|
Log-Analyse und Auswertung: Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.02.2016, 11:14 | #16 |
| Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B) FRST Teil 2: Code:
ATTFilter 2016-01-29 15:13 - 2015-02-03 04:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2016-01-29 15:13 - 2015-02-03 04:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2016-01-29 15:13 - 2015-02-03 04:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2016-01-29 15:13 - 2015-02-03 04:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2016-01-29 15:13 - 2015-02-03 04:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2016-01-29 15:13 - 2015-02-03 04:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2016-01-29 15:13 - 2015-02-03 04:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2016-01-29 15:13 - 2015-02-03 04:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2016-01-29 15:13 - 2015-02-03 04:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2016-01-29 15:13 - 2015-02-03 04:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2016-01-29 15:13 - 2015-02-03 04:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2016-01-29 15:13 - 2015-02-03 04:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2016-01-29 15:13 - 2015-02-03 04:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2016-01-29 15:13 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2016-01-29 15:13 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2016-01-29 15:13 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2016-01-29 15:13 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2016-01-29 15:13 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2016-01-29 15:13 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2016-01-29 15:13 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2016-01-29 15:12 - 2015-11-10 19:55 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2016-01-29 15:12 - 2015-11-10 19:37 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2016-01-29 15:12 - 2015-07-15 04:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll 2016-01-29 15:12 - 2015-07-01 21:49 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2016-01-29 15:12 - 2015-07-01 21:48 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2016-01-29 15:12 - 2015-07-01 21:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2016-01-29 15:12 - 2015-07-01 21:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2016-01-29 15:12 - 2015-02-03 04:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2016-01-29 15:12 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll 2016-01-29 15:12 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2016-01-29 15:12 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2016-01-29 15:12 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2016-01-29 15:12 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2016-01-29 15:12 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2016-01-29 15:12 - 2014-06-18 03:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2016-01-29 15:12 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2016-01-29 15:12 - 2014-04-05 03:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2016-01-29 15:12 - 2014-04-05 03:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2016-01-29 15:12 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2016-01-29 15:12 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2016-01-29 15:12 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2016-01-29 15:12 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2016-01-29 15:12 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2016-01-29 15:12 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2016-01-29 15:12 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2016-01-29 15:12 - 2011-03-11 07:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2016-01-29 15:12 - 2011-03-11 07:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2016-01-29 15:12 - 2011-03-11 06:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2016-01-29 15:12 - 2011-03-11 06:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2016-01-29 15:11 - 2015-11-11 19:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2016-01-29 15:11 - 2015-11-11 19:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2016-01-29 15:11 - 2015-11-11 19:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll 2016-01-29 15:11 - 2015-11-11 19:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll 2016-01-29 15:11 - 2015-11-05 20:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll 2016-01-29 15:11 - 2015-11-05 20:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll 2016-01-29 15:11 - 2015-11-05 10:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2016-01-29 15:11 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2016-01-29 15:11 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2016-01-29 15:11 - 2015-10-01 19:06 - 00692672 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2016-01-29 15:11 - 2015-10-01 19:04 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2016-01-29 15:11 - 2015-10-01 19:00 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2016-01-29 15:11 - 2015-10-01 19:00 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2016-01-29 15:11 - 2015-10-01 19:00 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2016-01-29 15:11 - 2015-10-01 19:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2016-01-29 15:11 - 2015-10-01 19:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2016-01-29 15:11 - 2015-10-01 18:50 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2016-01-29 15:11 - 2015-10-01 18:00 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2016-01-29 15:11 - 2015-07-04 19:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2016-01-29 15:11 - 2015-07-04 18:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2016-01-29 15:11 - 2015-06-15 22:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2016-01-29 15:11 - 2015-06-15 22:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2016-01-29 15:11 - 2015-06-15 22:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2016-01-29 15:11 - 2015-06-15 22:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2016-01-29 15:11 - 2015-06-15 22:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2016-01-29 15:11 - 2015-06-15 22:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2016-01-29 15:11 - 2015-06-15 22:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2016-01-29 15:11 - 2015-06-15 22:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2016-01-29 15:11 - 2015-06-03 21:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2016-01-29 15:11 - 2015-06-03 21:16 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2016-01-29 15:11 - 2015-06-03 21:16 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2016-01-29 15:11 - 2015-04-24 19:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2016-01-29 15:11 - 2015-04-24 18:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2016-01-29 15:11 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2016-01-29 15:11 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2016-01-29 15:11 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2016-01-29 15:11 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2016-01-29 15:11 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2016-01-29 15:11 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2016-01-29 15:11 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2016-01-29 15:11 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2016-01-29 15:11 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2016-01-29 15:11 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2016-01-29 15:11 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2016-01-29 15:11 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2016-01-29 15:11 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2016-01-29 15:11 - 2012-11-28 23:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2016-01-29 15:11 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2016-01-29 15:11 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2016-01-29 15:11 - 2011-03-03 07:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2016-01-29 15:11 - 2011-03-03 07:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2016-01-29 15:11 - 2011-03-03 07:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2016-01-29 15:11 - 2011-03-03 06:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2016-01-29 15:11 - 2011-03-03 06:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe 2016-01-29 15:10 - 2015-12-08 22:53 - 00509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2016-01-29 15:10 - 2015-12-08 20:07 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2016-01-29 15:10 - 2015-07-09 18:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe 2016-01-29 15:10 - 2015-07-09 18:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\notepad.exe 2016-01-29 15:10 - 2015-07-09 18:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe 2016-01-29 15:10 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2016-01-29 15:10 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2016-01-29 15:10 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2016-01-29 15:10 - 2014-03-04 10:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2016-01-29 15:10 - 2014-03-04 10:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2016-01-29 15:10 - 2014-03-04 10:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2016-01-29 15:10 - 2014-03-04 10:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2016-01-29 15:10 - 2014-03-04 10:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2016-01-29 15:10 - 2014-03-04 10:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2016-01-29 15:10 - 2014-03-04 10:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2016-01-29 15:10 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2016-01-29 15:10 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2016-01-29 15:10 