|
Alles rund um Windows: MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nichtWindows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
25.04.2016, 07:36 | #16 |
| MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] *#*ComboFix 16-04-22.01 - S-O 25.04.2016 7:33.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.1535.348 [GMT 2:00] ausgeführt von:: c:\users\S-O\Downloads\ComboFix.exe . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe C:\prefs.js c:\windows\mpwn.exe c:\windows\pwn.exe c:\windows\security\Database\tmp.edb c:\windows\SysWow64\DEBUG.log . . ((((((((((((((((((((((( Dateien erstellt von 2016-03-25 bis 2016-04-25 )))))))))))))))))))))))))))))) . . 2016-04-25 06:17 . 2016-04-25 06:17 -------- d-----w- c:\users\Default\AppData\Local\temp 2016-04-24 04:54 . 2016-03-17 01:45 11686560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9F9CF0C-50EF-47F2-89D9-3984F931FCB2}\mpengine.dll 2016-04-23 07:37 . 2016-04-23 07:39 -------- d-----w- c:\program files (x86)\Around the World in 80 Days 2016-04-23 05:49 . 2016-04-23 06:48 -------- d-----w- C:\AdwCleaner 2016-04-22 15:19 . 2016-03-21 17:43 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F57FDFC3-74A3-473A-8C73-953E4DB7128D}\gapaengine.dll 2016-04-22 14:51 . 2016-03-17 01:45 11686560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2016-04-22 13:09 . 2016-04-22 13:09 -------- d-sh--w- c:\windows\ftpcache 2016-04-22 08:06 . 2016-04-22 08:06 444416 ----a-w- c:\windows\system32\winhttp.dll 2016-04-22 08:06 . 2016-04-22 08:06 396800 ----a-w- c:\windows\system32\webio.dll 2016-04-22 08:06 . 2016-04-22 08:06 351744 ----a-w- c:\windows\SysWow64\winhttp.dll 2016-04-22 08:06 . 2016-04-22 08:06 316416 ----a-w- c:\windows\SysWow64\webio.dll 2016-04-22 08:04 . 2016-04-22 08:04 274944 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkDiv.dll 2016-04-22 08:04 . 2016-04-22 08:04 1416192 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkObj.dll 2016-04-22 08:04 . 2016-04-22 08:04 216064 ----a-w- c:\windows\SysWow64\InkEd.dll 2016-04-22 08:04 . 2016-04-22 08:04 353280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkDiv.dll 2016-04-22 08:04 . 2016-04-22 08:04 275456 ----a-w- c:\windows\system32\InkEd.dll 2016-04-22 08:04 . 2016-04-22 08:04 2104320 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll 2016-04-22 08:04 . 2016-04-22 08:04 18432 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2016-04-22 08:04 . 2016-04-22 08:04 169984 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\rtscom.dll 2016-04-22 08:04 . 2016-04-22 08:04 16384 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2016-04-22 08:04 . 2016-04-22 08:04 126464 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\rtscom.dll 2016-04-22 03:39 . 2016-04-22 03:42 -------- d-----w- c:\program files (x86)\Phantasmat - Teuflische Maskerade 2016-04-21 05:38 . 2016-04-21 05:38 -------- d-----w- c:\programdata\BlueStacks 2016-04-19 16:15 . 2016-04-19 16:15 1356512 ----a-w- c:\windows\system32\RTCOM64.dll 2016-04-19 16:14 . 2016-04-19 16:14 118600 ----a-w- c:\windows\system32\AERTAR64.dll 2016-04-19 16:14 . 2016-04-19 16:14 574760 ----a-w- c:\windows\system32\AERTAC64.dll 2016-04-19 16:14 . 2016-04-19 16:14 118600 ----a-w- c:\windows\system32\AcpiServiceVnA64.dll 2016-04-18 04:39 . 2016-04-23 05:40 -------- d-----w- C:\FRST 2016-04-15 13:37 . 2016-04-15 13:37 -------- d-----w- c:\programdata\blg 2016-04-14 15:38 . 2016-04-14 15:38 413912 ----a-w- c:\windows\system32\drivers\RtsUer.sys 2016-04-14 15:38 . 2016-04-14 15:38 4330200 ----a-w- c:\windows\RtCRU64.exe 2016-04-13 07:47 . 