![]() |
Plagegeister aller Art und deren Bekämpfung: Permanentes Herunterfahren nach angeblichem Windows UpdateWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
Hallo und
Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!

Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)

Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
![]() | #2 |
Permanentes Herunterfahren nach angeblichem Windows Update Hallo und
Ich weiß nicht welche Anleitung du da befolgst, aber meine ganz sicher nicht.
![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
![]() | #3 |
| ![]() Permanentes Herunterfahren nach angeblichem Windows Update Hi und danke für die schnelle Antwort =) das kam bei dem scann raus:
hoffe jetzt passt alles =)
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-02-2016 Ran by SYSTEM on MININT-KLHHCN6 (29-02-2016 11:54:28) Running from F:\ Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Englisch (USA) Internet Explorer Version 11 Boot Mode: Recovery Default: ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11543656 2010-10-26] (Realtek Semiconductor) HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-10-20] (Lenovo) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-14] (Logitech Inc.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-10] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [jmekey] => C:\windows\jmesoft\hotkey.exe HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-26] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Lenovo Eye Distance System] => C:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe [265216 2010-09-09] (Lenovo) HKLM-x32\...\Run: [Lenovo Dynamic Brightness System] => C:\Program Files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe [285696 2010-10-08] (Lenovo) HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-04] (CyberLink) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310128 2013-02-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [fst_de_92] => [X] HKLM-x32\...\Run: [AnyProtect Scanner] => "C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe" HKLM-x32\...\Run: [t4pc_en_8] => [X] HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [191528 2014-07-04] (Geek Software GmbH) HKU\JB\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\JB\...\Run: [ICQ] => C:\Program Files (x86)\ICQ7.7\ICQ.exe [127040 2012-01-23] (ICQ, LLC.) HKU\JB\...\Run: [MSConfig] => C:\Users\JB\uzybsgkl.exe [44810240 2016-02-26] (Remarbati) IFEO\DatamngrCoordinator.exe: [Debugger] tasklist.exe Startup: C:\Users\JB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kvvpa.html [2016-02-26] () Startup: C:\Users\JB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kvvpa.png [2016-02-26] () Startup: C:\Users\JB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kvvpa.txt [2016-02-26] () GroupPolicy: Restriction - Chrome <======= ATTENTION ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [476936 2013-08-08] (BitRaider, LLC) S2 HubService; C:\Users\JB\AppData\Roaming\Hub Timer\hub.exe [536576 2014-07-30] () S2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-15] () S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.292\McCHSvc.exe [293128 2016-02-05] (McAfee, Inc.) S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation) S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S2 Wajam Web Enhancer; C:\Program Files\WajaWebEnhancer\wajam_64.exe [2041344 2015-07-20] () <==== ATTENTION S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) S2 McAfee SiteAdvisor Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [X] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2013-08-08] (BitRaider) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S3 FsUsbExDisk; C:\windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () S3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-12] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-12] (Microsoft Corporation) S0 WinI2C-DDC; C:\Windows\System32\drivers\DDCDrv.sys [20832 2008-04-08] (Nicomsoft Ltd.) S0 WinI2C-DDC; C:\Windows\SysWOW64\drivers\DDCDrv.sys [15712 2010-03-22] (Nicomsoft Ltd.) S1 {9a9157bb-003e-4fef-8bd1-c09bc4586a28}Gw64; C:\Windows\System32\drivers\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}Gw64.sys [61120 2014-07-08] (StdLib) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-02-29 01:11 - 2016-02-29 01:12 - 00050628 _____ C:\Users\JB\Downloads\Addition.txt 2016-02-29 01:10 - 2016-02-29 01:12 - 00081801 _____ C:\Users\JB\Downloads\FRST.txt 2016-02-29 01:09 - 2016-02-29 11:54 - 00000000 ____D C:\FRST 2016-02-29 01:08 - 2016-02-29 01:09 - 02371072 _____ (Farbar) C:\Users\JB\Downloads\FRST64.exe 2016-02-29 01:08 - 2016-02-29 01:08 - 01722368 _____ (Farbar) C:\Users\JB\Downloads\FRST.exe 2016-02-28 11:51 - 2016-02-28 11:51 - 00000000 ____D C:\Windows\Temp0FEDB5CF-06FB-821F-B21D-38AF8BEBCFBF-Signatures 2016-02-28 11:12 - 2013-10-01 18:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys 2016-02-28 11:12 - 2013-10-01 18:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe 2016-02-28 11:12 - 2013-10-01 18:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll 2016-02-28 11:12 - 2013-10-01 17:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll 2016-02-28 11:12 - 2013-10-01 17:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll 2016-02-28 11:12 - 2013-10-01 17:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\System32\tsgqec.dll 2016-02-28 11:12 - 2013-10-01 17:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll 2016-02-28 11:12 - 2013-10-01 16:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\System32\rdvidcrl.dll 2016-02-28 11:12 - 2013-10-01 16:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2016-02-28 11:12 - 2013-10-01 16:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2016-02-28 11:12 - 2013-10-01 16:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe 2016-02-28 11:12 - 2013-10-01 16:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\System32\wksprt.exe 2016-02-28 11:12 - 2013-10-01 15:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2016-02-28 11:12 - 2013-10-01 15:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\System32\mstsc.exe 2016-02-28 11:12 - 2013-10-01 15:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2016-02-28 11:12 - 2013-10-01 14:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2016-02-28 11:12 - 2013-10-01 12:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\System32\mstscax.dll 2016-02-28 11:12 - 2013-10-01 12:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2016-02-28 11:10 - 2012-08-23 06:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\System32\rdpudd.dll 2016-02-28 11:10 - 2012-08-23 06:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys 2016-02-28 11:10 - 2012-08-23 06:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbGD.sys 2016-02-28 11:10 - 2012-08-23 05:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll 2016-02-28 11:10 - 2012-08-23 03:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2016-02-28 11:10 - 2012-08-23 02:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll 2016-02-28 11:10 - 2012-08-23 01:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll 2016-02-28 10:18 - 2016-02-28 11:52 - 00000000 ____D C:\Program Files\Microsoft Security Client 2016-02-28 10:18 - 2016-02-28 11:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2016-02-28 10:14 - 2016-02-28 14:46 - 00002154 _____ C:\Windows\epplauncher.mif 2016-02-28 09:41 - 2015-08-05 09:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\System32\icaapi.dll 2016-02-28 09:41 - 2015-08-05 09:06 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys 2016-02-28 09:40 - 2015-12-16 10:55 - 00069120 _____ (Microsoft Corporation) C:\Windows\System32\nlsbres.dll 2016-02-28 09:40 - 2015-12-16 10:53 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\kbdgeoqw.dll 2016-02-28 09:40 - 2015-12-16 10:53 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDAZEL.DLL 2016-02-28 09:40 - 2015-12-16 10:53 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDAZE.DLL 2016-02-28 09:40 - 2015-12-16 10:48 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL 2016-02-28 09:40 - 2015-12-16 10:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll 2016-02-28 09:40 - 2015-12-16 10:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL 2016-02-28 09:40 - 2015-12-16 10:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00994760 _____ (Microsoft Corporation) C:\Windows\System32\ucrtbase.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00063840 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-private-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00020832 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-math-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00019808 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-multibyte-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-string-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-stdio-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00016224 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-runtime-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00015712 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-convert-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-time-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00013664 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-filesystem-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-process-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-heap-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-conio-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-utility-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-locale-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-environment-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-1.