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2016-01-29 15:10 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2016-01-29 15:10 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2016-01-29 15:10 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2016-01-29 15:10 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2016-01-29 15:10 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2016-01-29 15:10 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2016-01-29 15:10 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2016-01-29 15:10 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll 2016-01-29 15:10 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax 2016-01-29 15:10 - 2011-04-29 04:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2016-01-29 15:10 - 2011-04-29 04:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2016-01-29 15:10 - 2011-04-29 04:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2016-01-29 15:10 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2016-01-29 15:09 - 2015-12-08 22:54 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2016-01-29 15:09 - 2015-12-08 22:54 - 01568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL 2016-01-29 15:09 - 2015-12-08 22:54 - 01325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL 2016-01-29 15:09 - 2015-12-08 22:54 - 00902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL 2016-01-29 15:09 - 2015-12-08 22:54 - 00815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL 2016-01-29 15:09 - 2015-12-08 22:54 - 00740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll 2016-01-29 15:09 - 2015-12-08 22:54 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL 2016-01-29 15:09 - 2015-12-08 22:54 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL 2016-01-29 15:09 - 2015-12-08 22:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL 2016-01-29 15:09 - 2015-12-08 22:54 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL 2016-01-29 15:09 - 2015-12-08 22:54 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL 2016-01-29 15:09 - 2015-12-08 22:53 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL 2016-01-29 15:09 - 2015-12-08 22:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL 2016-01-29 15:09 - 2015-12-08 22:53 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL 2016-01-29 15:09 - 2015-12-08 22:53 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL 2016-01-29 15:09 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL 2016-01-29 15:09 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL 2016-01-29 15:09 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax 2016-01-29 15:09 - 2015-12-08 22:53 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL 2016-01-29 15:09 - 2015-12-08 22:53 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL 2016-01-29 15:09 - 2015-12-08 22:53 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll 2016-01-29 15:09 - 2015-12-08 22:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2016-01-29 15:09 - 2015-12-08 22:53 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2016-01-29 15:09 - 2015-12-08 22:53 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll 2016-01-29 15:09 - 2015-12-08 22:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 01955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 01575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 01393152 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 01232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 01153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 01026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL 2016-01-29 15:09 - 2015-12-08 20:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll 2016-01-29 15:09 - 2015-12-08 20:07 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2016-01-29 15:09 - 2015-12-08 20:07 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll 2016-01-29 15:09 - 2015-12-08 20:06 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax 2016-01-29 15:09 - 2015-12-08 20:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2016-01-29 15:09 - 2015-12-08 20:04 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2016-01-29 15:09 - 2015-12-08 19:54 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2016-01-29 15:09 - 2015-12-08 19:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2016-01-29 15:09 - 2015-12-08 19:11 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys 2016-01-29 15:09 - 2015-12-08 18:58 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-01-29 15:09 - 2015-02-25 04:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2016-01-29 15:09 - 2015-02-18 08:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2016-01-29 15:09 - 2015-02-18 08:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2016-01-29 15:09 - 2015-01-17 03:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2016-01-29 15:09 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2016-01-29 15:09 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2016-01-29 15:09 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2016-01-29 15:09 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2016-01-29 15:09 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2016-01-29 15:09 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2016-01-29 15:09 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2016-01-29 15:09 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2016-01-29 15:09 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2016-01-29 15:09 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2016-01-29 15:09 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2016-01-29 15:09 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2016-01-29 15:09 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2016-01-29 15:09 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2016-01-29 15:09 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll 2016-01-29 15:09 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll 2016-01-29 15:09 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll 2016-01-29 15:09 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe 2016-01-29 15:09 - 2011-02-05 18:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2016-01-29 15:09 - 2011-02-05 18:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2016-01-29 15:09 - 2011-02-05 18:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2016-01-29 15:08 - 2015-12-08 22:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2016-01-29 15:08 - 2015-12-08 20:07 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2016-01-29 15:08 - 2015-11-03 20:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll 2016-01-29 15:08 - 2015-11-03 19:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll 2016-01-29 15:08 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2016-01-29 15:08 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2016-01-29 15:08 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll 2016-01-29 15:08 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2016-01-29 15:08 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2016-01-29 15:08 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2016-01-29 15:08 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2016-01-29 15:08 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2016-01-29 15:08 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll 2016-01-29 15:08 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2016-01-29 15:08 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2016-01-29 15:08 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2016-01-29 15:08 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2016-01-29 15:08 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2016-01-29 15:08 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2016-01-29 15:08 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2016-01-29 15:08 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2016-01-29 15:08 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2016-01-29 15:08 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2016-01-29 15:08 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2016-01-29 15:08 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2016-01-29 15:08 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2016-01-29 15:08 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2016-01-29 15:08 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2016-01-29 15:08 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2016-01-29 15:08 - 2011-02-12 12:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2016-01-29 15:07 - 2015-12-30 20:08 - 05572544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-01-29 15:07 - 2015-12-30 20:08 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-01-29 15:07 - 2015-12-30 20:08 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-01-29 15:07 - 2015-12-30 20:05 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-01-29 15:07 - 2015-12-30 20:02 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2016-01-29 15:07 - 2015-12-30 20:02 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2016-01-29 15:07 - 2015-12-30 20:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-01-29 15:07 - 2015-12-30 20:02 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-01-29 15:07 - 2015-12-30 20:02 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-01-29 15:07 - 2015-12-30 20:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2016-01-29 15:07 - 2015-12-30 20:01 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-01-29 15:07 - 2015-12-30 20:01 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-01-29 15:07 - 2015-12-30 20:01 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-01-29 15:07 - 2015-12-30 20:01 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-01-29 15:07 - 2015-12-30 20:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-01-29 15:07 - 2015-12-30 20:01 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-01-29 15:07 - 2015-12-30 20:01 