Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Anitvirus Programm findet Virus aber keine Probleme ?

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 11.12.2015, 18:37   #12
Ossel
 
Anitvirus Programm findet Virus aber keine Probleme ? - Standard

Anitvirus Programm findet Virus aber keine Probleme ?



FRST-Fix:

Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-12-2015
durchgeführt von Martin (2015-12-11 18:22:59) Run:1
Gestartet von C:\Users\Martin\Downloads
Geladene Profile: Martin & postgres (Verfügbare Profile: Martin & Franzi & Martin_2 & UpdatusUser & postgres)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
start
CloseProcesses:
RemoveProxy:
CMD: ipconfig /flushdns
CMD: netsh winsock reset
EmptyTemp:
end
         
*****************

Prozess erfolgreich geschlossen.

========= RemoveProxy: =========

HKU\S-1-5-21-1946159566-2597201721-649942275-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-1946159566-2597201721-649942275-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt


========= Ende von RemoveProxy: =========


=========  ipconfig /flushdns =========


Windows-IP-Konfiguration

Der DNS-Aufl�sungscache wurde geleert.

========= Ende von CMD: =========


=========  netsh winsock reset =========


Der Winsock-Katalog wurde zur�ckgesetzt.
Sie m�ssen den Computer neu starten, um den Vorgang abzuschlie�en.


========= Ende von CMD: =========

EmptyTemp: => 153 MB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 18:23:11 ====
         
HitmanPro:

Code:
ATTFilter
HitmanPro 3.7.10.251
www.hitmanpro.com

   Computer name . . . . : HORTKIND
   Windows . . . . . . . : 6.1.1.7601.X64/4
   User name . . . . . . : Hortkind\Martin
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Free

   Scan date . . . . . . : 2015-12-11 18:31:01
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 5m 27s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 0
   Traces  . . . . . . . : 92

   Objects scanned . . . : 2.017.790
   Files scanned . . . . : 56.587
   Remnants scanned  . . : 487.579 files / 1.473.624 keys

Suspicious files ____________________________________________________________

   C:\Users\Martin\AppData\Local\PunkBuster\BF3\pb\dll\wc002286.dll
      Size . . . . . . . : 942.907 bytes
      Age  . . . . . . . : 1426.7 days (2012-01-15 01:43:42)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 151573760160ED491B4528616FF16C058966B9555B73E804AF1CD60B3F8EB33D
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.

   C:\Users\Martin\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
      Size . . . . . . . : 942.907 bytes
      Age  . . . . . . . : 1426.7 days (2012-01-15 01:43:42)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 151573760160ED491B4528616FF16C058966B9555B73E804AF1CD60B3F8EB33D
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.

   C:\Users\Martin\AppData\Local\PunkBuster\BF3\pb\pbclold.dll
      Size . . . . . . . : 951.497 bytes
      Age  . . . . . . . : 1426.7 days (2012-01-15 01:39:27)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 43358BBCEC1EBE7927CA3B0A3DCA0597D5E8584F0FCBE987B8126A0C12D73A2B
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.

   C:\Users\Martin\AppData\Local\PunkBuster\BF3\pb\PnkBstrK.sys
      Size . . . . . . . : 139.688 bytes
      Age  . . . . . . . : 1426.7 days (2012-01-15 01:39:47)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 643818A644C5A07C59DFACE042F53ACF33FAE290276555B3688066C40A024FB2
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         The file is a device driver. Device drivers run as trusted (highly privileged) code.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin\Downloads\FRST64.exe
      Size . . . . . . . : 2.369.024 bytes
      Age  . . . . . . . : 2.7 days (2015-12-09 02:39:26)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : DD61D2EA4C8059F67734E11221DED682276773D0361CB530D346E4C01C0A0176
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      Forensic Cluster
          0.0s C:\Users\Martin\Downloads\FRST64.exe
          0.9s C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\5ftby32f.default\datareporting\archived\2015-12\1449624772249.1ef9583a-4807-40bc-b9cd-cda943a19bb8.main.jsonlz4