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l2-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-timezone-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l2-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2016-02-28 09:39 - 2016-01-11 11:11 - 01684416 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2016-02-28 09:06 - 2016-02-28 09:07 - 00375520 _____ C:\Windows\Minidump\022816-19172-01.dmp 2016-02-28 08:00 - 2016-02-28 08:00 - 01702688 _____ C:\Windows\Minidump\022816-30763-01.dmp 2016-02-28 07:26 - 2016-02-28 07:26 - 01702688 _____ C:\Windows\Minidump\022816-28438-01.dmp 2016-02-28 04:34 - 2016-02-28 04:34 - 00375584 _____ C:\Windows\Minidump\022816-16629-01.dmp 2016-02-27 19:40 - 2016-02-27 19:41 - 01702688 _____ C:\Windows\Minidump\022816-25974-01.dmp 2016-02-27 18:38 - 2016-02-27 18:38 - 01315576 _____ C:\Windows\Minidump\022816-16957-01.dmp 2016-02-27 18:19 - 2016-02-27 18:19 - 00644120 _____ C:\Windows\Minidump\022816-16286-01.dmp 2016-02-27 17:49 - 2016-02-27 17:49 - 00375560 _____ C:\Windows\Minidump\022816-20077-01.dmp 2016-02-27 04:19 - 2016-02-27 04:19 - 01180384 _____ C:\Windows\Minidump\022716-20638-01.dmp 2016-02-27 03:27 - 2016-02-27 03:27 - 01702688 _____ C:\Windows\Minidump\022716-25771-01.dmp 2016-02-26 18:07 - 2016-02-26 18:07 - 00644080 _____ C:\Windows\Minidump\022716-28750-01.dmp 2016-02-26 17:55 - 2016-02-26 17:55 - 00000000 ____D C:\Program Files\McAfee Security Scan 2016-02-26 17:54 - 2016-02-26 17:54 - 00000000 ____D C:\Users\JB\AppData\Local\Macromedia 2016-02-26 17:53 - 2016-02-29 02:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-02-26 17:53 - 2016-02-26 17:55 - 00001964 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2016-02-26 17:53 - 2016-02-26 17:55 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2016-02-26 17:53 - 2016-02-26 17:53 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-02-26 17:53 - 2016-02-26 17:53 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2016-02-26 17:53 - 2016-02-26 17:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-02-26 17:52 - 2016-02-26 17:52 - 01190608 _____ (Adobe Systems Incorporated) C:\Users\JB\Downloads\flashplayer20_ga_install(1).exe 2016-02-26 17:51 - 2016-02-26 17:51 - 00242312 _____ C:\Users\JB\Downloads\Firefox Setup Stub 44.0.2.exe 2016-02-26 17:44 - 2016-02-27 03:27 - 00181778 _____ C:\Windows\ntbtlog.txt 2016-02-26 17:44 - 2016-02-26 17:44 - 01702688 _____ C:\Windows\Minidump\022716-28532-01.dmp 2016-02-26 16:43 - 2016-02-26 16:43 - 00375544 _____ C:\Windows\Minidump\022716-28438-01.dmp 2016-02-26 16:41 - 2016-02-26 16:41 - 00011710 _____ C:\Users\JB\AppData\Recovery+kvvpa.html 2016-02-26 16:41 - 2016-02-26 16:41 - 00001961 _____ C:\Users\JB\AppData\Recovery+kvvpa.txt 2016-02-26 16:36 - 2016-02-26 16:36 - 00011710 _____ C:\Users\JB\AppData\LocalLow\Recovery+kvvpa.html 2016-02-26 16:36 - 2016-02-26 16:36 - 00001961 _____ C:\Users\JB\AppData\LocalLow\Recovery+kvvpa.txt 2016-02-26 16:25 - 2016-02-26 16:41 - 00011710 _____ C:\Users\JB\AppData\Roaming\Recovery+kvvpa.html 2016-02-26 16:25 - 2016-02-26 16:41 - 00001961 _____ C:\Users\JB\AppData\Roaming\Recovery+kvvpa.txt 2016-02-26 16:25 - 2016-02-26 16:36 - 00011710 _____ C:\Users\JB\AppData\Local\Recovery+kvvpa.html 2016-02-26 16:25 - 2016-02-26 16:36 - 00001961 _____ C:\Users\JB\AppData\Local\Recovery+kvvpa.txt 2016-02-26 16:24 - 2016-02-26 16:25 - 00011710 _____ C:\ProgramData\Recovery+kvvpa.html 2016-02-26 16:24 - 2016-02-26 16:25 - 00001961 _____ C:\ProgramData\Recovery+kvvpa.txt 2016-02-26 16:13 - 2016-02-28 17:12 - 00000000 ____D C:\Users\JB\AppData\Local\Opics 2016-02-26 16:13 - 2016-02-28 10:33 - 00000000 ___HD C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} 2016-02-26 16:13 - 2016-02-26 16:45 - 00049972 _____ C:\Users\JB\AppData\Roaming\part.autolabel.xml 2016-02-26 16:13 - 2016-02-26 16:26 - 00000000 ____D C:\Users\JB\AppData\Local\Ewwtion 2016-02-26 16:13 - 2016-02-26 16:13 - 44810240 ____H (Remarbati) C:\Users\JB\uzybsgkl.exe 2016-02-26 15:12 - 2016-02-26 15:12 - 00025041 _____ C:\Users\JB\AppData\Roaming\tweakRemoveTempFiles_ar.p5p 2016-02-26 15:12 - 2016-02-26 15:12 - 00024931 _____ C:\Users\JB\AppData\Roaming\Edge.mi 2016-02-26 15:12 - 2016-02-26 15:12 - 00001577 _____ C:\Users\JB\AppData\Roaming\MongooseMoonlightOphthalmometry 2016-02-26 14:44 - 2016-02-26 14:44 - 00067072 _____ (Paragon Software Group) C:\Users\JB\AppData\Roaming\neguses.dll 2016-02-10 09:05 - 2016-01-22 12:31 - 00387784 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2016-02-10 09:05 - 2016-01-22 12:10 - 00341200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-02-10 09:05 - 2016-01-21 22:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2016-02-10 09:05 - 2016-01-21 22:41 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2016-02-10 09:05 - 2016-01-21 22:40 - 00571904 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2016-02-10 09:05 - 2016-01-21 22:40 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec 2016-02-10 09:05 - 2016-01-21 22:40 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2016-02-10 09:05 - 2016-01-21 22:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2016-02-10 09:05 - 2016-01-21 22:33 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2016-02-10 09:05 - 2016-01-21 22:32 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2016-02-10 09:05 - 2016-01-21 22:29 - 06052352 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2016-02-10 09:05 - 2016-01-21 22:27 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2016-02-10 09:05 - 2016-01-21 22:27 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2016-02-10 09:05 - 2016-01-21 22:27 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2016-02-10 09:05 - 2016-01-21 22:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2016-02-10 09:05 - 2016-01-21 22:17 - 00489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2016-02-10 09:05 - 2016-01-21 22:09 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2016-02-10 09:05 - 2016-01-21 22:08 - 00107520 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll 2016-02-10 09:05 - 2016-01-21 22:05 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2016-02-10 09:05 - 2016-01-21 22:04 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2016-02-10 09:05 - 2016-01-21 22:02 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-02-10 09:05 - 2016-01-21 22:02 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2016-02-10 09:05 - 2016-01-21 22:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2016-02-10 09:05 - 2016-01-21 22:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2016-02-10 09:05 - 2016-01-21 22:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2016-02-10 09:05 - 2016-01-21 22:00 - 00152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll 2016-02-10 09:05 - 2016-01-21 22:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-02-10 09:05 - 2016-01-21 21:55 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2016-02-10 09:05 - 2016-01-21 21:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2016-02-10 09:05 - 2016-01-21 21:51 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-02-10 09:05 - 2016-01-21 21:51 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2016-02-10 09:05 - 2016-01-21 21:50 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2016-02-10 09:05 - 2016-01-21 21:48 - 00718336 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2016-02-10 09:05 - 2016-01-21 21:47 - 00798208 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2016-02-10 09:05 - 2016-01-21 21:46 - 02123264 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2016-02-10 09:05 - 2016-01-21 21:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2016-02-10 09:05 - 2016-01-21 21:43 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2016-02-10 09:05 - 2016-01-21 21:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-02-10 09:05 - 2016-01-21 21:38 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2016-02-10 09:05 - 2016-01-21 21:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2016-02-10 09:05 - 2016-01-21 21:35 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-02-10 09:05 - 2016-01-21 21:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2016-02-10 09:05 - 2016-01-21 21:34 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-02-10 09:05 - 2016-01-21 21:33 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2016-02-10 09:05 - 2016-01-21 21:31 - 02597376 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2016-02-10 09:05 - 2016-01-21 21:27 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-02-10 09:05 - 2016-01-21 21:25 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-02-10 09:05 - 2016-01-21 21:24 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-02-10 09:05 - 2016-01-21 21:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2016-02-10 09:05 - 2016-01-21 21:08 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2016-02-10 09:05 - 2016-01-21 21:07 - 02120704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-02-10 09:05 - 2016-01-21 21:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-02-10 09:04 - 2016-02-06 02:48 - 25839104 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2016-02-10 09:04 - 2016-02-06 02:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2016-02-10 09:04 - 2016-02-06 02:24 - 02887680 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2016-02-10 09:04 - 2016-02-06 02:11 - 00615936 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2016-02-10 09:04 - 2016-02-06 02:10 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2016-02-10 09:04 - 2016-02-06 02:01 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-02-10 09:04 - 2016-02-06 01:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2016-02-10 09:04 - 2016-02-06 01:43 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-02-10 09:04 - 2016-02-06 01:38 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-02-10 09:04 - 2016-02-06 01:37 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2016-02-10 09:04 - 2016-02-06 01:32 - 14458368 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2016-02-10 09:04 - 2016-02-06 01:16 - 12857856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-02-10 09:04 - 2016-02-06 01:09 - 01547264 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2016-02-10 09:04 - 2016-02-06 00:54 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-02-10 09:04 - 2016-01-16 11:06 - 00025024 _____ (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe 2016-02-10 09:04 - 2016-01-16 10:54 - 01162240 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 01362944 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 00696320 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 00677376 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 00499200 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll 2016-02-10 09:04 - 2016-01-06 11:02 - 00275456 _____ (Microsoft