D8-DE0B-4087-ADDB-4D558C3B8B1F}] => (Allow) F:\Programme\Nexus Mod Manager\NexusClient.exe FirewallRules: [{EEDE604C-7F55-416D-95F1-C5FE142E9A46}] => (Allow) F:\Programme\Nexus Mod Manager\NexusClient.exe FirewallRules: [{DE4CCCF6-C151-48DD-9085-06755CD3F3BC}] => (Allow) F:\Programme\Nexus Mod Manager\NexusClient.exe FirewallRules: [{D639379F-365E-4AC2-98EF-39C979916BA6}] => (Allow) F:\Programme\Nexus Mod Manager\NexusClient.exe FirewallRules: [{2BC70545-C9C2-41FF-A9AA-8B55E2A1CA11}] => (Allow) F:\Spiele\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{CA6A56AB-0869-4331-BDB4-62AD34036379}] => (Allow) F:\Spiele\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{6AB873FD-CBA6-4406-A19F-33A5D0ED1F69}] => (Allow) F:\Spiele\Steam\steamapps\common\Bully Scholarship Edition\Bully.exe FirewallRules: [{71376133-6A21-459C-BE8C-3B4D375F497A}] => (Allow) F:\Spiele\Steam\steamapps\common\Bully Scholarship Edition\Bully.exe FirewallRules: [{16F08E89-7FBF-4700-A8C0-DDB08A63EE53}] => (Allow) F:\Spiele\Steam\steamapps\common\Enslaved\Binaries\Win32\Enslaved.exe FirewallRules: [{102C4727-29EA-47A1-8657-5258E865259E}] => (Allow) F:\Spiele\Steam\steamapps\common\Enslaved\Binaries\Win32\Enslaved.exe FirewallRules: [{FAC254C3-C5A7-474C-9271-6F7790190BB1}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\ARMA2OASERVER.exe FirewallRules: [{1FBEB6C9-45B1-4645-BD2F-436FDECF75E9}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\ARMA2OASERVER.exe FirewallRules: [{46C37E19-9B46-42D0-A571-A286BE1402B7}] => (Allow) F:\Spiele\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe FirewallRules: [{6F9AA8C4-6AF1-473C-99DC-CFA1A8CDF785}] => (Allow) F:\Spiele\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe FirewallRules: [TCP Query User{79A41835-746C-4724-8952-BC0295FDA968}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{6B43E8F2-DBFD-4397-987A-BE9FE0B49C66}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{B1448FB8-38BB-4346-B60C-77217BDEF3F1}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{4DA2B681-926A-47CD-8172-9DF381D5297B}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{D96B2E3C-3978-4326-B914-0CC3790A0912}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{A82AE199-9553-4D2A-9175-F5D64B5A1FEF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{7E9E0AB0-7958-4D10-B49E-0671E46DB55C}] => (Allow) F:\Spiele\Steam\bin\steamwebhelper.exe FirewallRules: [{D45B3E3B-E0B7-4C37-A287-7B0E6DCF5DF3}] => (Allow) F:\Spiele\Steam\bin\steamwebhelper.exe FirewallRules: [{D3C27D52-1093-434F-BE94-6C5D022A5F39}] => (Allow) F:\Spiele\Steam\steamapps\common\Broforce\BROFORCE_Beta.exe FirewallRules: [{8CEF381D-E12E-4E58-8CFC-7C86CABD6FEE}] => (Allow) F:\Spiele\Steam\steamapps\common\Broforce\BROFORCE_Beta.exe FirewallRules: [TCP Query User{630760F7-8F71-4FD9-B857-EF85DBBFD154}F:\spiele\rising gods wow\world_of_warcraft_wotlk-rg\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe] => (Block) F:\spiele\rising gods wow\world_of_warcraft_wotlk-rg\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe FirewallRules: [UDP Query User{18F94FEC-C9F3-4DD7-9734-B7D00E3FCB59}F:\spiele\rising gods wow\world_of_warcraft_wotlk-rg\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe] => (Block) F:\spiele\rising gods wow\world_of_warcraft_wotlk-rg\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe FirewallRules: [{2652FE76-58DE-451E-A9A9-4017775E6FFC}] => (Allow) F:\Spiele\Steam\steamapps\common\Metro Last Light\MetroLL.exe FirewallRules: [{FAC2F888-BC5E-4099-A146-69F31192BAF0}] => (Allow) F:\Spiele\Steam\steamapps\common\Metro Last Light\MetroLL.exe FirewallRules: [{27C8A4E4-6C7B-46AC-BF1E-8A5D81C0EE40}] => (Allow) F:\Spiele\Steam\steamapps\common\Source SDK Base\hl2.exe FirewallRules: [{366348ED-41D7-4467-8F61-682A33255213}] => (Allow) F:\Spiele\Steam\steamapps\common\Source SDK Base\hl2.exe FirewallRules: [{82D1C822-BE8B-4837-9F85-B6A4A3B6EF67}] => (Allow) F:\Spiele\Steam\steamapps\common\Tomb Raider\TombRaider.exe FirewallRules: [{C00D009D-A4D9-423E-80F6-9694F4390115}] => (Allow) F:\Spiele\Steam\steamapps\common\Tomb Raider\TombRaider.exe FirewallRules: [{E147AAFA-067F-431C-B3B9-F64A26DF0C8F}] => (Allow) F:\Spiele\Steam\steamapps\common\Source SDK Base 2007\hl2.exe FirewallRules: [{05E2BBAD-F3BA-4306-9363-6658E999B512}] => (Allow) F:\Spiele\Steam\steamapps\common\Source SDK Base 2007\hl2.exe FirewallRules: [TCP Query User{FA9F82A5-9D6F-438A-BD4E-172848331E81}C:\programdata\battle.net\agent\agent.3182\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3182\agent.exe FirewallRules: [UDP Query User{7DEA6BAE-EEFC-494A-89FC-37C3D17B8F9B}C:\programdata\battle.net\agent\agent.3182\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3182\agent.exe FirewallRules: [{EEB9B9CA-59C6-4554-99EA-BE23B59DCD48}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4 Create A Sim Demo\Game\Bin\TS4CAS.exe FirewallRules: [{0925B725-624A-446E-AC46-EEAFA49EBC96}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4 Create A Sim Demo\Game\Bin\TS4CAS.exe FirewallRules: [TCP Query User{AC845656-2685-43E3-A46C-7BFEAF5E1A26}F:\spiele\tmnationsforever\tmforever.exe] => (Allow) F:\spiele\tmnationsforever\tmforever.exe FirewallRules: [UDP Query User{5AF20FEC-8EC0-4AC4-A1B1-B33D10E1C8A8}F:\spiele\tmnationsforever\tmforever.exe] => (Allow) F:\spiele\tmnationsforever\tmforever.exe FirewallRules: [{E8117924-0F17-442D-B660-9DC22BA2E36B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3182\Agent.exe FirewallRules: [{D6009473-4150-4828-BF3F-D4CC5E043F6E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3182\Agent.exe FirewallRules: [TCP Query User{1CC437FD-6319-45FE-B801-41D0ABA1E627}C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe] => (Allow) C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe FirewallRules: [UDP Query User{A7153A80-5163-47A3-8149-16ED0CAEF293}C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe] => (Allow) C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe FirewallRules: [{EE84E611-556F-49CC-AB75-37AB9B1ED8F0}] => (Block) C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe FirewallRules: [{1901E8D5-776A-489D-A4F8-8288FC5CF4B8}] => (Block) C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe FirewallRules: [TCP Query User{1841F0CE-944D-4406-950C-D8AE1E8490F4}C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe] => (Allow) C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe FirewallRules: [UDP Query User{51CDF0E2-409B-4BD1-91A0-85AD6271BDEF}C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe] => (Allow) C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe FirewallRules: [{2FBD9BC2-94FA-49C9-BE10-7DE2B9C6F8F3}] => (Block) C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe FirewallRules: [{0D177CA2-FECE-4D0B-AA05-756B3B90D6BB}] => (Block) C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe FirewallRules: [{80771493-9E65-4A2F-A673-21967CFD6B19}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{8C68C2F4-31DC-4BB9-AC0C-9DD495F68EB7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{27564E58-3B54-4DBF-98F0-8ADAF467DEDE}] => (Allow) F:\Spiele\Steam\steamapps\common\Bugbear Entertainment\Wreckfest.exe FirewallRules: [{CF992184-7850-435B-9F74-45C1712CDC83}] => (Allow) F:\Spiele\Steam\steamapps\common\Bugbear Entertainment\Wreckfest.exe FirewallRules: [{38C455B2-1AA3-43DC-A88E-9867B6F2DDCA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{CFAC61BC-A88D-4923-8DDF-17FC7A57808E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{B901CD78-20C3-443D-8442-ED7CFCF7C135}] => (Allow) F:\Spiele\Steam\steamapps\common\Bridge Constructor Playground\BridgeConstructorPlayground.exe FirewallRules: [{89A265FE-8756-40DF-86B6-C7C6E61C5E6C}] => (Allow) F:\Spiele\Steam\steamapps\common\Bridge Constructor Playground\BridgeConstructorPlayground.exe FirewallRules: [{EE12FD42-9E1F-4AC3-B92A-7361AF482CA0}] => (Allow) F:\Spiele\Steam\steamapps\common\Bridge Constructor Medieval\Bridge_Constructor_Medieval.exe FirewallRules: [{2CD7DC47-5CF6-4535-825F-BB349D2CE3B7}] => (Allow) F:\Spiele\Steam\steamapps\common\Bridge Constructor Medieval\Bridge_Constructor_Medieval.exe FirewallRules: [{D9678680-9CC6-4F30-BFF8-DA7A0F7D79F1}] => (Allow) F:\Spiele\Steam\steamapps\common\BridgeConstructor\BridgeConstructor.exe FirewallRules: [{3FFAADA3-30D8-46A8-B666-7CD9A83510C1}] => (Allow) F:\Spiele\Steam\steamapps\common\BridgeConstructor\BridgeConstructor.exe FirewallRules: [{6C5304E3-0642-4CDD-8D16-B5853F62AC17}] => (Allow) F:\Spiele\Steam\steamapps\common\Assassin's Creed Liberation\ac3lhd_32.exe FirewallRules: [{DACE09AE-4E4D-4D0A-B4E7-4EE4EE417D08}] => (Allow) F:\Spiele\Steam\steamapps\common\Assassin's Creed Liberation\ac3lhd_32.exe FirewallRules: [{52E78844-3D52-4AB1-A21C-110BB9E8E5B4}] => (Allow) F:\Spiele\Steam\steamapps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe FirewallRules: [{D2FA1D17-928E-4A32-A347-4BD003203988}] => (Allow) F:\Spiele\Steam\steamapps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe FirewallRules: [TCP Query User{64D00F2C-C613-4D46-9E8A-A0223A547D15}C:\users\sh\appdata\local\temp\ixp000.tmp\dear.exe] => (Block) C:\users\sh\appdata\local\temp\ixp000.tmp\dear.exe FirewallRules: [UDP Query User{50D0103B-1851-4F25-8B2A-58C2154BC8F7}C:\users\sh\appdata\local\temp\ixp000.tmp\dear.exe] => (Block) C:\users\sh\appdata\local\temp\ixp000.tmp\dear.exe FirewallRules: [TCP Query User{8F345F7B-A443-47A6-9ECB-9B6801DB47B4}C:\users\sh\desktop\freekshow\reveal\binaries\win32\udk.exe] => (Block) C:\users\sh\desktop\freekshow\reveal\binaries\win32\udk.exe FirewallRules: [UDP Query User{837DADA3-4227-4A28-B09E-77A5894CAD30}C:\users\sh\desktop\freekshow\reveal\binaries\win32\udk.exe] => (Block) C:\users\sh\desktop\freekshow\reveal\binaries\win32\udk.exe FirewallRules: [TCP Query User{D6B80ED4-9442-4FA0-B952-033D86A490F6}F:\spiele\ar2\game.exe] => (Allow) F:\spiele\ar2\game.exe FirewallRules: [UDP Query User{33DFCFEA-0263-40B1-8442-B454576C9F5E}F:\spiele\ar2\game.exe] => (Allow) F:\spiele\ar2\game.exe FirewallRules: [TCP Query User{4C2312F8-3ED6-48D0-BFCD-59FC97446F63}F:\spiele\clonk rage\clonk.exe] => (Allow) F:\spiele\clonk rage\clonk.exe FirewallRules: [UDP Query User{04B5C2CB-7B07-494D-B6CA-7DBC1A98E30A}F:\spiele\clonk rage\clonk.exe] => (Allow) F:\spiele\clonk rage\clonk.exe FirewallRules: [TCP Query User{04F82361-9A47-4D1D-ADA2-A1167264A2FA}F:\spiele\clonk endeavour\clonk.c4x] => (Allow) F:\spiele\clonk endeavour\clonk.c4x FirewallRules: [UDP Query User{7AC345A0-4A39-47EE-9828-B916992B5AA3}F:\spiele\clonk endeavour\clonk.c4x] => (Allow) F:\spiele\clonk endeavour\clonk.c4x FirewallRules: [{B7843A9F-B748-4189-8E0D-E5F356B8CD30}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe FirewallRules: [{84182764-9342-41D0-A2E1-CB877A395E03}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe FirewallRules: [TCP Query User{9EFFCB9D-D4E3-49E1-B5B8-7A80E4717CAC}F:\programme\remote control server\remote control server.exe] => (Allow) F:\programme\remote control server\remote control server.exe FirewallRules: [UDP Query User{F0644439-D505-426C-8481-BB4B69EF65D7}F:\programme\remote control server\remote control server.exe] => (Allow) F:\programme\remote control server\remote control server.exe FirewallRules: [{C121BF0D-1792-4FEF-9C05-352CD8A958EE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe FirewallRules: [{C387C3A5-941E-47C4-99D1-3B46E64DBCF4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe FirewallRules: [{74AA505F-3DF5-482F-B7CA-6AFA7312B84F}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{A4786641-DE1C-41D7-A0E9-1EA0F088876E}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{CBBF1A7D-45B3-4F1F-B69F-0B71D0465E93}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{43691564-9A58-476C-8488-9A9DE4C8F0B7}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [TCP Query User{9CAB7543-88D6-44B4-8179-3B38B1F3E5EE}F:\spiele\ubisoft\rayman origins\rayman origins.exe] => (Block) F:\spiele\ubisoft\rayman origins\rayman origins.exe FirewallRules: [UDP Query User{BEF7A399-A3E3-4892-85B9-500BEC6729D3}F:\spiele\ubisoft\rayman origins\rayman origins.exe] => (Block) F:\spiele\ubisoft\rayman origins\rayman origins.exe FirewallRules: [{3335D305-17AD-4BA1-8792-2F9DD8DEE99C}] => (Allow) F:\Spiele\Steam\steamapps\common\Besiege\Besiege.exe FirewallRules: [{0B479948-993B-4DA8-85B8-857D3F1E9F0B}] => (Allow) F:\Spiele\Steam\steamapps\common\Besiege\Besiege.exe FirewallRules: [{00DD4C03-7241-4BFB-9CC9-F20CF3C92713}] => (Allow) F:\Spiele\Steam\steamapps\common\CoJ Gunslinger\CoJGunslinger.exe FirewallRules: [{9B647514-ED75-4AE0-8B9F-D0E26FE86CAB}] => (Allow) F:\Spiele\Steam\steamapps\common\CoJ Gunslinger\CoJGunslinger.exe FirewallRules: [{51443128-C299-46B8-880D-43702562A729}] => (Allow) F:\Programme\Mozilla Firefox\firefox.exe FirewallRules: [{013A483B-AA9E-4491-AED5-2C52855EF75A}] => (Allow) F:\Programme\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{0EEA6DCA-1D26-4950-A6D8-943CB6B7EE13}C:\users\sh\appdata\local\hola\firefox\app\hola_plugin.exe] => (Allow) C:\users\sh\appdata\local\hola\firefox\app\hola_plugin.exe FirewallRules: [UDP Query User{CE01B0A4-4D12-426A-9E01-C52094FE6164}C:\users\sh\appdata\local\hola\firefox\app\hola_plugin.exe] => (Allow) C:\users\sh\appdata\local\hola\firefox\app\hola_plugin.exe FirewallRules: [{86FF776D-34BA-4C3E-8BBE-E08104CCA342}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{E16D80F9-1ADD-4A62-96C6-BA71A886D826}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{C962C669-DC9B-4025-8BC7-1A2578D9F7E8}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{4B03C4FB-10D6-4EA5-9B9C-70730342F800}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [TCP Query User{FEC1C191-2669-4A4E-BD3A-BCC8B570AB55}F:\spiele\electronic arts\need for speed(tm) hot pursuit\nfs11.exe] => (Block) F:\spiele\electronic arts\need for speed(tm) hot pursuit\nfs11.exe FirewallRules: [UDP Query User{5611D245-16E3-45F3-848E-E4FA1EE9DDF0}F:\spiele\electronic arts\need for speed(tm) hot pursuit\nfs11.exe] => (Block) F:\spiele\electronic arts\need for speed(tm) hot pursuit\nfs11.exe FirewallRules: [{67B97936-8267-445F-9E62-16CD21F289AB}] => (Allow) F:\Spiele\Steam\steamapps\common\Salt Demo\SaltTrial.exe FirewallRules: [{1DE59770-12A7-43F9-B19A-C6F24653BB9B}] => (Allow) F:\Spiele\Steam\steamapps\common\Salt Demo\SaltTrial.exe FirewallRules: [{0916DEE1-447A-445F-80CB-A7D7FA438DA3}] => (Allow) F:\Spiele\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe FirewallRules: [{0507C7A8-1C36-4122-901A-5CCF7145AE36}] => (Allow) F:\Spiele\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe FirewallRules: [{BDEAB6FB-91E9-49F0-8DD1-DFEDB7A160B5}] => (Allow) F:\Spiele\Steam\steamapps\common\Nidhogg\Nidhogg.exe FirewallRules: [{0824D022-381D-4693-8213-C9968F8C108E}] => (Allow) F:\Spiele\Steam\steamapps\common\Nidhogg\Nidhogg.exe FirewallRules: [{DEE3F90B-BC4F-4B3A-89C9-0CE1F8800DC2}] => (Allow) F:\Spiele\Steam\steamapps\common\Command and Conquer Red Alert 3 Uprising\RA3EP1.exe FirewallRules: [{555B0416-F205-4579-B618-8F5B8768921C}] => (Allow) F:\Spiele\Steam\steamapps\common\Command and Conquer Red Alert 3 Uprising\RA3EP1.exe FirewallRules: [{5179275A-945C-40F2-93FA-34462AB30BD3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{CC417F9E-2614-4000-A294-DF8D9D248925}] => (Allow) F:\Spiele\Steam\steamapps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{F1E83BD0-12ED-4A31-84A3-E95D6FF76022}] => (Allow) F:\Spiele\Steam\steamapps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{CC4130DE-3985-4E6E-AFFE-3763D50C6F58}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [{4E79BD64-52B2-46C0-8889-48358549D456}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe StandardProfile\AuthorizedApplications: [F:\Programme\TriDef\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe] => Enabled:TriDef 3D Media Player ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (06/25/2015 03:19:26 PM) (Source: Sophos Anti-Virus) (EventID: 38) (User: NT-AUTORITÄT) Description: Virus/Spyware 'Troj/Miner-AB' konnte nicht entfernt werden. Es traten Fehler auf. Error: (06/25/2015 03:16:17 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/25/2015 02:27:49 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/25/2015 00:13:24 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/24/2015 08:57:01 PM) (Source: Xbox_360_CC_Driver) (EventID: 4373) (User: ) Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar. Error: (06/24/2015 07:37:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/24/2015 07:34:33 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/24/2015 07:25:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: key.exe, Version: 0.0.0.0, Zeitstempel: 0x55885865 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x023028ad ID des fehlerhaften Prozesses: 0x1628 Startzeit der fehlerhaften Anwendung: 0xkey.exe0 Pfad der fehlerhaften Anwendung: key.exe1 Pfad des fehlerhaften Moduls: key.exe2 Berichtskennung: key.exe3 Error: (06/24/2015 07:25:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: key.exe, Version: 0.0.0.0, Zeitstempel: 0x55885865 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x022128ad ID des fehlerhaften Prozesses: 0x17d0 Startzeit der fehlerhaften Anwendung: 0xkey.exe0 Pfad der fehlerhaften Anwendung: key.exe1 Pfad des fehlerhaften Moduls: key.exe2 Berichtskennung: key.exe3 Error: (06/24/2015 07:17:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: SplitSecond.exe, Version: 1.0.0.1, Zeitstempel: 0x4be13c66 Name des fehlerhaften Moduls: SplitSecond.exe, Version: 1.0.0.1, Zeitstempel: 0x4be13c66 Ausnahmecode: 0x80000003 Fehleroffset: 0x00d8f167 ID des fehlerhaften Prozesses: 0xe54 Startzeit der fehlerhaften Anwendung: 0xSplitSecond.exe0 Pfad der fehlerhaften Anwendung: SplitSecond.exe1 Pfad des fehlerhaften Moduls: SplitSecond.exe2 Berichtskennung: SplitSecond.exe3 System errors: ============= Error: (06/25/2015 03:15:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: StarOpen Error: (06/25/2015 03:14:25 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (06/25/2015 03:13:35 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (06/25/2015 02:26:41 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: StarOpen Error: (06/25/2015 02:25:56 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (06/25/2015 00:12:18 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: StarOpen Error: (06/25/2015 00:11:31 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (06/24/2015 07:36:28 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: StarOpen Error: (06/24/2015 07:35:47 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (06/24/2015 07:33:34 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: StarOpen Microsoft Office: ========================= CodeIntegrity Errors: =================================== Date: 2014-07-27 12:16:45.953 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\SH\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-27 12:16:45.901 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\SH\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-27 12:16:43.529 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Programme\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-27 12:16:43.474 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Programme\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Quad CPU Q8400 @ 2.66GHz Percentage of memory in use: 47% Total physical RAM: 4094.55 MB Available physical RAM: 2138.83 MB Total Pagefile: 8187.32 MB Available Pagefile: 5737.23 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:200 GB) (Free:110.95 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Systemsicherung) (Fixed) (Total:465.75 GB) (Free:279.91 GB) NTFS Drive e: (Daten) (Fixed) (Total:465.75 GB) (Free:381.85 GB) NTFS Drive f: (Anwendungen) (Fixed) (Total:498.63 GB) (Free:185.28 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: E3B7363E) Partition 1: (Active) - (Size=200 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=498.6 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: 02340234) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.8 GB) - (Type=OF Extended) ==================== End of log ============================ Geändert von Shnoxxer (25.06.2015 um 17:08 Uhr) |
25.06.2015, 17:09 | #4 |
| Win 7: Sophos meldet "Troj/Miner-AB" Gmer: Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2015-06-25 15:58:29 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 WDC_WD7500AACS-00D6B1 rev.01.01A01 698,64GB Running: oxdekkrd.exe; Driver: C:\Users\SH\AppData\Local\Temp\pxldypoc.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll .text C:\Windows\Explorer.EXE[1464] C:\Windows\system32\kernel32.dll!CopyFileExW 00000000779b1870 5 bytes JMP 00000001379a00d8 .text C:\Windows\Explorer.EXE[1464] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW 0000000077a2f500 8 bytes JMP 00000001379a0110 .text C:\Windows\Explorer.EXE[1464] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefdf47490 11 bytes JMP 000007ffbdf300d8 .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\SysWOW64\ntdll.dll!KiUserExceptionDispatcher 0000000077db0154 5 bytes JMP 0000000175448710 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077ddaf7d 5 bytes JMP 0000000175444f00 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\SysWOW64\ntdll.dll!RtlExitUserThread 0000000077df69ec 5 bytes JMP 00000001754450e0 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!WriteFile 0000000077401282 5 bytes JMP 0000000175444f60 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!FreeLibrary 0000000077403478 5 bytes JMP 0000000175445330 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!VirtualProtect 0000000077404317 5 bytes JMP 0000000175444fc0 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!LoadLibraryExA 00000000774048cb 5 bytes JMP 0000000175445040 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!LoadLibraryW 00000000774048e3 5 bytes JMP 0000000175445000 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!LoadLibraryExW 0000000077404915 5 bytes JMP 0000000175445020 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!LoadLibraryA 000000007740498f 5 bytes JMP 0000000175445060 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!CreateFileA 000000007740537e 5 bytes JMP 0000000175445160 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!GlobalAlloc 0000000077405846 5 bytes JMP 0000000175445080 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000774079c8 5 bytes JMP 0000000175445100 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalA 000000007741a48f 5 bytes JMP 0000000175445120 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!WriteProcessMemory 000000007741d9b0 5 bytes JMP 0000000175444f20 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!GetThreadContext 000000007742799c 1 byte JMP 00000001754450a0 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!GetThreadContext + 2 000000007742799e 3 bytes {CALL RSI} .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!VirtualProtectEx 0000000077484b5f 5 bytes JMP 0000000175444fa0 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!WriteFileEx 0000000077484b8f 5 bytes JMP 0000000175444f40 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!SetThreadContext 0000000077485933 5 bytes JMP 0000000175444fe0 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll .text C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3876] 000007fef5284094 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3880] 000007fef376f5f8 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3884] 000007fef5284094 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3888] 000007fef398bc60 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3892] 000007fef5284094 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [3128:3484] 000007fef398bc60 Thread C:\Windows\System32\svchost.exe [5204:5348] 000007fee3669688 ---- Processes - GMER 2.1 ---- Library C:\Users\SH\AppData\Local\Temp\mdi564.dll (*** suspicious ***) @ C:\Windows\SysWOW64\rundll32.exe [2584](2015-06-24 17:25:18) 00000000745a0000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 F:\Programme\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x77 0x3D 0x06 0x69 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 F:\Programme\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x77 0x3D 0x06 0x69 ... ---- EOF - GMER 2.1 ---- |