   C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\pbcl.dll
      Size . . . . . . . : 930.024 bytes
      Age  . . . . . . . : 13.8 days (2015-11-27 22:48:51)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 13B3D879B8F163A8378CDD83EB290403BBA3708E7004380EF6645C39DE868FE1
      Fuzzy  . . . . . . : 30.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
         Program contains PE structure anomalies. This is not typical for most programs.
      Forensic Cluster
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\pbcl.db
         -0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\
         -0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\
         -0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\pbclgame.cfg
         -0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\pbcl.db
          0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\pbcl.dll
          0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\pbag.dll
          0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\scrnshot\
          0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\dll\
          0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\htm\
         11.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\PnkBstrB.exe
         13.5s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D47DBD2F9E3365FBBE008D71FB06716F_4DD1053BCC726DA41115FFF4C7D6E9CC
         13.5s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D47DBD2F9E3365FBBE008D71FB06716F_4DD1053BCC726DA41115FFF4C7D6E9CC
         13.7s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4DD39726D4B55AC3B4119B35A893323C_D9FA1A7D52109971837F7989B56BFE53
         13.7s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4DD39726D4B55AC3B4119B35A893323C_D9FA1A7D52109971837F7989B56BFE53
         20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\PnkBstrK.sys

   C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\PnkBstrK.sys
      Size . . . . . . . : 139.136 bytes
      Age  . . . . . . . : 13.8 days (2015-11-27 22:49:12)
      Entropy  . . . . . : 7.7
      SHA-256  . . . . . : 79CAD9D90619FEAECABBFD635AA54B9932345BC59656FAFA9169871ED28D299E
      RSA Key Size . . . : 1024
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 23.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
         Program contains PE structure anomalies. This is not typical for most programs.
         The file is a device driver. Device drivers run as trusted (highly privileged) code.
         Program is code signed with a valid Authenticode certificate.
      Forensic Cluster
         -20.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\pbcl.db
         -20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\
         -20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\
         -20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\pbclgame.cfg
         -20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\pbcl.db
         -20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\pbcl.dll
         -20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\pbag.dll
         -20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\scrnshot\
         -20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\dll\
         -20.7s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\htm\
         -9.1s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\PnkBstrB.exe
         -7.2s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D47DBD2F9E3365FBBE008D71FB06716F_4DD1053BCC726DA41115FFF4C7D6E9CC
         -7.2s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D47DBD2F9E3365FBBE008D71FB06716F_4DD1053BCC726DA41115FFF4C7D6E9CC
         -7.0s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4DD39726D4B55AC3B4119B35A893323C_D9FA1A7D52109971837F7989B56BFE53
         -7.0s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4DD39726D4B55AC3B4119B35A893323C_D9FA1A7D52109971837F7989B56BFE53
          0.0s C:\Users\Martin_2\AppData\Local\PunkBuster\AAO\pb\PnkBstrK.sys