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-01-29 15:07 - 2015-12-30 20:00 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2016-01-29 15:07 - 2015-12-30 19:59 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-01-29 15:07 - 2015-12-30 19:59 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-01-29 15:07 - 2015-12-30 19:59 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-01-29 15:07 - 2015-12-30 19:58 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-01-29 15:07 - 2015-12-30 19:58 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-01-29 15:07 - 2015-12-30 19:57 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-01-29 15:07 - 2015-12-30 19:57 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-01-29 15:07 - 2015-12-30 19:57 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-01-29 15:07 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-01-29 15:07 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-01-29 15:07 - 2015-12-30 19:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:47 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-01-29 15:07 - 2015-12-30 19:47 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-01-29 15:07 - 2015-12-30 19:44 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-01-29 15:07 - 2015-12-30 19:41 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-01-29 15:07 - 2015-12-30 19:41 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-01-29 15:07 - 2015-12-30 19:41 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-01-29 15:07 - 2015-12-30 19:41 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-01-29 15:07 - 2015-12-30 19:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-01-29 15:07 - 2015-12-30 19:41 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-01-29 15:07 - 2015-12-30 19:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-01-29 15:07 - 2015-12-30 19:41 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-01-29 15:07 - 2015-12-30 19:40 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-01-29 15:07 - 2015-12-30 19:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-01-29 15:07 - 2015-12-30 19:39 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-01-29 15:07 - 2015-12-30 19:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-01-29 15:07 - 2015-12-30 19:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-01-29 15:07 - 2015-12-30 19:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-01-29 15:07 - 2015-12-30 19:38 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-01-29 15:07 - 2015-12-30 19:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 18:57 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-01-29 15:07 - 2015-12-30 18:50 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-01-29 15:07 - 2015-12-30 18:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-01-29 15:07 - 2015-12-30 18:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-01-29 15:07 - 2015-12-30 18:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-01-29 15:07 - 2015-12-30 18:42 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-01-29 15:07 - 2015-12-30 18:42 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-01-29 15:07 - 2015-12-30 18:41 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-01-29 15:07 - 2015-12-30 18:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-01-29 15:07 - 2015-12-30 18:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-01-29 15:07 - 2015-12-30 18:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-01-29 15:07 - 2015-12-30 18:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-01-29 15:07 - 2015-12-30 18:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-01-29 15:07 - 2015-12-30 18:30 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-01-29 15:07 - 2015-12-30 18:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 18:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-01-29 15:07 - 2015-12-30 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-01-29 15:07 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2016-01-29 15:07 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll 2016-01-29 15:07 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2016-01-29 15:07 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2016-01-29 15:07 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2016-01-29 15:07 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll 2016-01-29 15:07 - 2015-03-04 05:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2016-01-29 15:07 - 2015-03-04 05:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2016-01-29 15:07 - 2015-03-04 05:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2016-01-29 15:07 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2016-01-29 15:07 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2016-01-29 15:07 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2016-01-29 15:07 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2016-01-29 15:07 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2016-01-29 15:07 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2016-01-29 15:07 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2016-01-29 15:07 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2016-01-29 15:07 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2016-01-29 15:07 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2016-01-29 15:07 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2016-01-29 15:07 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2016-01-29 15:07 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2016-01-29 15:07 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2016-01-29 15:07 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll 2016-01-29 15:07 - 2011-02-23 05:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2016-01-29 15:06 - 2015-09-02 04:04 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2016-01-29 15:06 - 2015-09-02 04:04 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2016-01-29 15:06 - 2015-09-02 04:04 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2016-01-29 15:06 - 2015-09-02 04:04 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2016-01-29 15:06 - 2015-09-02 03:48 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2016-01-29 15:06 - 2015-09-02 03:48 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2016-01-29 15:06 - 2015-09-02 03:48 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2016-01-29 15:06 - 2015-09-02 03:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2016-01-29 15:06 - 2015-09-02 02:47 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2016-01-29 15:06 - 2015-09-02 02:33 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2016-01-29 15:06 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2016-01-29 15:06 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2016-01-29 15:06 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2016-01-29 15:06 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2016-01-29 15:06 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2016-01-29 14:51 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2016-01-29 14:51 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2016-01-29 14:51 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2016-01-29 14:36 - 2016-01-29 14:36 - 00000000 ____D C:\Users\Stephan Blank\AppData\Local\Sony Corporation 2016-01-29 12:44 - 2016-01-29 12:44 - 00000000 ____D C:\3eb852b6b65315fdf8325989cb0c0a 2016-01-29 12:41 - 2016-01-29 12:41 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Main 2016-01-29 12:37 - 2016-01-29 12:37 - 45487704 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000268817.exe 2016-01-29 12:27 - 2016-01-29 12:27 - 01223672 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000255979.exe 2016-01-29 12:18 - 2016-01-29 12:19 - 23008216 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000317149.exe 2016-01-29 12:11 - 2016-01-29 12:11 - 19726336 _____ C:\Users\Stephan Blank\Downloads\EP0000303880.msi 2016-01-29 11:46 - 2016-01-29 11:46 - 00286056 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000298538.exe 2016-01-29 11:45 - 2016-01-29 11:45 - 00365776 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000296998.exe 2016-01-29 11:41 - 2016-01-29 11:42 - 10315480 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000295615.exe 2016-01-29 11:37 - 2016-01-29 11:38 - 60821240 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000261503.exe 2016-01-29 11:29 - 2016-01-29 11:29 - 00001303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Gallery.lnk 2016-01-29 11:28 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2016-01-29 11:28 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2016-01-29 11:28 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2016-01-29 11:28 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2016-01-29 11:28 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2016-01-29 11:28 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2016-01-29 11:28 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2016-01-29 11:11 - 2016-01-29 11:19 - 352086416 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000262450.exe 2016-01-29 10:58 - 2012-01-03 03:21 - 09888872 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsPStorIcon.dll 2016-01-29 10:56 - 2012-05-25 02:13 - 00017440 _____ C:\Windows\system32\iglhxs64.vp 2016-01-29 10:56 - 2012-05-25 02:08 - 04378944 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe 2016-01-29 10:56 - 2012-05-25 02:08 - 00506688 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe 2016-01-29 10:56 - 2012-05-25 02:08 - 00417088 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe 2016-01-29 10:56 - 2012-05-25 02:08 - 00392512 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe 2016-01-29 10:56 - 2012-05-25 02:08 - 00239936 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe 2016-01-29 10:56 - 2012-05-25 02:08 - 00184640 _____ (Intel Corporation) C:\Windows\system32\difx64.exe 2016-01-29 10:56 - 2012-05-25 