Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Win 7: Sophos meldet "Troj/Miner-AB"

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 25.06.2015, 15:52   #1
Shnoxxer
 
Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Hallo Trojaner-Feinde,
Gestern Abend fing mein Mauszeiger an langsamer und träge zu werden. Irgendwann meldete Sophos "Troj/Miner-AB" in "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" und verschob diese laut Nachricht in Quarantäne. Unter Maßnahmen zur Bereinigung stand lediglich "Keine Maßnahmen (Neustart erforderlich)", allerdings half der Neustart nicht weiter.

Das Problem ist vermutlich durch einen Keygen entstanden, habe versucht ein Spiel zum laufen zu kriegen, bei dem ich leider nur noch die Disk hatte. Die Dateien sollten aber soweit entfernt sein.

Ich habe bisher lediglich versucht das Problem mit dem "Sophos Virus Removal Tool" zu beseitigen, jedoch ohne Erfolg. Beim GMER Scan ist dwm.exe regelmäßig abgestürzt (Problemsignatur auch im Anhang). Außerdem habe ich mir erlaubt das Logfile von Sophos zu kürzen, da es sich über 4000 Zeilen ständig nur wiederholt.

Gruß und vielen Dank im Voraus,
Simon

FRST:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015
Ran by SH (administrator) on SH-PC on 25-06-2015 15:18:51
Running from C:\Users\SH\Desktop\trojaner
Loaded Profiles: SH (Available Profiles: SH)
Platform: Windows 7 Professional N Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
() F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
() F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) F:\Programme\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1240064 2012-07-04] (Marvell Semiconductor, Inc.)
HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1593640 2015-03-04] (Sophos Limited)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-04-20] (Cisco Systems, Inc.)
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation)
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [Remote Mouse] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe [2050048 2015-01-23] (RemoteMouse.net)
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [tsiVideo] => C:\Windows\SysWOW64\rundll32.exe C:\Users\SH\AppData\Local\Temp\\mdi564.dll,asdasd <===== ATTENTION
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\MountPoints2: {3ad94142-678a-11e2-b802-002618879046} - K:\NPSAI.exe
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll [217672 2015-01-14] (Sophos Limited)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll [275352 2015-01-14] (Sophos Limited)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

SearchScopes: HKU\S-1-5-21-2306031424-1336655547-1434631041-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC8} URL = hxxp://search.icq.com/search/results.php?q=%s&ch_id=hm&search_mode=web
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle Corporation)
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Hosts: 130.83.158.177	vpn.hrz.tu-darmstadt.de ###Cisco AnyConnect VPN client modified this file. Please do not modify contents until this comment is removed.
Tcpip\Parameters: [DhcpNameServer] 192.168.192.1

FireFox:
========
FF ProfilePath: C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7B%20var%20lhost%2C%20localIpAddresses%2C%20localDomains%2C%20ipNotation%2C%20i%3B%20function%20isPlainHostNameEx()%20%7B%20return%20!(!!~lhost.indexOf('.')%20%7C%7C%20!!~lhost.indexOf('%3A'))%3B%20%7D%20lhost%20%3D%20host.toLowerCase()%3B%20ipNotation%20%3D%20%2F%5E%5Cd%2B%5C.%5Cd%2B%5C.%5Cd%2B%5C.%5Cd%2B%24%2Fg%3B%20localIpAddresses%20%3D%20%5B'127.0.0.1'%2C'10.*.*.*'%2C'172.1%5B6-9%5D.*.*'%2C'172.2%5B1-9%5D.*.*'%2C'172.3%5B0-1%5D.*.*'%2C'192.168.*.*'%5D%3B%20localDomains%20%3D%20%5B'zeus.pm'%2C'zenguard.biz'%2C'local'%2C'dev'%2C'ip'%2C'box'%2C'lvh.me'%2C'ripe'%2C'invalid'%2C'intra'%2C'intranet'%2C'onion'%2C'vcap.me'%2C'127.0.0.1.xip.io'%2C'smackaho.st'%2C'localtest.me'%2C'site'%5D%3B%20if%20(isPlainHostNameEx())%20%7B%20return%20'DIRECT'%3B%20%7D%20if%20(ipNotation.test(lhost))%20%7B%20for%20(i%20%3D%200%3B%20i%20%3C%20localIpAddresses.length%3B%20i%2B%2B)%20%7B%20if%20(shExpMatch(lhost%2C%20localIpAddresses%5Bi%5D))%20%7B%20return%20'DIRECT'%3B%20%7D%20%7D%20%7D%20for%20(i%20%3D%200%3B%20i%20%3C%20localDomains.length%3B%20i%2B%2B)%20%7B%20if%20(dnsDomainIs(lhost%2C%20localDomains%5Bi%5D))%20%7B%20return%20'DIRECT'%3B%20%7D%20%7D%20return%20'PROXY%20127.0.0.1%3A49186'%3B%20%7D%20%2F*ZenMate*%2F"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-24] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-24] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> F:\Programme\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> F:\Programme\DivX\DivX Web Player\npdivx32.dll [2014-02-18] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> F:\Programme\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: @hola.org/vlc,version=1.8.369 -> C:\Users\SH\AppData\Local\Hola\firefox\app\vlc [2015-06-24] ()
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\SH\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.)
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: sony.com/MediaGoDetector -> F:\Programme\Media Go\npMediaGoDetector.dll [2013-08-22] (Sony Network Entertainment International LLC)
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-04-23] (Ubisoft)
FF Extension: Hola Better Internet - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack [2015-05-27]
FF Extension: WOT - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-05-30]
FF Extension: ZenMate Security & Privacy VPN - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\firefox@zenmate.com.xpi [2015-05-07]
FF Extension: flv movies downloader - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\flvmoviesdownloader@rzll.xpi [2013-10-17]
FF Extension: Media Hint - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\mediahint@jetpack.xpi [2014-03-13]
FF Extension: Adblock Plus - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-25]
StartMenuInternet: FIREFOX.EXE - F:\Programme\Mozilla Firefox\firefox.exe

Chrome: 
=======
CHR Profile: C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-27]
CHR Extension: (Google Drive) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-27]
CHR Extension: (WOT) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-06-22]
CHR Extension: (YouTube) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-27]
CHR Extension: (Adblock Plus) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-27]
CHR Extension: (Google Search) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-27]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-11-04]
CHR Extension: (Math Anywhere) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebhifiddmaaeecbaiemfpejghjdjmhc [2015-03-12]
CHR Extension: (AdBlock) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-27]
CHR Extension: (Hola Better Internet) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-01-31]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Wallet) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Enhanced Steam) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2014-06-20]
CHR Extension: (Gmail) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-27]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ForceWare Intelligent Application Manager (IAM); F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] ()
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 Media Jukebox 14 Service; F:\Programme\Media Jukebox 14\JRService.exe [379400 2010-07-15] (J. River, Inc.)
R2 nSvcIp; F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] ()
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [288552 2014-05-23] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [208168 2014-10-14] (Sophos Limited)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [340776 2015-03-04] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [341800 2014-10-14] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3274536 2015-01-14] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2065704 2015-01-14] (Sophos Limited)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
S3 NVENETFD; C:\Windows\System32\DRIVERS\nvm60x64.sys [742696 2009-06-10] (NVIDIA Corporation)
S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project)
S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [25600 2013-04-19] (Razer USA Ltd) [File not signed]
S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [23040 2013-04-19] (Razer USA Ltd) [File not signed]
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [158976 2014-05-23] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2014-05-23] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [27904 2014-05-23] (Sophos Limited)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-01-24] (Duplex Secure Ltd.)
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] ()
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-13] (Anchorfree Inc.)
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-25 15:18 - 2015-06-25 15:18 - 00000000 ____D C:\FRST
2015-06-25 15:15 - 2015-04-21 10:55 - 00000845 _____ C:\Windows\system32\Drivers\etc\hosts.ac
2015-06-25 15:13 - 2015-06-25 15:13 - 00000020 _____ C:\Users\SH\defogger_reenable
2015-06-25 15:11 - 2015-06-25 15:18 - 00000000 ____D C:\Users\SH\Desktop\trojaner
2015-06-24 19:50 - 2015-06-24 19:50 - 00002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2015-06-24 18:01 - 2015-06-24 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disney Interactive Studios
2015-06-24 16:13 - 2015-06-24 16:13 - 00000000 ____D C:\Users\SH\AppData\Local\Licenses
2015-06-24 15:43 - 2015-06-24 15:43 - 00001112 _____ C:\Users\Public\Desktop\TriDef 3D.lnk
2015-06-24 15:43 - 2015-06-24 15:43 - 00000000 ____D C:\ProgramData\TriDef 3D
2015-06-24 15:42 - 2015-06-24 15:43 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef
2015-06-24 15:41 - 2015-06-24 15:41 - 00000000 ____D C:\ProgramData\DDD
2015-06-17 21:39 - 2015-06-17 21:39 - 00001684 _____ C:\Users\Public\Desktop\roomeon Portal.lnk
2015-06-17 21:39 - 2015-06-17 21:39 - 00001661 _____ C:\Users\Public\Desktop\roomeon 3D-Planer.lnk
2015-06-17 21:39 - 2015-06-17 21:39 - 00000000 ____D C:\Users\SH\AppData\Local\roomeon
2015-06-17 21:28 - 2015-06-17 21:38 - 00000000 ____D C:\Users\SH\AppData\Local\Room Arranger
2015-06-16 16:19 - 2015-06-16 16:19 - 00000000 __SHD C:\Users\SH\AppData\Local\EmieBrowserModeList
2015-06-14 13:54 - 2015-06-14 13:54 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3 Uprising
2015-06-13 14:45 - 2015-06-13 14:45 - 00000040 _____ C:\ProgramData\ra3.ini
2015-06-13 14:45 - 2015-06-13 14:45 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3
2015-06-13 14:06 - 2015-06-13 14:36 - 00000000 ____D C:\Users\SH\AppData\Roaming\Nidhogg
2015-06-13 13:52 - 2015-06-13 13:52 - 00000208 _____ C:\Users\SH\Desktop\Nidhogg.url
2015-06-13 13:36 - 2015-06-13 13:36 - 00000208 _____ C:\Users\SH\Desktop\Command and Conquer Red Alert 3 - Uprising.url
2015-06-13 11:13 - 2015-06-13 11:13 - 00000209 _____ C:\Users\SH\Desktop\Salt Demo.url
2015-06-12 11:08 - 2015-06-12 11:08 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-11 15:28 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-11 15:28 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-11 15:28 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-11 15:28 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-11 15:28 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-11 15:28 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-06-11 15:28 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-06-11 15:28 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-06-11 15:28 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-06-11 15:28 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-06-11 15:28 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-06-11 15:28 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-06-11 15:28 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-06-11 15:28 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-06-11 15:28 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-11 15:28 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-11 15:28 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-06-11 15:28 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-06-11 15:28 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-11 15:28 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-11 15:28 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-11 15:28 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-11 15:28 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-11 15:28 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-11 15:28 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-06-11 15:28 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-06-11 15:28 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-06-11 15:28 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-11 15:28 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-11 15:28 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-11 15:27 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-11 15:27 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-11 15:27 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-11 15:27 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-11 15:27 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-06-11 15:27 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-11 15:27 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-06-11 15:27 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-06-11 15:27 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-11 15:27 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-06-11 15:27 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-11 15:27 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-06-11 15:27 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-06-11 15:27 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-06-11 15:27 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-11 15:27 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-06-11 15:27 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-11 15:27 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-06-11 15:27 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-06-11 15:27 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-06-11 15:27 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-11 15:27 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-11 15:27 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-11 15:27 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-11 15:27 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-11 15:27 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-06-11 15:27 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-11 15:27 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-11 15:27 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-11 15:27 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-11 15:27 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-11 15:27 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-11 15:27 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-11 15:27 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-11 15:27 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-11 15:27 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-11 15:27 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-11 15:27 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-11 15:27 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-11 15:27 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-11 15:27 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-11 15:27 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-11 15:27 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-11 15:27 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-11 15:27 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-11 15:27 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-11 15:27 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-11 15:27 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-11 15:27 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-11 15:27 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-11 15:27 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-11 15:27 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-11 15:27 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-11 15:27 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-11 15:27 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-11 15:27 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-11 15:27 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-11 15:27 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-11 15:27 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-11 15:27 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-02 20:16 - 2015-06-02 20:16 - 00000000 ____D C:\Users\SH\AppData\Local\PDF24
2015-06-01 20:27 - 2015-06-01 20:27 - 00000000 ____D C:\Users\SH\AppData\Local\GWX
2015-05-28 22:58 - 2015-05-01 15:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-28 22:58 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-28 19:09 - 2015-05-28 19:09 - 00000000 ____D C:\Users\SH\Documents\Criterion Games

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-25 15:18 - 2013-01-24 18:29 - 02060153 _____ C:\Windows\WindowsUpdate.log
2015-06-25 15:15 - 2014-07-29 12:52 - 00000000 ____D C:\Users\SH\AppData\Roaming\Raptr
2015-06-25 15:15 - 2013-01-24 19:04 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-25 15:15 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-25 15:15 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-25 15:14 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-25 15:14 - 2009-07-14 06:56 - 00121827 _____ C:\Windows\setupact.log
2015-06-25 15:13 - 2013-01-24 19:01 - 00000000 ____D C:\Users\SH
2015-06-25 15:06 - 2013-01-24 19:04 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-25 14:35 - 2014-03-08 16:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-25 14:26 - 2013-01-26 10:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-06-25 14:26 - 2010-11-21 05:47 - 00228388 _____ C:\Windows\PFRO.log
2015-06-25 14:24 - 2014-06-22 17:18 - 00000000 ____D C:\Users\SH\AppData\Local\LOOT
2015-06-25 14:20 - 2013-05-24 12:06 - 00000000 ___RD C:\Users\SH\Desktop\Spiele
2015-06-25 13:10 - 2011-04-12 10:14 - 00713958 _____ C:\Windows\system32\perfh007.dat
2015-06-25 13:10 - 2011-04-12 10:14 - 00154074 _____ C:\Windows\system32\perfc007.dat
2015-06-25 13:10 - 2009-07-14 07:12 - 01648656 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-25 12:43 - 2014-01-22 13:51 - 00000000 ____D C:\Users\SH\AppData\Local\Battle.net
2015-06-25 12:15 - 2013-06-03 12:01 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9941B8CD-7D1F-464E-A428-95CA8D62A133}
2015-06-24 21:10 - 2009-07-14 07:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-06-24 20:57 - 2014-04-04 17:16 - 00001048 _____ C:\Windows\Xbox_360_CC_Driver.log
2015-06-24 20:53 - 2013-05-23 13:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Byte
2015-06-24 19:51 - 2013-01-25 13:08 - 00000000 ____D C:\ProgramData\Sophos
2015-06-24 19:50 - 2014-05-23 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-06-24 19:50 - 2013-01-25 13:08 - 00000000 ____D C:\Program Files (x86)\Sophos
2015-06-24 19:25 - 2014-08-28 11:32 - 00000000 ____D C:\Users\SH\AppData\Local\CrashDumps
2015-06-24 18:50 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-06-24 17:08 - 2013-01-30 00:09 - 00649191 _____ C:\Windows\DirectX.log
2015-06-24 14:19 - 2015-01-10 16:37 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-24 11:35 - 2014-03-08 16:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-24 11:35 - 2014-03-08 16:32 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-24 11:35 - 2014-03-08 16:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-06-21 14:19 - 2013-01-30 09:33 - 00000000 ____D C:\Users\SH\AppData\Roaming\vlc
2015-06-19 10:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-06-19 09:17 - 2009-07-14 06:50 - 00320184 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-19 09:15 - 2015-04-21 10:42 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-19 09:15 - 2014-05-19 12:34 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-19 09:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-19 04:26 - 2013-02-25 13:03 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-19 04:25 - 2013-07-12 23:23 - 00000000 ____D C:\Windows\system32\MRT
2015-06-19 04:19 - 2013-01-24 19:47 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-17 21:38 - 2013-07-08 17:10 - 00000000 ____D C:\Users\SH\AppData\Local\Downloaded Installations
2015-06-16 18:15 - 2015-05-06 10:39 - 00007601 _____ C:\Users\SH\AppData\Local\Resmon.ResmonCfg
2015-06-16 16:18 - 2015-05-05 10:24 - 00000000 ____D C:\Users\SH\Desktop\SS 15
2015-06-12 11:08 - 2013-01-24 19:04 - 00000000 ____D C:\Program Files (x86)\Google
2015-06-02 11:26 - 2013-01-24 19:04 - 00066648 _____ C:\Users\SH\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\system32\GWX
2015-05-29 16:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-05-28 22:58 - 2013-01-30 00:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight

==================== Files in the root of some directories =======

2015-01-28 13:58 - 2015-01-28 13:59 - 0009918 _____ () C:\Users\SH\AppData\Local\CleanupUninstall.txt
2013-06-04 22:44 - 2013-06-04 22:44 - 0003072 _____ () C:\Users\SH\AppData\Local\file__0.localstorage
2015-05-06 10:39 - 2015-06-16 18:15 - 0007601 _____ () C:\Users\SH\AppData\Local\Resmon.ResmonCfg
2013-01-29 16:21 - 2013-01-29 16:21 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt
2015-06-13 14:45 - 2015-06-13 14:45 - 0000040 _____ () C:\ProgramData\ra3.ini

Some files in TEMP:
====================
C:\Users\SH\AppData\Local\Temp\amazonicon_v10.exe
C:\Users\SH\AppData\Local\Temp\amazoninstallernircmdc.exe
C:\Users\SH\AppData\Local\Temp\drm_dyndata_7410004.dll
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.919.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.7.974.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.103.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.13.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.131.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.143.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.183.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.188.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.204.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.277.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.28.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.308.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.328.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.369.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.4.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.77.exe
C:\Users\SH\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.8.89.exe
C:\Users\SH\AppData\Local\Temp\i4jdel0.exe
C:\Users\SH\AppData\Local\Temp\JExplorer32.2.7.1.dll
C:\Users\SH\AppData\Local\Temp\JExplorer32.2.7.1.exe
C:\Users\SH\AppData\Local\Temp\JExplorer64.2.7.1.dll
C:\Users\SH\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\SH\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\SH\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\SH\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\SH\AppData\Local\Temp\mdi064.dll
C:\Users\SH\AppData\Local\Temp\mdi164.dll
C:\Users\SH\AppData\Local\Temp\mdi264.dll
C:\Users\SH\AppData\Local\Temp\mdi364.dll
C:\Users\SH\AppData\Local\Temp\mdi464.dll
C:\Users\SH\AppData\Local\Temp\mdi564.dll
C:\Users\SH\AppData\Local\Temp\MouseKeyboardCenterx64_1031.exe
C:\Users\SH\AppData\Local\Temp\ose00000.exe
C:\Users\SH\AppData\Local\Temp\raptrpatch.exe
C:\Users\SH\AppData\Local\Temp\raptr_stub.exe
C:\Users\SH\AppData\Local\Temp\RemoteMouse.exe
C:\Users\SH\AppData\Local\Temp\sdan.exe
C:\Users\SH\AppData\Local\Temp\sdapk.exe
C:\Users\SH\AppData\Local\Temp\sdaspwn.exe
C:\Users\SH\AppData\Local\Temp\SiedlerPatch.exe
C:\Users\SH\AppData\Local\Temp\tmp539B.exe
C:\Users\SH\AppData\Local\Temp\tmp915.exe
C:\Users\SH\AppData\Local\Temp\tmpC062.exe
C:\Users\SH\AppData\Local\Temp\tmpDBCD.exe
C:\Users\SH\AppData\Local\Temp\vcredist_x86.exe
C:\Users\SH\AppData\Local\Temp\xruds137.exe
C:\Users\SH\AppData\Local\Temp\_isFC8.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-24 11:43