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\dll\wc002286.dll
      Size . . . . . . . : 942.907 bytes
      Age  . . . . . . . : 1438.8 days (2012-01-02 22:18:25)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 151573760160ED491B4528616FF16C058966B9555B73E804AF1CD60B3F8EB33D
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\dll\wc002287.dll
      Size . . . . . . . : 948.113 bytes
      Age  . . . . . . . : 1416.7 days (2012-01-25 00:33:07)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 1BE27031845D80D6803C15BCE2EBE1276C0CA17F3BD47FDA8EAD97DBF5A517AF
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\dll\wc002288.dll
      Size . . . . . . . : 948.118 bytes
      Age  . . . . . . . : 1411.7 days (2012-01-30 00:37:53)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 3192353354FE593051B33886088D4C312ACB9A653D874281B2EBF131B80415CB
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\dll\wc002292.dll
      Size . . . . . . . : 956.681 bytes
      Age  . . . . . . . : 1317.9 days (2012-05-02 20:07:16)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 7218A15A9890CE82EB25F7AB5AC7AA60B4E3055C5574B70A6CABA4274D6DE493
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\dll\wc002317.dll
      Size . . . . . . . : 949.613 bytes
      Age  . . . . . . . : 1171.9 days (2012-09-25 20:03:19)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 15059F09B1D62DEA6B5D22EF9E0D062411C167378D870AE339AAB50B0BDC7FC0
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\dll\wc002325.dll
      Size . . . . . . . : 959.376 bytes
      Age  . . . . . . . : 1021.1 days (2013-02-23 16:10:17)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A85592ACDCFDA7C0293504A5F5279C2654ACC0E6D2398ED8958F6E03F05DCEB5
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\dll\wc002331.dll
      Size . . . . . . . : 963.480 bytes
      Age  . . . . . . . : 580.9 days (2014-05-09 21:39:31)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 4693498864B2A4C15EECDD4D132FFDFEDE3F9E4BAFA427F77BC87046A7352D1E
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
      Size . . . . . . . : 963.480 bytes
      Age  . . . . . . . : 580.8 days (2014-05-09 23:11:21)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 4693498864B2A4C15EECDD4D132FFDFEDE3F9E4BAFA427F77BC87046A7352D1E
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\pbclold.dll
      Size . . . . . . . : 963.480 bytes
      Age  . . . . . . . : 1445.8 days (2011-12-26 22:41:48)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 4693498864B2A4C15EECDD4D132FFDFEDE3F9E4BAFA427F77BC87046A7352D1E
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin_2\AppData\Local\PunkBuster\BF3\pb\PnkBstrK.sys
      Size . . . . . . . : 139.032 bytes
      Age  . . . . . . . : 1445.8 days (2011-12-26 22:42:10)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 0CA9D48C9E3D938121A73EBE6EA3FBE19A9AE017EEDA066A22CF254A688A98C2
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         The file is a device driver. Device drivers run as trusted (highly privileged) code.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin_2\AppData\Local\PunkBuster\PG\pb\dll\wc002341.dll
      Size . . . . . . . : 965.880 bytes
      Age  . . . . . . . : 538.7 days (2014-06-21 02:14:14)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 9D84C917D9E747EDCBB23A765E2D70C8AE9E629556BB19613136B4C7598062BE
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin_2\AppData\Local\PunkBuster\PG\pb\pbcl.dll
      Size . . . . . . . : 965.880 bytes
      Age  . . . . . . . : 396.8 days (2014-11-09 22:51:16)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 9D84C917D9E747EDCBB23A765E2D70C8AE9E629556BB19613136B4C7598062BE
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin_2\AppData\Local\PunkBuster\PG\pb\pbclold.dll
      Size . . . . . . . : 965.880 bytes
      Age  . . . . . . . : 538.7 days (2014-06-21 01:02:28)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 9D84C917D9E747EDCBB23A765E2D70C8AE9E629556BB19613136B4C7598062BE
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin_2\AppData\Local\PunkBuster\PG\pb\PnkBstrK.sys
      Size . . . . . . . : 140.160 bytes
      Age  . . . . . . . : 538.7 days (2014-06-21 01:02:40)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : C5FF96EF8AC37C5B02579173DBA6BC9E8148381BC9817C426600968A7BAAF168
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         The file is a device driver. Device drivers run as trusted (highly privileged) code.
         Program is code signed with a valid Authenticode certificate.