02:08 - 00167744 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe 2016-01-29 10:56 - 2012-05-25 02:01 - 12312832 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdpmd64.sys 2016-01-29 10:56 - 2012-05-25 02:01 - 12312832 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys 2016-01-29 10:56 - 2012-05-25 02:01 - 08314368 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll 2016-01-29 10:56 - 2012-05-25 02:00 - 00963884 _____ C:\Windows\SysWOW64\igkrng600.bin 2016-01-29 10:56 - 2012-05-25 02:00 - 00963884 _____ C:\Windows\system32\igkrng600.bin 2016-01-29 10:56 - 2012-05-25 02:00 - 00221264 _____ C:\Windows\SysWOW64\igfcg600m.bin 2016-01-29 10:56 - 2012-05-25 02:00 - 00221264 _____ C:\Windows\system32\igfcg600m.bin 2016-01-29 10:56 - 2012-05-25 02:00 - 00075776 _____ C:\Windows\system32\igdde64.dll 2016-01-29 10:56 - 2012-05-25 01:57 - 06324224 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll 2016-01-29 10:56 - 2012-05-25 01:56 - 00056832 _____ C:\Windows\SysWOW64\igdde32.dll 2016-01-29 10:56 - 2012-05-25 01:53 - 00581120 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumdx32.dll 2016-01-29 10:56 - 2012-05-25 01:50 - 09528832 _____ (Intel Corporation) C:\Windows\system32\igd10umd64.dll 2016-01-29 10:56 - 2012-05-25 01:45 - 07988224 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll 2016-01-29 10:56 - 2012-05-25 01:40 - 18675712 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll 2016-01-29 10:56 - 2012-05-25 01:35 - 13913600 _____ C:\Windows\SysWOW64\ig4icd32.dll 2016-01-29 10:56 - 2012-05-25 01:33 - 00378368 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll 2016-01-29 10:56 - 2012-05-25 01:33 - 00287232 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00287232 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00287232 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00285696 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00285696 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00285184 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00285184 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00283648 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00283136 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00282624 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00282624 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc 2016-01-29 10:56 - 2012-05-25 01:33 - 00211303 _____ C:\Windows\system32\Gfxres.th-TH.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00198139 _____ C:\Windows\system32\Gfxres.el-GR.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00182706 _____ C:\Windows\system32\Gfxres.ru-RU.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00156233 _____ C:\Windows\system32\Gfxres.ar-SA.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00153167 _____ C:\Windows\system32\Gfxres.ja-JP.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00149009 _____ C:\Windows\system32\Gfxres.he-IL.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00140216 _____ C:\Windows\system32\Gfxres.it-IT.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00138727 _____ C:\Windows\system32\Gfxres.ko-KR.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00137846 _____ C:\Windows\system32\Gfxres.de-DE.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00137668 _____ C:\Windows\system32\Gfxres.es-ES.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00136603 _____ C:\Windows\system32\Gfxres.ro-RO.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00135628 _____ C:\Windows\system32\Gfxres.fr-FR.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00135370 _____ C:\Windows\system32\Gfxres.tr-TR.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00134836 _____ C:\Windows\system32\Gfxres.pt-BR.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00134412 _____ C:\Windows\system32\Gfxres.nl-NL.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00134384 _____ C:\Windows\system32\Gfxres.hu-HU.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00133846 _____ C:\Windows\system32\Gfxres.sv-SE.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00133709 _____ C:\Windows\system32\Gfxres.pt-PT.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00133404 _____ C:\Windows\system32\Gfxres.cs-CZ.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00133178 _____ C:\Windows\system32\Gfxres.pl-PL.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00132889 _____ C:\Windows\system32\Gfxres.fi-FI.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00132788 _____ C:\Windows\system32\Gfxres.sk-SK.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00131839 _____ C:\Windows\system32\Gfxres.hr-HR.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00128996 _____ C:\Windows\system32\Gfxres.sl-SI.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00128831 _____ C:\Windows\system32\Gfxres.nb-NO.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00128535 _____ C:\Windows\system32\Gfxres.da-DK.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl 2016-01-29 10:56 - 2012-05-25 01:33 - 00124052 _____ C:\Windows\system32\Gfxres.en-US.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00117636 _____ C:\Windows\system32\Gfxres.zh-TW.resources 2016-01-29 10:56 - 2012-05-25 01:33 - 00116348 _____ C:\Windows\system32\Gfxres.zh-CN.resources 2016-01-29 10:56 - 2012-05-25 01:32 - 00376320 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll 2016-01-29 10:56 - 2012-05-25 01:32 - 00146432 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll 2016-01-29 10:56 - 2012-05-25 01:32 - 00028672 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll 2016-01-29 10:56 - 2012-05-25 01:32 - 00004096 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll 2016-01-29 10:56 - 2012-05-25 01:31 - 09014784 _____ (Intel Corporation) C:\Windows\system32\igfxress.dll 2016-01-29 10:56 - 2012-05-25 01:31 - 00285696 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc 2016-01-29 10:56 - 2012-05-25 01:31 - 00142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll 2016-01-29 10:56 - 2012-05-25 01:28 - 00293888 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll 2016-01-29 10:56 - 2012-05-25 01:28 - 00024576 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll 2016-01-29 10:56 - 2012-05-25 01:26 - 02780160 _____ (Intel Corporation) C:\Windows\system32\igfxcmjit64.dll 2016-01-29 10:56 - 2012-05-25 01:26 - 02191872 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmjit32.dll 2016-01-29 10:56 - 2012-05-25 01:26 - 00246784 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll 2016-01-29 10:56 - 2012-05-25 01:26 - 00219136 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll 2016-01-29 10:39 - 2016-01-30 10:52 - 00000000 ____D C:\Update 2016-01-29 10:37 - 2016-01-29 10:37 - 25483032 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000260866.exe 2016-01-29 10:33 - 2016-01-29 10:33 - 00000000 ___HD C:\SPLASH.000 2016-01-29 10:32 - 2016-01-29 10:32 - 00000000 ___HD C:\SPLASH.SYS 2016-01-29 10:32 - 2016-01-29 10:32 - 00000000 ____D C:\Program Files (x86)\Downloaded Installations 2016-01-29 10:26 - 2016-01-29 10:28 - 266422568 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000257185.EXE 2016-01-29 10:23 - 2015-01-05 21:07 - 392242776 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000250759.exe 2016-01-29 10:19 - 2016-01-29 10:19 - 05032416 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000249241.exe 2016-01-29 10:10 - 2016-01-29 10:10 - 00000000 ____D C:\Users\Stephan Blank\Downloads\WWAN_Driver1_1_190 2016-01-29 10:10 - 2016-01-29 10:10 - 00000000 ____D C:\ProgramData\Wwan 2016-01-29 10:10 - 2016-01-29 10:10 - 00000000 ____D C:\ProgramData\QUALCOMM 2016-01-29 10:10 - 2016-01-29 10:10 - 00000000 ____D C:\Program Files (x86)\QUALCOMM 2016-01-29 10:09 - 2016-01-29 10:10 - 39267638 _____ C:\Users\Stephan Blank\Downloads\WWAN_Driver1_1_190.zip 2016-01-29 09:58 - 2016-01-29 09:58 - 50971445 _____ C:\Users\Stephan Blank\Downloads\SOAVCA-00245717-0042.zip 2016-01-28 14:04 - 2016-01-28 14:04 - 00002197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Smart Network.lnk 2016-01-28 13:58 - 2016-01-28 13:58 - 15198476 _____ C:\Users\Stephan Blank\Downloads\SOASNW-00247880-0042.zip 2016-01-28 13:53 - 2016-01-28 13:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATI Stream SDK v2 2016-01-28 13:53 - 2016-01-28 13:53 - 00000000 ____D C:\Program Files (x86)\ATI Stream 2016-01-28 13:44 - 2016-01-28 13:44 - 00000000 ____D C:\Users\Stephan Blank\AppData\LocalLow\Temp 2016-01-27 17:56 - 2016-01-27 17:56 - 03875192 _____ (Sony Corporation) C:\Users\Stephan Blank\Downloads\EP0000251540.exe 2016-01-27 17:48 - 2016-02-01 08:01 - 00000000 ____D C:\Windows\System32\Tasks\Sony Corporation 2016-01-27 17:44 - 2016-02-01 08:01 - 00000000 ____D C:\Program Files\Sony 2016-01-27 17:43 - 2016-01-27 17:43 - 00001531 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Control Center.lnk 2016-01-27 17:42 - 2016-02-01 08:01 - 00000000 ____D C:\Program Files (x86)\Sony 2016-01-27 17:33 - 2016-01-29 11:27 - 00000000 ____D C:\Program Files\Common Files\Sony Shared 2016-01-27 17:31 - 2016-01-27 17:31 - 00000000 ____D C:\Users\Stephan Blank\Documents\Bluetooth-Exchange-Ordner 2016-01-27 17:31 - 2016-01-27 17:31 - 00000000 ____D C:\Users\Stephan Blank\AppData\Local\Broadcom 2016-01-27 17:27 - 2016-01-27 17:27 - 00000000 ____D C:\Program Files\WIDCOMM 2016-01-27 17:27 - 2011-04-18 08:36 - 00344616 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwampfl.sys 2016-01-27 17:27 - 2011-04-18 08:36 - 00135720 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys 2016-01-27 17:27 - 2011-04-18 08:36 - 00102952 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys 2016-01-27 17:27 - 2011-04-18 08:36 - 00021544 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys 2016-01-27 17:27 - 2011-04-18 08:35 - 00039464 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys 2016-01-27 17:17 - 2016-01-27 17:17 - 00000000 ____D C:\Program Files (x86)\Renesas Electronics 2016-01-27 17:13 - 2016-01-29 10:58 - 00000000 ____D C:\Windows\SysWOW64\sda 2016-01-27 17:12 - 2012-01-03 03:21 - 00340072 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsPStor.sys 2016-01-27 17:09 - 2016-01-27 17:09 - 00000000 ___HD C:\Program Files (x86)\Temp 2016-01-27 17:09 - 2016-01-27 17:09 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2016-01-27 17:09 - 2016-01-27 17:09 - 00000000 ____D C:\Program Files\Realtek 2016-01-27 17:09 - 2011-04-17 14:16 - 02651240 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 02580824 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 02520936 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2016-01-27 17:09 - 2011-04-17 14:16 - 02051176 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 01239656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 01146984 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2016-01-27 17:09 - 2011-04-17 14:16 - 00618600 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00477800 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2016-01-27 17:09 - 2011-04-17 14:16 - 00372936 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00332392 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00307920 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00307920 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00220496 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\system32\SFNHK64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00201928 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00120208 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00099016 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00081232 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\system32\SFCOM64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00080488 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInst64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00078160 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\system32\SFAPO64.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00076488 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2016-01-27 17:09 - 2011-04-17 14:16 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 02197264 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 01770328 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 01716368 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 01325792 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 01178336 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 01110240 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00503520 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00489696 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00474336 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00419472 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00341336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00338336 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00334680 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00315616 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00268512 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00265440 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00200800 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00125584 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00124640 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00124128 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00123616 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00108960 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00106640 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll 2016-01-27 17:09 - 2011-04-17 14:15 - 00071824 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll 2016-01-27 17:09 - 2011-04-17 14:14 - 01251944 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll 2016-01-27 17:09 - 2011-04-17 14:14 - 00002204 _____ C:\Windows\system32\Drivers\RtPCEE3.DAT 2016-01-27 17:00 - 2016-01-27 17:00 - 00000000 ____D C:\Users\Stephan Blank\AppData\Roaming\Intel 2016-01-27 16:58 - 2016-01-27 16:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless 2016-01-27 16:58 - 2016-01-27 16:58 - 00000000 ____D C:\ProgramData\Intel 2016-01-27 16:58 - 2016-01-27 16:58 - 00000000 ____D C:\Program Files\Intel 2016-01-27 16:58 - 2016-01-27 16:58 - 00000000 ____D C:\Program Files (x86)\Cisco 2016-01-27 16:57 - 2016-01-27 16:57 - 00000000 ____D C:\Users\Stephan Blank\AppData\Roaming\Intel Corporation 2016-01-27 16:53 - 2016-01-27 16:53 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2016-01-27 16:52 - 2010-11-05 23:45 - 00438808 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStor.sys 2016-01-27 16:51 - 2016-01-27 16:51 - 12015134 _____ C:\Users\Stephan Blank\Downloads\INDOTH-00245071-0042.zip 2016-01-27 16:50 - 2016-01-27 16:50 - 00003898 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1453909801 2016-01-27 16:50 - 2016-01-27 16:50 - 00001174 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera beta.lnk 2016-01-27 16:50 - 2016-01-27 16:50 - 00000000 ____D C:\Users\Stephan Blank\AppData\Roaming\Opera Software 2016-01-27 16:50 - 2016-01-27 16:50 - 00000000 ____D C:\Users\Stephan Blank\AppData\Local\Opera Software 2016-01-27 16:49 - 2016-01-27 16:50 - 00000000 ____D C:\Program Files (x86)\Opera beta 2016-01-27 16:47 - 2016-01-27 16:47 - 00000000 ____D C:\ProgramData\Emsisoft 2016-01-27 16:33 - 2016-01-27 16:33 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2016-01-27 16:26 - 2016-02-02 11:06 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware 2016-01-27 16:26 - 2016-01-27 16:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware 2016-01-27 16:19 - 2011-04-17 15:02 - 00056344 _____ (Intel Corporation) C:\Windows\system32\Drivers\HECIx64.sys 2016-01-27 16:19 - 2011-04-17 15:02 - 00008192 _____ C:\Windows\system32\Drivers\IntelMEFWVer.dll 2016-01-27 16:16 - 2011-03-01 17:23 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll 2016-01-27 16:10 - 2016-01-27 16:10 - 00003222 _____ C:\Windows\System32\Tasks\{C689FB4B-0AE2-4AEE-B354-AB4CF4315EDC} 2016-01-27 16:10 - 2016-01-27 16:10 - 00000000 ____D C:\Infineon 2016-01-27 16:07 - 2016-01-27 16:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrueSuite 2016-01-27 16:07 - 2016-01-27 16:07 - 00000000 ____D C:\Windows\system32\wocaffe 2016-01-27 16:07 - 2016-01-27 16:07 - 00000000 ____D C:\ProgramData\TrueSuite 2016-01-27 16:07 - 2016-01-27 16:07 - 00000000 ____D C:\ProgramData\Downloaded Installations 2016-01-27 16:07 - 2016-01-27 16:07 - 00000000 ____D C:\Program Files\TrueSuite 2016-01-27 16:02 - 2016-01-29 12:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-01-27 16:02 - 2016-01-29 10:58 - 00000000 ____D C:\Program Files (x86)\Realtek 2016-01-27 16:02 - 2011-03-01 18:38 - 00425064 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2016-01-27 16:02 - 2011-03-01 18:38 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2016-01-27 16:02 - 2011-03-01 18:38 - 00074272 _____ C:\Windows\system32\RtNicProp64.dll 2016-01-27 16:00 - 2016-01-27 16:00 - 00000000 ____D C:\ProgramData\ATI 2016-01-27 15:57 - 2016-01-27 15:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center 2016-01-27 15:57 - 2016-01-27 15:57 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2016-01-27 15:57 - 2016-01-27 15:57 - 00000000 ____D C:\Program Files (x86)\AMD APP 2016-01-27 15:55 - 2011-12-22 08:30 - 09360896 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2016-01-27 15:55 - 2011-12-22 08:27 - 23336960 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2016-01-27 15:55 - 2011-12-22 08:02 - 17940992 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2016-01-27 15:55 - 2011-12-22 08:00 - 00166664 _____ C:\Windows\system32\atiapfxx.blb 2016-01-27 15:55 - 2011-12-22 07:59 - 00688128 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2016-01-27 15:55 - 2011-12-22 07:59 - 00151552 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2016-01-27 15:55 - 2011-12-22 07:55 - 00485376 _____ (AMD) C:\Windows\system32\atieclxx.exe 2016-01-27 15:55 - 2011-12-22 07:54 - 00204288 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2016-01-27 15:55 - 2011-12-22 07:53 - 00356352 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\atipdlxx.dll 2016-01-27 15:55 - 2011-12-22 07:53 - 00120320 _____ (AMD) C:\Windows\system32\atitmm64.dll 2016-01-27 15:55 - 2011-12-22 07:53 - 00016384 _____ (AMD) C:\Windows\system32\atimuixx.dll 2016-01-27 15:55 - 2011-12-22 07:52 - 00059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll 2016-01-27 15:55 - 2011-12-22 07:52 - 00043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2016-01-27 15:55 - 2011-12-22 07:49 - 04219904 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2016-01-27 15:55 - 2011-12-22 07:39 - 05008384 _____ (ATI Technologies Inc. ) C:\Windows\system32\atidxx64.dll 2016-01-27 15:55 - 2011-12-22 07:34 - 08489472 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2016-01-27 15:55 - 2011-12-22 07:34 - 00051200 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2016-01-27 15:55 - 2011-12-22 07:34 - 00046080 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2016-01-27 15:55 - 2011-12-22 07:34 - 00044544 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2016-01-27 15:55 - 2011-12-22 07:34 - 00044032 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2016-01-27 15:55 - 2011-12-22 07:30 - 01113088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6v.dll 2016-01-27 15:55 - 2011-12-22 07:29 - 06847488 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2016-01-27 15:55 - 2011-12-22 07:29 - 01828864 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll 2016-01-27 15:55 - 2011-12-22 07:27 - 04330496 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2016-01-27 15:55 - 2011-12-22 07:25 - 01127552 _____ C:\Windows\system32\atiumd6a.cap 2016-01-27 15:55 - 2011-12-22 07:22 - 04017152 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2016-01-27 15:55 - 2011-12-22 