==================== End of log ============================
         
Problemsignatur:
Code:
ATTFilter
Problemsignatur:
  Problemereignisname:	APPCRASH
  Anwendungsname:	dwm.exe
  Anwendungsversion:	0.0.0.0
  Anwendungszeitstempel:	000e6bfc
  Fehlermodulname:	dwm.exe
  Fehlermodulversion:	0.0.0.0
  Fehlermodulzeitstempel:	000e6bfc
  Ausnahmecode:	c000001d
  Ausnahmeoffset:	000000000005c0a8
  Betriebsystemversion:	6.1.7601.2.1.0.256.49
  Gebietsschema-ID:	1031
  Zusatzinformation 1:	a681
  Zusatzinformation 2:	a6815bd14801eb6a5d654ae1c7fe8bc1
  Zusatzinformation 3:	2769
  Zusatzinformation 4:	27699c8391b48bdc18ca43cf2940f9c4

Lesen Sie unsere Datenschutzbestimmungen online:
  hxxp://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0407

Wenn die Onlinedatenschutzbestimmungen nicht verfügbar sind, lesen Sie unsere Datenschutzbestimmungen offline:
  C:\Windows\system32\de-DE\erofflps.txt
         
Sophos:
Code:
ATTFilter
****************** Sophos Anti-Virus Protokoll - 25.06.2015 13:30:03 **************

    ...
20150625 130017	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 130020	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 130022	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 130022	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131452	Die Erkennungsdatenversion 5.16 (Detection Engine 3.58.3) wird verwendet. Diese Version kann 9404639 Objekte erkennen.
20150625 131453	Benutzer (NT-AUTORITÄT\LOKALER DIENST) hat den On-Access-Scan auf diesem Computer gestartet.
20150625 131512	Virus/Spyware 'Troj/Miner-AB' entfernt.
20150625 131620	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131622	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131622	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131626	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131626	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131628	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131628	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131630	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131631	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131633	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" wurde bereinigt.
20150625 131633	Virus/Spyware 'Troj/Miner-AB' entfernt.
20150625 131633	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131633	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131637	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131637	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131638	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131638	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131647	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131650	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" wurde bereinigt.
20150625 131650	Virus/Spyware 'Troj/Miner-AB' entfernt.
20150625 131901	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131903	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131903	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131907	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131907	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131908	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131908	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131910	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131911	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131913	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" wurde bereinigt.
20150625 131913	Virus/Spyware 'Troj/Miner-AB' entfernt.
20150625 131913	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131913	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131917	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131917	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131919	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131919	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131922	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131923	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131924	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131924	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131926	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" konnte nicht entfernt werden.
20150625 131926	Virus/Spyware 'Troj/Miner-AB' konnte nicht entfernt werden. Es traten Fehler auf.
20150625 131928	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131928	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131929	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131929	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131930	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131933	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131933	Entfernung von Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" wurde verschoben.
20150625 131935	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 131935	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 131935	VEA 'Troj/Miner-AB' erfordert einen Neustart, damit die Bereinigung abgeschlossen werden kann.
20150625 132148	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132150	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132150	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132154	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132155	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132155	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132158	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132201	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132201	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132204	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132206	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132206	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132209	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132211	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132211	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132215	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132216	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132216	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132220	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132222	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132222	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132225	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132227	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132227	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132230	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132232	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132232	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132236	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132236	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132237	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132237	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132241	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132243	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132243	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132247	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132247	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132248	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132248	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132251	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132254	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132254	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132352	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132352	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132353	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132353	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132357	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132359	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132359	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132403	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132403	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132404	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132404	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132408	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132410	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132410	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132413	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132413	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150625 132415	Datei "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" gehört zu Virus/Spyware 'Troj/Miner-AB'.
20150625 132415	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" für folgenden Benutzer verweigert: SH-PC\SH
      (119 Objekte)
         

Alt 25.06.2015, 16:51   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.
Ich kann auf Arbeit keine Anhänge öffnen, danke.

So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 25.06.2015, 17:02   #3
Shnoxxer
 
Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Sorry, ich dachte ich soll direkt anhängen, wenn es zu viel wird.

Addition:
[CODE]Additional
FRST Logfile:
Code:
ATTFilter
scan result of Farbar Recovery Scan Tool (x64) Version:24-06-2015
Ran by SH at 2015-06-25 15:20:19
Running from C:\Users\SH\Desktop\trojaner
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2306031424-1336655547-1434631041-500 - Administrator - Disabled)
Gast (S-1-5-21-2306031424-1336655547-1434631041-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2306031424-1336655547-1434631041-1009 - Limited - Enabled)
SH (S-1-5-21-2306031424-1336655547-1434631041-1000 - Administrator - Enabled) => C:\Users\SH
SophosSAUSH-PC0 (S-1-5-21-2306031424-1336655547-1434631041-1010 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Sophos Anti-Virus (Enabled - Up to date) {6BABF8F7-3EB6-BD1D-9167-8C5ECA060A29}
AS: Sophos Anti-Virus (Enabled - Up to date) {D0CA1913-188C-B293-ABD7-B72CB1814094}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.190 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Anki (HKLM-x32\...\Anki) (Version:  - )
ANNO 2070 (HKLM-x32\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft)
Antichamber (HKLM-x32\...\Steam App 219890) (Version:  - Alexander Bruce)
Application Verifier x64 External Package (Version: 8.59.29722 - Microsoft) Hidden
Assassins Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Liberation (HKLM-x32\...\Steam App 260210) (Version:  - Ubisoft Sofia)
Banished (HKLM-x32\...\Steam App 242920) (Version:  - Shining Rock Software LLC)
Battle Realms (HKLM-x32\...\{9AA761E6-CA51-4FF2-A552-D51638BF0595}) (Version: 0.10.000 - Liquid Entertainment)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Besiege (HKLM-x32\...\Steam App 346010) (Version:  - Spiderling Studios)
Bridge Constructor (HKLM-x32\...\Steam App 250460) (Version:  - )
Bridge Constructor Medieval (HKLM-x32\...\Steam App 319850) (Version:  - ClockStone)
Bridge Constructor Playground (HKLM-x32\...\Steam App 279990) (Version:  - ClockStone)
Broforce (HKLM-x32\...\Steam App 274190) (Version:  - Free Lives)
Bully: Scholarship Edition (HKLM-x32\...\Steam App 12200) (Version:  - Rockstar New England)
Call of Juarez Gunslinger (HKLM-x32\...\Steam App 204450) (Version:  - Techland)
Cisco AnyConnect Diagnostics and Reporting Tool (HKLM-x32\...\{9D2D6008-1122-47F3-8322-D6235CD8D1C5}) (Version: 3.1.08009 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.08009 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.08009 - Cisco Systems, Inc.) Hidden
Clonk Endeavour 4.95.5 (HKLM-x32\...\Clonk Endeavour) (Version: 4.95.5 - RedWolf Design GmbH)
Clonk Planet (HKLM-x32\...\Clonk Planet) (Version: 4.65 - RedWolf Design)
Clonk Rage (HKLM-x32\...\Clonk Rage) (Version:  - RedWolf Design GmbH)
Command & Conquer Alarmstufe Rot 2 (HKLM-x32\...\Red Alert 2) (Version:  - )
Command & Conquer(TM) Generäle (HKLM-x32\...\InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}) (Version: 0.50.0000 - Electronic Arts)
Command & Conquer(TM) Generäle (x32 Version: 0.50.0000 - Electronic Arts) Hidden
Command and Conquer: Red Alert 3 - Uprising (HKLM-x32\...\Steam App 24800) (Version:  - EA Los Angeles)
Construct 2 Free (HKLM-x32\...\Steam App 227240) (Version:  - )
Content Transfer (HKLM-x32\...\{CFADE4AF-C0CF-4A04-A776-741318F1658F}) (Version: 1.3.0.23190 - Sony Corporation)
Dark Souls: Prepare to Die Edition (HKLM-x32\...\Steam App 211420) (Version:  - FromSoftware)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Die Siedler - Aufbruch der Kulturen (HKLM-x32\...\SADK) (Version:  - )
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC)
English Country Tune (HKLM-x32\...\Steam App 207570) (Version:  - )
ENSLAVED™: Odyssey to the West™ Premium Edition (HKLM-x32\...\Steam App 245280) (Version:  - Ninja Theory)
EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
FlatOut 2 (HKLM-x32\...\Steam App 2990) (Version:  - Bugbear Entertainment)
FTL: Faster Than Light (HKLM-x32\...\Steam App 212680) (Version:  - Subset Games)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
GTA2 (HKLM-x32\...\{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}) (Version: 1.00.001 - )
Half-Life 2 (HKLM-x32\...\Steam App 220) (Version:  - Valve)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Hotline Miami (HKLM-x32\...\Steam App 219150) (Version:  - )
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Kits Configuration Installer (x32 Version: 8.59.25584 - Microsoft) Hidden
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
Left 4 Dead 2 Beta (HKLM-x32\...\Steam App 223530) (Version:  - )
Logon Screen (HKLM\...\{1730D13B-7517-4321-A88B-64627CF67CDC}_is1) (Version:  - Daniel Rebelo)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
ManiaPlanet (HKLM-x32\...\ManiaPlanet_is1) (Version:  - Nadeo)
Media Go (HKLM-x32\...\{8D92969D-A6A3-44C8-9D63-D377E94F44B5}) (Version: 2.6.205 - Sony)
Media Go Video Playback Engine 2.0.117.09030 (HKLM-x32\...\{49D9CE9D-C8B7-B941-90E1-608044A0FC8D}) (Version: 2.0.117.09030 - Sony)
Media Jukebox 14 (HKLM-x32\...\Media Jukebox 14) (Version: 14 - J. River, Inc.)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft AppLocale (HKLM-x32\...\{394BE3D9-7F57-4638-A8D1-1D88671913B7}) (Version: 1.0.0 - MS)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft LifeCam (HKLM\...\{5CE7E3F5-9803-4F32-AA89-2D8848A80109}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Standard 2007 (HKLM-x32\...\STANDARD) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Windows Application Compatibility Database (HKLM\...\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb) (Version:  - )
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Mozilla Firefox 37.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 de)) (Version: 37.0.2 - Mozilla)
Mozilla Firefox 38.0.5 (x86 de) (HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
My Game Long Name (HKLM\...\UDK-eeb62aa7-80fe-4449-9b21-540167131065) (Version:  - Epic Games, Inc.)
Need For Speed - Porsche (HKLM-x32\...\Need For Speed - Porsche) (Version:  - )
Next Car Game (HKLM-x32\...\Steam App 228380) (Version:  - )
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.50.3 - Black Tree Gaming)
Nidhogg (HKLM-x32\...\Steam App 94400) (Version:  - Messhof)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.57.35 - NVIDIA Corporation)
NVIDIA ForceWare Network Access Manager (HKLM-x32\...\{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version: 1.00.7325.0 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
NWZ-E460 WALKMAN Guide (HKLM-x32\...\{A4D58206-7E8F-41F2-BD94-85009F3AEA28}) (Version: 2.0.2.04130 - Sony Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Origin (HKLM-x32\...\Origin) (Version: 9.4.22.2815 - Electronic Arts, Inc.)
Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
PDF24 Creator 5.4.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
Plants vs. Zombies: Game of the Year (HKLM-x32\...\Steam App 3590) (Version:  - PopCap)
Portal 2 (HKLM-x32\...\Steam App 620) (Version:  - Valve)
Portal 2 Publishing Tool (HKLM-x32\...\Steam App 644) (Version:  - )
QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)
Remote Mouse version 2.70 (HKLM-x32\...\{01E4BC6D-3ACC-45E1-8928-C2FF626F63F3}_is1) (Version: 2.70 - Remote Mouse)
Reveal (HKLM\...\UDK-42ae296b-83a3-4b5f-b34f-2f44d830b3cf) (Version:  - Epic Games, Inc.)
Saints Row IV (HKLM-x32\...\Steam App 206420) (Version:  - Deep Silver Volition)
Salt Demo (HKLM-x32\...\Steam App 327870) (Version:  - Lavaboots Studios)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_15 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.3.14044_15 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14055.3 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.14055.3 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version:  - )
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version:  - )
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.40.0 - SAMSUNG Electronics Co., Ltd.)
ScummVM 1.5.0 (HKLM-x32\...\ScummVM_is1) (Version:  - The ScummVM Team)
SDK Debuggers (x32 Version: 8.59.29746 - Microsoft Corporation) Hidden
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Slender: The Arrival (HKLM-x32\...\Steam App 252330) (Version:  - Blue Isle Studios)
Sophos Anti-Virus (HKLM-x32\...\{D929B3B5-56C6-46CC-B3A3-A1A784CBB8E4}) (Version: 10.3.13 - Sophos Limited)
Sophos AutoUpdate (HKLM-x32\...\{7CD26A0C-9B59-4E84-B5EE-B386B2F7AA16}) (Version: 4.1.0.273 - Sophos Limited)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.4 - Sophos Limited)
South Park™: The Stick of Truth™ (HKLM-x32\...\Steam App 213670) (Version:  - Obsidian Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Endless Forest (HKLM-x32\...\The Endless Forest_is1) (Version:  - Tale of Tales)
The Stanley Parable (HKLM-x32\...\Steam App 221910) (Version:  - Galactic Cafe)
TmNationsForever (HKLM-x32\...\TmNationsForever_is1) (Version:  - Nadeo)
Tomb Raider (HKLM-x32\...\Steam App 203160) (Version:  - Crystal Dynamics)
TriDef 3D 6.6 (HKLM-x32\...\essentials-bundle) (Version: 6.6 - Dynamic Digital Depth Australia Pty Ltd)
Tropico 5 (HKLM-x32\...\Steam App 245620) (Version:  - Haemimont Games)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Ultracopier 1.2.0.2 (HKLM-x32\...\Ultracopier) (Version: 1.2.0.2 - Ultracopier)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_STANDARD_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_STANDARD_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_STANDARD_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_STANDARD_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 4.0 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player 2.0.5 (HKLM-x32\...\VLC media player) (Version: 2.0.5 - VideoLAN)
Warcraft III (HKLM-x32\...\Warcraft III) (Version:  - Blizzard Entertainment)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Software Development Kit (HKLM-x32\...\{363a2c1e-637f-45ce-933b-5a5463efd945}) (Version: 8.59.29750 - Microsoft Corporation)
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WPT Redistributables (x32 Version: 8.59.29750 - Microsoft) Hidden
WPTx64 (x32 Version: 8.59.29722 - Microsoft) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

31-05-2015 19:00:37 Windows-Sicherung
08-06-2015 13:27:45 Windows-Sicherung
08-06-2015 13:29:03 Windows Update
13-06-2015 14:39:53 DirectX wurde installiert
14-06-2015 19:00:37 Windows-Sicherung
17-06-2015 21:38:35 roomeon 3D-Planer wurde installiert.
19-06-2015 04:16:31 Windows Update
22-06-2015 09:37:04 Windows-Sicherung
24-06-2015 16:25:08 DirectX wurde installiert
24-06-2015 16:53:49 DirectX wurde installiert
24-06-2015 18:01:31 Installiert Split/Second
24-06-2015 19:40:27 Entfernt Split/Second
24-06-2015 19:50:13 Installed Sophos Virus Removal Tool.
24-06-2015 20:54:39 Removed Guitar Hero III.
24-06-2015 21:01:05 Removed Guitar Hero World Tour.
25-06-2015 00:58:20 Windows Update
25-06-2015 12:55:21 roomeon 3D-Planer wurde entfernt.
25-06-2015 14:22:54 Removed Dual Smart Solution

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-06-25 15:15 - 00001001 ____A C:\Windows\system32\Drivers\etc\hosts