Corporation) C:\Windows\System32\InkEd.dll 2016-02-10 09:04 - 2016-01-06 11:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\jnwmon.dll 2016-02-10 09:04 - 2016-01-06 10:41 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2016-02-10 08:58 - 2016-01-21 22:27 - 05573056 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2016-02-10 08:58 - 2016-01-21 22:27 - 00154560 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2016-02-10 08:58 - 2016-01-21 22:27 - 00095680 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2016-02-10 08:58 - 2016-01-21 22:24 - 01733592 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00215040 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll 2016-02-10 08:58 - 2016-01-21 22:19 - 01214464 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll 2016-02-10 08:58 - 2016-01-21 22:19 - 00344064 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll 2016-02-10 08:58 - 2016-01-21 22:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll 2016-02-10 08:58 - 2016-01-21 22:18 - 00961024 _____ (Microsoft Corporation) C:\Windows\System32\CPFilters.dll 2016-02-10 08:58 - 2016-01-21 22:18 - 00723968 _____ (Microsoft Corporation) C:\Windows\System32\EncDec.dll 2016-02-10 08:58 - 2016-01-21 22:18 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll 2016-02-10 08:58 - 2016-01-21 22:17 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll 2016-02-10 08:58 - 2016-01-21 22:17 - 00312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2016-02-10 08:58 - 2016-01-21 22:17 - 00159744 _____ (Microsoft Corporation) C:\Windows\System32\mtxoci.dll 2016-02-10 08:58 - 2016-01-21 22:16 - 01461248 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2016-02-10 08:58 - 2016-01-21 22:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll 2016-02-10 08:58 - 2016-01-21 22:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll 2016-02-10 08:58 - 2016-01-21 22:15 - 01163264 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll 2016-02-10 08:58 - 2016-01-21 22:15 - 00730112 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2016-02-10 08:58 - 2016-01-21 22:15 - 00422400 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll 2016-02-10 08:58 - 2016-01-21 22:13 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-02-10 08:58 - 2016-01-21 22:13 - 03938752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-02-10 08:58 - 2016-01-21 22:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll 2016-02-10 08:58 - 2016-01-21 22:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll 2016-02-10 08:58 - 2016-01-21 22:13 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00880128 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00686080 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:09 - 01314328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-02-10 08:58 - 2016-01-21 22:05 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-02-10 08:58 - 2016-01-21 22:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-02-10 08:58 - 2016-01-21 22:04 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2016-02-10 08:58 - 2016-01-21 22:04 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe 2016-02-10 08:58 - 2016-01-21 21:07 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe 2016-02-10 08:58 - 2016-01-21 21:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-02-10 08:58 - 2016-01-21 21:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe 2016-02-10 08:58 - 2016-01-21 20:59 - 00159232 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys 2016-02-10 08:58 - 2016-01-21 20:58 - 00290816 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys 2016-02-10 08:58 - 2016-01-21 20:58 - 00129024 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys 2016-02-10 08:58 - 2016-01-21 20:57 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe 2016-02-10 08:58 - 2016-01-21 20:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe 2016-02-10 08:58 - 2016-01-21 20:53 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-02-10 08:58 - 2016-01-21 20:53 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-02-10 08:58 - 2016-01-21 20:53 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-02-10 08:58 - 2016-01-21 20:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-02-10 08:58 - 2016-01-21 20:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-02-10 08:58 - 2016-01-21 20:51 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 20:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 20:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 20:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-02-10 08:58 - 2016-01-16 11:01 - 02085888 _____ (Microsoft Corporation) C:\Windows\System32\ole32.dll 2016-02-10 08:58 - 2016-01-16 10:36 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2016-02-10 08:58 - 2016-01-11 11:05 - 03169792 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2016-02-10 08:58 - 2016-01-11 11:05 - 00192512 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2016-02-10 08:58 - 2016-01-11 11:05 - 00098816 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2016-02-10 08:58 - 2016-01-11 10:52 - 00091136 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll 2016-02-10 08:58 - 2016-01-11 10:47 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2016-02-10 08:58 - 2016-01-11 10:26 - 02610176 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2016-02-10 08:58 - 2016-01-11 10:24 - 00709120 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2016-02-10 08:58 - 2016-01-11 10:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2016-02-10 08:58 - 2016-01-11 10:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll 2016-02-10 08:58 - 2016-01-11 10:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2016-02-10 08:58 - 2016-01-11 10:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll 2016-02-10 08:58 - 2016-01-11 10:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\System32\wu.upgrade.ps.dll 2016-02-10 08:58 - 2016-01-11 10:14 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2016-02-10 08:58 - 2016-01-11 10:14 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2016-02-10 08:58 - 2016-01-11 10:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2016-02-10 08:58 - 2016-01-11 10:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2016-02-10 08:58 - 2016-01-07 09:53 - 03211776 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2016-02-10 08:58 - 2016-01-07 09:42 - 00141312 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys 2016-02-10 08:57 - 2016-01-21 22:19 - 14179840 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll 2016-02-10 08:57 - 2016-01-21 22:15 - 01866752 _____ (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll 2016-02-10 08:57 - 2016-01-21 22:12 - 01940992 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll 2016-02-10 08:57 - 2016-01-21 22:05 - 12877824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2016-02-10 08:57 - 2016-01-21 22:00 - 01498624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2016-02-10 08:57 - 2016-01-21 21:59 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2016-02-10 08:57 - 2016-01-21 21:19 - 03231232 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2016-02-10 08:57 - 2016-01-21 21:12 - 02973184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-02-29 02:33 - 2011-10-20 11:39 - 00295061 _____ C:\Windows\System32\fastboot.set 2016-02-29 02:33 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-02-29 02:01 - 2011-10-20 11:38 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-02-29 01:36 - 2009-07-13 20:45 - 00020688 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-02-29 01:36 - 2009-07-13 20:45 - 00020688 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-02-29 01:34 - 2011-10-20 12:01 - 00699884 _____ C:\Windows\System32\perfh007.dat 2016-02-29 01:34 - 2011-10-20 12:01 - 00149766 _____ C:\Windows\System32\perfc007.dat 2016-02-29 01:34 - 2009-07-13 21:13 - 01622300 _____ C:\Windows\System32\PerfStringBackup.INI 2016-02-29 01:34 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf 2016-02-29 01:28 - 2011-10-20 11:38 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-02-29 01:14 - 2012-03-15 11:15 - 00000000 ____D C:\Users\JB\AppData\Roaming\SoftGrid Client 2016-02-29 00:24 - 2014-07-11 11:33 - 00000306 __RSH C:\ProgramData\ntuser.pol 2016-02-29 00:24 - 2009-07-13 20:45 - 00277160 _____ C:\Windows\System32\FNTCACHE.DAT 2016-02-28 14:47 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2016-02-28 09:06 - 2014-05-23 14:02 - 528800483 _____ C:\Windows\MEMORY.DMP 2016-02-28 09:06 - 2014-05-23 14:02 - 00000000 ____D C:\Windows\Minidump 2016-02-27 18:07 - 2011-12-27 10:58 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2016-02-26 18:07 - 2011-12-24 08:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-02-26 17:53 - 2014-03-18 12:31 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-02-26 17:53 - 2012-03-05 08:00 - 00000000 ____D C:\Users\JB\AppData\Local\Adobe 2016-02-26 17:53 - 2011-12-24 11:11 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-02-26 17:53 - 2011-10-20 11:36 - 00000000 ____D C:\ProgramData\McAfee 2016-02-26 17:36 - 2015-04-04 17:00 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2016-02-26 17:36 - 2015-04-04 17:00 - 00000000 ___SD C:\Windows\System32\GWX 2016-02-26 17:21 - 2015-02-16 17:55 - 00000000 ____D C:\Program Files\WajaWebEnhancer 2016-02-26 17:21 - 2011-12-27 10:58 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2016-02-26 17:21 - 2011-12-24 08:44 - 00000000 ____D C:\Users\JB\Desktop\Pc-Programme (Standard) 2016-02-26 17:21 - 2011-12-24 08:41 - 00000000 ____D C:\users\JB 2016-02-26 17:21 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration 2016-02-26 16:46 - 2014-08-08 19:57 - 00000000 ____D C:\Users\JB\AppData\LocalLow\Internet Explorer BHO 2016-02-26 16:46 - 2011-10-20 11:17 - 00000000 ____D C:\Intel 2016-02-26 16:41 - 2014-07-28 09:12 - 00000000 ____D C:\Users\JB\AppData\Roaming\TuneUp Software 2016-02-26 16:41 - 2012-10-30 15:09 - 00000000 ____D C:\Users\JB\AppData\Roaming\vlc 2016-02-26 16:41 - 2011-12-24 12:23 - 00000000 ____D C:\Users\JB\AppData\Roaming\WinRAR 2016-02-26 16:41 - 2011-12-24 09:19 - 00000000 ____D C:\Users\JB\Desktop\Alben 2016-02-26 16:41 - 2011-12-24 09:02 - 00000000 ____D C:\Users\JB\AppData\Roaming\TS3Client 2016-02-26 16:39 - 2015-12-19 11:45 - 