26.06.2015, 07:50 | #5 |
/// the machine /// TB-Ausbilder | Win 7: Sophos meldet "Troj/Miner-AB" hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.06.2015, 09:08 | #6 |
| Win 7: Sophos meldet "Troj/Miner-AB" Hi Schrauber, hier die ComboFix.txt: Code:
ATTFilter ComboFix 15-06-24.02 - SH 26.06.2015 9:33.1.4 - x64 Microsoft Windows 7 Professional N 6.1.7601.1.1252.49.1031.18.4095.1994 [GMT 2:00] ausgeführt von:: c:\users\SH\Desktop\trojaner\ComboFix.exe AV: Sophos Anti-Virus *Disabled/Updated* {6BABF8F7-3EB6-BD1D-9167-8C5ECA060A29} SP: Sophos Anti-Virus *Disabled/Updated* {D0CA1913-188C-B293-ABD7-B72CB1814094} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\END c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ar\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\bg\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ca\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\cs\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\da\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\de\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\el\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\en\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\es\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\fi\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\fr\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\gu\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\he\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\hr\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\hu\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\id\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\it\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ja\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\nb\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\nl\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\pl\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\pt_BR\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\pt_PT\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ro\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ru\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\sk\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\sl\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\sr\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\sv\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\te\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\tr\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\uk\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\vi\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\zh_CN\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\zh_TW\messages.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_metadata\computed_hashes.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_metadata\verified_contents.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\adblock_start_chrome.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\adblock_start_common.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\background.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\bandaids.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\popup.css c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\popup.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\popup.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\search\search.css c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\search\search.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\CHANGELOG.txt c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\checkupdates.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\chrome_oauth_receiver.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\chrome_oauth_receiver.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\dropbox-datastores.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\domainset.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\filternormalizer.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\filteroptions.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\filterset.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\filtertypes.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\myfilters.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\functions.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\gab_question.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\idlehandler.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\delete.gif c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\dropbox1.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\dropbox2.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\dropbox3.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\facebook-sprite.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\gifloader.gif c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\gplus-sprite.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon128.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon16.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon16_grayscale.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon16_grayscale@2x.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon19-grayscale.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon19-whitelisted.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon19.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon24.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon32.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon38-grayscale.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon38-whitelisted.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon38.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon48.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\logo.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\check.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\magnifying_glass.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\search-engine-card_no-shadow.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\search-engine-icons.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\search-omnibox-card_no-shadow.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\search_engine_select_arrow.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\twitter-sprite.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_flat_55_999999_40x100.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_flat_75_aaaaaa_40x100.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_glass_45_0078ae_1x400.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_glass_55_f8da4e_1x400.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_glass_75_79c9ec_1x400.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_gloss-wave_50_38cfff_500x100.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_gloss-wave_75_2191c0_500x100.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_inset-hard_100_fcfdfd_1x100.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-icons_056b93_256x240.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-icons_d8e7f3_256x240.png c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\jquery-ui.custom.css c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\override-page.css c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\jquery-ui.custom.min.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\jquery.cookie.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\jquery.min.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\LICENSE c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\manifest.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\notificationoverlay.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\customize.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\customize.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\filters.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\filters.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\general.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\general.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\index.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\index.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\options.css c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\support.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\support.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\adreport.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\adreport.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\resourceblock.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\resourceblock.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\subscribe.html c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\subscribe.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\port.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\punycode.min.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\README.markdown c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\focus.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\incognito.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\pitchpage.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\search-plus-one.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\secure_reminder.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\serp.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\stats.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\survey.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\translators.json c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\blacklistui.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\clickwatcher.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\elementchain.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\overlay.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\rightclick_hook.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\load_jquery_ui.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\send_content_to_back.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\top_open_blacklist_ui.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\top_open_whitelist_ui.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\ytchannel.js c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gighmmpiobklfepjocnamgkkbiglidom_0.localstorage-journal c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gighmmpiobklfepjocnamgkkbiglidom_0.localstorage c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Preferences c:\windows\apppatch\AppLoc.exe c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb c:\windows\IsUn0407.exe . . ((((((((((((((((((((((( Dateien erstellt von 2015-05-26 bis 2015-06-26 )))))))))))))))))))))))))))))) . . 2015-06-26 07:45 . 2015-06-26 07:45 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-06-25 13:18 . 2015-06-25 13:21 -------- d-----w- C:\FRST 2015-06-24 22:58 . 2015-05-03 03:16 12214312 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D2943C8-C5E7-4706-A20F-F8D36E1A2BA9}\mpengine.dll 2015-06-24 14:13 . 2015-06-24 14:13 -------- d-----w- c:\users\SH\AppData\Local\Licenses 2015-06-24 13:43 . 2015-06-24 13:43 -------- d-----w- c:\programdata\TriDef 3D 2015-06-24 13:41 . 2015-06-24 13:41 -------- d-----w- c:\programdata\DDD 2015-06-17 19:39 . 2015-06-17 19:39 -------- d-----w- c:\users\SH\AppData\Local\roomeon 2015-06-17 19:28 . 2015-06-17 19:38 -------- d-----w- c:\users\SH\AppData\Local\Room Arranger 2015-06-16 14:19 . 2015-06-16 14:19 -------- d-sh--w- c:\users\SH\AppData\Local\EmieBrowserModeList 2015-06-14 11:54 . 2015-06-14 11:54 -------- d-----w- c:\users\SH\AppData\Roaming\Red Alert 3 Uprising 2015-06-13 12:45 . 2015-06-13 12:45 -------- d-----w- c:\users\SH\AppData\Roaming\Red Alert 3 2015-06-13 12:06 . 2015-06-13 12:36 -------- d-----w- c:\users\SH\AppData\Roaming\Nidhogg 2015-06-11 13:27 . 2015-05-23 03:15 47616 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2015-06-02 18:16 . 2015-06-02 18:16 -------- d-----w- c:\users\SH\AppData\Local\PDF24 2015-06-01 18:27 . 2015-06-01 18:27 -------- d-----w- c:\users\SH\AppData\Local\GWX 2015-05-28 20:58 . 2015-05-01 13:17 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-05-28 20:58 . 