130.83.158.177	vpn.hrz.tu-darmstadt.de ###Cisco AnyConnect VPN client modified this file. Please do not modify contents until this comment is removed.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0AD3C8A4-FC5F-4D51-B2C2-45A9C67E3BE2} - System32\Tasks\{779EC37D-799F-4A57-BAE3-F28F40D31D34} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\3\SSCDUninstall.exe
Task: {1A2CB49F-4509-4BA0-9A03-D95D2BC98A7E} - System32\Tasks\{B166BB96-9AE6-4BBE-A6EF-F67E89249AB5} => H:\Setup.exe
Task: {1AA6D4D5-982E-4DC8-93FB-F75D65C472CE} - System32\Tasks\{9440065F-91F4-4361-824F-F66FDB50E594} => F:\Programme\OpenVPN\bin\openvpn-gui.exe
Task: {1D41D597-5EC0-4A9E-9ACA-7C3F47D404D2} - System32\Tasks\{1BD2999D-1483-4487-B81E-DCDB611CD4E7} => F:\Spiele\Siedler3\s3new160.exe
Task: {2ABA1560-E38A-4E97-9DAA-45A6D1D84D3E} - System32\Tasks\{0EB7F8ED-1F7F-43A3-9BC5-0B7705E710F6} => F:\Spiele\Dreamcast\emu\nullDC_Win32_Release-NoTrace.exe
Task: {3A2BDED6-1413-4638-98E8-BE643EB339E2} - System32\Tasks\{0ABC3413-E107-4FA4-83FC-1F89A4DAD5C2} => F:\Spiele\Desperados portable\DESPERADOS.exe
Task: {423C4B52-065D-4175-B9D0-475946AC6E88} - System32\Tasks\{DC143E6E-E949-4AF7-8EDF-1142EEA4E75D} => C:\Users\SH\Desktop\Daisys Garden\SETUP.EXE
Task: {5AEDC82C-41DB-4168-ADA8-25D6E7245795} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {66DAFC3A-12E2-4C39-BFBB-7DAB4BC22406} - System32\Tasks\{0A13E8E8-A30F-4AEA-BF68-D41E2B16944C} => F:\Spiele\Re-Volt\REVOLT.EXE
Task: {6855822B-6AC7-4456-8C89-64942C15CA3E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {6B70920D-A199-40FE-B8A4-490D8F85C72C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {6C62208F-3C37-4816-9425-3FE8D5D19786} - System32\Tasks\{5F62F224-F8AE-4AEC-9697-4BA3C6842947} => F:\Spiele\Re-Volt\REVOLT.EXE
Task: {6E464BA7-FCED-45D5-AC09-8BBD27C84E46} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2014-11-01] (Microsoft Corporation)
Task: {76432D79-BA5E-4708-9049-C2ADE83CA02F} - System32\Tasks\{CF011FBE-9634-4F17-8907-FA7923F15BB7} => E:\Downloads\Zoo Tycoon 2 portable\Zoo Tycoon 2.exe
Task: {7C5BE902-191A-4B36-9D63-954264545B71} - System32\Tasks\{6235236C-5FAC-4D95-B4FA-89AE45EF333F} => F:\Spiele\Siedler3\s3.exe
Task: {806CACB9-9907-4586-8141-708ECDDAD9C7} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Time-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {807C55E6-025D-458E-9669-4304666E730F} - System32\Tasks\{AEFD3B63-880A-4FED-B867-3FA3283FD068} => H:\Bin\Assetup.exe
Task: {83CF2559-908B-4420-B680-85F14AB99EEC} - System32\Tasks\{104CFDDB-9E2D-4220-BA3D-7988D83C9475} => G:\SETUP.EXE
Task: {84D02847-BE0C-40EC-8053-5360EF95303C} - System32\Tasks\{D17DD2A7-899F-4A66-8086-D064EFA9AD45} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\6\SSBCUninstall.exe
Task: {9027D29F-7717-48E2-A1D0-19354CFD44A4} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {A02D8CF0-FC88-4F88-9B8E-5E129EFE47E6} - System32\Tasks\{C810BC6A-04B8-4620-BCD2-FF0D3A0AE76C} => F:\Spiele\Siedler3\s3.exe
Task: {A616CCCE-9739-460D-BF61-1D61445EF1C9} - System32\Tasks\{73626858-316D-461C-B9BF-656D2B494E09} => I:\SETUP.EXE
Task: {A6555AD4-7E5E-4841-9010-6A012AE1C07B} - System32\Tasks\{E5FDEE13-FAAC-4FED-ADC9-57E77D2B85B1} => C:\Users\SH\Desktop\Daisys Garden\SETUP.EXE
Task: {AAB32953-09E6-4C26-9C6B-B8986F2DFCCC} - System32\Tasks\{F9881EAE-8D85-46DC-8A82-3CF7EBFD7B0F} => F:\Spiele\Battle Realms\Battle_Realms_F.exe [2002-08-29] ()
Task: {B671DD9A-3497-466D-A9B1-C2B57B8ABA4A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24] (Google Inc.)
Task: {BEEB576D-6900-4F49-BC06-62B54B4E8EE8} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {C8755AB7-B150-4928-9C2E-1DE3885A05AF} - System32\Tasks\{8214B320-F092-4CA1-9F00-60004BBB7886} => F:\Spiele\Stronghold Crusader\Stronghold Crusader.exe
Task: {D0BD4A0D-16B9-48AE-81F2-AAC146C12367} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {D451D33D-ECFC-416A-9EC3-5EE6897E16FF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24] (Google Inc.)
Task: {DD994869-5D1E-45D7-AC8A-1B225FF35B07} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {E34BDEEC-B41B-4172-9AE8-4F1F0B223BBD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {E7D1FA8A-125D-4132-8B5F-B414A746FE20} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated)
Task: {E9B983C0-AB48-4288-97C0-4575B5D2A05C} - System32\Tasks\{B5CB0BE8-BCE9-4214-BF8B-F589717B1D18} => F:\Programme\OpenVPN\bin\openvpn-gui.exe
Task: {EAE9B20F-EB9D-4A91-A90E-8E3F2D140B47} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-24] (Adobe Systems Incorporated)
Task: {ED50CB7B-FE6D-4B37-A286-19A28F2C0867} - System32\Tasks\{36A8A9B0-7B8F-42F9-A36A-E9497174D4F4} => F:\Spiele\AR2\Ra2.exe [2000-09-26] ()
Task: {EF525288-D933-4223-BA5E-C2D73D4E2728} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {FA210F85-2905-4608-B02F-74CC68B0F194} - System32\Tasks\{D2817F0E-C15B-4836-9384-EE921B14ACD0} => F:\Spiele\Die Siedler - Aufbruch der Kulturen\bin\SADK.exe [2008-08-02] ()
Task: {FEEC1CC0-E1E4-452B-941D-2342CA6721B3} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2013-01-26 10:00 - 2010-01-21 02:53 - 00496232 _____ () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
2013-01-26 10:00 - 2010-01-21 02:52 - 00076392 _____ () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll
2013-01-26 10:00 - 2010-01-21 02:53 - 00731752 _____ () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll
2013-01-26 10:00 - 2010-01-21 02:53 - 00209000 _____ () F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
2015-04-20 17:46 - 2015-04-20 17:46 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2014-02-19 22:41 - 2013-11-19 23:34 - 00152576 _____ () C:\Program Files (x86)\Remote Mouse\FileS.dll
2015-06-24 19:25 - 2015-06-24 19:25 - 01478656 _____ () C:\Users\SH\AppData\Local\Temp\mdi564.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SAVService => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\SH\AppData\Local\DisplayFusion\Wallpaper_2
DNS Servers: 192.168.192.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AmazonMP3DownloaderHelper => C:\Users\SH\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
MSCONFIG\startupreg: ContentTransferWMDetector.exe => F:\Programme\Sony\Content Transfer\ContentTransferWMDetector.exe
MSCONFIG\startupreg: DAEMON Tools Lite => "F:\Programme\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: IntelliPoint => "C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe"
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: PDFPrint => F:\Programme\PDF24\pdf24.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [TCP Query User{2C6BE19D-0E58-4CF3-B005-6220A278A365}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe
FirewallRules: [UDP Query User{031843FD-4ADA-4FD0-B69F-3DC035CDEF62}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe
FirewallRules: [{D8EC7F9A-2C0B-4A43-8EE9-335796C389D6}] => (Allow) F:\Spiele\Steam\Steam.exe
FirewallRules: [{1D71F7C7-2A48-4C2D-9324-998923888C84}] => (Allow) F:\Spiele\Steam\Steam.exe
FirewallRules: [{59DD7784-CD30-44CE-AD42-A796DAF4D798}] => (Allow) F:\Programme\Skype\Phone\Skype.exe
FirewallRules: [{CE4BC92F-D60E-4422-BB9F-812D1EFF6603}] => (Allow) F:\Spiele\Steam\steamapps\common\Plants Vs Zombies\PlantsVsZombies.exe
FirewallRules: [{26B43429-3072-4E2C-886B-ED50EC5F1380}] => (Allow) F:\Spiele\Steam\steamapps\common\Plants Vs Zombies\PlantsVsZombies.exe
FirewallRules: [{E58FF68A-ED08-46D8-9601-1FF67F6275C4}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [{B1BB17BD-FE0C-433D-9658-C326E0C9CD77}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [{93B5F8CB-0887-4F04-AB8A-40DF4DE8C970}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\_runA2CO.cmd
FirewallRules: [{1D37509C-0346-4930-8D5C-50D6A14A15D8}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\_runA2CO.cmd
FirewallRules: [TCP Query User{BC3A705F-913F-4159-BA1C-92108FF713A0}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{EA52438F-5FF5-4C80-8819-4C06F5B54965}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{3446894D-1667-41A5-8A2E-DB51CF487FEC}F:\spiele\ubisoft\related designs\anno 2070\autopatcher.exe] => (Block) F:\spiele\ubisoft\related designs\anno 2070\autopatcher.exe
FirewallRules: [UDP Query User{6EC20222-F622-445D-8700-44E4E433863C}F:\spiele\ubisoft\related designs\anno 2070\autopatcher.exe] => (Block) F:\spiele\ubisoft\related designs\anno 2070\autopatcher.exe
FirewallRules: [{AC0E2D0A-4994-4416-AADD-34A69D73760D}] => (Allow) F:\Spiele\Steam\steamapps\common\DmC Devil May Cry\Binaries\Win32\DMC-DevilMayCry.exe
FirewallRules: [{81F0C757-7FCC-4BD9-AFDB-2AC4F7E6F3B4}] => (Allow) F:\Spiele\Steam\steamapps\common\DmC Devil May Cry\Binaries\Win32\DMC-DevilMayCry.exe
FirewallRules: [{8C641A74-DA57-4BF0-9C66-21326C0DB3F0}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{13FBF50C-3A09-4F8F-8AA4-5A6F6080F6C2}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{88B8F40E-6055-4AB6-98E1-2B9689C0236D}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{7DFE11CA-EADF-491C-8CC0-2505A64AAC70}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{276EBDB5-8508-464B-B174-0323459A605E}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{5A55BECD-CC82-4D25-A2B0-24391E63B7B4}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{E0DEEC64-3D97-4B2B-89E5-8FBF40C9640F}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{9CEF791F-184C-4287-958E-EFF212FAAE64}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{9F9E4530-4EA2-47DC-A523-7FE187FAE15A}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{5FB50D35-4D5C-4A70-9BE5-AD087E5CE162}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [TCP Query User{942AF027-F1A3-4A25-8C3D-876AC4DE527C}F:\spiele\farcry 3\bin\farcry3.exe] => (Block) F:\spiele\farcry 3\bin\farcry3.exe
FirewallRules: [UDP Query User{DEE31A4C-FDDC-4399-B7CB-CEE8D0DD7DD6}F:\spiele\farcry 3\bin\farcry3.exe] => (Block) F:\spiele\farcry 3\bin\farcry3.exe
FirewallRules: [{6B62714C-6366-40FB-89D1-6FAADFF38A35}] => (Allow) F:\Spiele\Steam\steamapps\common\TinyAndBig\tinyandbig.exe
FirewallRules: [{1BBE2AA1-CD7A-40D4-BAF7-E7F34BEE87EE}] => (Allow) F:\Spiele\Steam\steamapps\common\TinyAndBig\tinyandbig.exe
FirewallRules: [{06B2838C-7296-447B-975A-1563444EDC80}] => (Allow) F:\Spiele\Steam\steamapps\common\English Country Tune\English Country Tune.exe
FirewallRules: [{D739DC95-EAA3-4C27-A8B7-CE0175151FBE}] => (Allow) F:\Spiele\Steam\steamapps\common\English Country Tune\English Country Tune.exe
FirewallRules: [{BB368750-D952-4687-8BF1-3D48B44F232A}] => (Allow) F:\Spiele\Steam\steamapps\common\Oil Rush\launcher_steam.bat
FirewallRules: [{5B5346D6-43F7-4EDE-8B0C-729335463910}] => (Allow) F:\Spiele\Steam\steamapps\common\Oil Rush\launcher_steam.bat
FirewallRules: [{7D7822C4-29EF-4283-A43E-29AE4A15910C}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{94CD086D-601D-4F7C-8EEA-035ACA431F63}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [TCP Query User{77278D68-09CC-4F94-8A29-D4F2E518D61F}F:\spiele\steam\steamapps\common\saints row 2\sr2_pcstart.exe] => (Allow) F:\spiele\steam\steamapps\common\saints row 2\sr2_pcstart.exe
FirewallRules: [UDP Query User{26FB494F-75A4-47D6-92FD-C0D6BD1F2805}F:\spiele\steam\steamapps\common\saints row 2\sr2_pcstart.exe] => (Allow) F:\spiele\steam\steamapps\common\saints row 2\sr2_pcstart.exe
FirewallRules: [TCP Query User{5EE45DA4-F539-481F-972F-61D75D8B6FF5}F:\spiele\steam\steam.exe] => (Allow) F:\spiele\steam\steam.exe
FirewallRules: [UDP Query User{A5424F79-D171-41D4-8A77-6BD6F6D42777}F:\spiele\steam\steam.exe] => (Allow) F:\spiele\steam\steam.exe
FirewallRules: [{01E7E936-24EA-480F-9E79-2EF6C6A41C24}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{82497CF8-B0BB-48C3-A42A-0C8DCCBB4BBA}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{022BCC5F-073B-4DCE-98A2-058870649A2A}] => (Allow) F:\Spiele\Steam\steamapps\alfonsbauer\source sdk base 2007\hl2.exe
FirewallRules: [{00A7551E-A036-4821-8D8D-30C9A3DF29D2}] => (Allow) F:\Spiele\Steam\steamapps\alfonsbauer\source sdk base 2007\hl2.exe
FirewallRules: [TCP Query User{B2E05E4B-2B46-4213-9C2C-532FFD5F5D3C}F:\programme\sharekm\sharekm.exe] => (Allow) F:\programme\sharekm\sharekm.exe
FirewallRules: [UDP Query User{72A782A5-2930-4248-B7B1-97DB1893267E}F:\programme\sharekm\sharekm.exe] => (Allow) F:\programme\sharekm\sharekm.exe
FirewallRules: [{2904C3B5-565E-4BF9-88D3-7E17C8C9608C}] => (Allow) F:\Spiele\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{D3A4C07B-5BE3-43B6-85FA-99D7A8F385BF}] => (Allow) F:\Spiele\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{7172B343-530D-4388-89E7-7D74B80174D4}] => (Allow) F:\Spiele\Steam\steamapps\common\Antichamber\Binaries\Win32\UDK.exe
FirewallRules: [{962B7401-1FFB-4908-940B-8521E76C7E9C}] => (Allow) F:\Spiele\Steam\steamapps\common\Antichamber\Binaries\Win32\UDK.exe
FirewallRules: [{58AD3F4A-53E4-4A3E-85C2-7AFA0893D50D}] => (Allow) F:\Spiele\Steam\steamapps\common\Construct2\Construct2.exe
FirewallRules: [{265C10D1-1274-4A64-96F1-70BE47939109}] => (Allow) F:\Spiele\Steam\steamapps\common\Construct2\Construct2.exe
FirewallRules: [{B52FD9C1-D7C7-44A1-ACD6-2B93E243BDB2}] => (Allow) F:\Spiele\Steam\steamapps\common\FlatOut2\FlatOut2.exe
FirewallRules: [{964188AE-D332-4B4D-9359-F8636FD7EBC1}] => (Allow) F:\Spiele\Steam\steamapps\common\FlatOut2\FlatOut2.exe
FirewallRules: [TCP Query User{1AD91E7C-7376-45FD-8AFE-0DB1B813C40D}F:\spiele\steam\steamapps\common\flatout ultimate carnage\fouc.exe] => (Allow) F:\spiele\steam\steamapps\common\flatout ultimate carnage\fouc.exe
FirewallRules: [UDP Query User{2F3DDF7C-B2A8-4FDF-86D3-3DED2976D829}F:\spiele\steam\steamapps\common\flatout ultimate carnage\fouc.exe] => (Allow) F:\spiele\steam\steamapps\common\flatout ultimate carnage\fouc.exe
FirewallRules: [{FEFA1B33-BEB0-4345-BA0D-B54D37317B43}] => (Allow) F:\Spiele\Steam\steamapps\common\Oil Rush\launcher_steam.bat
FirewallRules: [{1566EE63-81A6-49BE-8C85-F7B95BD64EEA}] => (Allow) F:\Spiele\Steam\steamapps\common\Oil Rush\launcher_steam.bat
FirewallRules: [{9253C1F4-BEA3-439A-A413-5BCD6AD9AD3A}] => (Allow) F:\Spiele\Steam\steamapps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{B5A30D86-9A68-4605-A588-B50D3BF98644}] => (Allow) F:\Spiele\Steam\steamapps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{ECA56855-D3CD-439F-A3B0-BDD2BAB5D5EF}] => (Allow) F:\Spiele\ANNO 2070\Anno5.exe
FirewallRules: [{FB2424E3-B1B2-4794-921B-6A7C072BDD0C}] => (Allow) F:\Spiele\ANNO 2070\Anno5.exe
FirewallRules: [{4AF967B5-631D-4E89-A424-F21C02EDFDBC}] => (Allow) F:\Spiele\ANNO 2070\AutoPatcher.exe
FirewallRules: [{0A63D2B5-7532-4102-ABE9-D7140D435729}] => (Allow) F:\Spiele\ANNO 2070\AutoPatcher.exe
FirewallRules: [{BB7419C8-C01A-41BE-9E6B-AD03B689D4D8}] => (Allow) F:\Spiele\ANNO 2070\InitEngine.exe
FirewallRules: [{9F1FD6D4-858F-4D97-BE43-7A8D5E5DFE47}] => (Allow) F:\Spiele\ANNO 2070\InitEngine.exe
FirewallRules: [TCP Query User{5D4D0921-F810-45EF-BCE3-274893E25D0A}F:\spiele\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) F:\spiele\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [UDP Query User{BC44A9B9-B745-4C56-AA17-3A91559F5CD5}F:\spiele\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) F:\spiele\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [{89337B81-6AA4-441B-B019-AFC35520EB7B}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal\hl2.exe
FirewallRules: [{2C2B7BA7-9034-46CF-9D74-9214F9DB9818}] => (Allow) F:\Spiele\Steam\steamapps\common\Portal\hl2.exe
FirewallRules: [TCP Query User{F74E6119-C35A-4DD7-9C4C-BD9D23E46F47}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{B325BB9A-16B9-4252-B55A-737B638D8AF6}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{12D69903-2EE3-4DD5-8AD5-24AE6B9D4591}] => (Allow) F:\Spiele\Steam\steamapps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{C24C8F33-4DE2-40D3-9F0C-021A7A803614}] => (Allow) F:\Spiele\Steam\steamapps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{15CDA757-8647-477D-AE9B-8A13848C7361}] => (Allow) F:\Spiele\Steam\steamapps\common\Construct2\Construct2.exe
FirewallRules: [{E7858CFD-FACC-4B94-A87B-6DC5604E8515}] => (Allow) F:\Spiele\Steam\steamapps\common\Construct2\Construct2.exe
FirewallRules: [{D7E45C8E-ABA4-4D87-8263-14FE14A672D5}] => (Allow) F:\Spiele\Steam\steamapps\common\Half-Life 2\hl2.exe
FirewallRules: [{927D2BC8-6AF0-4458-B575-FDB0813BCE44}] => (Allow) F:\Spiele\Steam\steamapps\common\Half-Life 2\hl2.exe
FirewallRules: [{1CD9155C-D66B-45F9-B24A-0C98D6760659}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{BAB16AD7-D254-42FF-8600-A8FA3D164795}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{2CF0155B-F63C-42CA-A6E5-2A7A3315E161}] => (Allow) F:\Spiele\Steam\steamapps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{A3B332C0-9E46-4846-9D20-029619FA9872}] => (Allow) F:\Spiele\Steam\steamapps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{310DB519-797B-4E17-9EA1-50F952FC4846}] => (Allow) F:\Spiele\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{B73B192C-1973-4309-93C4-9B2B59784BFA}] => (Allow) F:\Spiele\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{BE547D02-320F-4BB2-9467-5B7DDEE788C3}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2 Beta\left4dead2_beta.exe
FirewallRules: [{7C24EB07-E89A-46D4-B55F-F6B34AD6EC42}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2 Beta\left4dead2_beta.exe
FirewallRules: [{B6834AF7-0382-444E-9D7C-A39F8D4A5B43}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{CC768439-0388-4BD0-9FCE-ED06EC7CFA20}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{452621CA-EE61-436C-A1E9-0EA99A02B4BF}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{35212414-57B3-41E8-BACF-1341BFC08D98}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{A7C577DE-8769-4182-AD9A-82869E47B0BF}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{3FD181C2-632F-4B86-81A4-028B4BF32031}] => (Allow) F:\Spiele\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [TCP Query User{835A04A2-EA55-4497-960A-8B9B21A99B1D}F:\spiele\maniaplanet\maniaplanet.exe] => (Allow) F:\spiele\maniaplanet\maniaplanet.exe
FirewallRules: [UDP Query User{6D2909E2-1688-4431-8482-D1063F25E355}F:\spiele\maniaplanet\maniaplanet.exe] => (Allow) F:\spiele\maniaplanet\maniaplanet.exe
FirewallRules: [{8C2CA391-70C2-4C05-881A-8B76007B0EC9}] => (Allow) F:\Spiele\Steam\steamapps\common\Bugbear Entertainment\Next Car Game.exe
FirewallRules: [{E0E6142A-3BE0-46B4-9C28-33787E69F82A}] => (Allow) F:\Spiele\Steam\steamapps\common\Bugbear Entertainment\Next Car Game.exe
FirewallRules: [TCP Query User{CDACFFDA-449A-4BB0-BDA3-B0538313E096}C:\program files (x86)\tale of tales\the endless forest 3\forestviewer.exe] => (Allow) C:\program files (x86)\tale of tales\the endless forest 3\forestviewer.exe
FirewallRules: [UDP Query User{E8B277A8-B308-4085-A8DE-6060EA3436FC}C:\program files (x86)\tale of tales\the endless forest 3\forestviewer.exe] => (Allow) C:\program files (x86)\tale of tales\the endless forest 3\forestviewer.exe
FirewallRules: [{4CD95332-339F-4B1C-AE13-FF826C158486}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{CAA874F7-94C8-4480-9226-32708B80D708}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{4AB4647A-D046-42E4-B912-02E946B48E09}] => (Allow) F:\Spiele\Blizz\Battle.net\Battle.net.exe
FirewallRules: [{E3B8FF95-227D-433E-922D-14C29C8AF006}] => (Allow) F:\Spiele\Blizz\Battle.net\Battle.net.exe
FirewallRules: [{68E32DAC-03EF-47FB-BF4C-6B82CD0796C5}] => (Allow) F:\Spiele\Blizz\Diablo III\Diablo III.exe
FirewallRules: [{0BF65864-7E8D-4D03-8DB3-D65933DACB33}] => (Allow) F:\Spiele\Blizz\Diablo III\Diablo III.exe
FirewallRules: [{7980BD1D-4008-451C-A526-E1CB2285EA4C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{A3A8738E-B81C-4AD2-97D6-6A1EE691AB6E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{822C2752-B4D4-42F6-A54B-06324BC12F14}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe
FirewallRules: [{E6572DCD-E3C4-4891-8732-9F53F2DA6D1D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe
FirewallRules: [{34C3B52E-ACFD-4D64-8ACF-11ED27CCF393}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe
FirewallRules: [{E1B08DCB-7AA5-4F8D-9C95-BF3273F83331}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe
FirewallRules: [{6977B532-F320-4368-95EA-59ED582D90B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe
FirewallRules: [{9F8F6C0A-ECDD-4750-BCDD-D4EFA36C2DEA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe
FirewallRules: [{83C9B81A-AC09-41CC-B3C7-639B73469AA9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe
FirewallRules: [{F45323E9-E3C0-48A9-8E5D-E1A54A7EA748}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe
FirewallRules: [{7AEF91F2-AF59-479E-9ADF-C7D52E056862}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe
FirewallRules: [{83ACBEC3-E604-4BA3-9D52-3664DA8E05D5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe
FirewallRules: [{86D791A3-7B1A-4A9C-B586-D4D95E78D764}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe
FirewallRules: [{C44977CC-7CBE-448B-9305-1E4C73FA234A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe
FirewallRules: [{D9163973-BEA0-4614-99BD-AC674EE5D202}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe
FirewallRules: [{36A831EE-3C87-4232-BADB-13BD940BABB9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe
FirewallRules: [{AD178CBA-B256-4F4F-A6BD-D0E14793AE95}] => (Allow) F:\Spiele\Blizz\Hearthstone\Hearthstone.exe
FirewallRules: [{8E38F59A-9A66-457C-8327-72CFF64A5642}] => (Allow) F:\Spiele\Blizz\Hearthstone\Hearthstone.exe
FirewallRules: [{06FB27FD-0BFB-4BF9-A431-F971ABFBFA91}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{F83F8E36-91A1-40A9-90A7-824B38F4C449}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{4509308F-65C3-4CA6-9316-5F33E4934519}] => (Allow) F:\Spiele\Steam\steamapps\common\Banished\Application-steam-x64.exe
FirewallRules: [{D7129A8E-03CB-4387-BCE7-5F43EBBBDAF4}] => (Allow) F:\Spiele\Steam\steamapps\common\Banished\Application-steam-x64.exe
FirewallRules: [{F16A0A6B-5DB7-43FB-9D6E-85EBEE0B0C98}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{D8F1F1AF-282E-4D2F-A044-FC2FC126FD78}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [TCP Query User{34B1421A-C99C-464F-89B4-D40E58A4E2D6}C:\program files (x86)\remote mouse\remotemouse.exe] => (Allow) C:\program files (x86)\remote mouse\remotemouse.exe
FirewallRules: [UDP Query User{45B090D0-6B0F-436A-A634-5DD41FCEAA84}C:\program files (x86)\remote mouse\remotemouse.exe] => (Allow) C:\program files (x86)\remote mouse\remotemouse.exe
FirewallRules: [{D9CA769D-2CC1-499D-8CA7-F37B0AE07AA3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{6213593F-AB2D-483B-89B3-251622A63253}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{CAFE9F23-EC99-46EB-B068-1CCC1DD08C44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{6C8D8904-0D5A-4BE9-85A7-8DC71E84A499}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{B76795B7-C827-4F90-8A37-D98FF7CFBCC6}] => (Block) F:\spiele\guitar hero iii\gh3.exe
FirewallRules: [{683A0BCE-6EC5-4FAC-9557-4856CCEF29AF}] => (Block) F:\spiele\guitar hero iii\gh3.exe
FirewallRules: [{93B9A355-B15F-44C2-9FCF-F3C710EEB9DF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe
FirewallRules: [{824E04CC-1EFE-489D-AD70-45B13AA69A95}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe
FirewallRules: [{D55E23D3-BACA-4010-86AA-C2130C608AAD}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{B3A8007E-67F9-4BE4-AB2C-74B92922B322}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{9DA23C77-312B-477A-8999-F7184C48F6D7}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{B2BEA770-52AC-4EDD-A755-841333A62011}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{F369FC3F-2ED9-431D-8A9D-2A456439B759}] => (Allow) F:\Spiele\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{024406D0-7077-4A2B-AAC7-22BCF8BEF488}] => (Allow) F:\Spiele\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{56FFC565-6CDF-42EA-AEFD-C64168011B3A}] => (Allow) F:\Spiele\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{ACEEE806-FE56-4DB0-A042-D86BDE93B86B}] => (Allow) F:\Spiele\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{F203C828-AE6B-4A54-925C-BDBD310E6F43}] => (Allow) F:\Spiele\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{EC40F483-557D-4132-99BB-C94F5DA6DFE5}] => (Allow) F:\Spiele\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{EA79F339-3A31-4227-9697-21B7C939B639}] => (Allow) F:\Spiele\Stronghold Crusader\stronghold crusader.exe
FirewallRules: [{A3F09705-63EA-4C4C-83EA-E266A70E957D}] => (Allow) F:\Spiele\Steam\steamapps\common\The Stanley Parable\stanley.exe
FirewallRules: [{948464A7-3EC1-4D26-A325-6359CF7D60FA}] => (Allow) F:\Spiele\Steam\steamapps\common\The Stanley Parable\stanley.exe
FirewallRules: [{268860D8-DE0B-4087-ADDB-4D558C3B8B1F}] => (Allow) F:\Programme\Nexus Mod Manager\NexusClient.exe
FirewallRules: [{EEDE604C-7F55-416D-95F1-C5FE142E9A46}] => (Allow) F:\Programme\Nexus Mod Manager\NexusClient.exe
FirewallRules: [{DE4CCCF6-C151-48DD-9085-06755CD3F3BC}] => (Allow) F:\Programme\Nexus Mod Manager\NexusClient.exe
FirewallRules: [{D639379F-365E-4AC2-98EF-39C979916BA6}] => (Allow) F:\Programme\Nexus Mod Manager\NexusClient.exe
FirewallRules: [{2BC70545-C9C2-41FF-A9AA-8B55E2A1CA11}] => (Allow) F:\Spiele\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{CA6A56AB-0869-4331-BDB4-62AD34036379}] => (Allow) F:\Spiele\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{6AB873FD-CBA6-4406-A19F-33A5D0ED1F69}] => (Allow) F:\Spiele\Steam\steamapps\common\Bully Scholarship Edition\Bully.exe
FirewallRules: [{71376133-6A21-459C-BE8C-3B4D375F497A}] => (Allow) F:\Spiele\Steam\steamapps\common\Bully Scholarship Edition\Bully.exe
FirewallRules: [{16F08E89-7FBF-4700-A8C0-DDB08A63EE53}] => (Allow) F:\Spiele\Steam\steamapps\common\Enslaved\Binaries\Win32\Enslaved.exe
FirewallRules: [{102C4727-29EA-47A1-8657-5258E865259E}] => (Allow) F:\Spiele\Steam\steamapps\common\Enslaved\Binaries\Win32\Enslaved.exe
FirewallRules: [{FAC254C3-C5A7-474C-9271-6F7790190BB1}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\ARMA2OASERVER.exe
FirewallRules: [{1FBEB6C9-45B1-4645-BD2F-436FDECF75E9}] => (Allow) F:\Spiele\Steam\steamapps\common\Arma 2 Operation Arrowhead\ARMA2OASERVER.exe
FirewallRules: [{46C37E19-9B46-42D0-A571-A286BE1402B7}] => (Allow) F:\Spiele\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe
FirewallRules: [{6F9AA8C4-6AF1-473C-99DC-CFA1A8CDF785}] => (Allow) F:\Spiele\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe
FirewallRules: [TCP Query User{79A41835-746C-4724-8952-BC0295FDA968}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{6B43E8F2-DBFD-4397-987A-BE9FE0B49C66}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{B1448FB8-38BB-4346-B60C-77217BDEF3F1}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{4DA2B681-926A-47CD-8172-9DF381D5297B}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{D96B2E3C-3978-4326-B914-0CC3790A0912}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe
FirewallRules: [{A82AE199-9553-4D2A-9175-F5D64B5A1FEF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe
FirewallRules: [{7E9E0AB0-7958-4D10-B49E-0671E46DB55C}] => (Allow) F:\Spiele\Steam\bin\steamwebhelper.exe
FirewallRules: [{D45B3E3B-E0B7-4C37-A287-7B0E6DCF5DF3}] => (Allow) F:\Spiele\Steam\bin\steamwebhelper.exe
FirewallRules: [{D3C27D52-1093-434F-BE94-6C5D022A5F39}] => (Allow) F:\Spiele\Steam\steamapps\common\Broforce\BROFORCE_Beta.exe
FirewallRules: [{8CEF381D-E12E-4E58-8CFC-7C86CABD6FEE}] => (Allow) F:\Spiele\Steam\steamapps\common\Broforce\BROFORCE_Beta.exe
FirewallRules: [TCP Query User{630760F7-8F71-4FD9-B857-EF85DBBFD154}F:\spiele\rising gods wow\world_of_warcraft_wotlk-rg\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe] => (Block) F:\spiele\rising gods wow\world_of_warcraft_wotlk-rg\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe
FirewallRules: [UDP Query User{18F94FEC-C9F3-4DD7-9734-B7D00E3FCB59}F:\spiele\rising gods wow\world_of_warcraft_wotlk-rg\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe] => (Block) F:\spiele\rising gods wow\world_of_warcraft_wotlk-rg\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe
FirewallRules: [{2652FE76-58DE-451E-A9A9-4017775E6FFC}] => (Allow) F:\Spiele\Steam\steamapps\common\Metro Last Light\MetroLL.exe
FirewallRules: [{FAC2F888-BC5E-4099-A146-69F31192BAF0}] => (Allow) F:\Spiele\Steam\steamapps\common\Metro Last Light\MetroLL.exe
FirewallRules: [{27C8A4E4-6C7B-46AC-BF1E-8A5D81C0EE40}] => (Allow) F:\Spiele\Steam\steamapps\common\Source SDK Base\hl2.exe
FirewallRules: [{366348ED-41D7-4467-8F61-682A33255213}] => (Allow) F:\Spiele\Steam\steamapps\common\Source SDK Base\hl2.exe
FirewallRules: [{82D1C822-BE8B-4837-9F85-B6A4A3B6EF67}] => (Allow) F:\Spiele\Steam\steamapps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{C00D009D-A4D9-423E-80F6-9694F4390115}] => (Allow) F:\Spiele\Steam\steamapps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{E147AAFA-067F-431C-B3B9-F64A26DF0C8F}] => (Allow) F:\Spiele\Steam\steamapps\common\Source SDK Base 2007\hl2.exe
FirewallRules: [{05E2BBAD-F3BA-4306-9363-6658E999B512}] => (Allow) F:\Spiele\Steam\steamapps\common\Source SDK Base 2007\hl2.exe
FirewallRules: [TCP Query User{FA9F82A5-9D6F-438A-BD4E-172848331E81}C:\programdata\battle.net\agent\agent.3182\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3182\agent.exe
FirewallRules: [UDP Query User{7DEA6BAE-EEFC-494A-89FC-37C3D17B8F9B}C:\programdata\battle.net\agent\agent.3182\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3182\agent.exe
FirewallRules: [{EEB9B9CA-59C6-4554-99EA-BE23B59DCD48}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4 Create A Sim Demo\Game\Bin\TS4CAS.exe
FirewallRules: [{0925B725-624A-446E-AC46-EEAFA49EBC96}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4 Create A Sim Demo\Game\Bin\TS4CAS.exe
FirewallRules: [TCP Query User{AC845656-2685-43E3-A46C-7BFEAF5E1A26}F:\spiele\tmnationsforever\tmforever.exe] => (Allow) F:\spiele\tmnationsforever\tmforever.exe
FirewallRules: [UDP Query User{5AF20FEC-8EC0-4AC4-A1B1-B33D10E1C8A8}F:\spiele\tmnationsforever\tmforever.exe] => (Allow) F:\spiele\tmnationsforever\tmforever.exe
FirewallRules: [{E8117924-0F17-442D-B660-9DC22BA2E36B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3182\Agent.exe
FirewallRules: [{D6009473-4150-4828-BF3F-D4CC5E043F6E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3182\Agent.exe
FirewallRules: [TCP Query User{1CC437FD-6319-45FE-B801-41D0ABA1E627}C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe] => (Allow) C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe
FirewallRules: [UDP Query User{A7153A80-5163-47A3-8149-16ED0CAEF293}C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe] => (Allow) C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe
FirewallRules: [{EE84E611-556F-49CC-AB75-37AB9B1ED8F0}] => (Block) C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe
FirewallRules: [{1901E8D5-776A-489D-A4F8-8288FC5CF4B8}] => (Block) C:\users\sh\downloads\downloader_warcraft3_reign_of_chaos_engb.exe
FirewallRules: [TCP Query User{1841F0CE-944D-4406-950C-D8AE1E8490F4}C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe] => (Allow) C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe
FirewallRules: [UDP Query User{51CDF0E2-409B-4BD1-91A0-85AD6271BDEF}C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe] => (Allow) C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe
FirewallRules: [{2FBD9BC2-94FA-49C9-BE10-7DE2B9C6F8F3}] => (Block) C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe
FirewallRules: [{0D177CA2-FECE-4D0B-AA05-756B3B90D6BB}] => (Block) C:\users\sh\downloads\downloader_warcraft3_the_frozen_throne_engb.exe
FirewallRules: [{80771493-9E65-4A2F-A673-21967CFD6B19}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{8C68C2F4-31DC-4BB9-AC0C-9DD495F68EB7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{27564E58-3B54-4DBF-98F0-8ADAF467DEDE}] => (Allow) F:\Spiele\Steam\steamapps\common\Bugbear Entertainment\Wreckfest.exe
FirewallRules: [{CF992184-7850-435B-9F74-45C1712CDC83}] => (Allow) F:\Spiele\Steam\steamapps\common\Bugbear Entertainment\Wreckfest.exe
FirewallRules: [{38C455B2-1AA3-43DC-A88E-9867B6F2DDCA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{CFAC61BC-A88D-4923-8DDF-17FC7A57808E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{B901CD78-20C3-443D-8442-ED7CFCF7C135}] => (Allow) F:\Spiele\Steam\steamapps\common\Bridge Constructor Playground\BridgeConstructorPlayground.exe
FirewallRules: [{89A265FE-8756-40DF-86B6-C7C6E61C5E6C}] => (Allow) F:\Spiele\Steam\steamapps\common\Bridge Constructor Playground\BridgeConstructorPlayground.exe
FirewallRules: [{EE12FD42-9E1F-4AC3-B92A-7361AF482CA0}] => (Allow) F:\Spiele\Steam\steamapps\common\Bridge Constructor Medieval\Bridge_Constructor_Medieval.exe
FirewallRules: [{2CD7DC47-5CF6-4535-825F-BB349D2CE3B7}] => (Allow) F:\Spiele\Steam\steamapps\common\Bridge Constructor Medieval\Bridge_Constructor_Medieval.exe
FirewallRules: [{D9678680-9CC6-4F30-BFF8-DA7A0F7D79F1}] => (Allow) F:\Spiele\Steam\steamapps\common\BridgeConstructor\BridgeConstructor.exe
FirewallRules: [{3FFAADA3-30D8-46A8-B666-7CD9A83510C1}] => (Allow) F:\Spiele\Steam\steamapps\common\BridgeConstructor\BridgeConstructor.exe
FirewallRules: [{6C5304E3-0642-4CDD-8D16-B5853F62AC17}] => (Allow) F:\Spiele\Steam\steamapps\common\Assassin's Creed Liberation\ac3lhd_32.exe
FirewallRules: [{DACE09AE-4E4D-4D0A-B4E7-4EE4EE417D08}] => (Allow) F:\Spiele\Steam\steamapps\common\Assassin's Creed Liberation\ac3lhd_32.exe
FirewallRules: [{52E78844-3D52-4AB1-A21C-110BB9E8E5B4}] => (Allow) F:\Spiele\Steam\steamapps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe
FirewallRules: [{D2FA1D17-928E-4A32-A347-4BD003203988}] => (Allow) F:\Spiele\Steam\steamapps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe
FirewallRules: [TCP Query User{64D00F2C-C613-4D46-9E8A-A0223A547D15}C:\users\sh\appdata\local\temp\ixp000.tmp\dear.exe] => (Block) C:\users\sh\appdata\local\temp\ixp000.tmp\dear.exe
FirewallRules: [UDP Query User{50D0103B-1851-4F25-8B2A-58C2154BC8F7}C:\users\sh\appdata\local\temp\ixp000.tmp\dear.exe] => (Block) C:\users\sh\appdata\local\temp\ixp000.tmp\dear.exe
FirewallRules: [TCP Query User{8F345F7B-A443-47A6-9ECB-9B6801DB47B4}C:\users\sh\desktop\freekshow\reveal\binaries\win32\udk.exe] => (Block) C:\users\sh\desktop\freekshow\reveal\binaries\win32\udk.exe
FirewallRules: [UDP Query User{837DADA3-4227-4A28-B09E-77A5894CAD30}C:\users\sh\desktop\freekshow\reveal\binaries\win32\udk.exe] => (Block) C:\users\sh\desktop\freekshow\reveal\binaries\win32\udk.exe
FirewallRules: [TCP Query User{D6B80ED4-9442-4FA0-B952-033D86A490F6}F:\spiele\ar2\game.exe] => (Allow) F:\spiele\ar2\game.exe
FirewallRules: [UDP Query User{33DFCFEA-0263-40B1-8442-B454576C9F5E}F:\spiele\ar2\game.exe] => (Allow) F:\spiele\ar2\game.exe
FirewallRules: [TCP Query User{4C2312F8-3ED6-48D0-BFCD-59FC97446F63}F:\spiele\clonk rage\clonk.exe] => (Allow) F:\spiele\clonk rage\clonk.exe
FirewallRules: [UDP Query User{04B5C2CB-7B07-494D-B6CA-7DBC1A98E30A}F:\spiele\clonk rage\clonk.exe] => (Allow) F:\spiele\clonk rage\clonk.exe
FirewallRules: [TCP Query User{04F82361-9A47-4D1D-ADA2-A1167264A2FA}F:\spiele\clonk endeavour\clonk.c4x] => (Allow) F:\spiele\clonk endeavour\clonk.c4x
FirewallRules: [UDP Query User{7AC345A0-4A39-47EE-9828-B916992B5AA3}F:\spiele\clonk endeavour\clonk.c4x] => (Allow) F:\spiele\clonk endeavour\clonk.c4x
FirewallRules: [{B7843A9F-B748-4189-8E0D-E5F356B8CD30}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
FirewallRules: [{84182764-9342-41D0-A2E1-CB877A395E03}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
FirewallRules: [TCP Query User{9EFFCB9D-D4E3-49E1-B5B8-7A80E4717CAC}F:\programme\remote control server\remote control server.exe] => (Allow) F:\programme\remote control server\remote control server.exe
FirewallRules: [UDP Query User{F0644439-D505-426C-8481-BB4B69EF65D7}F:\programme\remote control server\remote control server.exe] => (Allow) F:\programme\remote control server\remote control server.exe
FirewallRules: [{C121BF0D-1792-4FEF-9C05-352CD8A958EE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe
FirewallRules: [{C387C3A5-941E-47C4-99D1-3B46E64DBCF4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe
FirewallRules: [{74AA505F-3DF5-482F-B7CA-6AFA7312B84F}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{A4786641-DE1C-41D7-A0E9-1EA0F088876E}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{CBBF1A7D-45B3-4F1F-B69F-0B71D0465E93}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{43691564-9A58-476C-8488-9A9DE4C8F0B7}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{9CAB7543-88D6-44B4-8179-3B38B1F3E5EE}F:\spiele\ubisoft\rayman origins\rayman origins.exe] => (Block) F:\spiele\ubisoft\rayman origins\rayman origins.exe
FirewallRules: [UDP Query User{BEF7A399-A3E3-4892-85B9-500BEC6729D3}F:\spiele\ubisoft\rayman origins\rayman origins.exe] => (Block) F:\spiele\ubisoft\rayman origins\rayman origins.exe
FirewallRules: [{3335D305-17AD-4BA1-8792-2F9DD8DEE99C}] => (Allow) F:\Spiele\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{0B479948-993B-4DA8-85B8-857D3F1E9F0B}] => (Allow) F:\Spiele\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{00DD4C03-7241-4BFB-9CC9-F20CF3C92713}] => (Allow) F:\Spiele\Steam\steamapps\common\CoJ Gunslinger\CoJGunslinger.exe
FirewallRules: [{9B647514-ED75-4AE0-8B9F-D0E26FE86CAB}] => (Allow) F:\Spiele\Steam\steamapps\common\CoJ Gunslinger\CoJGunslinger.exe
FirewallRules: [{51443128-C299-46B8-880D-43702562A729}] => (Allow) F:\Programme\Mozilla Firefox\firefox.exe
FirewallRules: [{013A483B-AA9E-4491-AED5-2C52855EF75A}] => (Allow) F:\Programme\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{0EEA6DCA-1D26-4950-A6D8-943CB6B7EE13}C:\users\sh\appdata\local\hola\firefox\app\hola_plugin.exe] => (Allow) C:\users\sh\appdata\local\hola\firefox\app\hola_plugin.exe
FirewallRules: [UDP Query User{CE01B0A4-4D12-426A-9E01-C52094FE6164}C:\users\sh\appdata\local\hola\firefox\app\hola_plugin.exe] => (Allow) C:\users\sh\appdata\local\hola\firefox\app\hola_plugin.exe
FirewallRules: [{86FF776D-34BA-4C3E-8BBE-E08104CCA342}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{E16D80F9-1ADD-4A62-96C6-BA71A886D826}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{C962C669-DC9B-4025-8BC7-1A2578D9F7E8}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{4B03C4FB-10D6-4EA5-9B9C-70730342F800}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{FEC1C191-2669-4A4E-BD3A-BCC8B570AB55}F:\spiele\electronic arts\need for speed(tm) hot pursuit\nfs11.exe] => (Block) F:\spiele\electronic arts\need for speed(tm) hot pursuit\nfs11.exe
FirewallRules: [UDP Query User{5611D245-16E3-45F3-848E-E4FA1EE9DDF0}F:\spiele\electronic arts\need for speed(tm) hot pursuit\nfs11.exe] => (Block) F:\spiele\electronic arts\need for speed(tm) hot pursuit\nfs11.exe
FirewallRules: [{67B97936-8267-445F-9E62-16CD21F289AB}] => (Allow) F:\Spiele\Steam\steamapps\common\Salt Demo\SaltTrial.exe
FirewallRules: [{1DE59770-12A7-43F9-B19A-C6F24653BB9B}] => (Allow) F:\Spiele\Steam\steamapps\common\Salt Demo\SaltTrial.exe
FirewallRules: [{0916DEE1-447A-445F-80CB-A7D7FA438DA3}] => (Allow) F:\Spiele\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe
FirewallRules: [{0507C7A8-1C36-4122-901A-5CCF7145AE36}] => (Allow) F:\Spiele\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe
FirewallRules: [{BDEAB6FB-91E9-49F0-8DD1-DFEDB7A160B5}] => (Allow) F:\Spiele\Steam\steamapps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{0824D022-381D-4693-8213-C9968F8C108E}] => (Allow) F:\Spiele\Steam\steamapps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{DEE3F90B-BC4F-4B3A-89C9-0CE1F8800DC2}] => (Allow) F:\Spiele\Steam\steamapps\common\Command and Conquer Red Alert 3 Uprising\RA3EP1.exe
FirewallRules: [{555B0416-F205-4579-B618-8F5B8768921C}] => (Allow) F:\Spiele\Steam\steamapps\common\Command and Conquer Red Alert 3 Uprising\RA3EP1.exe
FirewallRules: [{5179275A-945C-40F2-93FA-34462AB30BD3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{CC417F9E-2614-4000-A294-DF8D9D248925}] => (Allow) F:\Spiele\Steam\steamapps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{F1E83BD0-12ED-4A31-84A3-E95D6FF76022}] => (Allow) F:\Spiele\Steam\steamapps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{CC4130DE-3985-4E6E-AFFE-3763D50C6F58}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [{4E79BD64-52B2-46C0-8889-48358549D456}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
StandardProfile\AuthorizedApplications: [F:\Programme\TriDef\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe] => Enabled:TriDef 3D Media Player