07:21 - 01127552 _____ C:\Windows\SysWOW64\atiumdva.cap 2016-01-27 15:55 - 2011-12-22 07:13 - 00262144 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2016-01-27 15:55 - 2011-12-22 07:13 - 00014848 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2016-01-27 15:55 - 2011-12-22 07:13 - 00012800 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2016-01-27 15:55 - 2011-12-22 07:12 - 00309760 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2016-01-27 15:55 - 2011-12-22 07:12 - 00039936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2016-01-27 15:55 - 2011-12-22 07:12 - 00032768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2016-01-27 15:55 - 2011-12-22 07:11 - 00031744 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2016-01-27 15:55 - 2011-12-22 07:11 - 00029184 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2016-01-27 15:55 - 2011-12-22 07:10 - 00053760 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2016-01-27 15:55 - 2011-12-22 07:10 - 00053760 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2016-01-27 15:55 - 2011-12-22 07:10 - 00053248 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2016-01-27 15:55 - 2011-12-22 07:10 - 00052736 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2016-01-27 15:55 - 2011-12-22 07:10 - 00052736 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2016-01-27 15:55 - 2011-08-09 12:44 - 01981696 _____ C:\Windows\system32\iglhxa64.cpa 2016-01-27 15:55 - 2011-08-09 12:44 - 00376832 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll 2016-01-27 15:55 - 2011-08-09 12:44 - 00376832 _____ (Intel Corporation) C:\Windows\system32\iglhsip64.dll 2016-01-27 15:55 - 2011-08-09 12:44 - 00098304 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhcp32.dll 2016-01-27 15:55 - 2011-08-09 12:44 - 00098304 _____ (Intel Corporation) C:\Windows\system32\iglhcp64.dll 2016-01-27 15:55 - 2011-08-09 12:44 - 00059243 _____ C:\Windows\system32\iglhxo64.vp 2016-01-27 15:55 - 2011-08-09 12:44 - 00059174 _____ C:\Windows\system32\iglhxg64.vp 2016-01-27 15:55 - 2011-08-09 12:44 - 00059062 _____ C:\Windows\system32\iglhxc64.vp 2016-01-27 15:55 - 2011-08-09 12:44 - 00001074 _____ C:\Windows\system32\iglhxa64.vp 2016-01-27 15:55 - 2011-05-19 10:13 - 00032635 _____ C:\Windows\atiogl.xml 2016-01-27 15:55 - 2011-04-20 18:30 - 00233765 _____ C:\Windows\system32\atiicdxx.dat 2016-01-27 15:55 - 2011-03-17 19:51 - 00003929 _____ C:\Windows\SysWOW64\atipblag.dat 2016-01-27 15:55 - 2011-03-17 19:51 - 00003929 _____ C:\Windows\system32\atipblag.dat 2016-01-27 15:54 - 2016-01-27 15:57 - 00000000 ____D C:\Program Files\ATI Technologies 2016-01-27 15:51 - 2016-02-01 10:24 - 00086160 _____ C:\Users\Stephan Blank\AppData\Local\GDIPFONTCACHEV1.DAT 2016-01-27 15:50 - 2016-01-27 15:50 - 00000000 ____D C:\Users\Stephan Blank\AppData\Roaming\ATI 2016-01-27 15:50 - 2016-01-27 15:50 - 00000000 ____D C:\Users\Stephan Blank\AppData\Local\ATI 2016-01-27 15:48 - 2016-01-27 15:48 - 00000000 _____ C:\Windows\ativpsrm.bin 2016-01-27 15:47 - 2016-01-27 16:58 - 00000000 ____D C:\Program Files\Common Files\Intel 2016-01-27 15:47 - 2016-01-27 16:52 - 00000000 ____D C:\Program Files (x86)\Intel 2016-01-27 15:47 - 2016-01-27 15:47 - 00000000 ____D C:\Intel 2016-01-27 15:46 - 2016-01-27 15:56 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2016-01-27 15:46 - 2016-01-27 15:46 - 00000000 ____D C:\Program Files\ATI 2016-01-27 15:46 - 2011-02-25 14:30 - 00003143 _____ C:\Windows\SysWOW64\atipblup.dat 2016-01-27 15:46 - 2011-02-25 14:30 - 00003143 _____ C:\Windows\system32\atipblup.dat 2016-01-27 15:45 - 2012-05-25 01:32 - 00390144 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll 2016-01-27 15:45 - 2012-05-25 01:32 - 00110080 _____ (Intel Corporation) C:\Windows\system32\hccutils.dll 2016-01-27 15:45 - 2012-05-25 01:32 - 00062464 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll 2016-01-27 15:45 - 2011-12-22 07:58 - 00811008 _____ (ATI Technologies Inc. ) C:\Windows\system32\aticfx64.dll 2016-01-27 15:45 - 2011-12-22 07:55 - 00462848 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll 2016-01-27 15:45 - 2011-12-22 07:53 - 00423424 _____ (ATI Technologies, Inc.) C:\Windows\system32\atipdl64.dll 2016-01-27 15:45 - 2011-12-22 07:29 - 03810816 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2016-01-27 15:45 - 2011-12-22 07:21 - 05486592 _____ (ATI Technologies Inc. ) C:\Windows\system32\atiumd64.dll 2016-01-27 15:45 - 2011-12-22 07:20 - 00058880 _____ (AMD) C:\Windows\system32\coinst.dll 2016-01-27 15:45 - 2011-12-22 07:13 - 00366592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2016-01-27 15:45 - 2011-12-22 07:11 - 00040960 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2016-01-27 15:45 - 2011-12-22 07:11 - 00038912 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2016-01-27 15:45 - 2011-04-17 13:29 - 00145804 _____ C:\Windows\SysWOW64\igcompkrng600.bin 2016-01-27 15:45 - 2011-04-17 13:29 - 00145804 _____ C:\Windows\system32\igcompkrng600.bin 2016-01-27 15:45 - 2011-04-17 13:28 - 00094208 _____ C:\Windows\system32\IccLibDll_x64.dll 2016-01-27 15:45 - 2011-04-17 13:28 - 00000151 _____ C:\Windows\system32\GfxUI.exe.config 2016-01-27 15:45 - 2011-04-17 13:26 - 00118784 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atibtmon.exe 2016-01-27 15:44 - 2016-01-29 09:59 - 00000021 _____ C:\Windows\Model.txt 2016-01-27 15:43 - 2016-02-01 07:58 - 00000000 ____D C:\ProgramData\Sony Corporation 2016-01-27 15:35 - 2016-01-29 18:54 - 00001409 _____ C:\Users\Stephan Blank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-01-27 15:34 - 2016-02-01 14:08 - 00000000 ____D C:\Users\Stephan Blank 2016-01-27 15:34 - 2016-01-27 15:34 - 00000020 ___SH C:\Users\Stephan Blank\ntuser.ini 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Vorlagen 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Startmenü 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Netzwerkumgebung 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Lokale Einstellungen 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Eigene Dateien 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Druckumgebung 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Documents\Eigene Videos 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Documents\Eigene Musik 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Documents\Eigene Bilder 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\AppData\Local\Verlauf 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\AppData\Local\Anwendungsdaten 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 _SHDL C:\Users\Stephan Blank\Anwendungsdaten 2016-01-27 15:34 - 2016-01-27 15:34 - 00000000 ____D C:\Users\Stephan Blank\AppData\Local\VirtualStore 2016-01-27 15:34 - 2011-04-12 08:54 - 00000000 ____D C:\Users\Stephan Blank\AppData\Roaming\Media Center Programs 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Videos 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Vorlagen 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Startmenü 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Programme 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\ProgramData\Vorlagen 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\ProgramData\Startmenü 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\ProgramData\Favoriten 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\ProgramData\Dokumente 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2016-01-27 15:33 - 2016-01-27 15:33 - 00000000 _SHDL C:\Dokumente und Einstellungen 2016-01-27 15:29 - 2016-01-27 15:29 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2016-01-27 15:29 - 2016-01-27 15:29 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2016-01-27 15:25 - 2016-01-29 21:55 - 00000000 ____D C:\Windows\Panther 2016-01-27 15:25 - 2016-01-27 15:25 - 00008192 __RSH C:\BOOTSECT.BAK 2016-01-27 15:25 - 2010-11-21 04:23 - 00383786 __RSH C:\bootmgr ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-02-02 10:47 - 2009-07-14 05:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-02-02 10:47 - 2009-07-14 05:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-02-02 10:19 - 2011-04-12 08:43 - 00698926 _____ C:\Windows\system32\perfh007.dat 2016-02-02 10:19 - 2011-04-12 08:43 - 00149034 _____ C:\Windows\system32\perfc007.dat 2016-02-02 10:19 - 2009-07-14 06:13 - 01618320 _____ C:\Windows\system32\PerfStringBackup.INI 2016-02-02 10:19 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2016-02-02 09:45 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-02-02 08:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat 2016-02-01 10:22 - 2009-07-14 05:45 - 00341880 _____ C:\Windows\system32\FNTCACHE.DAT 2016-02-01 09:37 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2016-01-30 12:07 - 2011-04-12 08:54 - 00000000 ____D C:\Windows\ShellNew 2016-01-30 12:07 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2016-01-29 19:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2016-01-29 19:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2016-01-29 19:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism 2016-01-29 19:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers 2016-01-29 18:38 - 2011-04-12 08:55 - 00000000 ____D C:\Program Files\Windows Journal 2016-01-29 18:38 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2016-01-29 18:38 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2016-01-29 18:38 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System 2016-01-29 11:02 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2016-01-29 10:33 - 2011-07-14 20:02 - 00000074 ____H C:\splash.idx 2016-01-27 16:04 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2016-01-27 15:33 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT 2016-01-27 15:32 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2016-01-27 15:29 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2016-01-27 15:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep 2016-01-27 15:25 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template Einige Dateien in TEMP: ==================== C:\Users\Stephan Blank\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-02-01 15:15 ==================== Ende von FRST.txt ============================ |