   C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\dll\wc002243.dll
      Size . . . . . . . : 930.024 bytes
      Age  . . . . . . . : 13.8 days (2015-11-27 22:43:52)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 13B3D879B8F163A8378CDD83EB290403BBA3708E7004380EF6645C39DE868FE1
      Fuzzy  . . . . . . : 30.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
         Program contains PE structure anomalies. This is not typical for most programs.
      Forensic Cluster
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\splash.bmp
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AA.key
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\sso.public.rsa.key
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pbag.bin
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\RunServer.bat
         -1.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\RunServerTournament.bat
         -1.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Config\
         -1.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Config\AceKilla.txt
         -1.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AdditionalCredits.txt
         -1.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ArmyOpsGlossary.txt
         -1.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ArmyOpsReadMe.txt
         -1.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\credits.txt
         -1.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\creditsarmy.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_Acog_4x.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_ACOG_Reflex.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_Harris_Bipod.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_heatshield.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_Ironsight.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_M203A1_Grenade.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_M4qd_suppressor.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_M583A1_Flare.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_M68_Aimpoint.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_NONE.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\overview.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Config\Poland.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Weapon_AKS74U.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Weapon_M4A1.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AntiPoke.ini
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Build.ini
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Default.ini
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\DefUnrealEd.ini
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\DefUser.ini
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Distribution.ini
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\FanSites.ini
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Help.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\KeyBindings.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Links.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\maap71.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\maap720.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\maap721.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Partners.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\server.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Services.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\tournament.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\tours.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UPlaylists.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\WeaponMods.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ArmyGameEULA.rtf
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\PunkBusterEULA.rtf
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\libandromeda.so
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\DtC6dal.dat
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\DtC6dl.dat
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Wt16M9bs.dat
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Wt16M9fs.dat
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Wt8S9bs.dat
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Wt8S9fs.dat
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\aa.sdk.key.data
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\aa.sdk.rsa.data
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP.int
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Interface.int
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Vehicles.int
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ALAudio.int
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Core.int
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\D3DDrv.int
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Editor.int
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Engine.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\IpDrv.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Setup.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Skins.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\SoftDrv.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Startup.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UnrealEd.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UWeb.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Vehicles.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Window.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\WinDrv.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\XInterface.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\CivDoc_3P.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\CivDoc_3P.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\COGGruntMesh.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\DI-oc3entver.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\DI-oc3entver.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\DocF_Nurse.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\DocM_Labcoat.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\George_FlakVest.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SF_3P.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierF_Infantry_ClassB.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_Infantry_ClassB.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_Instr_AA.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_Pilot.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_SF_RBA_AdvMarksman.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_SF_RBA_Rifleman.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_SF_RBA_Saw.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\UT-Ref-maya.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\CivDocFemale_3P.map
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\CivDoc_3P.map
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\COGGruntMesh.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\DI-oc3entver.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\SF_3P.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\SoldierM_Infantry_ClassB.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\UT-Ref-maya.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Packages.MD5
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AA25Characters.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_AI.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Characters.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Effects.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Game.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Gameplay.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Interface.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Inventory.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Objects.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Script.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Security.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_UI.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Vehicles.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Andromeda.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AntiPoke.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Core.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Editor.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Engine.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Fire.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Gameplay.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\IpDrv.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\mAApFriend.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\mAApKActor.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\SpankyCameraTextureClient.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\TriggerLightReset.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UnrealEd.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UTelnet.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\XInterface.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\BugSubmit.URL
         -0.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ArmyOps.exe
         -0.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\BugReport.exe
         -0.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Server.exe
         -0.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Interface.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Utils.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Vehicles.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ALAudio.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Andromeda.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Core.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\D3DDrv.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\DBGHELP.DLL
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\defOpenAL32.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Editor.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Engine.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Fire.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\GSMSLibrary.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\IFC23.DLL
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ImpersonatorLib_rd.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\IpDrv.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\libandromeda.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\libgmp.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\msvcp71.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\msvcr71.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ogg.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\pbag.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\pbcl.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\vorbis.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\vorbisfile.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\dll\
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\dll\wa001371.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\dll\wc002243.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Window.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\WinDrv.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\XInterface.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Save\
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\scrnshot\
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\htm\
          1.2s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\pbclgame.cfg