==================== Faulty Device Manager Devices =============

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/25/2015 03:19:26 PM) (Source: Sophos Anti-Virus) (EventID: 38) (User: NT-AUTORITÄT)
Description: Virus/Spyware 'Troj/Miner-AB' konnte nicht entfernt werden. Es traten Fehler auf.

Error: (06/25/2015 03:16:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/25/2015 02:27:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/25/2015 00:13:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/24/2015 08:57:01 PM) (Source: Xbox_360_CC_Driver) (EventID: 4373) (User: )
Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar.

Error: (06/24/2015 07:37:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/24/2015 07:34:33 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/24/2015 07:25:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: key.exe, Version: 0.0.0.0, Zeitstempel: 0x55885865
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x023028ad
ID des fehlerhaften Prozesses: 0x1628
Startzeit der fehlerhaften Anwendung: 0xkey.exe0
Pfad der fehlerhaften Anwendung: key.exe1
Pfad des fehlerhaften Moduls: key.exe2
Berichtskennung: key.exe3

Error: (06/24/2015 07:25:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: key.exe, Version: 0.0.0.0, Zeitstempel: 0x55885865
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x022128ad
ID des fehlerhaften Prozesses: 0x17d0
Startzeit der fehlerhaften Anwendung: 0xkey.exe0
Pfad der fehlerhaften Anwendung: key.exe1
Pfad des fehlerhaften Moduls: key.exe2
Berichtskennung: key.exe3

Error: (06/24/2015 07:17:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: SplitSecond.exe, Version: 1.0.0.1, Zeitstempel: 0x4be13c66
Name des fehlerhaften Moduls: SplitSecond.exe, Version: 1.0.0.1, Zeitstempel: 0x4be13c66
Ausnahmecode: 0x80000003
Fehleroffset: 0x00d8f167
ID des fehlerhaften Prozesses: 0xe54
Startzeit der fehlerhaften Anwendung: 0xSplitSecond.exe0
Pfad der fehlerhaften Anwendung: SplitSecond.exe1
Pfad des fehlerhaften Moduls: SplitSecond.exe2
Berichtskennung: SplitSecond.exe3


System errors:
=============
Error: (06/25/2015 03:15:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
StarOpen

Error: (06/25/2015 03:14:25 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.

Error: (06/25/2015 03:13:35 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

Error: (06/25/2015 02:26:41 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
StarOpen

Error: (06/25/2015 02:25:56 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.

Error: (06/25/2015 00:12:18 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
StarOpen

Error: (06/25/2015 00:11:31 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.

Error: (06/24/2015 07:36:28 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
StarOpen

Error: (06/24/2015 07:35:47 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.

Error: (06/24/2015 07:33:34 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
StarOpen


Microsoft Office:
=========================

CodeIntegrity Errors:
===================================
  Date: 2014-07-27 12:16:45.953
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\SH\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-27 12:16:45.901
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\SH\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-27 12:16:43.529
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Programme\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-27 12:16:43.474
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Programme\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM)2 Quad CPU Q8400 @ 2.66GHz
Percentage of memory in use: 47%
Total physical RAM: 4094.55 MB
Available physical RAM: 2138.83 MB
Total Pagefile: 8187.32 MB
Available Pagefile: 5737.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:200 GB) (Free:110.95 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Systemsicherung) (Fixed) (Total:465.75 GB) (Free:279.91 GB) NTFS
Drive e: (Daten) (Fixed) (Total:465.75 GB) (Free:381.85 GB) NTFS
Drive f: (Anwendungen) (Fixed) (Total:498.63 GB) (Free:185.28 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: E3B7363E)
Partition 1: (Active) - (Size=200 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=498.6 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 02340234)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.8 GB) - (Type=OF Extended)

==================== End of log ============================
         
--- --- ---
__________________

Geändert von Shnoxxer (25.06.2015 um 17:08 Uhr)

Alt 25.06.2015, 17:09   #4
Shnoxxer
 
Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Gmer:
Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-06-25 15:58:29
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 WDC_WD7500AACS-00D6B1 rev.01.01A01 698,64GB
Running: oxdekkrd.exe; Driver: C:\Users\SH\AppData\Local\Temp\pxldypoc.sys


---- User code sections - GMER 2.1 ----

.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                         0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                           0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                         0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                         0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                  * 9
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                            0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                     0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                            0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                     0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                           0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                         0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                           0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                              0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                           0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                         0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                     0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                     0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\Explorer.EXE[1464] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                           00000000779b1870 5 bytes JMP 00000001379a00d8
.text    C:\Windows\Explorer.EXE[1464] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                 0000000077a2f500 8 bytes JMP 00000001379a0110
.text    C:\Windows\Explorer.EXE[1464] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                         000007fefdf47490 11 bytes JMP 000007ffbdf300d8
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17      0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17        0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17      0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42      0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                  * 9
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17         0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17  0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17         0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17  0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17        0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17             0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17      0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17        0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17           0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17        0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17      0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20  0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1800] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31  0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                           0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                             0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                           0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                           0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                  * 9
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                              0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                       0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                              0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                       0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                             0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                  0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                           0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                             0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                             0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                           0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                       0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                       0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                  0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                    0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                  0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                  0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                  * 9
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                     0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17              0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                     0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17              0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                    0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                         0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                  0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                    0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                       0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                    0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                  0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20              0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31              0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\SysWOW64\ntdll.dll!KiUserExceptionDispatcher                                                       0000000077db0154 5 bytes JMP 0000000175448710
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                      0000000077ddaf7d 5 bytes JMP 0000000175444f00
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\SysWOW64\ntdll.dll!RtlExitUserThread                                                               0000000077df69ec 5 bytes JMP 00000001754450e0
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!WriteFile                                                                    0000000077401282 5 bytes JMP 0000000175444f60
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!FreeLibrary                                                                  0000000077403478 5 bytes JMP 0000000175445330
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!VirtualProtect                                                               0000000077404317 5 bytes JMP 0000000175444fc0
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!LoadLibraryExA                                                               00000000774048cb 5 bytes JMP 0000000175445040
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!LoadLibraryW                                                                 00000000774048e3 5 bytes JMP 0000000175445000
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!LoadLibraryExW                                                               0000000077404915 5 bytes JMP 0000000175445020
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!LoadLibraryA                                                                 000000007740498f 5 bytes JMP 0000000175445060
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!CreateFileA                                                                  000000007740537e 5 bytes JMP 0000000175445160
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!GlobalAlloc                                                                  0000000077405846 5 bytes JMP 0000000175445080
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!ExitProcess                                                                  00000000774079c8 5 bytes JMP 0000000175445100
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalA                                                       000000007741a48f 5 bytes JMP 0000000175445120
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!WriteProcessMemory                                                           000000007741d9b0 5 bytes JMP 0000000175444f20
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!GetThreadContext                                                             000000007742799c 1 byte JMP 00000001754450a0
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!GetThreadContext + 2                                                         000000007742799e 3 bytes {CALL RSI}
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!VirtualProtectEx                                                             0000000077484b5f 5 bytes JMP 0000000175444fa0
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!WriteFileEx                                                                  0000000077484b8f 5 bytes JMP 0000000175444f40
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\kernel32.dll!SetThreadContext                                                             0000000077485933 5 bytes JMP 0000000175444fe0
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                       0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                         0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                       0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                       0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                  * 9
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                          0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                   0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                          0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                   0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                         0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                              0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                       0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                         0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                            0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                         0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                       0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                   0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                   0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17            0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17              0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17            0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42            0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                  * 9
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17               0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17        0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17               0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17        0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17              0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                   0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17            0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17              0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                 0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17              0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17            0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20        0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2756] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31        0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17       0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17         0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17       0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42       0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                  * 9
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17          0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17   0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17          0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17   0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17         0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17              0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17       0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17         0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17            0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17         0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17       0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20   0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2872] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31   0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17              0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17              0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42              0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                  * 9
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                 0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17          0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                 0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17          0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                     0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17              0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                   0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17              0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20          0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31          0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                               0000000075e31401 2 bytes JMP 7742b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                 0000000075e31419 2 bytes JMP 7742b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                               0000000075e31431 2 bytes JMP 774a8f29 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                               0000000075e3144a 2 bytes CALL 7740489d C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                  * 9
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                  0000000075e314dd 2 bytes JMP 774a8822 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                           0000000075e314f5 2 bytes JMP 774a89f8 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                  0000000075e3150d 2 bytes JMP 774a8718 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                           0000000075e31525 2 bytes JMP 774a8ae2 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                 0000000075e3153d 2 bytes JMP 7741fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                      0000000075e31555 2 bytes JMP 774268ef C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                               0000000075e3156d 2 bytes JMP 774a8fe3 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                 0000000075e31585 2 bytes JMP 774a8b42 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                    0000000075e3159d 2 bytes JMP 774a86dc C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                 0000000075e315b5 2 bytes JMP 7741fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                               0000000075e315cd 2 bytes JMP 7742b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                           0000000075e316b2 2 bytes JMP 774a8ea4 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\SH\Desktop\trojaner\oxdekkrd.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                           0000000075e316bd 2 bytes JMP 774a8671 C:\Windows\syswow64\kernel32.dll

---- Threads - GMER 2.1 ----

Thread   C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3876]                                                                          000007fef5284094
Thread   C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3880]                                                                          000007fef376f5f8
Thread   C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3884]                                                                          000007fef5284094
Thread   C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3888]                                                                          000007fef398bc60
Thread   C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3116:3892]                                                                          000007fef5284094
Thread   C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [3128:3484]                                                                           000007fef398bc60
Thread   C:\Windows\System32\svchost.exe [5204:5348]                                                                                                          000007fee3669688
---- Processes - GMER 2.1 ----

Library  C:\Users\SH\AppData\Local\Temp\mdi564.dll (*** suspicious ***) @ C:\Windows\SysWOW64\rundll32.exe [2584](2015-06-24 17:25:18)                        00000000745a0000

---- Registry - GMER 2.1 ----

Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                     
Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                                  F:\Programme\DAEMON Tools Lite\
Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                  0x00 0x00 0x00 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                  0
Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                               0x77 0x3D 0x06 0x69 ...
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                                                 
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                                      F:\Programme\DAEMON Tools Lite\
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                      0x00 0x00 0x00 0x00 ...
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                      0
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                   0x77 0x3D 0x06 0x69 ...