2015-05-01 13:16 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-06-24 09:35 . 2014-03-08 14:32 778416 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2015-06-24 09:35 . 2014-03-08 14:32 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-06-19 02:19 . 2013-01-24 17:47 140135120 ----a-w- c:\windows\system32\MRT.exe 2015-05-25 18:01 . 2015-06-11 13:28 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2015-04-20 15:46 . 2015-04-20 15:46 11152 ----a-w- c:\windows\SysWow64\vpncategories.dll 2015-04-20 15:46 . 2015-04-20 15:46 34192 ----a-w- c:\windows\SysWow64\vpnevents.dll 2015-04-20 15:25 . 2015-04-20 15:25 112496 ----a-r- c:\windows\system32\drivers\acsock64.sys 2015-04-20 03:17 . 2015-05-14 17:49 1179136 ----a-w- c:\windows\system32\FntCache.dll 2015-04-20 03:17 . 2015-05-14 17:49 1647104 ----a-w- c:\windows\system32\DWrite.dll 2015-04-20 02:56 . 2015-05-14 17:49 1250816 ----a-w- c:\windows\SysWow64\DWrite.dll 2015-04-18 03:10 . 2015-05-14 17:51 460800 ----a-w- c:\windows\system32\certcli.dll 2015-04-18 02:56 . 2015-05-14 17:51 342016 ----a-w- c:\windows\SysWow64\certcli.dll 2015-04-13 03:28 . 2015-05-14 17:50 328704 ----a-w- c:\windows\system32\services.exe 2015-04-08 03:29 . 2015-05-14 17:49 275456 ----a-w- c:\windows\system32\InkEd.dll 2015-04-08 03:14 . 2015-05-14 17:49 216064 ----a-w- c:\windows\SysWow64\InkEd.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608] "Remote Mouse"="c:\program files (x86)\Remote Mouse\RemoteMouse.exe" [2015-01-23 2050048] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2010-12-13 135536] "ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632] "StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176] "Raptr"="c:\program files (x86)\Raptr\raptrstub.exe" [2015-05-15 55568] "Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2015-03-04 1593640] "Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2015-04-20 708496] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService] @="service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [x] R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys;c:\windows\SYSNATIVE\DRIVERS\acsock64.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv_x64.sys [x] R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x] R3 Media Jukebox 14 Service;Media Jukebox 14 Service;f:\programme\Media Jukebox 14\JRService.exe;f:\programme\Media Jukebox 14\JRService.exe [x] R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys;c:\windows\SYSNATIVE\Drivers\nx6000.sys [x] R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] R3 ptun0901;TAP Adapter V9 for Private Tunnel;c:\windows\system32\DRIVERS\ptun0901.sys;c:\windows\SYSNATIVE\DRIVERS\ptun0901.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 rzdaendpt;Razer DeathAdder end point;c:\windows\system32\DRIVERS\rzdaendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzdaendpt.sys [x] R3 rzvkeyboard;Razer Virtual Keyboard Driver;c:\windows\system32\DRIVERS\rzvkeyboard.sys;c:\windows\SYSNATIVE\DRIVERS\rzvkeyboard.sys [x] R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys;c:\windows\SYSNATIVE\DRIVERS\sdcfilter.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x] R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys;c:\windows\SYSNATIVE\DRIVERS\SophosBootDriver.sys [x] R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys;c:\windows\SYSNATIVE\DRIVERS\savonaccess.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 SAVAdminService;Sophos Anti-Virus Statusreporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [x] S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [x] S2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [x] S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [x] S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 rzudd;Razer Mouse Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-06-24 09:07 990024 ----a-w- c:\program files (x86)\Google\Chrome\Application\43.0.2357.130\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2015-06-26 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-08 09:35] . 2015-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24 17:04] . 2015-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24 17:04] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184] "PrnStatusMX"="c:\program files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe" [2012-07-04 1240064] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: Nach Microsoft E&xel exportieren - f:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: {{c0e8ae32-0758-4c8d-ab71-23b361fe8964} - c:\users\SH\AppData\Local\Temp\ie_script.htm LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll TCP: DhcpNameServer = 192.168.192.1 FF - ProfilePath - c:\users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\ FF - prefs.js: network.proxy.type - 2 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-Clonk Planet - c:\windows\system32\GKSUI18.EXE AddRemove-Need For Speed - Porsche - c:\windows\IsUn0407.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-2306031424-1336655547-1434631041-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:9f,aa,dc,d5,97,0e,4b,6b,74,45,42,f2,75,22,5c,1a,6c,2e,21,82,6c,9d,50, bf,4c,23,1f,ea,59,ac,db,f5,b4,58,d2,d2,f4,c1,07,7b,16,88,11,ab,6e,d1,9f,5c,\ "??"=hex:72,09,6e,72,ba,1a,c1,28,d1,6a,51,39,96,6d,8f,e5 . [HKEY_USERS\S-1-5-21-2306031424-1336655547-1434631041-1000\Software\SecuROM\License information*] "datasecu"=hex:04,fb,ba,c2,de,95,59,48,51,15,86,18,94,2a,cc,e5,28,6b,0b,f4,dc, 83,99,cc,bc,22,8a,dd,0f,36,be,94,ba,88,74,ed,c9,95,c1,23,9f,bf,23,ca,0b,f8,\ "rkeysecu"=hex:a4,99,ff,e7,14,53,f3,ea,b3,b7,3d,e8,61,fa,cf,60 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2015-06-26 09:58:11 ComboFix-quarantined-files.txt 2015-06-26 07:58 . Vor Suchlauf: 11 Verzeichnis(se), 113.138.089.984 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 117.132.058.624 Bytes frei . - - End Of File - - FE983C4156C6ADA204BB3F836CCFC845 A36C5E4F47E84449FF07ED3517B43A31 |
27.06.2015, 08:08 | #7 |
/// the machine /// TB-Ausbilder | Win 7: Sophos meldet "Troj/Miner-AB" Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.06.2015, 12:30 | #8 |
| Win 7: Sophos meldet "Troj/Miner-AB" Hi Schrauber, hier die Logfiles. Bei dem mbam Scan ist mein Sophos angesprungen und hat folgendes gemeckert: Code:
ATTFilter ****************** Sophos Anti-Virus Protokoll - 27.06.2015 11:24:30 ************** ... 20150627 091205 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091205 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150627 091207 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091207 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150627 091208 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091208 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150627 091210 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091210 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150627 091212 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091212 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150627 091213 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091213 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150627 091215 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091215 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150627 091217 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091217 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150627 091218 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091218 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH 20150627 091220 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150627 091220 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH ... (20 Objekte) Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 27.06.2015 Suchlauf-Zeit: 10:59:31 Logdatei: mbam.txt Administrator: Ja Version: 2.01.6.1022 Malware Datenbank: v2015.06.26.08 Rootkit Datenbank: v2015.06.26.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: SH Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 387792 Verstrichene Zeit: 17 Min, 1 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente gefunden) Module: 0 (Keine schädliche Elemente gefunden) Registrierungsschlüssel: 1 PUP.Optional.ICQ.A, HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}, In Quarantäne, [341ca41b6e1c3006e71bf09d46bf3ec2], Registrierungswerte: 3 PUP.Optional.ICQ.A, HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}|DisplayName, Search@Icq.Com, In Quarantäne, [341ca41b6e1c3006e71bf09d46bf3ec2] PUP.Optional.ICQ.A, HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}|URL, hxxp://search.icq.com/search/results.php?q=%s&ch_id=hm&search_mode=web, In Quarantäne, [53fda41bd5b573c335cdcfbe36cfc23e] PUP.Optional.ICQ.A, HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}|FaviconURLFallback, hxxp://search.icq.com/favicon.ico, In Quarantäne, [153bd6e94842cd69986ab0dd07fe768a] Registrierungsdaten: 0 (Keine schädliche Elemente gefunden) Ordner: 0 (Keine schädliche Elemente gefunden) Dateien: 0 (Keine schädliche Elemente gefunden) Physische Sektoren: 0 (Keine schädliche Elemente gefunden) (end) Code:
ATTFilter # AdwCleaner v4.207 - Bericht erstellt 27/06/2015 um 11:30:42 # Aktualisiert 21/06/2015 von Xplode # Datenbank : 2015-06-23.1 [Server] # Betriebssystem : Windows 7 Professional N Service Pack 1 (x64) # Benutzername : SH - SH-PC # Gestarted von : C:\Users\SH\Desktop\trojaner\AdwCleaner_4.207.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : mcaudrv_simple [#] Dienst Gelöscht : ManyCam ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\SH\AppData\Local\Hola Datei Gelöscht : C:\Windows\System32\drivers\mcaudrv_x64.sys Datei Gelöscht : C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\invalidprefs.js Datei Gelöscht : C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage Datei Gelöscht : C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C43F0D7D-78F0-47B8-954C-8FB36960B785} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C43F0D7D-78F0-47B8-954C-8FB36960B785} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17840 -\\ Mozilla Firefox v37.0.2 (x86 de) -\\ Google Chrome v43.0.2357.130 ************************* AdwCleaner[R0].txt - [2815 Bytes] - [27/06/2015 11:29:28] AdwCleaner[S0].txt - [2534 Bytes] - [27/06/2015 11:30:42] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2593 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 7.1.8 (06.27.2015:1) OS: Windows 7 Professional N x64 Ran by SH on 27.06.2015 at 11:40:33,72 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\Users\SH\appdata\local\google\chrome\user data\default\local storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage Successfully deleted: [File] C:\Users\SH\appdata\local\google\chrome\user data\default\local storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage-journal ~~~ Folders ~~~ Chrome Successfully deleted: [Folder] C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset [C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted: [C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset [C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted: [ bopakagnckmlgajfccecajhnimjiiedh, gkojfkhlekighikafcpjkiklfbnlmeio ] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 27.06.2015 at 11:44:15,56 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015 Ran by SH (administrator) on SH-PC on 27-06-2015 12:38:12 Running from C:\Users\SH\Desktop\trojaner Loaded Profiles: SH (Available Profiles: SH) Platform: Windows 7 Professional N Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1240064 2012-07-04] (Marvell Semiconductor, Inc.) HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc) HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1593640 2015-03-04] (Sophos Limited) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-04-20] (Cisco Systems, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [Remote Mouse] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe [2050048 2015-01-23] (RemoteMouse.net) AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll [217672 2015-01-14] (Sophos Limited) AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured.dll => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll [275352 2015-01-14] (Sophos Limited) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-26] (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-26] (Oracle Corporation) Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Tcpip\Parameters: [DhcpNameServer] 192.168.192.1 FireFox: ======== FF ProfilePath: C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-24] () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-24] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> F:\Programme\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> F:\Programme\DivX\DivX Web Player\npdivx32.dll [2014-02-18] (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-26] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> F:\Programme\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: @hola.org/vlc,version=1.8.369 -> C:\Users\SH\AppData\Local\Hola\firefox\app\vlc No File FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\SH\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.) FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: sony.com/MediaGoDetector -> F:\Programme\Media Go\npMediaGoDetector.dll [2013-08-22] (Sony Network Entertainment International LLC) FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-04-23] (Ubisoft) FF Extension: Hola Better Internet - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack [2015-05-27] FF Extension: WOT - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-05-30] FF Extension: ZenMate Security & Privacy VPN - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\firefox@zenmate.com.xpi [2015-05-07] FF Extension: flv movies downloader - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\flvmoviesdownloader@rzll.xpi [2013-10-17] FF Extension: Media Hint - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\mediahint@jetpack.xpi [2014-03-13] FF Extension: Adblock Plus - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-25] StartMenuInternet: FIREFOX.EXE - F:\Programme\Mozilla Firefox\firefox.exe Chrome: ======= CHR Profile: C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-27] CHR Extension: (Google Drive) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-27] CHR Extension: (WOT) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-06-22] CHR Extension: (YouTube) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-27] CHR Extension: (Adblock Plus) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-27] CHR Extension: (Google Search) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-27] CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-11-04] CHR Extension: (Math Anywhere) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebhifiddmaaeecbaiemfpejghjdjmhc [2015-03-12] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13] CHR Extension: (Google Wallet) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Enhanced Steam) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2014-06-20] CHR Extension: (Gmail) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-27] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 ForceWare Intelligent Application Manager (IAM); F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] () S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed] S3 Media Jukebox 14 Service; F:\Programme\Media Jukebox 14\JRService.exe [379400 2010-07-15] (J. River, Inc.) S2 nSvcIp; F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] () R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [288552 2014-05-23] (Sophos Limited) R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [208168 2014-10-14] (Sophos Limited) S2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [340776 2015-03-04] (Sophos Limited) R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [341800 2014-10-14] (Sophos Limited) R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3274536 2015-01-14] (Sophos Limited) S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2065704 2015-01-14] (Sophos Limited) S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation) S3 NVENETFD; C:\Windows\System32\DRIVERS\nvm60x64.sys [742696 2009-06-10] (NVIDIA Corporation) S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project) S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [25600 2013-04-19] (Razer USA Ltd) [File not signed] S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [23040 2013-04-19] (Razer USA Ltd) [File not signed] R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [158976 2014-05-23] (Sophos Limited) S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2014-05-23] (Sophos Limited) S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [27904 2014-05-23] (Sophos Limited) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-01-24] (Duplex Secure Ltd.) S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-13] (Anchorfree Inc.) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-27 11:44 - 2015-06-27 11:44 - 00001603 _____ C:\Users\SH\Desktop\JRT.txt 2015-06-27 11:40 - 2015-06-27 11:40 - 00000207 _____ C:\Windows\tweaking.com-regbackup-SH-PC-Windows-7-Professional-N-(64-bit).dat 2015-06-27 11:40 - 2015-06-27 11:40 - 00000000 ____D C:\RegBackup 2015-06-27 11:29 - 2015-06-27 11:31 - 00000000 ____D C:\AdwCleaner 2015-06-27 10:56 - 2015-06-27 10:56 - 00001106 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-06-26 14:53 - 2015-06-26 14:54 - 00561248 _____ (Oracle Corporation) C:\Users\SH\Downloads\jxpiinstall.exe 2015-06-26 14:35 - 2015-06-26 14:36 - 00000000 ____D C:\Users\SH\Downloads\Hola 2015-06-26 09:31 - 2015-06-26 09:59 - 00000000 ____D C:\Qoobox 2015-06-26 09:31 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2015-06-26 09:31 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2015-06-26 09:31 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2015-06-26 09:30 - 2015-06-26 09:54 - 00000000 ____D C:\Windows\erdnt 2015-06-25 16:31 - 2015-06-25 16:31 - 01182149 _____ C:\Users\SH\Downloads\7z936.exe 2015-06-25 16:31 - 2015-06-25 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-06-25 15:18 - 2015-06-27 12:38 - 00000000 ____D C:\FRST 2015-06-25 15:13 - 2015-06-25 15:13 - 00000020 _____ C:\Users\SH\defogger_reenable 2015-06-25 15:11 - 2015-06-27 11:36 - 00000000 ____D C:\Users\SH\Desktop\trojaner 2015-06-24 19:50 - 2015-06-24 19:50 - 00002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk 2015-06-24 18:01 - 2015-06-24 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disney Interactive Studios 2015-06-24 16:13 - 2015-06-24 16:13 - 00000000 ____D C:\Users\SH\AppData\Local\Licenses 2015-06-24 15:43 - 2015-06-24 15:43 - 00001112 _____ C:\Users\Public\Desktop\TriDef 3D.lnk 2015-06-24 15:43 - 2015-06-24 15:43 - 00000000 ____D C:\ProgramData\TriDef 3D 2015-06-24 15:42 - 2015-06-24 15:43 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef 2015-06-24 15:41 - 2015-06-24 15:41 - 00000000 ____D C:\ProgramData\DDD 2015-06-17 21:39 - 2015-06-17 21:39 - 00001684 _____ C:\Users\Public\Desktop\roomeon Portal.lnk 2015-06-17 21:39 - 2015-06-17 21:39 - 00001661 _____ C:\Users\Public\Desktop\roomeon 3D-Planer.lnk 2015-06-17 21:39 - 2015-06-17 21:39 - 00000000 ____D C:\Users\SH\AppData\Local\roomeon 2015-06-17 21:28 - 2015-06-17 21:38 - 00000000 ____D C:\Users\SH\AppData\Local\Room Arranger 2015-06-16 16:19 - 2015-06-16 16:19 - 00000000 __SHD C:\Users\SH\AppData\Local\EmieBrowserModeList 2015-06-14 13:54 - 2015-06-14 13:54 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3 Uprising 2015-06-13 14:45 - 2015-06-13 14:45 - 00000040 _____ C:\ProgramData\ra3.ini 2015-06-13 14:45 - 2015-06-13 14:45 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3 2015-06-13 14:06 - 2015-06-13 14:36 - 00000000 ____D C:\Users\SH\AppData\Roaming\Nidhogg 2015-06-13 13:52 - 2015-06-13 13:52 - 00000208 _____ C:\Users\SH\Desktop\Nidhogg.url 2015-06-13 13:36 - 2015-06-13 13:36 - 00000208 _____ C:\Users\SH\Desktop\Command and Conquer Red Alert 3 - Uprising.url 2015-06-13 11:13 - 2015-06-13 11:13 - 00000209 _____ C:\Users\SH\Desktop\Salt Demo.url 2015-06-12 11:08 - 2015-06-12 11:08 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2015-06-11 15:28 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-06-11 15:28 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-06-11 15:28 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-06-11 15:28 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-06-11 15:28 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-06-11 15:28 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-06-11 15:28 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-06-11 15:28 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-06-11 15:28 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe 2015-06-11 15:28 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-06-11 15:28 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-06-11 15:28 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-06-11 15:28 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-06-11 15:28 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-06-11 15:28 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-06-11 15:28 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-06-11 15:28 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-06-11 15:28 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-06-11 15:28 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-06-11 15:28 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-06-11 15:28 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-06-11 15:28 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-06-11 15:28 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-06-11 15:28 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-06-11 15:28 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-06-11 15:28 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-06-11 15:28 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-06-11 15:28 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-11 15:28 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2015-06-11 15:28 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-06-11 15:27 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-06-11 15:27 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-06-11 15:27 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-06-11 15:27 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-06-11 15:27 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-06-11 15:27 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-06-11 15:27 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-06-11 15:27 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-06-11 15:27 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-06-11 15:27 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-06-11 15:27 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-06-11 15:27 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-06-11 15:27 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-06-11 15:27 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-06-11 15:27 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-06-11 15:27 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-06-11 15:27 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-06-11 15:27 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-06-11 15:27 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-06-11 15:27 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-06-11 15:27 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-06-11 15:27 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-06-11 15:27 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-06-11 15:27 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-06-11 15:27 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-06-11 15:27 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-06-11 15:27 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-06-11 15:27 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-06-11 15:27 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-06-11 15:27 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-06-11 15:27 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-06-11 15:27 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-06-11 