00000000 ____D C:\Users\JB\AppData\Roaming\TeamViewer 2016-02-26 16:39 - 2015-02-16 17:54 - 00000000 ____D C:\Users\JB\AppData\Roaming\RHEng 2016-02-26 16:39 - 2014-08-08 19:57 - 00000000 ____D C:\Users\JB\AppData\Roaming\Security Systems 2016-02-26 16:39 - 2014-07-12 07:02 - 00000000 ____D C:\Users\JB\AppData\Roaming\Systweak 2016-02-26 16:39 - 2013-07-23 17:32 - 00000000 ____D C:\Users\JB\AppData\Roaming\Riot Games 2016-02-26 16:39 - 2013-06-24 13:10 - 00000000 ____D C:\Users\JB\AppData\Roaming\RIFT 2016-02-26 16:39 - 2013-02-14 08:00 - 00000000 ____D C:\Users\JB\AppData\Roaming\Samsung 2016-02-26 16:39 - 2012-03-15 11:14 - 00000000 ____D C:\Users\JB\AppData\Roaming\TP 2016-02-26 16:39 - 2011-12-24 08:48 - 00000000 ____D C:\Users\JB\AppData\Roaming\Mozilla 2016-02-26 16:37 - 2011-12-24 08:47 - 00000000 ____D C:\Users\JB\AppData\Roaming\Macromedia 2016-02-26 16:37 - 2011-12-24 08:41 - 00000000 ____D C:\Users\JB\AppData\Roaming\Media Center Programs 2016-02-26 16:36 - 2015-06-02 13:03 - 00000000 ____D C:\Users\JB\AppData\Local\TERA 2016-02-26 16:36 - 2014-11-21 11:35 - 00000000 __SHD C:\Users\JB\AppData\LocalLow\EmieBrowserModeList 2016-02-26 16:36 - 2014-08-08 19:57 - 00000000 ____D C:\Users\JB\AppData\Roaming\Hub Timer 2016-02-26 16:36 - 2014-07-28 09:12 - 00000000 ____D C:\Users\JB\AppData\Local\TuneUp Software 2016-02-26 16:36 - 2014-07-28 09:08 - 00000000 ____D C:\Users\JB\AppData\Roaming\DVDVideoSoft 2016-02-26 16:36 - 2014-07-12 19:08 - 00000000 ____D C:\Users\JB\AppData\LocalLow\Temp 2016-02-26 16:36 - 2014-07-10 13:28 - 00000000 ____D C:\Users\JB\AppData\Local\Windows Live 2016-02-26 16:36 - 2014-07-10 13:28 - 00000000 ____D C:\Users\JB\AppData\Local\{C71E1463-1F4E-4EBA-BE33-928CF04C947B} 2016-02-26 16:36 - 2014-04-25 07:25 - 00000000 ____D C:\Users\JB\AppData\Roaming\Logitech 2016-02-26 16:36 - 2014-04-25 07:25 - 00000000 ____D C:\Users\JB\AppData\Roaming\Logishrd 2016-02-26 16:36 - 2014-04-19 17:26 - 00000000 __SHD C:\Users\JB\AppData\LocalLow\EmieUserList 2016-02-26 16:36 - 2014-04-19 17:26 - 00000000 __SHD C:\Users\JB\AppData\LocalLow\EmieSiteList 2016-02-26 16:36 - 2014-02-07 07:03 - 00000000 ____D C:\Users\JB\AppData\Roaming\Battle.net 2016-02-26 16:36 - 2013-07-23 19:22 - 00000000 ____D C:\Users\JB\AppData\Roaming\LolClient 2016-02-26 16:36 - 2012-04-16 05:43 - 00000000 ____D C:\Users\JB\AppData\Local\{FFCB9107-F76B-4CC4-90A6-4247576C6A7C} 2016-02-26 16:36 - 2012-03-18 15:38 - 00000000 ____D C:\Users\JB\AppData\Local\{D57DB36C-7837-43C7-86A4-73F27034B04A} 2016-02-26 16:36 - 2012-03-18 15:38 - 00000000 ____D C:\Users\JB\AppData\Local\{36DA50EA-877B-4DCD-9B66-887849A68C4D} 2016-02-26 16:36 - 2012-03-05 08:00 - 00000000 ____D C:\Users\JB\AppData\LocalLow\Adobe 2016-02-26 16:36 - 2011-12-24 08:54 - 00000000 ____D C:\Users\JB\AppData\Roaming\ICQ 2016-02-26 16:36 - 2011-12-24 08:46 - 00000000 ____D C:\Users\JB\AppData\Roaming\Adobe 2016-02-26 16:36 - 2011-12-24 08:45 - 00000000 ____D C:\Users\JB\AppData\Roaming\ATI 2016-02-26 16:36 - 2011-12-24 08:41 - 00000000 ____D C:\Users\JB\AppData\Local\VirtualStore 2016-02-26 16:35 - 2015-04-24 13:38 - 00000000 ____D C:\Users\JB\AppData\Local\Steam 2016-02-26 16:35 - 2014-10-04 08:42 - 00000000 ____D C:\Users\JB\AppData\Local\PDF24 2016-02-26 16:35 - 2014-08-11 08:48 - 00000000 ____D C:\Users\JB\AppData\Local\Microsoft Help 2016-02-26 16:35 - 2013-08-08 19:44 - 00000000 ____D C:\Users\JB\AppData\Local\SWTOR 2016-02-26 16:35 - 2013-08-08 09:47 - 00000000 ____D C:\Users\JB\AppData\Local\SWTORPerf 2016-02-26 16:35 - 2013-02-14 08:00 - 00000000 ____D C:\Users\JB\AppData\Local\Samsung 2016-02-26 16:35 - 2012-03-15 11:15 - 00000000 ____D C:\Users\JB\AppData\Local\SoftGrid Client 2016-02-26 16:35 - 2011-12-24 08:48 - 00000000 ____D C:\Users\JB\AppData\Local\Mozilla 2016-02-26 16:35 - 2011-12-24 08:43 - 00000000 ____D C:\Users\JB\AppData\Local\Power2Go 2016-02-26 16:26 - 2015-12-14 10:16 - 00000000 ____D C:\Users\JB\AppData\Local\FluxSoftware 2016-02-26 16:26 - 2014-11-21 11:35 - 00000000 __SHD C:\Users\JB\AppData\Local\EmieBrowserModeList 2016-02-26 16:26 - 2014-07-11 11:02 - 00000000 ____D C:\Users\JB\AppData\Local\globalUpdate 2016-02-26 16:26 - 2014-07-11 11:01 - 00000000 ____D C:\Users\JB\AppData\Local\Genesis_07111901 2016-02-26 16:26 - 2014-04-25 07:28 - 00000000 ____D C:\Users\JB\AppData\Local\Logitech 2016-02-26 16:26 - 2014-04-19 17:26 - 00000000 __SHD C:\Users\JB\AppData\Local\EmieUserList 2016-02-26 16:26 - 2014-04-19 17:26 - 00000000 __SHD C:\Users\JB\AppData\Local\EmieSiteList 2016-02-26 16:26 - 2014-02-08 08:05 - 00000000 ____D C:\Users\JB\AppData\Local\Blizzard 2016-02-26 16:26 - 2014-02-07 07:03 - 00000000 ____D C:\Users\JB\AppData\Local\Battle.net 2016-02-26 16:26 - 2014-01-13 08:33 - 00000000 ____D C:\Users\JB\AppData\Local\FalloutNV 2016-02-26 16:26 - 2013-09-10 19:02 - 00000000 ____D C:\Users\JB\AppData\Local\Blizzard Entertainment 2016-02-26 16:26 - 2013-02-14 07:51 - 00000000 ____D C:\Users\JB\AppData\Local\Downloaded Installations 2016-02-26 16:26 - 2011-12-24 08:45 - 00000000 ____D C:\Users\JB\AppData\Local\Google 2016-02-26 16:26 - 2011-12-24 08:43 - 00000000 ____D C:\Users\JB\AppData\Local\Lenovo 2016-02-26 16:25 - 2015-06-02 13:03 - 00000000 ____D C:\ProgramData\boost_interprocess 2016-02-26 16:25 - 2014-07-28 09:11 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2016-02-26 16:25 - 2014-07-28 09:11 - 00000000 ____D C:\ProgramData\TuneUp Software 2016-02-26 16:25 - 2014-04-25 07:28 - 00000000 ____D C:\ProgramData\LogiShrd 2016-02-26 16:25 - 2014-03-18 12:31 - 00000000 ____D C:\ProgramData\Google 2016-02-26 16:25 - 2013-02-14 07:57 - 00000000 ____D C:\ProgramData\Samsung 2016-02-26 16:25 - 2012-07-12 22:30 - 00000000 ____D C:\ProgramData\InstallShield 2016-02-26 16:25 - 2012-04-26 03:37 - 00000000 ____D C:\ProgramData\Mozilla 2016-02-26 16:25 - 2012-03-15 13:26 - 00000000 ____D C:\ProgramData\VirtualizedApplications 2016-02-26 16:25 - 2011-12-24 11:00 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2016-02-26 16:25 - 2011-12-24 08:54 - 00000000 ____D C:\ProgramData\ICQ 2016-02-26 16:25 - 2011-12-24 08:45 - 00000000 ____D C:\Users\JB\AppData\Local\ATI 2016-02-26 16:25 - 2011-10-21 08:53 - 00000000 ____D C:\ProgramData\Lenovo 2016-02-26 16:25 - 2011-10-20 11:43 - 00000000 ____D C:\ProgramData\Temp 2016-02-26 16:25 - 2011-10-20 11:43 - 00000000 ____D C:\ProgramData\CyberLink 2016-02-26 16:25 - 2011-10-20 11:39 - 00000000 ____D C:\ProgramData\Partner 2016-02-26 16:24 - 2013-08-08 09:47 - 00000000 ____D C:\ProgramData\BitRaider 2016-02-26 16:24 - 2013-07-23 17:36 - 00000000 ____D C:\Riot Games 2016-02-26 16:24 - 2012-08-04 18:09 - 00000000 ____D C:\ProgramData\Battle.net 2016-02-26 16:24 - 2012-06-29 07:04 - 00000000 ____D C:\ProgramData\Age of Empires 3 2016-02-26 16:24 - 2012-03-01 09:52 - 00000000 ____D C:\ProgramData\Adobe 2016-02-26 16:24 - 2011-10-20 11:37 - 00000000 ____D C:\ProgramData\ATI 2016-02-26 16:24 - 2011-10-20 11:33 - 00000000 ____D C:\Templenovo 2016-02-26 08:50 - 2011-12-24 08:46 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2016-02-26 08:49 - 2014-02-07 07:03 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-02-19 13:50 - 2015-01-17 14:17 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm 2016-02-14 04:00 - 2014-03-31 14:43 - 00000000 ____D C:\Program Files (x86)\Diablo III 2016-02-11 10:20 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache 2016-02-11 08:46 - 2015-04-15 20:00 - 00000000 ____D C:\Windows\System32\appraiser 2016-02-11 08:46 - 2014-05-05 21:18 - 00000000 ___SD C:\Windows\System32\CompatTel 2016-02-11 08:46 - 2011-02-15 02:41 - 00000000 ____D C:\Program Files\Windows Journal 2016-02-10 13:32 - 2013-08-14 17:01 - 00000000 ____D C:\Windows\System32\MRT 2016-02-10 13:30 - 2012-02-24 14:51 - 146614896 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2016-02-03 08:56 - 2011-10-20 11:38 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-02-03 08:56 - 2011-10-20 11:38 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore Files to move or delete: ==================== C:\ProgramData\08zo99od.odd C:\ProgramData\flashax10.exe C:\ProgramData\rj8jwdbg.fvv C:\Users\JB\uzybsgkl.exe ==================== Known DLLs (Whitelisted) ========================= ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe [2016-02-10 08:57] - [2016-01-21 21:19] - 3231232 ____A (Microsoft Corporation) 9D77CC4A36FEEA644D002CFB9B2D42C0 C:\Windows\SysWOW64\explorer.exe [2016-02-10 08:57] - [2016-01-21 21:12] - 2973184 ____A (Microsoft Corporation) 2A156D5EBF221EF2A6AE7CE452324DAC C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll [2015-12-09 09:04] - [2015-11-10 10:55] - 1008640 ____A (Microsoft Corporation) 06BF84D26A05D400F6B3FB3D3DE0B03A C:\Windows\SysWOW64\User32.dll [2015-12-09 09:04] - [2015-11-10 10:37] - 0833024 ____A (Microsoft Corporation) 0A78439765E31510D75C9E2284F3A722 C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\dnsapi.dll => MD5 is legit C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE Association (Whitelisted) ============= ==================== Restore Points ========================= Restore point date: 2016-02-26 17:36 Restore point date: 2016-02-28 09:41 Restore point date: 2016-02-28 10:17 Restore point date: 2016-02-28 14:52 ==================== Memory info =========================== Percentage of memory in use: 13% Total physical RAM: 6126.39 MB Available physical RAM: 5312.7 MB Total Virtual: 6124.59 MB Available Virtual: 5309.88 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:906.34 GB) (Free:665.19 GB) NTFS Drive e: (AOE3Y) (CDROM) (Total:0.54 GB) (Free:0 GB) CDFS Drive f: () (Removable) (Total:3.73 GB) (Free:3.67 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 04067489) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=906.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=25.1 GB) - (Type=12) ======================================================== Disk: 1 (Size: 3.7 GB) (Disk ID: 987FD79F) Partition 1: (Not Active) - (Size=3.7 GB) - (Type=0B) LastRegBack: 2016-02-27 15:46 ==================== End of FRST.txt ============================ --- --- --- |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Permanentes Herunterfahren nach angeblichem Windows Update FRST Anleitung bitte richtig lesen und auch so umsetzen. Ansonsten bitte ich um eine Erklärung warum du das so gemacht hast.