---- EOF - GMER 2.1 ----
         

Alt 26.06.2015, 07:50   #5
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 26.06.2015, 09:08   #6
Shnoxxer
 
Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Hi Schrauber,
hier die ComboFix.txt:
Code:
ATTFilter
ComboFix 15-06-24.02 - SH 26.06.2015   9:33.1.4 - x64
Microsoft Windows 7 Professional N   6.1.7601.1.1252.49.1031.18.4095.1994 [GMT 2:00]
ausgeführt von:: c:\users\SH\Desktop\trojaner\ComboFix.exe
AV: Sophos Anti-Virus *Disabled/Updated* {6BABF8F7-3EB6-BD1D-9167-8C5ECA060A29}
SP: Sophos Anti-Virus *Disabled/Updated* {D0CA1913-188C-B293-ABD7-B72CB1814094}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ar\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\bg\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ca\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\cs\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\da\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\de\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\el\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\en\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\es\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\fi\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\fr\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\gu\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\he\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\hr\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\hu\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\id\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\it\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ja\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\nb\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\nl\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\pl\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\pt_BR\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\pt_PT\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ro\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\ru\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\sk\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\sl\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\sr\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\sv\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\te\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\tr\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\uk\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\vi\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\zh_CN\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_locales\zh_TW\messages.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_metadata\computed_hashes.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\_metadata\verified_contents.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\adblock_start_chrome.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\adblock_start_common.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\background.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\bandaids.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\popup.css
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\popup.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\popup.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\search\search.css
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\button\search\search.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\CHANGELOG.txt
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\checkupdates.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\chrome_oauth_receiver.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\chrome_oauth_receiver.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\dropbox-datastores.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\domainset.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\filternormalizer.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\filteroptions.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\filterset.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\filtertypes.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\filtering\myfilters.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\functions.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\gab_question.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\idlehandler.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\delete.gif
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\dropbox1.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\dropbox2.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\dropbox3.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\facebook-sprite.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\gifloader.gif
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\gplus-sprite.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon128.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon16.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon16_grayscale.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon16_grayscale@2x.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon19-grayscale.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon19-whitelisted.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon19.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon24.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon32.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon38-grayscale.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon38-whitelisted.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon38.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\icon48.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\logo.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\check.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\magnifying_glass.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\search-engine-card_no-shadow.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\search-engine-icons.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\search-omnibox-card_no-shadow.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\search\search_engine_select_arrow.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\img\twitter-sprite.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_flat_55_999999_40x100.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_flat_75_aaaaaa_40x100.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_glass_45_0078ae_1x400.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_glass_55_f8da4e_1x400.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_glass_75_79c9ec_1x400.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_gloss-wave_50_38cfff_500x100.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_gloss-wave_75_2191c0_500x100.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-bg_inset-hard_100_fcfdfd_1x100.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-icons_056b93_256x240.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\images\ui-icons_d8e7f3_256x240.png
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\jquery-ui.custom.css
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\css\override-page.css
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\jquery-ui.custom.min.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\jquery.cookie.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\jquery\jquery.min.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\LICENSE
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\manifest.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\notificationoverlay.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\customize.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\customize.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\filters.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\filters.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\general.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\general.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\index.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\index.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\options.css
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\support.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\options\support.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\adreport.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\adreport.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\resourceblock.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\resourceblock.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\subscribe.html
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\pages\subscribe.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\port.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\punycode.min.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\README.markdown
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\focus.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\incognito.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\pitchpage.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\search-plus-one.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\secure_reminder.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\search\serp.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\stats.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\survey.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\translators.json
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\blacklistui.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\clickwatcher.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\elementchain.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\overlay.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\blacklisting\rightclick_hook.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\load_jquery_ui.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\send_content_to_back.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\top_open_blacklist_ui.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\uiscripts\top_open_whitelist_ui.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.35_0\ytchannel.js
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gighmmpiobklfepjocnamgkkbiglidom_0.localstorage-journal
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gighmmpiobklfepjocnamgkkbiglidom_0.localstorage
c:\users\SH\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\windows\apppatch\AppLoc.exe
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\IsUn0407.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2015-05-26 bis 2015-06-26  ))))))))))))))))))))))))))))))
.
.
2015-06-26 07:45 . 2015-06-26 07:45	--------	d-----w-	c:\users\Default\AppData\Local\temp
2015-06-25 13:18 . 2015-06-25 13:21	--------	d-----w-	C:\FRST
2015-06-24 22:58 . 2015-05-03 03:16	12214312	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D2943C8-C5E7-4706-A20F-F8D36E1A2BA9}\mpengine.dll
2015-06-24 14:13 . 2015-06-24 14:13	--------	d-----w-	c:\users\SH\AppData\Local\Licenses
2015-06-24 13:43 . 2015-06-24 13:43	--------	d-----w-	c:\programdata\TriDef 3D
2015-06-24 13:41 . 2015-06-24 13:41	--------	d-----w-	c:\programdata\DDD
2015-06-17 19:39 . 2015-06-17 19:39	--------	d-----w-	c:\users\SH\AppData\Local\roomeon
2015-06-17 19:28 . 2015-06-17 19:38	--------	d-----w-	c:\users\SH\AppData\Local\Room Arranger
2015-06-16 14:19 . 2015-06-16 14:19	--------	d-sh--w-	c:\users\SH\AppData\Local\EmieBrowserModeList
2015-06-14 11:54 . 2015-06-14 11:54	--------	d-----w-	c:\users\SH\AppData\Roaming\Red Alert 3 Uprising
2015-06-13 12:45 . 2015-06-13 12:45	--------	d-----w-	c:\users\SH\AppData\Roaming\Red Alert 3
2015-06-13 12:06 . 2015-06-13 12:36	--------	d-----w-	c:\users\SH\AppData\Roaming\Nidhogg
2015-06-11 13:27 . 2015-05-23 03:15	47616	----a-w-	c:\windows\SysWow64\ieetwproxystub.dll
2015-06-02 18:16 . 2015-06-02 18:16	--------	d-----w-	c:\users\SH\AppData\Local\PDF24
2015-06-01 18:27 . 2015-06-01 18:27	--------	d-----w-	c:\users\SH\AppData\Local\GWX
2015-05-28 20:58 . 2015-05-01 13:17	124112	----a-w-	c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-28 20:58 . 2015-05-01 13:16	102608	----a-w-	c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-06-24 09:35 . 2014-03-08 14:32	778416	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2015-06-24 09:35 . 2014-03-08 14:32	142512	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-06-19 02:19 . 2013-01-24 17:47	140135120	----a-w-	c:\windows\system32\MRT.exe
2015-05-25 18:01 . 2015-06-11 13:28	44032	----a-w-	c:\windows\apppatch\acwow64.dll
2015-04-20 15:46 . 2015-04-20 15:46	11152	----a-w-	c:\windows\SysWow64\vpncategories.dll
2015-04-20 15:46 . 2015-04-20 15:46	34192	----a-w-	c:\windows\SysWow64\vpnevents.dll
2015-04-20 15:25 . 2015-04-20 15:25	112496	----a-r-	c:\windows\system32\drivers\acsock64.sys
2015-04-20 03:17 . 2015-05-14 17:49	1179136	----a-w-	c:\windows\system32\FntCache.dll
2015-04-20 03:17 . 2015-05-14 17:49	1647104	----a-w-	c:\windows\system32\DWrite.dll
2015-04-20 02:56 . 2015-05-14 17:49	1250816	----a-w-	c:\windows\SysWow64\DWrite.dll
2015-04-18 03:10 . 2015-05-14 17:51	460800	----a-w-	c:\windows\system32\certcli.dll
2015-04-18 02:56 . 2015-05-14 17:51	342016	----a-w-	c:\windows\SysWow64\certcli.dll
2015-04-13 03:28 . 2015-05-14 17:50	328704	----a-w-	c:\windows\system32\services.exe
2015-04-08 03:29 . 2015-05-14 17:49	275456	----a-w-	c:\windows\system32\InkEd.dll
2015-04-08 03:14 . 2015-05-14 17:49	216064	----a-w-	c:\windows\SysWow64\InkEd.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"Remote Mouse"="c:\program files (x86)\Remote Mouse\RemoteMouse.exe" [2015-01-23 2050048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2010-12-13 135536]
"ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176]
"Raptr"="c:\program files (x86)\Raptr\raptrstub.exe" [2015-05-15 55568]
"Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2015-03-04 1593640]
"Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2015-04-20 708496]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [x]
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys;c:\windows\SYSNATIVE\DRIVERS\acsock64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv_x64.sys [x]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x]
R3 Media Jukebox 14 Service;Media Jukebox 14 Service;f:\programme\Media Jukebox 14\JRService.exe;f:\programme\Media Jukebox 14\JRService.exe [x]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys;c:\windows\SYSNATIVE\Drivers\nx6000.sys [x]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 ptun0901;TAP Adapter V9 for Private Tunnel;c:\windows\system32\DRIVERS\ptun0901.sys;c:\windows\SYSNATIVE\DRIVERS\ptun0901.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 rzdaendpt;Razer DeathAdder end point;c:\windows\system32\DRIVERS\rzdaendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzdaendpt.sys [x]
R3 rzvkeyboard;Razer Virtual Keyboard Driver;c:\windows\system32\DRIVERS\rzvkeyboard.sys;c:\windows\SYSNATIVE\DRIVERS\rzvkeyboard.sys [x]
R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys;c:\windows\SYSNATIVE\DRIVERS\sdcfilter.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys;c:\windows\SYSNATIVE\DRIVERS\SophosBootDriver.sys [x]
R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys;c:\windows\SYSNATIVE\DRIVERS\savonaccess.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 SAVAdminService;Sophos Anti-Virus Statusreporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [x]
S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [x]
S2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [x]
S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [x]
S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 rzudd;Razer Mouse Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-06-24 09:07	990024	----a-w-	c:\program files (x86)\Google\Chrome\Application\43.0.2357.130\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-06-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-08 09:35]
.
2015-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24 17:04]
.
2015-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24 17:04]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
"PrnStatusMX"="c:\program files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe" [2012-07-04 1240064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Nach Microsoft E&xel exportieren - f:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{c0e8ae32-0758-4c8d-ab71-23b361fe8964} - c:\users\SH\AppData\Local\Temp\ie_script.htm
LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll
TCP: DhcpNameServer = 192.168.192.1
FF - ProfilePath - c:\users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\
FF - prefs.js: network.proxy.type - 2
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Clonk Planet - c:\windows\system32\GKSUI18.EXE
AddRemove-Need For Speed - Porsche - c:\windows\IsUn0407.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2306031424-1336655547-1434631041-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:9f,aa,dc,d5,97,0e,4b,6b,74,45,42,f2,75,22,5c,1a,6c,2e,21,82,6c,9d,50,
   bf,4c,23,1f,ea,59,ac,db,f5,b4,58,d2,d2,f4,c1,07,7b,16,88,11,ab,6e,d1,9f,5c,\
"??"=hex:72,09,6e,72,ba,1a,c1,28,d1,6a,51,39,96,6d,8f,e5
.
[HKEY_USERS\S-1-5-21-2306031424-1336655547-1434631041-1000\Software\SecuROM\License information*]
"datasecu"=hex:04,fb,ba,c2,de,95,59,48,51,15,86,18,94,2a,cc,e5,28,6b,0b,f4,dc,
   83,99,cc,bc,22,8a,dd,0f,36,be,94,ba,88,74,ed,c9,95,c1,23,9f,bf,23,ca,0b,f8,\
"rkeysecu"=hex:a4,99,ff,e7,14,53,f3,ea,b3,b7,3d,e8,61,fa,cf,60
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2015-06-26  09:58:11
ComboFix-quarantined-files.txt  2015-06-26 07:58
.
Vor Suchlauf: 11 Verzeichnis(se), 113.138.089.984 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 117.132.058.624 Bytes frei
.
- - End Of File - - FE983C4156C6ADA204BB3F836CCFC845
A36C5E4F47E84449FF07ED3517B43A31
         

Alt 27.06.2015, 08:08   #7
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 27.06.2015, 12:30   #8
Shnoxxer
 
Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Hi Schrauber,
hier die Logfiles. Bei dem mbam Scan ist mein Sophos angesprungen und hat folgendes gemeckert:
Code:
ATTFilter
****************** Sophos Anti-Virus Protokoll - 27.06.2015 11:24:30 **************

    ...
20150627 091205	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091205	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150627 091207	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091207	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150627 091208	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091208	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150627 091210	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091210	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150627 091212	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091212	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150627 091213	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091213	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150627 091215	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091215	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150627 091217	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091217	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150627 091218	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091218	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
20150627 091220	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150627 091220	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
    ...
      (20 Objekte)
         
MBAM:
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 27.06.2015
Suchlauf-Zeit: 10:59:31
Logdatei: mbam.txt
Administrator: Ja

Version: 2.01.6.1022
Malware Datenbank: v2015.06.26.08
Rootkit Datenbank: v2015.06.26.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: SH

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 387792
Verstrichene Zeit: 17 Min, 1 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente gefunden)

Module: 0
(Keine schädliche Elemente gefunden)

Registrierungsschlüssel: 1
PUP.Optional.ICQ.A, HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}, In Quarantäne, [341ca41b6e1c3006e71bf09d46bf3ec2], 

Registrierungswerte: 3
PUP.Optional.ICQ.A, HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}|DisplayName, Search@Icq.Com, In Quarantäne, [341ca41b6e1c3006e71bf09d46bf3ec2]
PUP.Optional.ICQ.A, HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}|URL, hxxp://search.icq.com/search/results.php?q=%s&ch_id=hm&search_mode=web, In Quarantäne, [53fda41bd5b573c335cdcfbe36cfc23e]
PUP.Optional.ICQ.A, HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}|FaviconURLFallback, hxxp://search.icq.com/favicon.ico, In Quarantäne, [153bd6e94842cd69986ab0dd07fe768a]

Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)

Ordner: 0
(Keine schädliche Elemente gefunden)

Dateien: 0
(Keine schädliche Elemente gefunden)

Physische Sektoren: 0
(Keine schädliche Elemente gefunden)


(end)
         
ADWCleaner:
Code:
ATTFilter
# AdwCleaner v4.207 - Bericht erstellt 27/06/2015 um 11:30:42
# Aktualisiert 21/06/2015 von Xplode
# Datenbank : 2015-06-23.1 [Server]
# Betriebssystem : Windows 7 Professional N Service Pack 1 (x64)
# Benutzername : SH - SH-PC
# Gestarted von : C:\Users\SH\Desktop\trojaner\AdwCleaner_4.207.exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : mcaudrv_simple
[#] Dienst Gelöscht : ManyCam

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Users\SH\AppData\Local\Hola
Datei Gelöscht : C:\Windows\System32\drivers\mcaudrv_x64.sys
Datei Gelöscht : C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\invalidprefs.js
Datei Gelöscht : C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
Datei Gelöscht : C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal

***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C43F0D7D-78F0-47B8-954C-8FB36960B785}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C43F0D7D-78F0-47B8-954C-8FB36960B785}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar

***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Mozilla Firefox v37.0.2 (x86 de)


-\\ Google Chrome v43.0.2357.130


*************************

AdwCleaner[R0].txt - [2815 Bytes] - [27/06/2015 11:29:28]
AdwCleaner[S0].txt - [2534 Bytes] - [27/06/2015 11:30:42]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2593  Bytes] ##########
         
JRT:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.1.8 (06.27.2015:1)
OS: Windows 7 Professional N x64
Ran by SH on 27.06.2015 at 11:40:33,72
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\Users\SH\appdata\local\google\chrome\user data\default\local storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage
Successfully deleted: [File] C:\Users\SH\appdata\local\google\chrome\user data\default\local storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage-journal



~~~ Folders



~~~ Chrome

Successfully deleted: [Folder] C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio

[C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\SH\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  bopakagnckmlgajfccecajhnimjiiedh,
  gkojfkhlekighikafcpjkiklfbnlmeio
]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.06.2015 at 11:44:15,56
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
FRST:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015
Ran by SH (administrator) on SH-PC on 27-06-2015 12:38:12
Running from C:\Users\SH\Desktop\trojaner
Loaded Profiles: SH (Available Profiles: SH)
Platform: Windows 7 Professional N Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1240064 2012-07-04] (Marvell Semiconductor, Inc.)
HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1593640 2015-03-04] (Sophos Limited)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-04-20] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation)
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [Remote Mouse] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe [2050048 2015-01-23] (RemoteMouse.net)
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll [217672 2015-01-14] (Sophos Limited)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured.dll => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll [275352 2015-01-14] (Sophos Limited)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-26] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-26] (Oracle Corporation)
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.192.1

FireFox:
========
FF ProfilePath: C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-24] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-24] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> F:\Programme\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> F:\Programme\DivX\DivX Web Player\npdivx32.dll [2014-02-18] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-26] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> F:\Programme\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: @hola.org/vlc,version=1.8.369 -> C:\Users\SH\AppData\Local\Hola\firefox\app\vlc No File
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\SH\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.)
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: sony.com/MediaGoDetector -> F:\Programme\Media Go\npMediaGoDetector.dll [2013-08-22] (Sony Network Entertainment International LLC)
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-04-23] (Ubisoft)
FF Extension: Hola Better Internet - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack [2015-05-27]
FF Extension: WOT - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-05-30]
FF Extension: ZenMate Security & Privacy VPN - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\firefox@zenmate.com.xpi [2015-05-07]
FF Extension: flv movies downloader - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\flvmoviesdownloader@rzll.xpi [2013-10-17]
FF Extension: Media Hint - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\mediahint@jetpack.xpi [2014-03-13]
FF Extension: Adblock Plus - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-25]
StartMenuInternet: FIREFOX.EXE - F:\Programme\Mozilla Firefox\firefox.exe