02.02.2016, 11:19 | #17 |
| Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B) Und hier noch der Addition.txt:
__________________Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:27-01-2016 durchgeführt von Stephan Blank (2016-02-02 11:06:34) Gestartet von C:\Users\Stephan Blank\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2016-01-27 14:33:58) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-726656456-2167350209-4180810081-500 - Administrator - Disabled) Gast (S-1-5-21-726656456-2167350209-4180810081-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-726656456-2167350209-4180810081-1002 - Limited - Enabled) Stephan Blank (S-1-5-21-726656456-2167350209-4180810081-1000 - Administrator - Enabled) => C:\Users\Stephan Blank ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Emsisoft Anti-Malware (Enabled - Up to date) {15510D9D-6530-DA29-224F-7BA1BDD1CB58} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Emsisoft Anti-Malware (Enabled - Up to date) {AE30EC79-430A-D5A7-18FF-40D3C65681E5} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov) ATI Catalyst Install Manager (HKLM\...\{158BEEC4-CC30-BF2F-248D-B52AF953E9C1}) (Version: 3.0.829.0 - ATI Technologies, Inc.) ATI Stream SDK v2 Developer (HKLM\...\{22441735-5983-AD2A-5CC5-FA2CCD7EF732}) (Version: 2.3.0.0 - ATI Technologies Inc.) AuthenTec TrueSuite (HKLM\...\{81B43AC9-B334-45D0-8D15-0A3642AFBDA1}) (Version: 4.0.100.16 - AuthenTec, Inc.) BioEdit (HKLM-x32\...\{AF6D9313-E338-48F0-9B0C-7DE20EDB99CF}) (Version: 7.2.5.0 - Tom Hall) CCleaner (HKLM\...\CCleaner) (Version: 5.14 - Piriform) Chromas Lite 2.1.1 (HKLM-x32\...\Chromas Lite) (Version: 2.1.1 - Technelysium Pty Ltd) Emsisoft Anti-Malware (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 10.0 - Emsisoft Ltd.) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.3.0.118 - Foxit Software Inc.) ImageMagick 6.7.5-7 Q16 (2012-03-01) (HKLM-x32\...\ImageMagick 6.7.5 Q16_is1) (Version: 6.7.5 - ImageMagick Studio LLC) Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3086 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{1927E640-A2C6-4BA7-8F43-FFD2AE3DFCF3}) (Version: 14.0.2000 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation) Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Media Gallery (Version: 2.0.0.11150 - Sony Corporation) Hidden MEGA6 .06 (HKLM-x32\...\{EE7E4984-0208-48E7-959C-A5F5F06F0DE0}_is1) (Version: .06 - Center for Evolutionary Medicine and Informatics) Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 44.0 - Mozilla) Mozilla Thunderbird 38.5.1 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 38.5.1 (x86 de)) (Version: 38.5.1 - Mozilla) Opera beta 35.0.2066.35 (HKLM-x32\...\Opera 35.0.2066.35) (Version: 35.0.2066.35 - Opera Software) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.2.2 - pdfforge) PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden Qualcomm Gobi 2000 Package for Sony (HKLM-x32\...\{C3081594-4B05-4FBD-A7C3-70DE2988C9B7}) (Version: 1.1.190 - QUALCOMM) Quick Web Access (HKLM-x32\...\splashtop) (Version: 1.4.7.0 - Sony Corporation) Quick Web Access (x32 Version: 1.4.7.0 - Sony Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.40.126.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6225 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.92 - Realtek Semiconductor Corp.) Remote Keyboard (x32 Version: 1.1.1.07060 - Sony Corporation) Hidden Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.34.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0 - Renesas Electronics Corporation) Hidden Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) SSLx64 (Version: 1.0.0 - Sony Corporation ) Hidden SSLx86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden VAIO - Media Gallery - VAIO Personalization Manager Update (HKLM\...\{50A7190B-5DA6-4A51-B275-3D413E617BA6}) (Version: 4.2.5.07160 - Sony Corporation) VAIO - Media Gallery (HKLM-x32\...\{DD696AF7-8A89-41D5-976A-2053E41A69BE}) (Version: 2.2.3.04170 - Sony Corporation) VAIO - Remote-Tastatur (HKLM-x32\...\{7396FB15-9AB4-4B78-BDD8-24A9C15D2C65}) (Version: 1.1.0.07060 - Sony Corporation) VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 4.5.0.03040 - Sony Corporation) VAIO Event Service (HKLM-x32\...\{73D8886A-D416-4687-B609-0D3836BA410C}) (Version: 5.5.0.03040 - Sony Corporation) VAIO Smart Network (HKLM-x32\...\{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}) (Version: 3.5.0.03280 - Sony Corporation) VCCx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden VESx64 (Version: 1.0.0 - Sony Corporation) Hidden VESx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN) VPMx64 (Version: 1.0.0 - Sony Corporation ) Hidden VSNx64 (Version: 1.0.0 - Sony Corporation) Hidden WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.6300 - Broadcom Corporation) WinEdt 7 (HKU\S-1-5-21-726656456-2167350209-4180810081-1000\...\WinEdt 7) (Version: 7.1 - WinEdt Team) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {5CC7F33E-EB86-4364-9FFE-1F35F0FAA7DB} - System32\Tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start => C:\Program Files\Sony\VAIO Smart Network\VSNClient Task: {709772FF-881A-448D-BD37-2B8B0B2499B3} - System32\Tasks\Sony Corporation\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2011-02-14] (Sony Corporation) Task: {8361A510-7074-4A9E-9EF3-F0026FC2A66E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation) Task: {83B6F012-ECE9-4ECF-BFC7-BAC5F764026A} - System32\Tasks\Sony Corporation\VAIO Boot Manager\VAIO Boot Manager => C:\Program Files (x86)\Sony\VAIO Boot Manager\SetProcessTask.exe [2011-05-26] (Sony Corporation) Task: {8BCC7669-778A-4135-AFDF-32F44E8F4808} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-01-15] (Piriform Ltd) Task: {9AA85A17-88AC-42A6-BD77-00F417D6C277} - System32\Tasks\{C689FB4B-0AE2-4AEE-B354-AB4CF4315EDC} => pcalua.exe -a "C:\Users\Stephan Blank\AppData\Local\Temp\Temp1_IFAOTH-00231600-0042.zip\IFAOTH-00231600-0042.EXE" Task: {A1C995D5-CC3F-411E-B8DB-72AFBD370A24} - System32\Tasks\Opera scheduled Autoupdate 1453909801 => C:\Program Files (x86)\Opera beta\launcher.exe [2016-01-25] (Opera Software) Task: {BD58A529-807E-4C88-A078-9954813899E5} - System32\Tasks\Sony Corporation\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2011-02-14] (Sony Corporation) Task: {CF1683E8-8EAF-48ED-B7B9-58BFE013674C} - System32\Tasks\{61805B8C-1129-481D-88AB-13483DF6B542} => pcalua.exe -a "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe" -d "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller" Task: {D8CA4EC2-A1BD-437F-8104-7D92AD2227B3} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation) Task: {D8E80A45-2FB1-43E9-BE12-4D456480E897} - System32\Tasks\Sony Corporation\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2011-02-14] (Sony Corporation) Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2011-01-05 12:53 - 2011-01-05 12:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2016-01-27 15:45 - 2011-04-17 13:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-01-05 12:53 - 2011-01-05 12:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2011-12-01 12:27 - 2011-12-01 12:27 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2011-12-22 01:53 - 2011-12-22 01:53 - 00243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2016-01-27 17:43 - 2011-03-05 16:42 - 00013824 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll 2016-01-29 19:12 - 2016-01-29 19:12 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\93182e9779b8be0f688fd0784df6d7fb\IsdiInterop.ni.dll 2016-01-27 16:52 - 2010-11-05 23:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2016-01-27 16:50 - 2016-01-25 09:24 - 62318200 _____ () C:\Program Files (x86)\Opera beta\35.0.2066.35\opera.dll 2016-01-27 16:50 - 2016-01-25 09:24 - 02074232 _____ () C:\Program Files (x86)\Opera beta\35.0.2066.35\libglesv2.dll 2016-01-27 16:50 - 2016-01-25 09:24 - 00081528 _____ () C:\Program Files (x86)\Opera beta\35.0.2066.35\libegl.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-726656456-2167350209-4180810081-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Stephan Blank\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{844EC904-9940-4991-8DE2-3A494376F659}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ==================== Wiederherstellungspunkte ========================= 29-01-2016 22:09:16 Entfernt Xperia Link 30-01-2016 10:50:09 Entfernt VAIO Care 30-01-2016 12:05:32 Installed Microsoft Office Home and Student 2010 31-01-2016 18:39:20 Windows Update 01-02-2016 07:58:34 Entfernt VAIO Update 01-02-2016 07:59:27 Removed VAIO Care. 01-02-2016 09:22:35 Windows Update 01-02-2016 09:55:23 Windows Update 01-02-2016 10:51:37 Installed PDF Architect 4 View Module 01-02-2016 10:52:10 Installed PDF Architect 4 Edit Module 01-02-2016 10:53:22 Installed PDF Architect 4 Create Module 01-02-2016 10:54:59 Installed Manager 01-02-2016 20:25:42 JRT Pre-Junkware Removal 02-02-2016 09:44:21 Revo Uninstaller's restore point - Adobe Flash Player 20 NPAPI 02-02-2016 09:54:39 Revo Uninstaller's restore point - Adobe Flash Player 20 NPAPI 02-02-2016 10:14:04 Revo Uninstaller's restore point - Mozilla Firefox 44.0 (x86 de) ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (02/02/2016 09:47:36 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/02/2016 09:44:38 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe, Version: 0.0.0.0, Zeitstempel: 0x56944f86 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x764148f3 ID des fehlerhaften Prozesses: 0x7e4 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_20_0_0_286.