| ![]() Permanentes Herunterfahren nach angeblichem Windows Update So, ich habe jetzt alles nach Anleitung an einem "sauberen" PC gemacht: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-02-2016 Ran by SYSTEM on MININT-2M4HJJN (29-02-2016 14:05:24) Running from G:\ Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Englisch (USA) Internet Explorer Version 11 Boot Mode: Recovery Default: ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11543656 2010-10-26] (Realtek Semiconductor) HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-10-20] (Lenovo) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-14] (Logitech Inc.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-10] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [jmekey] => C:\windows\jmesoft\hotkey.exe HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-26] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Lenovo Eye Distance System] => C:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe [265216 2010-09-09] (Lenovo) HKLM-x32\...\Run: [Lenovo Dynamic Brightness System] => C:\Program Files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe [285696 2010-10-08] (Lenovo) HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-04] (CyberLink) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310128 2013-02-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [fst_de_92] => [X] HKLM-x32\...\Run: [AnyProtect Scanner] => "C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe" HKLM-x32\...\Run: [t4pc_en_8] => [X] HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [191528 2014-07-04] (Geek Software GmbH) HKU\JB\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\JB\...\Run: [ICQ] => C:\Program Files (x86)\ICQ7.7\ICQ.exe [127040 2012-01-23] (ICQ, LLC.) HKU\JB\...\Run: [MSConfig] => C:\Users\JB\uzybsgkl.exe [44810240 2016-02-26] (Remarbati) IFEO\DatamngrCoordinator.exe: [Debugger] tasklist.exe Startup: C:\Users\JB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kvvpa.html [2016-02-26] () Startup: C:\Users\JB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kvvpa.png [2016-02-26] () Startup: C:\Users\JB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kvvpa.txt [2016-02-26] () GroupPolicy: Restriction - Chrome <======= ATTENTION ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [476936 2013-08-08] (BitRaider, LLC) S2 HubService; C:\Users\JB\AppData\Roaming\Hub Timer\hub.exe [536576 2014-07-30] () S2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-15] () S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.292\McCHSvc.exe [293128 2016-02-05] (McAfee, Inc.) S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation) S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S2 Wajam Web Enhancer; C:\Program Files\WajaWebEnhancer\wajam_64.exe [2041344 2015-07-20] () <==== ATTENTION S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) S2 McAfee SiteAdvisor Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [X] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2013-08-08] (BitRaider) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S3 FsUsbExDisk; C:\windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () S3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-12] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-12] (Microsoft Corporation) S0 WinI2C-DDC; C:\Windows\System32\drivers\DDCDrv.sys [20832 2008-04-08] (Nicomsoft Ltd.) S0 WinI2C-DDC; C:\Windows\SysWOW64\drivers\DDCDrv.sys [15712 2010-03-22] (Nicomsoft Ltd.) S1 {9a9157bb-003e-4fef-8bd1-c09bc4586a28}Gw64; C:\Windows\System32\drivers\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}Gw64.sys [61120 2014-07-08] (StdLib) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-02-29 01:11 - 2016-02-29 01:12 - 00050628 _____ C:\Users\JB\Downloads\Addition.txt 2016-02-29 01:10 - 2016-02-29 01:12 - 00081801 _____ C:\Users\JB\Downloads\FRST.txt 2016-02-29 01:09 - 2016-02-29 14:05 - 00000000 ____D C:\FRST 2016-02-29 01:08 - 2016-02-29 01:09 - 02371072 _____ (Farbar) C:\Users\JB\Downloads\FRST64.exe 2016-02-29 01:08 - 2016-02-29 01:08 - 01722368 _____ (Farbar) C:\Users\JB\Downloads\FRST.exe 2016-02-28 11:51 - 2016-02-28 11:51 - 00000000 ____D C:\Windows\Temp0FEDB5CF-06FB-821F-B21D-38AF8BEBCFBF-Signatures 2016-02-28 11:12 - 2013-10-01 18:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys 2016-02-28 11:12 - 2013-10-01 18:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe 2016-02-28 11:12 - 2013-10-01 18:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll 2016-02-28 11:12 - 2013-10-01 17:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll 2016-02-28 11:12 - 2013-10-01 17:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll 2016-02-28 11:12 - 2013-10-01 17:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\System32\tsgqec.dll 2016-02-28 11:12 - 2013-10-01 17:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll 2016-02-28 11:12 - 2013-10-01 16:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\System32\rdvidcrl.dll 2016-02-28 11:12 - 2013-10-01 16:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2016-02-28 11:12 - 2013-10-01 16:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2016-02-28 11:12 - 2013-10-01 16:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe 2016-02-28 11:12 - 2013-10-01 16:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\System32\wksprt.exe 2016-02-28 11:12 - 2013-10-01 15:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2016-02-28 11:12 - 2013-10-01 15:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\System32\mstsc.exe 2016-02-28 11:12 - 2013-10-01 15:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2016-02-28 11:12 - 2013-10-01 14:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2016-02-28 11:12 - 2013-10-01 12:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\System32\mstscax.dll 2016-02-28 11:12 - 2013-10-01 12:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2016-02-28 11:10 - 2012-08-23 06:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\System32\rdpudd.dll 2016-02-28 11:10 - 2012-08-23 06:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys 2016-02-28 11:10 - 2012-08-23 06:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbGD.sys 2016-02-28 11:10 - 2012-08-23 05:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll 2016-02-28 11:10 - 2012-08-23 03:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2016-02-28 11:10 - 2012-08-23 02:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll 2016-02-28 11:10 - 2012-08-23 01:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll 2016-02-28 10:18 - 2016-02-28 11:52 - 00000000 ____D C:\Program Files\Microsoft Security Client 2016-02-28 10:18 - 2016-02-28 11:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2016-02-28 10:14 - 2016-02-28 14:46 - 00002154 _____ C:\Windows\epplauncher.mif 2016-02-28 09:41 - 2015-08-05 09:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\System32\icaapi.dll 2016-02-28 09:41 - 2015-08-05 09:06 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys 2016-02-28 09:40 - 2015-12-16 10:55 - 00069120 _____ (Microsoft Corporation) C:\Windows\System32\nlsbres.dll 2016-02-28 09:40 - 2015-12-16 10:53 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\kbdgeoqw.dll 2016-02-28 09:40 - 2015-12-16 10:53 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDAZEL.DLL 2016-02-28 09:40 - 2015-12-16 10:53 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDAZE.DLL 2016-02-28 09:40 - 2015-12-16 10:48 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL 2016-02-28 09:40 - 2015-12-16 10:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll 2016-02-28 09:40 - 2015-12-16 10:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL 2016-02-28 09:40 - 2015-12-16 10:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00994760 _____ (Microsoft Corporation) C:\Windows\System32\ucrtbase.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00063840 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-private-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00020832 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-math-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00019808 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-multibyte-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-string-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-stdio-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00016224 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-runtime-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00015712 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-convert-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-time-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00013664 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-filesystem-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-process-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-heap-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-conio-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-utility-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-locale-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-environment-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-1.