Chrome: 
=======
CHR Profile: C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-27]
CHR Extension: (Google Drive) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-27]
CHR Extension: (WOT) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-06-22]
CHR Extension: (YouTube) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-27]
CHR Extension: (Adblock Plus) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-27]
CHR Extension: (Google Search) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-27]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-11-04]
CHR Extension: (Math Anywhere) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebhifiddmaaeecbaiemfpejghjdjmhc [2015-03-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Wallet) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Enhanced Steam) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2014-06-20]
CHR Extension: (Gmail) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-27]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 ForceWare Intelligent Application Manager (IAM); F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] ()
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 Media Jukebox 14 Service; F:\Programme\Media Jukebox 14\JRService.exe [379400 2010-07-15] (J. River, Inc.)
S2 nSvcIp; F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] ()
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [288552 2014-05-23] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [208168 2014-10-14] (Sophos Limited)
S2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [340776 2015-03-04] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [341800 2014-10-14] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3274536 2015-01-14] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2065704 2015-01-14] (Sophos Limited)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
S3 NVENETFD; C:\Windows\System32\DRIVERS\nvm60x64.sys [742696 2009-06-10] (NVIDIA Corporation)
S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project)
S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [25600 2013-04-19] (Razer USA Ltd) [File not signed]
S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [23040 2013-04-19] (Razer USA Ltd) [File not signed]
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [158976 2014-05-23] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2014-05-23] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [27904 2014-05-23] (Sophos Limited)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-01-24] (Duplex Secure Ltd.)
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] ()
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-13] (Anchorfree Inc.)
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-27 11:44 - 2015-06-27 11:44 - 00001603 _____ C:\Users\SH\Desktop\JRT.txt
2015-06-27 11:40 - 2015-06-27 11:40 - 00000207 _____ C:\Windows\tweaking.com-regbackup-SH-PC-Windows-7-Professional-N-(64-bit).dat
2015-06-27 11:40 - 2015-06-27 11:40 - 00000000 ____D C:\RegBackup
2015-06-27 11:29 - 2015-06-27 11:31 - 00000000 ____D C:\AdwCleaner
2015-06-27 10:56 - 2015-06-27 10:56 - 00001106 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-06-26 14:53 - 2015-06-26 14:54 - 00561248 _____ (Oracle Corporation) C:\Users\SH\Downloads\jxpiinstall.exe
2015-06-26 14:35 - 2015-06-26 14:36 - 00000000 ____D C:\Users\SH\Downloads\Hola
2015-06-26 09:31 - 2015-06-26 09:59 - 00000000 ____D C:\Qoobox
2015-06-26 09:31 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2015-06-26 09:31 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2015-06-26 09:31 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2015-06-26 09:30 - 2015-06-26 09:54 - 00000000 ____D C:\Windows\erdnt
2015-06-25 16:31 - 2015-06-25 16:31 - 01182149 _____ C:\Users\SH\Downloads\7z936.exe
2015-06-25 16:31 - 2015-06-25 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-06-25 15:18 - 2015-06-27 12:38 - 00000000 ____D C:\FRST
2015-06-25 15:13 - 2015-06-25 15:13 - 00000020 _____ C:\Users\SH\defogger_reenable
2015-06-25 15:11 - 2015-06-27 11:36 - 00000000 ____D C:\Users\SH\Desktop\trojaner
2015-06-24 19:50 - 2015-06-24 19:50 - 00002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2015-06-24 18:01 - 2015-06-24 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disney Interactive Studios
2015-06-24 16:13 - 2015-06-24 16:13 - 00000000 ____D C:\Users\SH\AppData\Local\Licenses
2015-06-24 15:43 - 2015-06-24 15:43 - 00001112 _____ C:\Users\Public\Desktop\TriDef 3D.lnk
2015-06-24 15:43 - 2015-06-24 15:43 - 00000000 ____D C:\ProgramData\TriDef 3D
2015-06-24 15:42 - 2015-06-24 15:43 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef
2015-06-24 15:41 - 2015-06-24 15:41 - 00000000 ____D C:\ProgramData\DDD
2015-06-17 21:39 - 2015-06-17 21:39 - 00001684 _____ C:\Users\Public\Desktop\roomeon Portal.lnk
2015-06-17 21:39 - 2015-06-17 21:39 - 00001661 _____ C:\Users\Public\Desktop\roomeon 3D-Planer.lnk
2015-06-17 21:39 - 2015-06-17 21:39 - 00000000 ____D C:\Users\SH\AppData\Local\roomeon
2015-06-17 21:28 - 2015-06-17 21:38 - 00000000 ____D C:\Users\SH\AppData\Local\Room Arranger
2015-06-16 16:19 - 2015-06-16 16:19 - 00000000 __SHD C:\Users\SH\AppData\Local\EmieBrowserModeList
2015-06-14 13:54 - 2015-06-14 13:54 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3 Uprising
2015-06-13 14:45 - 2015-06-13 14:45 - 00000040 _____ C:\ProgramData\ra3.ini
2015-06-13 14:45 - 2015-06-13 14:45 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3
2015-06-13 14:06 - 2015-06-13 14:36 - 00000000 ____D C:\Users\SH\AppData\Roaming\Nidhogg
2015-06-13 13:52 - 2015-06-13 13:52 - 00000208 _____ C:\Users\SH\Desktop\Nidhogg.url
2015-06-13 13:36 - 2015-06-13 13:36 - 00000208 _____ C:\Users\SH\Desktop\Command and Conquer Red Alert 3 - Uprising.url
2015-06-13 11:13 - 2015-06-13 11:13 - 00000209 _____ C:\Users\SH\Desktop\Salt Demo.url
2015-06-12 11:08 - 2015-06-12 11:08 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-11 15:28 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-11 15:28 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-11 15:28 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-11 15:28 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-11 15:28 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-11 15:28 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-06-11 15:28 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-06-11 15:28 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-06-11 15:28 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-06-11 15:28 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-06-11 15:28 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-06-11 15:28 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-06-11 15:28 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-06-11 15:28 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-06-11 15:28 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-11 15:28 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-11 15:28 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-06-11 15:28 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-06-11 15:28 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-11 15:28 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-11 15:28 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-11 15:28 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-11 15:28 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-11 15:28 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-11 15:28 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-06-11 15:28 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-06-11 15:28 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-06-11 15:28 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-11 15:28 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-11 15:28 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-11 15:27 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-11 15:27 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-11 15:27 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-11 15:27 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-11 15:27 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-06-11 15:27 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-11 15:27 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-06-11 15:27 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-06-11 15:27 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-11 15:27 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-06-11 15:27 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-11 15:27 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-06-11 15:27 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-06-11 15:27 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-06-11 15:27 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-11 15:27 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-06-11 15:27 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-11 15:27 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-06-11 15:27 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-06-11 15:27 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-06-11 15:27 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-11 15:27 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-11 15:27 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-11 15:27 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-11 15:27 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-11 15:27 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-06-11 15:27 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-11 15:27 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-11 15:27 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-11 15:27 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-11 15:27 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-11 15:27 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-11 15:27 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-11 15:27 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-11 15:27 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-11 15:27 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-11 15:27 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-11 15:27 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-11 15:27 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-11 15:27 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-11 15:27 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-11 15:27 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-11 15:27 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-11 15:27 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-11 15:27 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-11 15:27 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-11 15:27 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-11 15:27 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-11 15:27 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-11 15:27 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-11 15:27 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-11 15:27 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-11 15:27 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-11 15:27 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-11 15:27 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-11 15:27 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-11 15:27 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-11 15:27 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-11 15:27 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-11 15:27 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-02 20:16 - 2015-06-02 20:16 - 00000000 ____D C:\Users\SH\AppData\Local\PDF24
2015-06-01 20:27 - 2015-06-01 20:27 - 00000000 ____D C:\Users\SH\AppData\Local\GWX
2015-05-28 22:58 - 2015-05-01 15:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-28 22:58 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-28 19:09 - 2015-05-28 19:09 - 00000000 ____D C:\Users\SH\Documents\Criterion Games

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-27 12:35 - 2014-03-08 16:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-27 12:06 - 2013-01-24 19:04 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-27 11:47 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-27 11:47 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-27 11:42 - 2013-01-24 18:29 - 01143461 _____ C:\Windows\WindowsUpdate.log
2015-06-27 11:39 - 2014-07-29 12:52 - 00000000 ____D C:\Users\SH\AppData\Roaming\Raptr
2015-06-27 11:39 - 2013-01-24 19:04 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-27 11:39 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-27 11:39 - 2009-07-14 06:56 - 00122331 _____ C:\Windows\setupact.log
2015-06-27 10:57 - 2014-06-11 17:42 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-27 10:56 - 2014-06-11 17:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-06-27 10:56 - 2014-06-11 17:42 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-06-26 14:57 - 2013-10-16 16:00 - 00000000 ____D C:\ProgramData\Oracle
2015-06-26 14:55 - 2014-10-17 13:16 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-26 14:55 - 2013-02-26 01:25 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-26 12:56 - 2013-06-03 12:01 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9941B8CD-7D1F-464E-A428-95CA8D62A133}
2015-06-26 10:05 - 2010-11-21 05:47 - 00228934 _____ C:\Windows\PFRO.log
2015-06-26 09:46 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2015-06-26 09:38 - 2013-06-24 13:25 - 00000000 ____D C:\ProgramData\Temp
2015-06-25 23:50 - 2015-05-06 10:39 - 00007602 _____ C:\Users\SH\AppData\Local\Resmon.ResmonCfg
2015-06-25 15:56 - 2014-08-28 11:32 - 00000000 ____D C:\Users\SH\AppData\Local\CrashDumps
2015-06-25 15:13 - 2013-01-24 19:01 - 00000000 ____D C:\Users\SH
2015-06-25 14:26 - 2013-01-26 10:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-06-25 14:24 - 2014-06-22 17:18 - 00000000 ____D C:\Users\SH\AppData\Local\LOOT
2015-06-25 14:20 - 2013-05-24 12:06 - 00000000 ___RD C:\Users\SH\Desktop\Spiele
2015-06-25 13:10 - 2011-04-12 10:14 - 00713958 _____ C:\Windows\system32\perfh007.dat
2015-06-25 13:10 - 2011-04-12 10:14 - 00154074 _____ C:\Windows\system32\perfc007.dat
2015-06-25 13:10 - 2009-07-14 07:12 - 01648656 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-25 12:43 - 2014-01-22 13:51 - 00000000 ____D C:\Users\SH\AppData\Local\Battle.net
2015-06-24 21:10 - 2009-07-14 07:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-06-24 20:57 - 2014-04-04 17:16 - 00001048 _____ C:\Windows\Xbox_360_CC_Driver.log
2015-06-24 20:53 - 2013-05-23 13:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Byte
2015-06-24 19:51 - 2013-01-25 13:08 - 00000000 ____D C:\ProgramData\Sophos
2015-06-24 19:50 - 2014-05-23 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-06-24 19:50 - 2013-01-25 13:08 - 00000000 ____D C:\Program Files (x86)\Sophos
2015-06-24 18:50 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-06-24 17:08 - 2013-01-30 00:09 - 00649191 _____ C:\Windows\DirectX.log
2015-06-24 14:19 - 2015-01-10 16:37 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-24 11:35 - 2014-03-08 16:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-24 11:35 - 2014-03-08 16:32 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-24 11:35 - 2014-03-08 16:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-06-21 14:19 - 2013-01-30 09:33 - 00000000 ____D C:\Users\SH\AppData\Roaming\vlc
2015-06-19 10:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-06-19 09:17 - 2009-07-14 06:50 - 00320184 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-19 09:15 - 2015-04-21 10:42 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-19 09:15 - 2014-05-19 12:34 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-19 09:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-19 04:26 - 2013-02-25 13:03 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-19 04:25 - 2013-07-12 23:23 - 00000000 ____D C:\Windows\system32\MRT
2015-06-19 04:19 - 2013-01-24 19:47 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-17 21:38 - 2013-07-08 17:10 - 00000000 ____D C:\Users\SH\AppData\Local\Downloaded Installations
2015-06-16 16:18 - 2015-05-05 10:24 - 00000000 ____D C:\Users\SH\Desktop\SS 15
2015-06-12 11:08 - 2013-01-24 19:04 - 00000000 ____D C:\Program Files (x86)\Google
2015-06-02 11:26 - 2013-01-24 19:04 - 00066648 _____ C:\Users\SH\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\system32\GWX
2015-05-29 16:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-05-28 22:58 - 2013-01-30 00:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight

==================== Files in the root of some directories =======

2015-01-28 13:58 - 2015-01-28 13:59 - 0009918 _____ () C:\Users\SH\AppData\Local\CleanupUninstall.txt
2013-06-04 22:44 - 2013-06-04 22:44 - 0003072 _____ () C:\Users\SH\AppData\Local\file__0.localstorage
2015-05-06 10:39 - 2015-06-25 23:50 - 0007602 _____ () C:\Users\SH\AppData\Local\Resmon.ResmonCfg
2013-01-29 16:21 - 2013-01-29 16:21 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt
2015-06-13 14:45 - 2015-06-13 14:45 - 0000040 _____ () C:\ProgramData\ra3.ini

Some files in TEMP:
====================
C:\Users\SH\AppData\Local\Temp\Quarantine.exe
C:\Users\SH\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-24 11:43

==================== End of log ============================
         

Alt 27.06.2015, 18:17   #9
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 28.06.2015, 09:02   #10
Shnoxxer
 
Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Hier erst mal das ESET log:
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=3271ad63bd383b40abb7f60df9343f7c
# end=init
# utc_time=2015-06-27 06:57:07
# local_time=2015-06-27 08:57:07 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 24533
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=3271ad63bd383b40abb7f60df9343f7c
# end=updated
# utc_time=2015-06-27 06:59:54
# local_time=2015-06-27 08:59:54 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=3271ad63bd383b40abb7f60df9343f7c
# engine=24533
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-06-28 12:01:00
# local_time=2015-06-28 02:01:00 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 119200 187079510 0 0
# compatibility_mode_1='Sophos Anti-Virus'
# compatibility_mode=8450 16777213 100 99 19021 57780026 0 0
# scanned=447007
# found=9
# cleaned=0
# scan_time=18065
sh=E906BF646AE3EAE31BBA483A770364E8D5D95ADE ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2013-07-14 190009\Backup Files 2013-07-14 190009\Backup files 6.zip"
sh=3ECE64CC0AEEBABFA5E0E1E412FC4E2F917B6B7D ft=0 fh=0000000000000000 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2013-07-14 190009\Backup Files 2013-08-11 190010\Backup files 2.zip"
sh=FA64EA3EB9598ACA35E9F7049D2DEA798AFD59D2 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2013-10-13 190010\Backup Files 2013-10-13 190010\Backup files 8.zip"
sh=B6143294396222C5ACC5785CCF72AF04821D8A5B ft=0 fh=0000000000000000 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2013-10-13 190010\Backup Files 2013-10-13 190010\Backup files 9.zip"
sh=F8413082A82FB81B681D8B1472DD376CC38BD4B1 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2014-02-03 100450\Backup Files 2014-02-03 100450\Backup files 9.zip"
sh=1BB75391FEAF0CCADED36DC7768CE1E83F139364 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2014-08-31 190002\Backup Files 2014-08-31 190002\Backup files 13.zip"
sh=5A44C6087A3C06E0F91A822709A3692080C9D94D ft=0 fh=0000000000000000 vn="Variante von Win32/WinloadSDA.I evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2014-08-31 190002\Backup Files 2014-10-26 190011\Backup files 4.zip"
sh=C5089EC9E5E09986B532113E387869602DC85369 ft=0 fh=0000000000000000 vn="Variante von Win32/WinloadSDA.I evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2015-05-31 190010\Backup Files 2015-05-31 190010\Backup files 17.zip"
sh=7B8D9CCBE43CA26C1DAADF1E16F9BFC7AD49CB17 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\SH-PC\Backup Set 2015-05-31 190010\Backup Files 2015-05-31 190010\Backup files 18.zip"
         