   C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\pbcl.dll
      Size . . . . . . . : 930.024 bytes
      Age  . . . . . . . : 13.8 days (2015-11-27 22:43:52)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 13B3D879B8F163A8378CDD83EB290403BBA3708E7004380EF6645C39DE868FE1
      Fuzzy  . . . . . . : 30.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
         Program contains PE structure anomalies. This is not typical for most programs.
      Forensic Cluster
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\splash.bmp
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AA.key
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\sso.public.rsa.key
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pbag.bin
         -1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\RunServer.bat
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\RunServerTournament.bat
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Config\
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Config\AceKilla.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AdditionalCredits.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ArmyOpsGlossary.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ArmyOpsReadMe.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\credits.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\creditsarmy.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_Acog_4x.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_ACOG_Reflex.txt
         -1.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_Harris_Bipod.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_heatshield.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_Ironsight.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_M203A1_Grenade.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_M4qd_suppressor.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_M583A1_Flare.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_M68_Aimpoint.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Mod_NONE.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\overview.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Config\Poland.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Weapon_AKS74U.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Descriptions\Weapon_M4A1.txt
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AntiPoke.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Build.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Default.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\DefUnrealEd.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\DefUser.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Distribution.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\FanSites.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Help.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\KeyBindings.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Links.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\maap71.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\maap720.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\maap721.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Partners.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\server.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Services.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\tournament.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\tours.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UPlaylists.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\WeaponMods.ini
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ArmyGameEULA.rtf
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\PunkBusterEULA.rtf
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\libandromeda.so
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\DtC6dal.dat
         -1.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\DtC6dl.dat
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Wt16M9bs.dat
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Wt16M9fs.dat
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Wt8S9bs.dat
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Wt8S9fs.dat
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\aa.sdk.key.data
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\aa.sdk.rsa.data
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Interface.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Vehicles.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ALAudio.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Core.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\D3DDrv.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Editor.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Engine.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\IpDrv.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Setup.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Skins.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\SoftDrv.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Startup.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UnrealEd.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UWeb.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Vehicles.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Window.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\WinDrv.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\XInterface.int
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\CivDoc_3P.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\CivDoc_3P.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\COGGruntMesh.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\DI-oc3entver.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\DI-oc3entver.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\DocF_Nurse.lad
         -0.9s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\DocM_Labcoat.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\George_FlakVest.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SF_3P.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierF_Infantry_ClassB.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_Infantry_ClassB.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_Instr_AA.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_Pilot.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_SF_RBA_AdvMarksman.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_SF_RBA_Rifleman.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\SoldierM_SF_RBA_Saw.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Controllers\UT-Ref-maya.lad
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\CivDocFemale_3P.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\CivDoc_3P.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\COGGruntMesh.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\DI-oc3entver.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\SF_3P.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\SoldierM_Infantry_ClassB.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\LipSincData\Mappings\UT-Ref-maya.map
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Packages.MD5
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AA25Characters.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_AI.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Characters.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Effects.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Game.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Gameplay.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Interface.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Inventory.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Objects.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Script.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Security.u
         -0.8s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_UI.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Vehicles.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Andromeda.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AntiPoke.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Core.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Editor.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Engine.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Fire.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Gameplay.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\IpDrv.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\mAApFriend.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\mAApKActor.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\SpankyCameraTextureClient.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\TriggerLightReset.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UnrealEd.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\UTelnet.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\XInterface.u
         -0.7s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\BugSubmit.URL
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ArmyOps.exe
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\BugReport.exe
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Server.exe
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Interface.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Utils.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\AGP_Vehicles.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ALAudio.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Andromeda.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Core.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\D3DDrv.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\DBGHELP.DLL
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\defOpenAL32.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Editor.dll
         -0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Engine.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Fire.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\GSMSLibrary.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\IFC23.DLL
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ImpersonatorLib_rd.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\IpDrv.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\libandromeda.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\libgmp.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\msvcp71.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\msvcr71.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\ogg.dll
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\
         -0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\pbag.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\pbcl.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\vorbis.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\vorbisfile.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\dll\
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\dll\wa001371.dll
          0.0s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\dll\wc002243.dll
          0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Window.dll
          0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\WinDrv.dll
          0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\XInterface.dll
          0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\Save\
          0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\scrnshot\
          0.1s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\htm\
          1.3s C:\Users\Martin_2\AppData\Roaming\25Assist\armyops\System\pb\pbclgame.cfg