15:27 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-06-11 15:27 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-06-11 15:27 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-06-11 15:27 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-06-11 15:27 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-06-11 15:27 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-06-11 15:27 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-06-11 15:27 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-06-11 15:27 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-06-11 15:27 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-06-11 15:27 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-06-11 15:27 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-06-11 15:27 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-06-11 15:27 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-06-11 15:27 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-11 15:27 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-06-11 15:27 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-11 15:27 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-06-11 15:27 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-06-11 15:27 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-06-11 15:27 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-06-11 15:27 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-06-11 15:27 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-06-11 15:27 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-06-11 15:27 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-06-11 15:27 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-06-11 15:27 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-06-11 15:27 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-06-02 20:16 - 2015-06-02 20:16 - 00000000 ____D C:\Users\SH\AppData\Local\PDF24 2015-06-01 20:27 - 2015-06-01 20:27 - 00000000 ____D C:\Users\SH\AppData\Local\GWX 2015-05-28 22:58 - 2015-05-01 15:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-05-28 22:58 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-05-28 19:09 - 2015-05-28 19:09 - 00000000 ____D C:\Users\SH\Documents\Criterion Games ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-27 12:35 - 2014-03-08 16:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-06-27 12:06 - 2013-01-24 19:04 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-06-27 11:47 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-06-27 11:47 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-06-27 11:42 - 2013-01-24 18:29 - 01143461 _____ C:\Windows\WindowsUpdate.log 2015-06-27 11:39 - 2014-07-29 12:52 - 00000000 ____D C:\Users\SH\AppData\Roaming\Raptr 2015-06-27 11:39 - 2013-01-24 19:04 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-06-27 11:39 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-06-27 11:39 - 2009-07-14 06:56 - 00122331 _____ C:\Windows\setupact.log 2015-06-27 10:57 - 2014-06-11 17:42 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-06-27 10:56 - 2014-06-11 17:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-06-27 10:56 - 2014-06-11 17:42 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-06-26 14:57 - 2013-10-16 16:00 - 00000000 ____D C:\ProgramData\Oracle 2015-06-26 14:55 - 2014-10-17 13:16 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-06-26 14:55 - 2013-02-26 01:25 - 00000000 ____D C:\Program Files (x86)\Java 2015-06-26 12:56 - 2013-06-03 12:01 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9941B8CD-7D1F-464E-A428-95CA8D62A133} 2015-06-26 10:05 - 2010-11-21 05:47 - 00228934 _____ C:\Windows\PFRO.log 2015-06-26 09:46 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2015-06-26 09:38 - 2013-06-24 13:25 - 00000000 ____D C:\ProgramData\Temp 2015-06-25 23:50 - 2015-05-06 10:39 - 00007602 _____ C:\Users\SH\AppData\Local\Resmon.ResmonCfg 2015-06-25 15:56 - 2014-08-28 11:32 - 00000000 ____D C:\Users\SH\AppData\Local\CrashDumps 2015-06-25 15:13 - 2013-01-24 19:01 - 00000000 ____D C:\Users\SH 2015-06-25 14:26 - 2013-01-26 10:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2015-06-25 14:24 - 2014-06-22 17:18 - 00000000 ____D C:\Users\SH\AppData\Local\LOOT 2015-06-25 14:20 - 2013-05-24 12:06 - 00000000 ___RD C:\Users\SH\Desktop\Spiele 2015-06-25 13:10 - 2011-04-12 10:14 - 00713958 _____ C:\Windows\system32\perfh007.dat 2015-06-25 13:10 - 2011-04-12 10:14 - 00154074 _____ C:\Windows\system32\perfc007.dat 2015-06-25 13:10 - 2009-07-14 07:12 - 01648656 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-25 12:43 - 2014-01-22 13:51 - 00000000 ____D C:\Users\SH\AppData\Local\Battle.net 2015-06-24 21:10 - 2009-07-14 07:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-06-24 20:57 - 2014-04-04 17:16 - 00001048 _____ C:\Windows\Xbox_360_CC_Driver.log 2015-06-24 20:53 - 2013-05-23 13:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Byte 2015-06-24 19:51 - 2013-01-25 13:08 - 00000000 ____D C:\ProgramData\Sophos 2015-06-24 19:50 - 2014-05-23 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos 2015-06-24 19:50 - 2013-01-25 13:08 - 00000000 ____D C:\Program Files (x86)\Sophos 2015-06-24 18:50 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-06-24 17:08 - 2013-01-30 00:09 - 00649191 _____ C:\Windows\DirectX.log 2015-06-24 14:19 - 2015-01-10 16:37 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-06-24 11:35 - 2014-03-08 16:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-06-24 11:35 - 2014-03-08 16:32 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-06-24 11:35 - 2014-03-08 16:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-06-21 14:19 - 2013-01-30 09:33 - 00000000 ____D C:\Users\SH\AppData\Roaming\vlc 2015-06-19 10:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2015-06-19 09:17 - 2009-07-14 06:50 - 00320184 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-19 09:15 - 2015-04-21 10:42 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-19 09:15 - 2014-05-19 12:34 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-06-19 09:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2015-06-19 04:26 - 2013-02-25 13:03 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-06-19 04:25 - 2013-07-12 23:23 - 00000000 ____D C:\Windows\system32\MRT 2015-06-19 04:19 - 2013-01-24 19:47 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-06-17 21:38 - 2013-07-08 17:10 - 00000000 ____D C:\Users\SH\AppData\Local\Downloaded Installations 2015-06-16 16:18 - 2015-05-05 10:24 - 00000000 ____D C:\Users\SH\Desktop\SS 15 2015-06-12 11:08 - 2013-01-24 19:04 - 00000000 ____D C:\Program Files (x86)\Google 2015-06-02 11:26 - 2013-01-24 19:04 - 00066648 _____ C:\Users\SH\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\system32\GWX 2015-05-29 16:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers 2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2015-05-28 22:58 - 2013-01-30 00:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight ==================== Files in the root of some directories ======= 2015-01-28 13:58 - 2015-01-28 13:59 - 0009918 _____ () C:\Users\SH\AppData\Local\CleanupUninstall.txt 2013-06-04 22:44 - 2013-06-04 22:44 - 0003072 _____ () C:\Users\SH\AppData\Local\file__0.localstorage 2015-05-06 10:39 - 2015-06-25 23:50 - 0007602 _____ () C:\Users\SH\AppData\Local\Resmon.ResmonCfg 2013-01-29 16:21 - 2013-01-29 16:21 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt 2015-06-13 14:45 - 2015-06-13 14:45 - 0000040 _____ () C:\ProgramData\ra3.ini Some files in TEMP: ==================== C:\Users\SH\AppData\Local\Temp\Quarantine.exe C:\Users\SH\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-24 11:43 ==================== End of log ============================ |
27.06.2015, 18:17 | #9 |
/// the machine /// TB-Ausbilder | Win 7: Sophos meldet "Troj/Miner-AB"ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.06.2015, 09:02 | #10 |
| Win 7: Sophos meldet "Troj/Miner-AB" Hier erst mal das ESET log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=3271ad63bd383b40abb7f60df9343f7c # end=init # utc_time=2015-06-27 06:57:07 # local_time=2015-06-27 08:57:07 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 24533 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=3271ad63bd383b40abb7f60df9343f7c # end=updated # utc_time=2015-06-27 06:59:54 # local_time=2015-06-27 08:59:54 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=3271ad63bd383b40abb7f60df9343f7c # engine=24533 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-06-28 12:01:00 # local_time=2015-06-28 02:01:00 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 119200 187079510 0 0 # compatibility_mode_1='Sophos Anti-Virus' # compatibility_mode=8450 16777213 100 99 19021 57780026 0 0 # scanned=447007 # found=9 # cleaned=0 # scan_time=18065 sh=E906BF646AE3EAE31BBA483A770364E8D5D95ADE ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2013-07-14 190009\Backup Files 2013-07-14 190009\Backup files 6.zip" sh=3ECE64CC0AEEBABFA5E0E1E412FC4E2F917B6B7D ft=0 fh=0000000000000000 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2013-07-14 190009\Backup Files 2013-08-11 190010\Backup files 2.zip" sh=FA64EA3EB9598ACA35E9F7049D2DEA798AFD59D2 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2013-10-13 190010\Backup Files 2013-10-13 190010\Backup files 8.zip" sh=B6143294396222C5ACC5785CCF72AF04821D8A5B ft=0 fh=0000000000000000 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2013-10-13 190010\Backup Files 2013-10-13 190010\Backup files 9.zip" sh=F8413082A82FB81B681D8B1472DD376CC38BD4B1 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2014-02-03 100450\Backup Files 2014-02-03 100450\Backup files 9.zip" sh=1BB75391FEAF0CCADED36DC7768CE1E83F139364 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2014-08-31 190002\Backup Files 2014-08-31 190002\Backup files 13.zip" sh=5A44C6087A3C06E0F91A822709A3692080C9D94D ft=0 fh=0000000000000000 vn="Variante von Win32/WinloadSDA.I evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2014-08-31 190002\Backup Files 2014-10-26 190011\Backup files 4.zip" sh=C5089EC9E5E09986B532113E387869602DC85369 ft=0 fh=0000000000000000 vn="Variante von Win32/WinloadSDA.I evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2015-05-31 190010\Backup Files 2015-05-31 190010\Backup files 17.zip" sh=7B8D9CCBE43CA26C1DAADF1E16F9BFC7AD49CB17 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2015-05-31 190010\Backup Files 2015-05-31 190010\Backup files 18.zip" Code:
ATTFilter Results of screen317's Security Check version 1.004 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Sophos Anti-Virus WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java 8 Update 45 Adobe Flash Player 17.0.0.190 Flash Player out of Date! Adobe Reader XI Mozilla Firefox 37.0.2 Firefox out of Date! Google Chrome (43.0.2357.124) Google Chrome (43.0.2357.130) ````````Process Check: objlist.exe by Laurent```````` Sophos Sophos Anti-Virus SavService.exe Sophos Sophos Anti-Virus SAVAdminService.exe Sophos Sophos Anti-Virus Web Control swc_service.exe Sophos Sophos Anti-Virus Web Intelligence swi_service.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015 Ran by SH (administrator) on SH-PC on 28-06-2015 09:59:54 Running from C:\Users\SH\Desktop\trojaner Loaded Profiles: SH (Available Profiles: SH) Platform: Windows 7 Professional N Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (AMD) C:\Windows\System32\atieclxx.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe (RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) F:\Programme\Mozilla Firefox\firefox.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavMain.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1240064 2012-07-04] (Marvell Semiconductor, Inc.) HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc) HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1593640 2015-03-04] (Sophos Limited) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-04-20] (Cisco Systems, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [Remote Mouse] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe [2050048 2015-01-23] (RemoteMouse.net) AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll [217672 2015-01-14] (Sophos Limited) AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured.dll => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll [275352 2015-01-14] (Sophos Limited) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-26] (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-26] (Oracle Corporation) Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited) Tcpip\Parameters: [DhcpNameServer] 192.168.192.1 Tcpip\..\Interfaces\{2141132E-14AD-4573-837A-4E6B7BB4B483}: [NameServer] 130.83.22.60,130.83.22.63 FireFox: ======== FF ProfilePath: C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-24] () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-24] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> F:\Programme\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> F:\Programme\DivX\DivX Web Player\npdivx32.dll [2014-02-18] (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-26] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> F:\Programme\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: @hola.org/vlc,version=1.8.369 -> C:\Users\SH\AppData\Local\Hola\firefox\app\vlc No File FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\SH\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.) FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: sony.com/MediaGoDetector -> F:\Programme\Media Go\npMediaGoDetector.dll [2013-08-22] (Sony Network Entertainment International LLC) FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-04-23] (Ubisoft) FF Extension: Hola Better Internet - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack [2015-05-27] FF Extension: WOT - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-05-30] FF Extension: ZenMate Security & Privacy VPN - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\firefox@zenmate.com.xpi [2015-05-07] FF Extension: flv movies downloader - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\flvmoviesdownloader@rzll.xpi [2013-10-17] FF Extension: Media Hint - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\mediahint@jetpack.xpi [2014-03-13] FF Extension: Adblock Plus - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-25] StartMenuInternet: FIREFOX.EXE - F:\Programme\Mozilla Firefox\firefox.exe Chrome: ======= CHR Profile: C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-27] CHR Extension: (Google Drive) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-27] CHR Extension: (WOT) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-06-22] CHR Extension: (YouTube) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-27] CHR Extension: (Adblock Plus) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-27] CHR Extension: (Google Search) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-27] CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-11-04] CHR Extension: (Math Anywhere) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebhifiddmaaeecbaiemfpejghjdjmhc [2015-03-12] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13] CHR Extension: (Google Wallet) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Enhanced Steam) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2014-06-20] CHR Extension: (Gmail) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-27] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ForceWare Intelligent Application Manager (IAM); F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] () S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed] S3 Media Jukebox 14 Service; F:\Programme\Media Jukebox 14\JRService.exe [379400 2010-07-15] (J. River, Inc.) R2 nSvcIp; F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] () R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [288552 2014-05-23] (Sophos Limited) R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [208168 2014-10-14] (Sophos Limited) R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [340776 2015-03-04] (Sophos Limited) R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [341800 2014-10-14] (Sophos Limited) R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3274536 2015-01-14] (Sophos Limited) S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2065704 2015-01-14] (Sophos Limited) S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation) S3 NVENETFD; C:\Windows\System32\DRIVERS\nvm60x64.sys [742696 2009-06-10] (NVIDIA Corporation) S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project) S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [25600 2013-04-19] (Razer USA Ltd) [File not signed] S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [23040 2013-04-19] (Razer USA Ltd) [File not signed] R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [158976 2014-05-23] (Sophos Limited) S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2014-05-23] (Sophos Limited) S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [27904 2014-05-23] (Sophos Limited) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-01-24] (Duplex Secure Ltd.) S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-13] (Anchorfree Inc.) R3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-27 14:42 - 2015-06-27 14:42 - 00000209 _____ C:\Users\SH\Desktop\Call of Juarez Gunslinger.url 2015-06-27 11:40 - 2015-06-27 11:40 - 00000207 _____ C:\Windows\tweaking.com-regbackup-SH-PC-Windows-7-Professional-N-(64-bit).dat 2015-06-27 11:40 - 2015-06-27 11:40 - 00000000 ____D C:\RegBackup 2015-06-27 11:29 - 2015-06-27 11:31 - 00000000 ____D C:\AdwCleaner 2015-06-27 10:56 - 2015-06-27 10:56 - 00001106 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-06-26 14:53 - 2015-06-26 14:54 - 00561248 _____ (Oracle Corporation) C:\Users\SH\Downloads\jxpiinstall.exe 2015-06-26 14:35 - 2015-06-26 14:36 - 00000000 ____D C:\Users\SH\Downloads\Hola 2015-06-26 09:31 - 2015-06-26 09:59 - 00000000 ____D C:\Qoobox 2015-06-26 09:31 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2015-06-26 09:31 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2015-06-26 09:31 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2015-06-26 09:30 - 2015-06-26 09:54 - 00000000 ____D C:\Windows\erdnt 2015-06-25 16:31 - 2015-06-25 16:31 - 01182149 _____ C:\Users\SH\Downloads\7z936.exe 2015-06-25 16:31 - 2015-06-25 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-06-25 15:18 - 2015-06-28 09:59 - 00000000 ____D C:\FRST 2015-06-25 15:13 - 2015-06-25 15:13 - 00000020 _____ C:\Users\SH\defogger_reenable 2015-06-25 15:11 - 2015-06-28 09:56 - 00000000 ____D C:\Users\SH\Desktop\trojaner 2015-06-24 19:50 - 2015-06-24 19:50 - 00002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk 2015-06-24 18:01 - 2015-06-24 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disney Interactive Studios 2015-06-24 16:13 - 2015-06-24 16:13 - 00000000 ____D C:\Users\SH\AppData\Local\Licenses 2015-06-24 15:43 - 2015-06-24 15:43 - 00001112 _____ C:\Users\Public\Desktop\TriDef 3D.lnk 2015-06-24 15:43 - 2015-06-24 15:43 - 00000000 ____D C:\ProgramData\TriDef 3D 2015-06-24 15:42 - 2015-06-24 15:43 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef 2015-06-24 15:41 - 2015-06-24 15:41 - 00000000 ____D C:\ProgramData\DDD 2015-06-17 21:39 - 2015-06-17 21:39 - 00000000 ____D C:\Users\SH\AppData\Local\roomeon 2015-06-17 21:28 - 2015-06-17 21:38 - 00000000 ____D C:\Users\SH\AppData\Local\Room Arranger 2015-06-16 16:19 - 2015-06-16 16:19 - 00000000 __SHD C:\Users\SH\AppData\Local\EmieBrowserModeList 2015-06-14 13:54 - 2015-06-14 13:54 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3 Uprising 2015-06-13 14:45 - 2015-06-13 14:45 - 00000040 _____ C:\ProgramData\ra3.ini 2015-06-13 14:45 - 2015-06-13 14:45 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3 2015-06-13 14:06 - 2015-06-27 13:32 - 00000000 ____D C:\Users\SH\AppData\Roaming\Nidhogg 2015-06-13 13:52 - 2015-06-13 13:52 - 00000208 _____ C:\Users\SH\Desktop\Nidhogg.url 2015-06-13 13:36 - 2015-06-13 13:36 - 00000208 _____ C:\Users\SH\Desktop\Command and Conquer Red Alert 3 - Uprising.url 2015-06-13 11:13 - 2015-06-13 11:13 - 00000209 _____ C:\Users\SH\Desktop\Salt Demo.url 2015-06-12 11:08 - 2015-06-12 11:08 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2015-06-11 15:28 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-06-11 15:28 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-06-11 15:28 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-06-11 15:28 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-06-11 15:28 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-06-11 15:28 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-06-11 15:28 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-06-11 15:28 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-06-11 15:28 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-06-11 15:28 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-06-11 15:28 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-06-11 15:28 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-06-11 15:28 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-06-11 15:28 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe 2015-06-11 15:28 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-06-11 15:28 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-06-11 15:28 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-06-11 15:28 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-06-11 15:28 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-06-11 15:28 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-06-11 15:28 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-06-11 15:28 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-06-11 15:28 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-06-11 15:28 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-06-11 15:28 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-06-11 15:28 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-06-11 15:28 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-06-11 15:28 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-06-11 15:28 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-06-11 15:28 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-06-11 15:28 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-06-11 15:28 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-06-11 15:28 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-06-11 15:28 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-06-11 15:28 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-11 15:28 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2015-06-11 15:28 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-06-11 15:27 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-06-11 15:27 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-06-11 15:27 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-06-11 15:27 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-06-11 15:27 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-06-11 15:27 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-06-11 15:27 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-06-11 15:27 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-06-11 15:27 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-06-11 15:27 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-06-11 15:27 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-06-11 15:27 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-06-11 15:27 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-06-11 15:27 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-06-11 15:27 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-06-11 15:27 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-06-11 15:27 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-06-11 15:27 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-06-11 15:27 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-06-11 15:27 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-06-11 15:27 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-06-11 15:27 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-06-11 15:27 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-06-11 15:27 