SecurityCheck:
Code:
ATTFilter
 Results of screen317's Security Check version 1.004  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Sophos Anti-Virus   
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 Java 8 Update 45  
  Adobe Flash Player 17.0.0.190 Flash Player out of Date!  
 Adobe Reader XI  
 Mozilla Firefox 37.0.2 Firefox out of Date!  
 Google Chrome (43.0.2357.124) 
 Google Chrome (43.0.2357.130) 
````````Process Check: objlist.exe by Laurent````````  
 Sophos Sophos Anti-Virus SavService.exe  
 Sophos Sophos Anti-Virus SAVAdminService.exe  
 Sophos Sophos Anti-Virus Web Control swc_service.exe 
 Sophos Sophos Anti-Virus Web Intelligence swi_service.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
und FRST:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015
Ran by SH (administrator) on SH-PC on 28-06-2015 09:59:54
Running from C:\Users\SH\Desktop\trojaner
Loaded Profiles: SH (Available Profiles: SH)
Platform: Windows 7 Professional N Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) F:\Programme\Mozilla Firefox\firefox.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavMain.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1240064 2012-07-04] (Marvell Semiconductor, Inc.)
HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1593640 2015-03-04] (Sophos Limited)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-04-20] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation)
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\...\Run: [Remote Mouse] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe [2050048 2015-01-23] (RemoteMouse.net)
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll [217672 2015-01-14] (Sophos Limited)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured.dll => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll [275352 2015-01-14] (Sophos Limited)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2306031424-1336655547-1434631041-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-26] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-26] (Oracle Corporation)
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [126760 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [173864 2013-01-25] (Sophos Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.192.1
Tcpip\..\Interfaces\{2141132E-14AD-4573-837A-4E6B7BB4B483}: [NameServer] 130.83.22.60,130.83.22.63

FireFox:
========
FF ProfilePath: C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-24] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-24] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> F:\Programme\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> F:\Programme\DivX\DivX Web Player\npdivx32.dll [2014-02-18] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-26] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> F:\Programme\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: @hola.org/vlc,version=1.8.369 -> C:\Users\SH\AppData\Local\Hola\firefox\app\vlc No File
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\SH\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.)
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: sony.com/MediaGoDetector -> F:\Programme\Media Go\npMediaGoDetector.dll [2013-08-22] (Sony Network Entertainment International LLC)
FF Plugin HKU\S-1-5-21-2306031424-1336655547-1434631041-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-04-23] (Ubisoft)
FF Extension: Hola Better Internet - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack [2015-05-27]
FF Extension: WOT - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-05-30]
FF Extension: ZenMate Security & Privacy VPN - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\firefox@zenmate.com.xpi [2015-05-07]
FF Extension: flv movies downloader - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\flvmoviesdownloader@rzll.xpi [2013-10-17]
FF Extension: Media Hint - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\mediahint@jetpack.xpi [2014-03-13]
FF Extension: Adblock Plus - C:\Users\SH\AppData\Roaming\Mozilla\Firefox\Profiles\c56xiudu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-25]
StartMenuInternet: FIREFOX.EXE - F:\Programme\Mozilla Firefox\firefox.exe

Chrome: 
=======
CHR Profile: C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-27]
CHR Extension: (Google Drive) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-27]
CHR Extension: (WOT) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-06-22]
CHR Extension: (YouTube) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-27]
CHR Extension: (Adblock Plus) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-27]
CHR Extension: (Google Search) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-27]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-11-04]
CHR Extension: (Math Anywhere) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebhifiddmaaeecbaiemfpejghjdjmhc [2015-03-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Wallet) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Enhanced Steam) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2014-06-20]
CHR Extension: (Gmail) - C:\Users\SH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-27]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ForceWare Intelligent Application Manager (IAM); F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] ()
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 Media Jukebox 14 Service; F:\Programme\Media Jukebox 14\JRService.exe [379400 2010-07-15] (J. River, Inc.)
R2 nSvcIp; F:\Programme\NVIDIA Corporation\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] ()
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [288552 2014-05-23] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [208168 2014-10-14] (Sophos Limited)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [340776 2015-03-04] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [341800 2014-10-14] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3274536 2015-01-14] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2065704 2015-01-14] (Sophos Limited)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
S3 NVENETFD; C:\Windows\System32\DRIVERS\nvm60x64.sys [742696 2009-06-10] (NVIDIA Corporation)
S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project)
S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [25600 2013-04-19] (Razer USA Ltd) [File not signed]
S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [23040 2013-04-19] (Razer USA Ltd) [File not signed]
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [158976 2014-05-23] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2014-05-23] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [27904 2014-05-23] (Sophos Limited)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-01-24] (Duplex Secure Ltd.)
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] ()
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-13] (Anchorfree Inc.)
R3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-27 14:42 - 2015-06-27 14:42 - 00000209 _____ C:\Users\SH\Desktop\Call of Juarez Gunslinger.url
2015-06-27 11:40 - 2015-06-27 11:40 - 00000207 _____ C:\Windows\tweaking.com-regbackup-SH-PC-Windows-7-Professional-N-(64-bit).dat
2015-06-27 11:40 - 2015-06-27 11:40 - 00000000 ____D C:\RegBackup
2015-06-27 11:29 - 2015-06-27 11:31 - 00000000 ____D C:\AdwCleaner
2015-06-27 10:56 - 2015-06-27 10:56 - 00001106 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-06-26 14:53 - 2015-06-26 14:54 - 00561248 _____ (Oracle Corporation) C:\Users\SH\Downloads\jxpiinstall.exe
2015-06-26 14:35 - 2015-06-26 14:36 - 00000000 ____D C:\Users\SH\Downloads\Hola
2015-06-26 09:31 - 2015-06-26 09:59 - 00000000 ____D C:\Qoobox
2015-06-26 09:31 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2015-06-26 09:31 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2015-06-26 09:31 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2015-06-26 09:30 - 2015-06-26 09:54 - 00000000 ____D C:\Windows\erdnt
2015-06-25 16:31 - 2015-06-25 16:31 - 01182149 _____ C:\Users\SH\Downloads\7z936.exe
2015-06-25 16:31 - 2015-06-25 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-06-25 15:18 - 2015-06-28 09:59 - 00000000 ____D C:\FRST
2015-06-25 15:13 - 2015-06-25 15:13 - 00000020 _____ C:\Users\SH\defogger_reenable
2015-06-25 15:11 - 2015-06-28 09:56 - 00000000 ____D C:\Users\SH\Desktop\trojaner
2015-06-24 19:50 - 2015-06-24 19:50 - 00002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2015-06-24 18:01 - 2015-06-24 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disney Interactive Studios
2015-06-24 16:13 - 2015-06-24 16:13 - 00000000 ____D C:\Users\SH\AppData\Local\Licenses
2015-06-24 15:43 - 2015-06-24 15:43 - 00001112 _____ C:\Users\Public\Desktop\TriDef 3D.lnk
2015-06-24 15:43 - 2015-06-24 15:43 - 00000000 ____D C:\ProgramData\TriDef 3D
2015-06-24 15:42 - 2015-06-24 15:43 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef
2015-06-24 15:41 - 2015-06-24 15:41 - 00000000 ____D C:\ProgramData\DDD
2015-06-17 21:39 - 2015-06-17 21:39 - 00000000 ____D C:\Users\SH\AppData\Local\roomeon
2015-06-17 21:28 - 2015-06-17 21:38 - 00000000 ____D C:\Users\SH\AppData\Local\Room Arranger
2015-06-16 16:19 - 2015-06-16 16:19 - 00000000 __SHD C:\Users\SH\AppData\Local\EmieBrowserModeList
2015-06-14 13:54 - 2015-06-14 13:54 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3 Uprising
2015-06-13 14:45 - 2015-06-13 14:45 - 00000040 _____ C:\ProgramData\ra3.ini
2015-06-13 14:45 - 2015-06-13 14:45 - 00000000 ____D C:\Users\SH\AppData\Roaming\Red Alert 3
2015-06-13 14:06 - 2015-06-27 13:32 - 00000000 ____D C:\Users\SH\AppData\Roaming\Nidhogg
2015-06-13 13:52 - 2015-06-13 13:52 - 00000208 _____ C:\Users\SH\Desktop\Nidhogg.url
2015-06-13 13:36 - 2015-06-13 13:36 - 00000208 _____ C:\Users\SH\Desktop\Command and Conquer Red Alert 3 - Uprising.url
2015-06-13 11:13 - 2015-06-13 11:13 - 00000209 _____ C:\Users\SH\Desktop\Salt Demo.url
2015-06-12 11:08 - 2015-06-12 11:08 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-11 15:28 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-11 15:28 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-11 15:28 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-11 15:28 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-06-11 15:28 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-11 15:28 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-11 15:28 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-11 15:28 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-11 15:28 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-06-11 15:28 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-06-11 15:28 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-06-11 15:28 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-06-11 15:28 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-06-11 15:28 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-06-11 15:28 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-06-11 15:28 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-06-11 15:28 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-06-11 15:28 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-06-11 15:28 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-06-11 15:28 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-11 15:28 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-11 15:28 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-06-11 15:28 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-06-11 15:28 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-06-11 15:28 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-11 15:28 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-11 15:28 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-11 15:28 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-11 15:28 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-11 15:28 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-11 15:28 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-11 15:28 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-11 15:28 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-06-11 15:28 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-06-11 15:28 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-06-11 15:28 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-06-11 15:28 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-11 15:28 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-11 15:28 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-11 15:27 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-11 15:27 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-11 15:27 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-11 15:27 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-11 15:27 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-06-11 15:27 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-11 15:27 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-06-11 15:27 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-06-11 15:27 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-11 15:27 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-06-11 15:27 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-11 15:27 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-06-11 15:27 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-06-11 15:27 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-06-11 15:27 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-11 15:27 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-06-11 15:27 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-11 15:27 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-06-11 15:27 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-06-11 15:27 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-06-11 15:27 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-11 15:27 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-11 15:27 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-11 15:27 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-11 15:27 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-11 15:27 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-06-11 15:27 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-11 15:27 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-11 15:27 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-11 15:27 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-11 15:27 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-11 15:27 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-11 15:27 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-11 15:27 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-11 15:27 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-11 15:27 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-11 15:27 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-11 15:27 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-11 15:27 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-11 15:27 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-11 15:27 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-11 15:27 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-11 15:27 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-11 15:27 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-11 15:27 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-11 15:27 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-11 15:27 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-11 15:27 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-11 15:27 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-11 15:27 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-11 15:27 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-11 15:27 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-11 15:27 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-11 15:27 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-11 15:27 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-11 15:27 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-11 15:27 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-11 15:27 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-11 15:27 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-11 15:27 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-02 20:16 - 2015-06-02 20:16 - 00000000 ____D C:\Users\SH\AppData\Local\PDF24
2015-06-01 20:27 - 2015-06-01 20:27 - 00000000 ____D C:\Users\SH\AppData\Local\GWX

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-28 09:35 - 2014-03-08 16:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-28 09:12 - 2013-01-24 18:29 - 01206188 _____ C:\Windows\WindowsUpdate.log
2015-06-28 09:06 - 2013-01-24 19:04 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-28 02:06 - 2013-01-24 19:04 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-27 20:53 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-27 20:53 - 2009-07-14 06:50 - 00020144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-27 20:42 - 2014-07-29 12:52 - 00000000 ____D C:\Users\SH\AppData\Roaming\Raptr
2015-06-27 20:41 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-27 20:41 - 2009-07-14 06:56 - 00122723 _____ C:\Windows\setupact.log
2015-06-27 15:02 - 2013-01-30 00:09 - 00667550 _____ C:\Windows\DirectX.log
2015-06-27 13:38 - 2013-06-03 12:01 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9941B8CD-7D1F-464E-A428-95CA8D62A133}
2015-06-27 10:57 - 2014-06-11 17:42 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-27 10:56 - 2014-06-11 17:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-06-27 10:56 - 2014-06-11 17:42 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-06-26 14:57 - 2013-10-16 16:00 - 00000000 ____D C:\ProgramData\Oracle
2015-06-26 14:55 - 2014-10-17 13:16 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-26 14:55 - 2013-02-26 01:25 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-26 10:05 - 2010-11-21 05:47 - 00228934 _____ C:\Windows\PFRO.log
2015-06-26 09:46 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2015-06-26 09:38 - 2013-06-24 13:25 - 00000000 ____D C:\ProgramData\Temp
2015-06-25 23:50 - 2015-05-06 10:39 - 00007602 _____ C:\Users\SH\AppData\Local\Resmon.ResmonCfg
2015-06-25 15:56 - 2014-08-28 11:32 - 00000000 ____D C:\Users\SH\AppData\Local\CrashDumps
2015-06-25 15:13 - 2013-01-24 19:01 - 00000000 ____D C:\Users\SH
2015-06-25 14:26 - 2013-01-26 10:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-06-25 14:24 - 2014-06-22 17:18 - 00000000 ____D C:\Users\SH\AppData\Local\LOOT
2015-06-25 14:20 - 2013-05-24 12:06 - 00000000 ___RD C:\Users\SH\Desktop\Spiele
2015-06-25 13:10 - 2011-04-12 10:14 - 00713958 _____ C:\Windows\system32\perfh007.dat
2015-06-25 13:10 - 2011-04-12 10:14 - 00154074 _____ C:\Windows\system32\perfc007.dat
2015-06-25 13:10 - 2009-07-14 07:12 - 01648656 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-25 12:43 - 2014-01-22 13:51 - 00000000 ____D C:\Users\SH\AppData\Local\Battle.net
2015-06-24 21:10 - 2009-07-14 07:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-06-24 20:57 - 2014-04-04 17:16 - 00001048 _____ C:\Windows\Xbox_360_CC_Driver.log
2015-06-24 20:53 - 2013-05-23 13:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Byte
2015-06-24 19:51 - 2013-01-25 13:08 - 00000000 ____D C:\ProgramData\Sophos
2015-06-24 19:50 - 2014-05-23 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-06-24 19:50 - 2013-01-25 13:08 - 00000000 ____D C:\Program Files (x86)\Sophos
2015-06-24 18:50 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-06-24 14:19 - 2015-01-10 16:37 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-24 11:35 - 2014-03-08 16:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-24 11:35 - 2014-03-08 16:32 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-24 11:35 - 2014-03-08 16:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-06-21 14:19 - 2013-01-30 09:33 - 00000000 ____D C:\Users\SH\AppData\Roaming\vlc
2015-06-19 10:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-06-19 09:17 - 2009-07-14 06:50 - 00320184 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-19 09:15 - 2015-04-21 10:42 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-19 09:15 - 2014-05-19 12:34 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-19 09:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-19 04:26 - 2013-02-25 13:03 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-19 04:25 - 2013-07-12 23:23 - 00000000 ____D C:\Windows\system32\MRT
2015-06-19 04:19 - 2013-01-24 19:47 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-17 21:38 - 2013-07-08 17:10 - 00000000 ____D C:\Users\SH\AppData\Local\Downloaded Installations
2015-06-16 16:18 - 2015-05-05 10:24 - 00000000 ____D C:\Users\SH\Desktop\SS 15
2015-06-12 11:08 - 2013-01-24 19:04 - 00000000 ____D C:\Program Files (x86)\Google
2015-06-02 11:26 - 2013-01-24 19:04 - 00066648 _____ C:\Users\SH\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-05-29 16:26 - 2015-04-11 15:41 - 00000000 ___SD C:\Windows\system32\GWX
2015-05-29 16:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-29 16:25 - 2013-01-30 00:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight

==================== Files in the root of some directories =======

2015-01-28 13:58 - 2015-01-28 13:59 - 0009918 _____ () C:\Users\SH\AppData\Local\CleanupUninstall.txt
2013-06-04 22:44 - 2013-06-04 22:44 - 0003072 _____ () C:\Users\SH\AppData\Local\file__0.localstorage
2015-05-06 10:39 - 2015-06-25 23:50 - 0007602 _____ () C:\Users\SH\AppData\Local\Resmon.ResmonCfg
2013-01-29 16:21 - 2013-01-29 16:21 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt
2015-06-13 14:45 - 2015-06-13 14:45 - 0000040 _____ () C:\ProgramData\ra3.ini

Some files in TEMP:
====================
C:\Users\SH\AppData\Local\Temp\Quarantine.exe
C:\Users\SH\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-24 11:43

==================== End of log ============================
         
So weit erst mal keine Probleme mehr, danke schon mal.

Alt 28.06.2015, 17:46   #11
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Flash und Firefox updaten. Backups auf D löschen.


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
Tcpip\..\Interfaces\{2141132E-14AD-4573-837A-4E6B7BB4B483}: [NameServer] 130.83.22.60,130.83.22.63
Emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.






Cleanup:
(Die Reihenfolge ist hier entscheidend)

Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken.

Falls Combofix verwendet wurde:
Combofix deinstallieren
  • Wichtig: Bitte Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.
  • Drücke bitte die + R Taste und schreibe Combofix /Uninstall in das Ausführen-Fenster.
  • Klicke auf OK.
    Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert.
  • Nun die eben deaktivierten Programme wieder aktivieren.

Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
  • Schließe alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.

Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen.

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen.


Absicherung:
Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen:

Browser
Java
Flash-Player
PDF-Reader

Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren.
Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen.

Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.

Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank.
Meine Empfehlung:

Emsisoft

Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen.

Optional:
NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen.
Malwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen.


Lade Software von einem sauberen Portal wie .
Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen.
Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwcleaner .


Abschließend noch ein paar grundsätzliche Bemerkungen:
Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems.
Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 28.06.2015, 19:50   #12
Shnoxxer
 
Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



erst mal Fixlog:
Code:
ATTFilter
Fix result of Farbar Recovery Scan Tool (x64) Version:24-06-2015
Ran by SH at 2015-06-28 20:13:51 Run:1
Running from C:\Users\SH\Desktop\trojaner
Loaded Profiles: SH (Available Profiles: SH)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Tcpip\..\Interfaces\{2141132E-14AD-4573-837A-4E6B7BB4B483}: [NameServer] 130.83.22.60,130.83.22.63
Emptytemp:
*****************

HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2141132E-14AD-4573-837A-4E6B7BB4B483}\\NameServer => value removed successfully
EmptyTemp: => 1.3 GB temporary data Removed.


The system needed a reboot.. 

==== End of Fixlog 20:16:18 ====
         
Mein Sophos wird nicht müde mir immer mal wieder etwas wegen der NirCmd.exe zu melden. Kommt das durch die Bereinigungstools oder hat sich hier was durchgemogelt?
Code:
ATTFilter
****************** Sophos Anti-Virus Protokoll - 28.06.2015 18:38:59 **************

    ...
20150628 183655	Datei "C:\Windows\NIRCMD.exe" gehört zu Adware/PUA 'NirCmd' (Typ Andere).
20150628 183655	On-Access-Scanner hat den Zugriff auf den Speicherort "C:\Windows\NIRCMD.exe" für folgenden Benutzer verweigert: SH-PC\SH
      (2 Objekte)
         
und hier noch das log von Delfix (brauchst du das überhaupt?):
Code:
ATTFilter
# DelFix v1.010 - Datei am 28/06/2015 um 20:42:59 erstellt
# Aktualisiert am 26/04/2015 von Xplode
# Benutzer : SH - SH-PC
# Betriebssystem : Windows 7 Professional N Service Pack 1 (64 bits)

~ Aktiviere die Benutzerkontensteuerung ... OK

~ Entferne die Bereinigungsprogramme ...

Gelöscht : C:\Combofix
Gelöscht : C:\FRST
Gelöscht : C:\AdwCleaner
Gelöscht : C:\RegBackup
Gelöscht : C:\Windows\NIRCMD.exe
Gelöscht : HKLM\SOFTWARE\AdwCleaner
Gelöscht : HKLM\SOFTWARE\Swearware

~ Erstelle ein Backup der Registrierungsdatenbank ... OK

~ Lösche die Wiederherstellungspunkte ...

Gelöscht : RP #422 [ComboFix created restore point | 06/28/2015 18:35:40]

Ein neuer Wiederherstellungspunkt wurde erstellt !

~ Stelle die Systemeinstellungen wieder her ... OK

########## - EOF - ##########
         
Danke auf jeden Fall für die schnelle und verständliche Unterstützung.

Alt 29.06.2015, 12:03   #13
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Das ist ne fehlmeldung, unsere Tools haben die angelegt, sollte aber jetzt nach Delfix Ruhe sein
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 29.06.2015, 15:44   #14
Shnoxxer
 
Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Alles klar, danke für die kompetente Hilfe!
Ansonsten soweit keine Probleme mehr.

Gruß, Simon

Alt 30.06.2015, 06:26   #15
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: Sophos meldet "Troj/Miner-AB" - Standard

Win 7: Sophos meldet "Troj/Miner-AB"



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Win 7: Sophos meldet "Troj/Miner-AB"
alert, browser, computer, defender, desktop, firefox, flash player, google, helper, installation, keygen, logfile, miner, monitor, mozilla, problem, realtek, registry, rundll, scan, security, software, svchost.exe, system, troj/miner-ab, trojaner, virus, windows




Ähnliche Themen: Win 7: Sophos meldet "Troj/Miner-AB"


  1. Nach dem Installieren des "Sophos Antivirus" sind einige Komplikationen aufgetreten
    Antiviren-, Firewall- und andere Schutzprogramme - 17.04.2015 (2)
  2. Diverse Malware ("CoolSaleCoupon", "ddownlloaditkeep", "omiga-plus", "SaveSense", "SaleItCoupon"); lahmer PC & viel Werbung!
    Plagegeister aller Art und deren Bekämpfung - 11.01.2015 (16)
  3. Windows 8.1 "Telekom-Trojaner" Avira meldet "Emotet.A.43"
    Log-Analyse und Auswertung - 24.11.2014 (9)
  4. ~ 3 BitCoin Miner, Avira + Malwarebytes finden nichts. Beim Start startet sich Browser "unsichtbar"
    Plagegeister aller Art und deren Bekämpfung - 18.09.2014 (13)
  5. Windows 7: Bit Coin Miner "Befall"
    Log-Analyse und Auswertung - 01.01.2014 (9)
  6. Trojaner MacroMedia.exe "Coin-Miner"
    Log-Analyse und Auswertung - 16.10.2013 (32)
  7. Win 8 (64bit): Avast meldet "FileRepMalware" & "Win32:evo-gen [Susp]"
    Plagegeister aller Art und deren Bekämpfung - 11.09.2013 (20)
  8. WIN 7: Malwarebytes Anti-Malware meldet "PUM.UserWLoad" & "Trojan.Ransom"
    Log-Analyse und Auswertung - 04.09.2013 (21)
  9. Hohe GPU Auslastung durch "miner.exe"
    Log-Analyse und Auswertung - 16.07.2013 (19)
  10. Avira meldet Trojaner "TR/Sirefef.AG.9" und "TR/ATRAPS.Gen2"
    Plagegeister aller Art und deren Bekämpfung - 26.04.2013 (9)
  11. TrendMicro Worry Free Business Security meldet: "At1.job" und "ojswjz.ouu" (Mal_DownadJ und WORM_DOWNAD.AD)
    Plagegeister aller Art und deren Bekämpfung - 25.03.2013 (28)
  12. Avira meldet "TR/Downloader.Gen8" und "TR/Matsnu.EB.130" nach öffnen von Malware
    Plagegeister aller Art und deren Bekämpfung - 20.03.2013 (32)
  13. Sophos meldet im Speicher: Troj/ZbotMem-B
    Plagegeister aller Art und deren Bekämpfung - 27.11.2012 (10)
  14. Bekomme Meldung "Troj/JSRedir-HZ" und "MW:JS:JJ677"
    Plagegeister aller Art und deren Bekämpfung - 15.10.2012 (42)
  15. AVIRA meldet "W32/Patched.ZA", "TR/ATRAPS.Gen2", "TR/ATRAPS.Gen", "ZR/sirefe.P.487"
    Log-Analyse und Auswertung - 30.07.2012 (9)
  16. Trojaner mit Sophos Anti-Rootkit "enfernt" - sicher?
    Plagegeister aller Art und deren Bekämpfung - 19.07.2012 (7)
  17. Avira meldet "R/Crypt.XPACK.Gen2" und "BDS/Bredolab.foh"
    Plagegeister aller Art und deren Bekämpfung - 16.08.2010 (43)

Zum Thema Win 7: Sophos meldet "Troj/Miner-AB" - Hallo Trojaner-Feinde, Gestern Abend fing mein Mauszeiger an langsamer und träge zu werden. Irgendwann meldete Sophos "Troj/Miner-AB" in "C:\Users\SH\AppData\Local\Temp\msupdate71\dwm.exe" und verschob diese laut Nachricht in Quarantäne. Unter Maßnahmen zur Bereinigung - Win 7: Sophos meldet "Troj/Miner-AB"...
Archiv
Du betrachtest: Win 7: Sophos meldet "Troj/Miner-AB" auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.