Potential Unwanted Programs _________________________________________________

   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\06B42F08F6F40FA4F83EA94EF9F03F63\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\06FCEE940712E4B4C8A7362CD8D249A1\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\085CE460BADC1D14EA94D8A62E517577\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0B2690283E07C9B4085B3B794202E7F7\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12D3738E79C70C74E9D808E162BD6691\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\189F6D048E923EA48B11D15B30CDAC81\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0968491626AD249A2A6CBAC4DE352D\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22A78C977EC431247B2ECECC374DFE13\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2CAC1D959B4188B4F8E8C251A25DA9DB\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\33990057697C62f47BB9FFD59CB4AEEB\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41BF64DDE5C2457478691CB0675759BA\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42F5B13BF4BAD8D409578286A354E360\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4374E71C5355C4B4AACC93BBBF40E99F\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4410C9B6FF0094C418865CD2B243B258\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45B0A4620F799834C82DE0BD4E90E40B\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4859A93046C917F408248F3C16F75E77\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A3D29BA507550f4F87F6F33D42B24D6\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4E28C30B25E21BF4C9418857AEB2AF7C\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50390A9E27AD04A4698BF297EF564973\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D5D3B13CCBA08C479F107E50BD81C8A\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\65655A3C1C3738748BE6470495D534FC\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\661134B612233374391C95E8AC373BA3\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\734F787B99D52824EAB6CA1A89F801F7\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\73A172B6C18A3594A9FA363311A187A3\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A0CF0C6A9F9B8642A392A1896DCCCF2\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE43E6BAE0DC0B43883C669D8DCE8B1\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D7860B78D7B6F64887AFCB83061837A\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7EC46CC5C43127A45A99762BF7A9C9E5\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFDE7BEC9977ac46B41B0A2BF7D88CD\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8011A895DAAC4CC45AF1397E3CE9CA16\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\81EE804DA9066C64A859E01A38075C59\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\879DDA62492E58A40898AD146BBB572E\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88761D7BAC02ccc428CD5EF352BB933C\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CB53AD495D2C5443B95C9EE29E47902\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F85A4D374D5bf245B8722C062C2D00E\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9516FC331A505934FA76C22DCFFEC47E\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98B242210207F2D48AF879D69C381D08\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98FD652EB4839214E97B69DD8EEA1D29\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A08449608E3Ca1f4ABF236256A256754\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A431C8F3F57D7844B89242F5F7A5F62C\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A66E2D84F93A9E94FBA6AB3524D85958\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA27FE018F87f5e4F97F31C09E7C5370\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC049320EE27170499EC0B6124142ED7\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B448F401EF39C8346BF7BE9B8D1C7060\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5211271DD585A740AA28576B137D09D\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B58469E2C54833741B90BAD9CE5A1159\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B6DA77032731EEE40B463A325128D613\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCC2BCA248E19F74F9AEDE4D1EFEFBC9\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C70C6F53DEE245249956FC291D801A71\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C7C0052DD04CBC84C81C0AC586485E50\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C879DCC3D00BE8E4282F02F1735E78DF\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C9FBD8E8A2691564FA012512BCC3748C\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB3AEBFFA9E907145906294AB669B1F2\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE142BFA81B72674892EB318BD603CB0\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE90A73A5D5A01a43A2EDCCF04BA9487\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D03E28F842DF79F4DA05A3B6B86B095C\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D05B2B3F5629f9d41A7E57FB534168CA\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D158B0E5D051EA046B8E08BF6B004842\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D45A81F48EF19334EABB33FF8871C4F5\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D538E650623CB2C43AD5FBF587227D55\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D8D06C15BF8AFCD449EFF90B935AEF7C\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB1AE396B3BBfe940922C55C6EEF740A\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDF3C3F412F4F954F9F2723C62C65C25\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDF89DEE0C7E9A5448382117C4436818\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E55AA93871A0fde4490A708053AC6501\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E954A03F45EC92B419A55A0D4815C0A3\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E97C12D46BF588241856422D760336B4\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EA1332016439DD54C840C7D45CFB2705\ (AskBar)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EFBB6B0872B0DBB4D912A0F52986399D\ (AskBar)
         