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_20_0_0_286.exe2 Berichtskennung: FlashPlayerPlugin_20_0_0_286.exe3 Error: (02/02/2016 09:44:28 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe, Version: 0.0.0.0, Zeitstempel: 0x56944f86 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x764148f3 ID des fehlerhaften Prozesses: 0x1068 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_20_0_0_286.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_20_0_0_286.exe2 Berichtskennung: FlashPlayerPlugin_20_0_0_286.exe3 Error: (02/02/2016 09:44:18 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe, Version: 0.0.0.0, Zeitstempel: 0x56944f86 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x764148f3 ID des fehlerhaften Prozesses: 0x95c Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_20_0_0_286.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_20_0_0_286.exe2 Berichtskennung: FlashPlayerPlugin_20_0_0_286.exe3 Error: (02/02/2016 09:44:08 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe, Version: 0.0.0.0, Zeitstempel: 0x56944f86 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x764148f3 ID des fehlerhaften Prozesses: 0x1298 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_20_0_0_286.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_20_0_0_286.exe2 Berichtskennung: FlashPlayerPlugin_20_0_0_286.exe3 Error: (02/02/2016 09:43:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe, Version: 0.0.0.0, Zeitstempel: 0x56944f86 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x764148f3 ID des fehlerhaften Prozesses: 0xc70 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_20_0_0_286.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_20_0_0_286.exe2 Berichtskennung: FlashPlayerPlugin_20_0_0_286.exe3 Error: (02/02/2016 09:43:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe, Version: 0.0.0.0, Zeitstempel: 0x56944f86 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x764148f3 ID des fehlerhaften Prozesses: 0x14b0 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_20_0_0_286.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_20_0_0_286.exe2 Berichtskennung: FlashPlayerPlugin_20_0_0_286.exe3 Error: (02/02/2016 09:43:37 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe, Version: 0.0.0.0, Zeitstempel: 0x56944f86 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x764148f3 ID des fehlerhaften Prozesses: 0x109c Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_20_0_0_286.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_20_0_0_286.exe2 Berichtskennung: FlashPlayerPlugin_20_0_0_286.exe3 Error: (02/02/2016 09:43:27 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe, Version: 0.0.0.0, Zeitstempel: 0x56944f86 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x764148f3 ID des fehlerhaften Prozesses: 0xa64 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_20_0_0_286.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_20_0_0_286.exe2 Berichtskennung: FlashPlayerPlugin_20_0_0_286.exe3 Error: (02/02/2016 09:43:17 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe, Version: 0.0.0.0, Zeitstempel: 0x56944f86 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x764148f3 ID des fehlerhaften Prozesses: 0xe54 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_20_0_0_286.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_20_0_0_286.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_20_0_0_286.exe2 Berichtskennung: FlashPlayerPlugin_20_0_0_286.exe3 Systemfehler: ============= Error: (02/02/2016 10:53:55 AM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (02/02/2016 10:53:53 AM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (02/02/2016 09:46:35 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\System32\IWMSSvc.dll Fehlercode: 87 Error: (02/02/2016 09:44:46 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (02/02/2016 09:00:21 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (02/02/2016 08:23:12 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (02/02/2016 08:17:46 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 01.02.2016 um 20:56:13 unerwartet heruntergefahren. Error: (02/01/2016 05:55:27 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (02/01/2016 05:44:12 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\Windows\System32\IWMSSvc.dll Error: (02/01/2016 05:44:12 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\Windows\System32\IWMSSvc.dll ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz Prozentuale Nutzung des RAM: 28% Installierter physikalischer RAM: 8107.86 MB Verfügbarer physikalischer RAM: 5782.24 MB Summe virtueller Speicher: 16213.93 MB Verfügbarer virtueller Speicher: 13335.92 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:465.76 GB) (Free:348.68 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 000796F5) Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
02.02.2016, 11:28 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B) FRST-Fix
__________________Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ |
02.02.2016, 11:55 | #19 |
| Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B) Hier ist das Fixlog: Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:27-01-2016 durchgeführt von Stephan Blank (2016-02-02 11:43:26) Run:1 Gestartet von C:\Users\Stephan Blank\Desktop Geladene Profile: Stephan Blank (Verfügbare Profile: Stephan Blank) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** emptytemp: ***************** EmptyTemp: => 55.2 MB temporäre Dateien entfernt. Das System musste neu gestartet werden. ==== Ende von Fixlog 11:43:28 ==== |
02.02.2016, 12:06 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B) Okay, dann Kontrollscans mit (1) MBAM, (2) ESET und (3) SecurityCheck bitte: 1. Schritt: MBAM Downloade Dir bitte Malwarebytes Anti-Malware
2. Schritt: ESET ESET Online Scanner
3. Schritt: SecurityCheck Downloade Dir bitte SecurityCheck und:
__________________ Logfiles bitte immer in CODE-Tags posten |
02.02.2016, 15:32 | #21 |
| Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B) Den Malewarebytes hatte ich bereits zuvor installiert. Der hatte auch bei einem anderen Lauf nichts gefunden. Hier das log: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 02.02.2016 Suchlaufzeit: 12:10 Protokolldatei: mbamlog.txt Administrator: Ja Version: 2.2.0.1024 Malware-Datenbank: v2016.02.02.01 Rootkit-Datenbank: v2016.01.20.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Stephan Blank Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 325151 Abgelaufene Zeit: 7 Min., 33 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswerte: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 0 (keine bösartigen Elemente erkannt) Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=834224a58301404a84ed93101843761e # end=init # utc_time=2016-02-01 08:20:16 # local_time=2016-02-01 09:20:16 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=834224a58301404a84ed93101843761e # end=init # utc_time=2016-02-02 11:21:19 # local_time=2016-02-02 12:21:19 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 27934 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=834224a58301404a84ed93101843761e # end=updated # utc_time=2016-02-02 11:25:13 # local_time=2016-02-02 12:25:13 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=834224a58301404a84ed93101843761e # engine=27934 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2016-02-02 12:35:47 # local_time=2016-02-02 01:35:47 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 17767 206046397 0 0 # compatibility_mode_1='Emsisoft Anti-Malware' # compatibility_mode=16901 16777213 100 86 6061 146981413 0 0 # scanned=227769 # found=2 # cleaned=0 # scan_time=4233 sh=148BC745CB91B9DFDD09FF955DCE01CA6DC10F5A ft=1 fh=cce6864c1bf4fbda vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Stephan Blank\Downloads\PDFCreator-2_2_2-setup.exe" sh=5A092347FE283ACA26E1D29B57687D4EBE362DD0 ft=1 fh=9d6602c6828fdac0 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Stephan Blank\Downloads\SQLite - CHIP-Installer.exe" Code:
ATTFilter Results of screen317's Security Check version 1.009 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Emsisoft Anti-Malware Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Mozilla Thunderbird (38.5.1) ````````Process Check: objlist.exe by Laurent```````` Emsisoft Anti-Malware a2service.exe Emsisoft Anti-Malware a2guard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
02.02.2016, 15:40 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B) FRST-Fix Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Stephan Blank\Downloads\PDFCreator-2_2_2-setup.exe C:\Users\Stephan Blank\Downloads\SQLite - CHIP-Installer.exe emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
03.02.2016, 17:17 | #23 |
| Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B) Ok, hatte ich gestern bereits gemacht. Hier ist dann das fixlog: Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:27-01-2016 durchgeführt von Stephan Blank (2016-02-02 16:30:01) Run:2 Gestartet von C:\Users\Stephan Blank\Desktop Geladene Profile: Stephan Blank (Verfügbare Profile: Stephan Blank) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** C:\Users\Stephan Blank\Downloads\PDFCreator-2_2_2-setup.exe C:\Users\Stephan Blank\Downloads\SQLite - CHIP-Installer.exe emptytemp: ***************** C:\Users\Stephan Blank\Downloads\PDFCreator-2_2_2-setup.exe => erfolgreich verschoben C:\Users\Stephan Blank\Downloads\SQLite - CHIP-Installer.exe => erfolgreich verschoben EmptyTemp: => 6 MB temporäre Dateien entfernt. Das System musste neu gestartet werden. ==== Ende von Fixlog 16:30:06 ==== |
03.02.2016, 19:29 | #24 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B)Zitat:
Sieht soweit ok aus Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Win 7: Trojaner entdeckt: trojan.genericKD.2180047 (B) |
absturz, anti-malware, computer, explorer, fehlermeldung, firefox, folge, freude, gen, google, infiziert, internet-explorer, neu, neuinstallation, neustart, opera, probleme, programm, rechner, scan, suche, trojaner, vaio, win, windows, öffnen |