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-06-11 15:27 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-06-11 15:27 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-06-11 15:27 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-06-11 15:27 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-06-11 15:27 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-06-11 15:27 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-06-11 15:27 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-06-11 15:27 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-06-11 15:27 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-06-11 15:27 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-06-11 15:27 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-06-11 15:27 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-06-11 15:27 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-06-11 15:27 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-06-11 15:27 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-06-11 15:27 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-06-11 15:27 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-06-11 15:27 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-06-11 15:27 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-06-11 15:27 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-06-11 15:27 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-06-11 15:27 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-06-11 15:27 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-11 15:27 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-06-11 15:27 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-11 15:27 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-06-11 15:27 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-06-11 15:27 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-06-11 15:27 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-06-11 15:27 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-06-11 15:27 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-06-11 15:27 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-06-11 15:27 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-06-11 15:27 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-06-11 15:27 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-06-11 15:27 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-06-02 20:16 - 2015-06-02 20:16 - 00000000 ____D C:\Users\SH\AppData\Local\PDF24 2015-06-01 20:27 - 2015-06-01 20:27 - 00000000 ____D C:\Users\SH\AppData\Local\GWX ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-28 09:35 - 2014-03-08 16:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-06-28 09:12 - 2013-01-24 18:29 - 01206188 _____ C:\Windows\WindowsUpdate.log 2015-06-28 09:06 - 2013-01-24 19:04 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-06-28 02:06 - 2013-01-24 19:04 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-06-27 20:53 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-06-27 20:53 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-06-27 20:42 - 2014-07-29 12:52 - 00000000 ____D C:\Users\SH\AppData\Roaming\Raptr 2015-06-27 20:41 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-06-27 20:41 - 2009-07-14 06:56 - 00122723 _____ C:\Windows\setupact.log 2015-06-27 15:02 - 2013-01-30 00:09 - 00667550 _____ C:\Windows\DirectX.log 2015-06-27 13:38 - 2013-06-03 12:01 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9941B8CD-7D1F-464E-A428-95CA8D62A133} 2015-06-27 10:57 - 2014-06-11 17:42 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-06-27 10:56 - 2014-06-11 17:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-06-27 10:56 - 2014-06-11 17:42 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-06-26 14:57 - 2013-10-16 16:00 - 00000000 ____D C:\ProgramData\Oracle 2015-06-26 14:55 - 2014-10-17 13:16 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-06-26 14:55 - 2013-02-26 01:25 - 00000000 ____D C:\Program Files (x86)\Java 2015-06-26 10:05 - 2010-11-21 05:47 - 00228934 _____ C:\Windows\PFRO.log 2015-06-26 09:46 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2015-06-26 09:38 - 2013-06-24 13:25 - 00000000 ____D C:\ProgramData\Temp 2015-06-25 23:50 - 2015-05-06 10:39 - 00007602 _____ C:\Users\SH\AppData\Local\Resmon.ResmonCfg 2015-06-25 15:56 - 2014-08-28 11:32 - 00000000 ____D C:\Users\SH\AppData\Local\CrashDumps 2015-06-25 15:13 - 2013-01-24 19:01 - 00000000 ____D C:\Users\SH 2015-06-25 14:26 - 2013-01-26 10:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2015-06-25 14:24 - 2014-06-22 17:18 - 00000000 ____D C:\Users\SH\AppData\Local\LOOT 2015-06-25 14:20 - 2013-05-24 12:06 - 00000000 ___RD C:\Users\SH\Desktop\Spiele 2015-06-25 13:10 - 2011-04-12 10:14 - 00713958 _____ C:\Windows\system32\perfh007.dat 2015-06-25 13:10 - 2011-04-12 10:14 - 00154074 _____ C:\Windows\system32\perfc007.dat 2015-06-25 13:10 - 2009-07-14 07:12 - 01648656 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-25 12:43 - 2014-01-22 13:51 - 00000000 ____D C:\Users\SH\AppData\Local\Battle.net 2015-06-24 21:10 - 2009-07-14 07:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-06-24 20:57 - 2014-04-04 17:16 - 00001048 _____ C:\Windows\Xbox_360_CC_Driver.log 2015-06-24 20:53 - 2013-05-23 13:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Byte 2015-06-24 19:51 - 2013-01-25 13:08 - 00000000 ____D C:\ProgramData\Sophos 2015-06-24 19:50 - 2014-05-23 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos 2015-06-24 19:50 - 2013-01-25 13:08 - 00000000 ____D C:\Program Files (x86)\Sophos 2015-06-24 18:50 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-06-24 14:19 - 2015-01-10 16:37 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-06-24 11:35 - 2014-03-08 16:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-06-24 11:35 - 2014-03-08 16:32 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-06-24 11:35 - 2014-03-08 16:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-06-21 14:19 - 2013-01-30 09:33 - 00000000 ____D C:\Users\SH\AppData\Roaming\vlc 2015-06-19 10:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2015-06-19 09:17 - 2009-07-14 06:50 - 00320184 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-19 09:15 - 2015-04-21 10:42 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-19 09:15 - 2014-05-19 12:34 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-06-19 09:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2015-06-19 04:26 - 2013-02-25 13:03 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-06-19 04:25 - 2013-07-12 23:23 - 00000000 ____D C:\Windows\system32\MRT 2015-06-19 04:19 - 2013-01-24 19:47 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-06-17 21:38 - 2013-07-08 17:10 - 00000000 ____D C:\Users\SH\AppData\Local\Downloaded Installations 2015-06-16 16:18 - 2015-05-05 10:24 - 00000000 ____D C:\Users\SH\Desktop\SS 15 2015-06-12 11:08 - 2013-01-24 19:04 - 00000000 ____D C:\Program Files (x86)\Google 2015-06-02 11:26 - 2013-01-24 19:04 - 00066648 _____ C:\Users\SH\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\system32\GWX 2015-05-29 16:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers 2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight ==================== Files in the root of some directories ======= 2015-01-28 13:58 - 2015-01-28 13:59 - 0009918 _____ () C:\Users\SH\AppData\Local\CleanupUninstall.txt 2013-06-04 22:44 - 2013-06-04 22:44 - 0003072 _____ () C:\Users\SH\AppData\Local\file__0.localstorage 2015-05-06 10:39 - 2015-06-25 23:50 - 0007602 _____ () C:\Users\SH\AppData\Local\Resmon.ResmonCfg 2013-01-29 16:21 - 2013-01-29 16:21 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt 2015-06-13 14:45 - 2015-06-13 14:45 - 0000040 _____ () C:\ProgramData\ra3.ini Some files in TEMP: ==================== C:\Users\SH\AppData\Local\Temp\Quarantine.exe C:\Users\SH\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-24 11:43 ==================== End of log ============================ |
28.06.2015, 17:46 | #11 |
/// the machine /// TB-Ausbilder | Win 7: Sophos meldet "Troj/Miner-AB" Flash und Firefox updaten. Backups auf D löschen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Tcpip\..\Interfaces\{2141132E-14AD-4573-837A-4E6B7BB4B483}: [NameServer] 130.83.22.60,130.83.22.63 Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Cleanup: (Die Reihenfolge ist hier entscheidend) Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken. Falls Combofix verwendet wurde: Combofix deinstallieren
Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen. Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen. Absicherung: Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen: Browser Java Flash-Player PDF-Reader Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren. Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen. Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig. Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank. Meine Empfehlung: Emsisoft Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen. Optional: NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. Malwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen. Lade Software von einem sauberen Portal wie . Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen. Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwcleaner . Abschließend noch ein paar grundsätzliche Bemerkungen: Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems. Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.06.2015, 19:50 | #12 |
| Win 7: Sophos meldet "Troj/Miner-AB" erst mal Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Scan Tool (x64) Version:24-06-2015 Ran by SH at 2015-06-28 20:13:51 Run:1 Running from C:\Users\SH\Desktop\trojaner Loaded Profiles: SH (Available Profiles: SH) Boot Mode: Normal ============================================== fixlist content: ***************** Tcpip\..\Interfaces\{2141132E-14AD-4573-837A-4E6B7BB4B483}: [NameServer] 130.83.22.60,130.83.22.63 Emptytemp: ***************** HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2141132E-14AD-4573-837A-4E6B7BB4B483}\\NameServer => value removed successfully EmptyTemp: => 1.3 GB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 20:16:18 ==== Code:
ATTFilter ****************** Sophos Anti-Virus Protokoll - 28.06.2015 18:38:59 ************** ... 20150628 183655 Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere). 20150628 183655 On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH (2 Objekte) Code:
ATTFilter # DelFix v1.010 - Datei am 28/06/2015 um 20:42:59 erstellt # Aktualisiert am 26/04/2015 von Xplode # Benutzer : SH - SH-PC # Betriebssystem : Windows 7 Professional N Service Pack 1 (64 bits) ~ Aktiviere die Benutzerkontensteuerung ... OK ~ Entferne die Bereinigungsprogramme ... Gelöscht : C:\Combofix Gelöscht : C:\FRST Gelöscht : C:\AdwCleaner Gelöscht : C:\RegBackup Gelöscht : C:\Windows\NIRCMD.exe Gelöscht : HKLM\SOFTWARE\AdwCleaner Gelöscht : HKLM\SOFTWARE\Swearware ~ Erstelle ein Backup der Registrierungsdatenbank ... OK ~ Lösche die Wiederherstellungspunkte ... Gelöscht : RP #422 [ComboFix created restore point | 06/28/2015 18:35:40] Ein neuer Wiederherstellungspunkt wurde erstellt ! ~ Stelle die Systemeinstellungen wieder her ... OK ########## - EOF - ########## |
29.06.2015, 12:03 | #13 |
/// the machine /// TB-Ausbilder | Win 7: Sophos meldet "Troj/Miner-AB" Das ist ne fehlmeldung, unsere Tools haben die angelegt, sollte aber jetzt nach Delfix Ruhe sein
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.06.2015, 15:44 | #14 |
| Win 7: Sophos meldet "Troj/Miner-AB" Alles klar, danke für die kompetente Hilfe! Ansonsten soweit keine Probleme mehr. Gruß, Simon |
30.06.2015, 06:26 | #15 |
/// the machine /// TB-Ausbilder | Win 7: Sophos meldet "Troj/Miner-AB" Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Win 7: Sophos meldet "Troj/Miner-AB" |
alert, browser, computer, defender, desktop, firefox, flash player, google, helper, installation, keygen, logfile, miner, monitor, mozilla, problem, realtek, registry, rundll, scan, security, software, svchost.exe, system, troj/miner-ab, trojaner, virus, windows |