 

Themen zu Anitvirus Programm findet Virus aber keine Probleme ?
ansicht, archiv, archive, auswertung, bestanden, converter, dankeschön, dateien, forum, frage, fragen, fund, hinweis, infizierte, namen, probleme, programm, sache, seite, seiten, software, suche, tmp, virus, warnung




Ähnliche Themen: Anitvirus Programm findet Virus aber keine Probleme ?


  1. Datenträger ist 100% ausgelastet, aber keine Probleme auffindbar!
    Plagegeister aller Art und deren Bekämpfung - 14.04.2015 (12)
  2. Virus aber Programm findet nichts
    Log-Analyse und Auswertung - 02.04.2015 (3)
  3. Windows 7 Bluescreen beim Start aber im Betrieb keine Probleme
    Netzwerk und Hardware - 30.07.2014 (7)
  4. BKA- Trojaner aber keine Symptome oder Probleme?
    Plagegeister aller Art und deren Bekämpfung - 05.02.2014 (3)
  5. Anitvirus meldet ein Virus; URL;Mal (Windos\System32\wscript.exe
    Plagegeister aller Art und deren Bekämpfung - 21.12.2013 (8)
  6. Das eingebaute Modem in meinem Laptop funktioniert nicht mehr, WLAN hat aber keine Probleme.
    Netzwerk und Hardware - 16.07.2013 (12)
  7. Malwarebytes findet Trojan.inject - Rechner zeigt aber keine Probleme
    Plagegeister aller Art und deren Bekämpfung - 28.05.2013 (23)
  8. Trojan.Win32.infect.fexk, Malware findet nichts, bis jetzt auch keine Probleme
    Plagegeister aller Art und deren Bekämpfung - 07.03.2013 (1)
  9. Trojaner an Bord oder nicht? html/malicious.pdf.gen gefunden - aber bisher keine Probleme
    Plagegeister aller Art und deren Bekämpfung - 27.03.2012 (37)
  10. Keine Probleme, aber unsicher bezüglich Hijack File
    Log-Analyse und Auswertung - 14.12.2010 (4)
  11. AVIRA findet Virus, aber bekommt ihn nicht weg...
    Antiviren-, Firewall- und andere Schutzprogramme - 12.03.2010 (7)
  12. antivirus programm findet virus nicht :S?
    Log-Analyse und Auswertung - 15.03.2009 (4)
  13. AntiVir findet Virus oder unerwünschtes Programm TR/Agent.105720
    Plagegeister aller Art und deren Bekämpfung - 25.02.2009 (3)
  14. Viele Probleme aber Keine Ahnung!
    Log-Analyse und Auswertung - 08.12.2007 (1)
  15. HILFE !! keine ahnung mein antivir findet watt aber kann nix machen !!!
    Log-Analyse und Auswertung - 15.12.2005 (1)
  16. I-Net-Verbindung steht, aber findet keine Seite
    Plagegeister aller Art und deren Bekämpfung - 30.12.2004 (8)
  17. Virus auf PC aber keiner findet was??!!
    Plagegeister aller Art und deren Bekämpfung - 03.10.2004 (7)

Zum Thema Anitvirus Programm findet Virus aber keine Probleme ? - FRST-Fix: Code: Alles auswählen Aufklappen ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-12-2015 durchgeführt von Martin (2015-12-11 18:22:59) Run:1 Gestartet von C:\Users\Martin\Downloads Geladene Profile: Martin & postgres (Verfügbare Profile: - Anitvirus Programm findet Virus aber keine Probleme ?...
Archiv
Du betrachtest: Anitvirus Programm findet Virus aber keine Probleme ? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.