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l2-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-timezone-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l2-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2016-02-28 09:40 - 2015-11-19 06:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2016-02-28 09:39 - 2016-01-11 11:11 - 01684416 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2016-02-28 09:06 - 2016-02-28 09:07 - 00375520 _____ C:\Windows\Minidump\022816-19172-01.dmp 2016-02-28 08:00 - 2016-02-28 08:00 - 01702688 _____ C:\Windows\Minidump\022816-30763-01.dmp 2016-02-28 07:26 - 2016-02-28 07:26 - 01702688 _____ C:\Windows\Minidump\022816-28438-01.dmp 2016-02-28 04:34 - 2016-02-28 04:34 - 00375584 _____ C:\Windows\Minidump\022816-16629-01.dmp 2016-02-27 19:40 - 2016-02-27 19:41 - 01702688 _____ C:\Windows\Minidump\022816-25974-01.dmp 2016-02-27 18:38 - 2016-02-27 18:38 - 01315576 _____ C:\Windows\Minidump\022816-16957-01.dmp 2016-02-27 18:19 - 2016-02-27 18:19 - 00644120 _____ C:\Windows\Minidump\022816-16286-01.dmp 2016-02-27 17:49 - 2016-02-27 17:49 - 00375560 _____ C:\Windows\Minidump\022816-20077-01.dmp 2016-02-27 04:19 - 2016-02-27 04:19 - 01180384 _____ C:\Windows\Minidump\022716-20638-01.dmp 2016-02-27 03:27 - 2016-02-27 03:27 - 01702688 _____ C:\Windows\Minidump\022716-25771-01.dmp 2016-02-26 18:07 - 2016-02-26 18:07 - 00644080 _____ C:\Windows\Minidump\022716-28750-01.dmp 2016-02-26 17:55 - 2016-02-26 17:55 - 00000000 ____D C:\Program Files\McAfee Security Scan 2016-02-26 17:54 - 2016-02-26 17:54 - 00000000 ____D C:\Users\JB\AppData\Local\Macromedia 2016-02-26 17:53 - 2016-02-29 04:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-02-26 17:53 - 2016-02-26 17:55 - 00001964 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2016-02-26 17:53 - 2016-02-26 17:55 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2016-02-26 17:53 - 2016-02-26 17:53 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-02-26 17:53 - 2016-02-26 17:53 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2016-02-26 17:53 - 2016-02-26 17:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-02-26 17:52 - 2016-02-26 17:52 - 01190608 _____ (Adobe Systems Incorporated) C:\Users\JB\Downloads\flashplayer20_ga_install(1).exe 2016-02-26 17:51 - 2016-02-26 17:51 - 00242312 _____ C:\Users\JB\Downloads\Firefox Setup Stub 44.0.2.exe 2016-02-26 17:44 - 2016-02-27 03:27 - 00181778 _____ C:\Windows\ntbtlog.txt 2016-02-26 17:44 - 2016-02-26 17:44 - 01702688 _____ C:\Windows\Minidump\022716-28532-01.dmp 2016-02-26 16:43 - 2016-02-26 16:43 - 00375544 _____ C:\Windows\Minidump\022716-28438-01.dmp 2016-02-26 16:41 - 2016-02-26 16:41 - 00011710 _____ C:\Users\JB\AppData\Recovery+kvvpa.html 2016-02-26 16:41 - 2016-02-26 16:41 - 00001961 _____ C:\Users\JB\AppData\Recovery+kvvpa.txt 2016-02-26 16:36 - 2016-02-26 16:36 - 00011710 _____ C:\Users\JB\AppData\LocalLow\Recovery+kvvpa.html 2016-02-26 16:36 - 2016-02-26 16:36 - 00001961 _____ C:\Users\JB\AppData\LocalLow\Recovery+kvvpa.txt 2016-02-26 16:25 - 2016-02-26 16:41 - 00011710 _____ C:\Users\JB\AppData\Roaming\Recovery+kvvpa.html 2016-02-26 16:25 - 2016-02-26 16:41 - 00001961 _____ C:\Users\JB\AppData\Roaming\Recovery+kvvpa.txt 2016-02-26 16:25 - 2016-02-26 16:36 - 00011710 _____ C:\Users\JB\AppData\Local\Recovery+kvvpa.html 2016-02-26 16:25 - 2016-02-26 16:36 - 00001961 _____ C:\Users\JB\AppData\Local\Recovery+kvvpa.txt 2016-02-26 16:24 - 2016-02-26 16:25 - 00011710 _____ C:\ProgramData\Recovery+kvvpa.html 2016-02-26 16:24 - 2016-02-26 16:25 - 00001961 _____ C:\ProgramData\Recovery+kvvpa.txt 2016-02-26 16:13 - 2016-02-28 17:12 - 00000000 ____D C:\Users\JB\AppData\Local\Opics 2016-02-26 16:13 - 2016-02-28 10:33 - 00000000 ___HD C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} 2016-02-26 16:13 - 2016-02-26 16:45 - 00049972 _____ C:\Users\JB\AppData\Roaming\part.autolabel.xml 2016-02-26 16:13 - 2016-02-26 16:26 - 00000000 ____D C:\Users\JB\AppData\Local\Ewwtion 2016-02-26 16:13 - 2016-02-26 16:13 - 44810240 ____H (Remarbati) C:\Users\JB\uzybsgkl.exe 2016-02-26 15:12 - 2016-02-26 15:12 - 00025041 _____ C:\Users\JB\AppData\Roaming\tweakRemoveTempFiles_ar.p5p 2016-02-26 15:12 - 2016-02-26 15:12 - 00024931 _____ C:\Users\JB\AppData\Roaming\Edge.mi 2016-02-26 15:12 - 2016-02-26 15:12 - 00001577 _____ C:\Users\JB\AppData\Roaming\MongooseMoonlightOphthalmometry 2016-02-26 14:44 - 2016-02-26 14:44 - 00067072 _____ (Paragon Software Group) C:\Users\JB\AppData\Roaming\neguses.dll 2016-02-10 09:05 - 2016-01-22 12:31 - 00387784 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2016-02-10 09:05 - 2016-01-22 12:10 - 00341200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-02-10 09:05 - 2016-01-21 22:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2016-02-10 09:05 - 2016-01-21 22:41 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2016-02-10 09:05 - 2016-01-21 22:40 - 00571904 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2016-02-10 09:05 - 2016-01-21 22:40 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec 2016-02-10 09:05 - 2016-01-21 22:40 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2016-02-10 09:05 - 2016-01-21 22:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2016-02-10 09:05 - 2016-01-21 22:33 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2016-02-10 09:05 - 2016-01-21 22:32 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2016-02-10 09:05 - 2016-01-21 22:29 - 06052352 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2016-02-10 09:05 - 2016-01-21 22:27 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2016-02-10 09:05 - 2016-01-21 22:27 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2016-02-10 09:05 - 2016-01-21 22:27 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2016-02-10 09:05 - 2016-01-21 22:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2016-02-10 09:05 - 2016-01-21 22:17 - 00489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2016-02-10 09:05 - 2016-01-21 22:09 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2016-02-10 09:05 - 2016-01-21 22:08 - 00107520 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll 2016-02-10 09:05 - 2016-01-21 22:05 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2016-02-10 09:05 - 2016-01-21 22:04 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2016-02-10 09:05 - 2016-01-21 22:02 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-02-10 09:05 - 2016-01-21 22:02 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2016-02-10 09:05 - 2016-01-21 22:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2016-02-10 09:05 - 2016-01-21 22:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2016-02-10 09:05 - 2016-01-21 22:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2016-02-10 09:05 - 2016-01-21 22:00 - 00152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll 2016-02-10 09:05 - 2016-01-21 22:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-02-10 09:05 - 2016-01-21 21:55 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2016-02-10 09:05 - 2016-01-21 21:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2016-02-10 09:05 - 2016-01-21 21:51 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-02-10 09:05 - 2016-01-21 21:51 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2016-02-10 09:05 - 2016-01-21 21:50 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2016-02-10 09:05 - 2016-01-21 21:48 - 00718336 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2016-02-10 09:05 - 2016-01-21 21:47 - 00798208 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2016-02-10 09:05 - 2016-01-21 21:46 - 02123264 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2016-02-10 09:05 - 2016-01-21 21:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2016-02-10 09:05 - 2016-01-21 21:43 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2016-02-10 09:05 - 2016-01-21 21:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-02-10 09:05 - 2016-01-21 21:38 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2016-02-10 09:05 - 2016-01-21 21:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2016-02-10 09:05 - 2016-01-21 21:35 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-02-10 09:05 - 2016-01-21 21:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2016-02-10 09:05 - 2016-01-21 21:34 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-02-10 09:05 - 2016-01-21 21:33 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2016-02-10 09:05 - 2016-01-21 21:31 - 02597376 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2016-02-10 09:05 - 2016-01-21 21:27 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-02-10 09:05 - 2016-01-21 21:25 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-02-10 09:05 - 2016-01-21 21:24 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-02-10 09:05 - 2016-01-21 21:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2016-02-10 09:05 - 2016-01-21 21:08 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2016-02-10 09:05 - 2016-01-21 21:07 - 02120704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-02-10 09:05 - 2016-01-21 21:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-02-10 09:04 - 2016-02-06 02:48 - 25839104 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2016-02-10 09:04 - 2016-02-06 02:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2016-02-10 09:04 - 2016-02-06 02:24 - 02887680 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2016-02-10 09:04 - 2016-02-06 02:11 - 00615936 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2016-02-10 09:04 - 2016-02-06 02:10 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2016-02-10 09:04 - 2016-02-06 02:01 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-02-10 09:04 - 2016-02-06 01:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2016-02-10 09:04 - 2016-02-06 01:43 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-02-10 09:04 - 2016-02-06 01:38 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-02-10 09:04 - 2016-02-06 01:37 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2016-02-10 09:04 - 2016-02-06 01:32 - 14458368 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2016-02-10 09:04 - 2016-02-06 01:16 - 12857856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-02-10 09:04 - 2016-02-06 01:09 - 01547264 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2016-02-10 09:04 - 2016-02-06 00:54 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-02-10 09:04 - 2016-01-16 11:06 - 00025024 _____ (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe 2016-02-10 09:04 - 2016-01-16 10:54 - 01162240 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 01362944 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 00696320 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 00677376 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 00499200 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll 2016-02-10 09:04 - 2016-01-11 06:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll 2016-02-10 09:04 - 2016-01-06 11:02 - 00275456 _____ (Microsoft Corporation) C:\Windows\System32\InkEd.dll 2016-02-10 09:04 - 2016-01-06 11:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\jnwmon.dll 2016-02-10 09:04 - 2016-01-06 10:41 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2016-02-10 08:58 - 2016-01-21 22:27 - 05573056 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2016-02-10 08:58 - 2016-01-21 22:27 - 00154560 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2016-02-10 08:58 - 2016-01-21 22:27 - 00095680 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2016-02-10 08:58 - 2016-01-21 22:24 - 01733592 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00215040 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll 2016-02-10 08:58 - 2016-01-21 22:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll 2016-02-10 08:58 - 2016-01-21 22:19 - 01214464 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll 2016-02-10 08:58 - 2016-01-21 22:19 - 00344064 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll 2016-02-10 08:58 - 2016-01-21 22:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll 2016-02-10 08:58 - 2016-01-21 22:18 - 00961024 _____ (Microsoft Corporation) C:\Windows\System32\CPFilters.dll 2016-02-10 08:58 - 2016-01-21 22:18 - 00723968 _____ (Microsoft Corporation) C:\Windows\System32\EncDec.dll 2016-02-10 08:58 - 2016-01-21 22:18 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll 2016-02-10 08:58 - 2016-01-21 22:17 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll 2016-02-10 08:58 - 2016-01-21 22:17 - 00312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2016-02-10 08:58 - 2016-01-21 22:17 - 00159744 _____ (Microsoft Corporation) C:\Windows\System32\mtxoci.dll 2016-02-10 08:58 - 2016-01-21 22:16 - 01461248 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2016-02-10 08:58 - 2016-01-21 22:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll 2016-02-10 08:58 - 2016-01-21 22:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll 2016-02-10 08:58 - 2016-01-21 22:15 - 01163264 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll 2016-02-10 08:58 - 2016-01-21 22:15 - 00730112 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2016-02-10 08:58 - 2016-01-21 22:15 - 00422400 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll 2016-02-10 08:58 - 2016-01-21 22:13 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-02-10 08:58 - 2016-01-21 22:13 - 03938752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-02-10 08:58 - 2016-01-21 22:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll 2016-02-10 08:58 - 2016-01-21 22:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll 2016-02-10 08:58 - 2016-01-21 22:13 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00880128 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00686080 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 22:09 - 01314328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-02-10 08:58 - 2016-01-21 22:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-02-10 08:58 - 2016-01-21 22:05 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-02-10 08:58 - 2016-01-21 22:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-02-10 08:58 - 2016-01-21 22:04 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2016-02-10 08:58 - 2016-01-21 22:04 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2016-02-10 08:58 - 2016-01-21 22:02 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 21:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe 2016-02-10 08:58 - 2016-01-21 21:07 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe 2016-02-10 08:58 - 2016-01-21 21:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-02-10 08:58 - 2016-01-21 21:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe 2016-02-10 08:58 - 2016-01-21 20:59 - 00159232 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys 2016-02-10 08:58 - 2016-01-21 20:58 - 00290816 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys 2016-02-10 08:58 - 2016-01-21 20:58 - 00129024 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys 2016-02-10 08:58 - 2016-01-21 20:57 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe 2016-02-10 08:58 - 2016-01-21 20:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe 2016-02-10 08:58 - 2016-01-21 20:53 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-02-10 08:58 - 2016-01-21 20:53 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-02-10 08:58 - 2016-01-21 20:53 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-02-10 08:58 - 2016-01-21 20:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-02-10 08:58 - 2016-01-21 20:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-02-10 08:58 - 2016-01-21 20:51 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 20:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 20:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-02-10 08:58 - 2016-01-21 20:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-02-10 08:58 - 2016-01-16 11:01 - 02085888 _____ (Microsoft Corporation) C:\Windows\System32\ole32.dll 2016-02-10 08:58 - 2016-01-16 10:36 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2016-02-10 08:58 - 2016-01-11 11:05 - 03169792 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2016-02-10 08:58 - 2016-01-11 11:05 - 00192512 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2016-02-10 08:58 - 2016-01-11 11:05 - 00098816 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2016-02-10 08:58 - 2016-01-11 10:52 - 00091136 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll 2016-02-10 08:58 - 2016-01-11 10:47 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2016-02-10 08:58 - 2016-01-11 10:26 - 02610176 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2016-02-10 08:58 - 2016-01-11 10:24 - 00709120 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2016-02-10 08:58 - 2016-01-11 10:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2016-02-10 08:58 - 2016-01-11 10:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll 2016-02-10 08:58 - 2016-01-11 10:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2016-02-10 08:58 - 2016-01-11 10:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll 2016-02-10 08:58 - 2016-01-11 10:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\System32\wu.upgrade.ps.dll 2016-02-10 08:58 - 2016-01-11 10:14 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2016-02-10 08:58 - 2016-01-11 10:14 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2016-02-10 08:58 - 2016-01-11 10:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2016-02-10 08:58 - 2016-01-11 10:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2016-02-10 08:58 - 2016-01-07 09:53 - 03211776 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2016-02-10 08:58 - 2016-01-07 09:42 - 00141312 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys 2016-02-10 08:57 - 2016-01-21 22:19 - 14179840 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll 2016-02-10 08:57 - 2016-01-21 22:15 - 01866752 _____ (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll 2016-02-10 08:57 - 2016-01-21 22:12 - 01940992 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll 2016-02-10 08:57 - 2016-01-21 22:05 - 12877824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2016-02-10 08:57 - 2016-01-21 22:00 - 01498624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2016-02-10 08:57 - 2016-01-21 21:59 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2016-02-10 08:57 - 2016-01-21 21:19 - 03231232 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2016-02-10 08:57 - 2016-01-21 21:12 - 02973184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-02-29 04:49 - 2012-03-15 11:15 - 00000000 ____D C:\Users\JB\AppData\Roaming\SoftGrid Client 2016-02-29 04:01 - 2011-10-20 11:38 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-02-29 03:12 - 2009-07-13 20:45 - 00020688 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-02-29 03:12 - 2009-07-13 20:45 - 00020688 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-02-29 03:08 - 2011-10-20 12:01 - 00699884 _____ C:\Windows\System32\perfh007.dat 2016-02-29 03:08 - 2011-10-20 12:01 - 00149766 _____ C:\Windows\System32\perfc007.dat 2016-02-29 03:08 - 2009-07-13 21:13 - 01622300 _____ C:\Windows\System32\PerfStringBackup.INI 2016-02-29 03:08 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf 2016-02-29 03:04 - 2011-10-20 11:39 - 00272921 _____ C:\Windows\System32\fastboot.set 2016-02-29 03:04 - 2011-10-20 11:38 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-02-29 03:03 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-02-29 00:24 - 2014-07-11 11:33 - 00000306 __RSH C:\ProgramData\ntuser.pol 2016-02-29 00:24 - 2009-07-13 20:45 - 00277160 _____ C:\Windows\System32\FNTCACHE.DAT 2016-02-28 14:47 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2016-02-28 09:06 - 2014-05-23 14:02 - 528800483 _____ C:\Windows\MEMORY.DMP 2016-02-28 09:06 - 2014-05-23 14:02 - 00000000 ____D C:\Windows\Minidump 2016-02-27 18:07 - 2011-12-27 10:58 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2016-02-26 18:07 - 2011-12-24 08:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-02-26 17:53 - 2014-03-18 12:31 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-02-26 17:53 - 2012-03-05 08:00 - 00000000 ____D C:\Users\JB\AppData\Local\Adobe 2016-02-26 17:53 - 2011-12-24 11:11 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-02-26 17:53 - 2011-10-20 11:36 - 00000000 ____D C:\ProgramData\McAfee 2016-02-26 17:36 - 2015-04-04 17:00 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2016-02-26 17:36 - 2015-04-04 17:00 - 00000000 ___SD C:\Windows\System32\GWX 2016-02-26 17:21 - 2015-02-16 17:55 - 00000000 ____D C:\Program Files\WajaWebEnhancer 2016-02-26 17:21 - 2011-12-27 10:58 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2016-02-26 17:21 - 2011-12-24 08:44 - 00000000 ____D C:\Users\JB\Desktop\Pc-Programme (Standard) 2016-02-26 17:21 - 2011-12-24 08:41 - 00000000 ____D C:\users\JB 2016-02-26 17:21 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration 2016-02-26 16:46 - 2014-08-08 19:57 - 00000000 ____D C:\Users\JB\AppData\LocalLow\Internet Explorer BHO 2016-02-26 16:46 - 2011-10-20 11:17 - 00000000 ____D C:\Intel 2016-02-26 16:41 - 2014-07-28 09:12 - 00000000 ____D C:\Users\JB\AppData\Roaming\TuneUp Software 2016-02-26 16:41 - 2012-10-30 15:09 - 00000000 ____D C:\Users\JB\AppData\Roaming\vlc 2016-02-26 16:41 - 2011-12-24 12:23 - 00000000 ____D C:\Users\JB\AppData\Roaming\WinRAR 2016-02-26 16:41 - 2011-12-24 09:19 - 00000000 ____D C:\Users\JB\Desktop\Alben 2016-02-26 16:41 - 2011-12-24 09:02 - 00000000 ____D C:\Users\JB\AppData\Roaming\TS3Client 2016-02-26 16:39 - 2015-12-19 11:45 - 00000000 ____D C:\Users\JB\AppData\Roaming\TeamViewer 2016-02-26 16:39 - 2015-02-16 17:54 - 00000000 ____D C:\Users\JB\AppData\Roaming\RHEng 2016-02-26 16:39 - 2014-08-08 19:57 - 00000000 ____D C:\Users\JB\AppData\Roaming\Security Systems 2016-02-26 16:39 - 2014-07-12 07:02 - 00000000 ____D C:\Users\JB\AppData\Roaming\Systweak 2016-02-26 16:39 - 2013-07-23 17:32 - 00000000 ____D C:\Users\JB\AppData\Roaming\Riot Games 2016-02-26 16:39 - 2013-06-24 13:10 - 00000000 ____D C:\Users\JB\AppData\Roaming\RIFT 2016-02-26 16:39 - 2013-02-14 08:00 - 00000000 ____D C:\Users\JB\AppData\Roaming\Samsung 2016-02-26 16:39 - 2012-03-15 11:14 - 00000000 ____D C:\Users\JB\AppData\Roaming\TP 2016-02-26 16:39 - 2011-12-24 08:48 - 00000000 ____D C:\Users\JB\AppData\Roaming\Mozilla 2016-02-26 16:37 - 2011-12-24 08:47 - 00000000 ____D C:\Users\JB\AppData\Roaming\Macromedia 2016-02-26 16:37 - 2011-12-24 08:41 - 00000000 ____D C:\Users\JB\AppData\Roaming\Media Center Programs 2016-02-26 16:36 - 2015-06-02 13:03 - 00000000 ____D C:\Users\JB\AppData\Local\TERA 2016-02-26 16:36 - 2014-11-21 11:35 - 00000000 __SHD C:\Users\JB\AppData\LocalLow\EmieBrowserModeList 2016-02-26 16:36 - 2014-08-08 19:57 - 00000000 ____D C:\Users\JB\AppData\Roaming\Hub Timer 2016-02-26 16:36 - 2014-07-28 09:12 - 00000000 ____D C:\Users\JB\AppData\Local\TuneUp Software 2016-02-26 16:36 - 2014-07-28 09:08 - 00000000 ____D C:\Users\JB\AppData\Roaming\DVDVideoSoft 2016-02-26 16:36 - 2014-07-12 19:08 - 00000000 ____D C:\Users\JB\AppData\LocalLow\Temp 2016-02-26 16:36 - 2014-07-10 13:28 - 00000000 ____D C:\Users\JB\AppData\Local\Windows Live 2016-02-26 16:36 - 2014-07-10 13:28 - 00000000 ____D C:\Users\JB\AppData\Local\{C71E1463-1F4E-4EBA-BE33-928CF04C947B} 2016-02-26 16:36 - 2014-04-25 07:25 - 00000000 ____D C:\Users\JB\AppData\Roaming\Logitech 2016-02-26 16:36 - 2014-04-25 07:25 - 00000000 ____D C:\Users\JB\AppData\Roaming\Logishrd 2016-02-26 16:36 - 2014-04-19 17:26 - 00000000 __SHD C:\Users\JB\AppData\LocalLow\EmieUserList 2016-02-26 16:36 - 2014-04-19 17:26 - 00000000 __SHD C:\Users\JB\AppData\LocalLow\EmieSiteList 2016-02-26 16:36 - 2014-02-07 07:03 - 00000000 ____D C:\Users\JB\AppData\Roaming\Battle.net 2016-02-26 16:36 - 2013-07-23 19:22 - 00000000 ____D C:\Users\JB\AppData\Roaming\LolClient 2016-02-26 16:36 - 2012-04-16 05:43 - 00000000 ____D C:\Users\JB\AppData\Local\{FFCB9107-F76B-4CC4-90A6-4247576C6A7C} 2016-02-26 16:36 - 2012-03-18 15:38 - 00000000 ____D C:\Users\JB\AppData\Local\{D57DB36C-7837-43C7-86A4-73F27034B04A} 2016-02-26 16:36 - 2012-03-18 15:38 - 00000000 ____D C:\Users\JB\AppData\Local\{36DA50EA-877B-4DCD-9B66-887849A68C4D} 2016-02-26 16:36 - 2012-03-05 08:00 - 00000000 ____D C:\Users\JB\AppData\LocalLow\Adobe 2016-02-26 16:36 - 2011-12-24 08:54 - 00000000 ____D C:\Users\JB\AppData\Roaming\ICQ 2016-02-26 16:36 - 2011-12-24 08:46 - 00000000 ____D C:\Users\JB\AppData\Roaming\Adobe 2016-02-26 16:36 - 2011-12-24 08:45 - 00000000 ____D C:\Users\JB\AppData\Roaming\ATI 2016-02-26 16:36 - 2011-12-24 08:41 - 00000000 ____D C:\Users\JB\AppData\Local\VirtualStore 2016-02-26 16:35 - 2015-04-24 13:38 - 00000000 ____D C:\Users\JB\AppData\Local\Steam 2016-02-26 16:35 - 2014-10-04 08:42 - 00000000 ____D C:\Users\JB\AppData\Local\PDF24 2016-02-26 16:35 - 2014-08-11 08:48 - 00000000 ____D C:\Users\JB\AppData\Local\Microsoft Help 2016-02-26 16:35 - 2013-08-08 19:44 - 00000000 ____D C:\Users\JB\AppData\Local\SWTOR 2016-02-26 16:35 - 2013-08-08 09:47 - 00000000 ____D C:\Users\JB\AppData\Local\SWTORPerf 2016-02-26 16:35 - 2013-02-14 08:00 - 00000000 ____D C:\Users\JB\AppData\Local\Samsung 2016-02-26 16:35 - 2012-03-15 11:15 - 00000000 ____D C:\Users\JB\AppData\Local\SoftGrid Client 2016-02-26 16:35 - 2011-12-24 08:48 - 00000000 ____D C:\Users\JB\AppData\Local\Mozilla 2016-02-26 16:35 - 2011-12-24 08:43 - 00000000 ____D C:\Users\JB\AppData\Local\Power2Go 2016-02-26 16:26 - 2015-12-14 10:16 - 00000000 ____D C:\Users\JB\AppData\Local\FluxSoftware 2016-02-26 16:26 - 2014-11-21 11:35 - 00000000 __SHD C:\Users\JB\AppData\Local\EmieBrowserModeList 2016-02-26 16:26 - 2014-07-11 11:02 - 00000000 ____D C:\Users\JB\AppData\Local\globalUpdate 2016-02-26 16:26 - 2014-07-11 11:01 - 00000000 ____D C:\Users\JB\AppData\Local\Genesis_07111901 2016-02-26 16:26 - 2014-04-25 07:28 - 00000000 ____D C:\Users\JB\AppData\Local\Logitech 2016-02-26 16:26 - 2014-04-19 17:26 - 00000000 __SHD C:\Users\JB\AppData\Local\EmieUserList 2016-02-26 16:26 - 2014-04-19 17:26 - 00000000 __SHD C:\Users\JB\AppData\Local\EmieSiteList 2016-02-26 16:26 - 2014-02-08 08:05 - 00000000 ____D C:\Users\JB\AppData\Local\Blizzard 2016-02-26 16:26 - 2014-02-07 07:03 - 00000000 ____D C:\Users\JB\AppData\Local\Battle.net 2016-02-26 16:26 - 2014-01-13 08:33 - 00000000 ____D C:\Users\JB\AppData\Local\FalloutNV 2016-02-26 16:26 - 2013-09-10 19:02 - 00000000 ____D C:\Users\JB\AppData\Local\Blizzard Entertainment 2016-02-26 16:26 - 2013-02-14 07:51 - 00000000 ____D C:\Users\JB\AppData\Local\Downloaded Installations 2016-02-26 16:26 - 2011-12-24 08:45 - 00000000 ____D C:\Users\JB\AppData\Local\Google 2016-02-26 16:26 - 2011-12-24 08:43 - 00000000 ____D C:\Users\JB\AppData\Local\Lenovo 2016-02-26 16:25 - 2015-06-02 13:03 - 00000000 ____D C:\ProgramData\boost_interprocess 2016-02-26 16:25 - 2014-07-28 09:11 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2016-02-26 16:25 - 2014-07-28 09:11 - 00000000 ____D C:\ProgramData\TuneUp Software 2016-02-26 16:25 - 2014-04-25 07:28 - 00000000 ____D C:\ProgramData\LogiShrd 2016-02-26 16:25 - 2014-03-18 12:31 - 00000000 ____D C:\ProgramData\Google 2016-02-26 16:25 - 2013-02-14 07:57 - 00000000 ____D C:\ProgramData\Samsung 2016-02-26 16:25 - 2012-07-12 22:30 - 00000000 ____D C:\ProgramData\InstallShield 2016-02-26 16:25 - 2012-04-26 03:37 - 00000000 ____D C:\ProgramData\Mozilla 2016-02-26 16:25 - 2012-03-15 13:26 - 00000000 ____D C:\ProgramData\VirtualizedApplications 2016-02-26 16:25 - 2011-12-24 11:00 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2016-02-26 16:25 - 2011-12-24 08:54 - 00000000 ____D C:\ProgramData\ICQ 2016-02-26 16:25 - 2011-12-24 08:45 - 00000000 ____D C:\Users\JB\AppData\Local\ATI 2016-02-26 16:25 - 2011-10-21 08:53 - 00000000 ____D C:\ProgramData\Lenovo 2016-02-26 16:25 - 2011-10-20 11:43 - 00000000 ____D C:\ProgramData\Temp 2016-02-26 16:25 - 2011-10-20 11:43 - 00000000 ____D C:\ProgramData\CyberLink 2016-02-26 16:25 - 2011-10-20 11:39 - 00000000 ____D C:\ProgramData\Partner 2016-02-26 16:24 - 2013-08-08 09:47 - 00000000 ____D C:\ProgramData\BitRaider 2016-02-26 16:24 - 2013-07-23 17:36 - 00000000 ____D C:\Riot Games 2016-02-26 16:24 - 2012-08-04 18:09 - 00000000 ____D C:\ProgramData\Battle.net 2016-02-26 16:24 - 2012-06-29 07:04 - 00000000 ____D C:\ProgramData\Age of Empires 3 2016-02-26 16:24 - 2012-03-01 09:52 - 00000000 ____D C:\ProgramData\Adobe 2016-02-26 16:24 - 2011-10-20 11:37 - 00000000 ____D C:\ProgramData\ATI 2016-02-26 16:24 - 2011-10-20 11:33 - 00000000 ____D C:\Templenovo 2016-02-26 08:50 - 2011-12-24 08:46 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2016-02-26 08:49 - 2014-02-07 07:03 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-02-19 13:50 - 2015-01-17 14:17 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm 2016-02-14 04:00 - 2014-03-31 14:43 - 00000000 ____D C:\Program Files (x86)\Diablo III 2016-02-11 10:20 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache 2016-02-11 08:46 - 2015-04-15 20:00 - 00000000 ____D C:\Windows\System32\appraiser 2016-02-11 08:46 - 2014-05-05 21:18 - 00000000 ___SD C:\Windows\System32\CompatTel 2016-02-11 08:46 - 2011-02-15 02:41 - 00000000 ____D C:\Program Files\Windows Journal 2016-02-10 13:32 - 2013-08-14 17:01 - 00000000 ____D C:\Windows\System32\MRT 2016-02-10 13:30 - 2012-02-24 14:51 - 146614896 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2016-02-03 08:56 - 2011-10-20 11:38 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-02-03 08:56 - 2011-10-20 11:38 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore Files to move or delete: ==================== C:\ProgramData\08zo99od.odd C:\ProgramData\flashax10.exe C:\ProgramData\rj8jwdbg.fvv C:\Users\JB\uzybsgkl.exe ==================== Known DLLs (Whitelisted) ========================= ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe [2016-02-10 08:57] - [2016-01-21 21:19] - 3231232 ____A (Microsoft Corporation) 9D77CC4A36FEEA644D002CFB9B2D42C0 C:\Windows\SysWOW64\explorer.exe [2016-02-10 08:57] - [2016-01-21 21:12] - 2973184 ____A (Microsoft Corporation) 2A156D5EBF221EF2A6AE7CE452324DAC C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll [2015-12-09 09:04] - [2015-11-10 10:55] - 1008640 ____A (Microsoft Corporation) 06BF84D26A05D400F6B3FB3D3DE0B03A C:\Windows\SysWOW64\User32.dll [2015-12-09 09:04] - [2015-11-10 10:37] - 0833024 ____A (Microsoft Corporation) 0A78439765E31510D75C9E2284F3A722 C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\dnsapi.dll => MD5 is legit C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE Association (Whitelisted) ============= ==================== Restore Points ========================= Restore point date: 2016-02-26 17:36 Restore point date: 2016-02-28 09:41 Restore point date: 2016-02-28 10:17 Restore point date: 2016-02-29 03:26 ==================== Memory info =========================== Percentage of memory in use: 13% Total physical RAM: 6126.39 MB Available physical RAM: 5317.37 MB Total Virtual: 6124.59 MB Available Virtual: 5312.03 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:906.34 GB) (Free:664.85 GB) NTFS Drive e: (AOE3Y) (CDROM) (Total:0.54 GB) (Free:0 GB) CDFS Drive g: () (Removable) (Total:0.96 GB) (Free:0.96 GB) FAT Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 04067489) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=906.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=25.1 GB) - (Type=12) ======================================================== Disk: 2 (Size: 985.5 MB) (Disk ID: 00000000) Partition: GPT. LastRegBack: 2016-02-27 15:46 ==================== End of FRST.txt ============================ |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Permanentes Herunterfahren nach angeblichem Windows Update Ich weiß nicht welche Anleitung du da befolgst, aber meine ganz sicher nicht.
| ![]() Permanentes Herunterfahren nach angeblichem Windows Update Entschuldigung was habe ich falsch gemacht bzw soll ich anders machen ?=/ |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Permanentes Herunterfahren nach angeblichem Windows Update Hast du denn mein Posting überhaupt mal gelesen?? Du führst FRST völlig anders aus als gefordert! Oder hast du überhaupt keine Chance FRST richtig auszuführen? Weil Windows, egal was du versuchst, sofoer wieder runterfährt?
| ![]() Permanentes Herunterfahren nach angeblichem Windows Update hoffe jetzt passt alles =) Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:27-02-2016 durchgeführt von JB (Administrator) auf JB-PC (29-02-2016 20:05:51) Gestartet von C:\Users\JB\Downloads Geladene Profile: JB (Verfügbare Profile: JB) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) ja so isses richtig
![]() | #12 |
Lade Dir bitte von hier
Das habe ich jetzt alles gemacht, jedoch wenn ich den PC hochfahre erscheint immer ein Fenster wo das drin steht
Das System können wir aber noch bereinigen.