2016-03-06 18:53 1885696 ----a-w- c:\windows\system32\msxml3.dll 2016-04-13 07:47 . 2016-03-06 18:53 2048 ----a-w- c:\windows\system32\msxml3r.dll 2016-04-13 07:47 . 2016-03-06 18:38 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll 2016-04-13 07:47 . 2016-03-06 18:38 1240576 ----a-w- c:\windows\SysWow64\msxml3.dll 2016-04-13 07:47 . 2016-03-16 18:50 156672 ----a-w- c:\windows\system32\mtxoci.dll 2016-04-13 07:47 . 2016-03-16 18:28 111616 ----a-w- c:\windows\SysWow64\mtxoci.dll 2016-04-13 07:47 . 2016-03-16 18:28 176128 ----a-w- c:\windows\SysWow64\msorcl32.dll 2016-04-13 07:47 . 2016-03-16 18:27 286720 ----a-w- c:\program files (x86)\Common Files\System\Ole DB\msdaora.dll 2016-04-13 07:45 . 2016-03-31 00:21 34304 ----a-w- c:\windows\system32\iernonce.dll 2016-04-13 07:44 . 2016-03-31 00:36 10949120 ----a-w- c:\program files\Internet Explorer\F12Resources.dll 2016-04-12 13:21 . 2016-04-12 13:21 -------- d-----w- c:\programdata\LittleGamesCompany 2016-04-12 12:05 . 2016-04-12 12:07 -------- d-----w- c:\programdata\TheFallTrilogyEp3 2016-04-10 11:20 . 2016-04-11 04:17 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2016-03-30 05:28 . 2016-03-30 05:28 22704 ----a-w- c:\windows\system32\drivers\EsgScanner.sys 2016-03-26 16:08 . 2016-03-30 04:24 -------- d-----w- C:\searchplugins 2016-03-26 16:07 . 2016-03-26 16:07 -------- d-----w- c:\users\S-O\AppData\Local\Lavasoft 2016-03-26 16:07 . 2016-03-27 16:13 -------- d-----w- c:\users\S-O\AppData\Roaming\Lavasoft 2016-03-26 16:06 . 2016-03-30 04:23 -------- d-----w- c:\program files (x86)\Lavasoft 2016-03-26 16:06 . 2016-03-30 04:23 -------- d-----w- c:\programdata\Lavasoft 2016-03-26 14:18 . 2016-03-26 14:18 -------- d-----w- c:\users\S-O\AppData\Roaming\Gestalt Games . . |
25.04.2016, 17:54 | #17 |
/// Malwareteam | MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] Hi, da fehlt einiges. Hast du das ganze Logfile kopiert?
__________________Wenn in der Log Datei echt nicht mehr steht, starte bitte einen neuen Scan von Combofix. Mache während des Scans nichts am PC!
__________________ |
26.04.2016, 06:33 | #18 |
| MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] Hallo Raphael,
__________________ich habe alles noch mal neu gestartet, hier das Ergebnis: *#*Combofix Logfile: Code:
ATTFilter ComboFix 16-04-22.01 - S-O 26.04.2016 6:56.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.1535.363 [GMT 2:00] ausgeführt von:: c:\users\S-O\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Updated* {768124D7-F5F7-6D2F-DDC2-94DFA4017C95} SP: Microsoft Security Essentials *Enabled/Updated* {CDE0C533-D3CD-62A1-E772-AFADDF863628} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2016-03-26 bis 2016-04-26 )))))))))))))))))))))))))))))) . . 2016-04-26 05:14 . 2016-04-26 05:14 -------- d-----w- c:\users\Default\AppData\Local\temp 2016-04-26 04:44 . 2016-04-26 04:47 -------- d-----w- c:\program files (x86)\Sea of Lies - In den Tiefen der Meere 2016-04-25 10:45 . 2016-03-17 01:45 11686560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C586A1D5-2587-4F8A-AAC7-9741B5DA5D38}\mpengine.dll 2016-04-25 10:23 . 2016-04-25 16:07 -------- d-----w- c:\programdata\Trymedia 2016-04-25 06:42 . 2016-04-25 06:47 -------- d-----w- c:\program files (x86)\Warlock - Der Fluch des Schamanen 2016-04-24 04:54 . 2016-03-17 01:45 11686560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2016-04-23 07:37 . 2016-04-23 07:39 -------- d-----w- c:\program files (x86)\Around the World in 80 Days 2016-04-23 05:49 . 2016-04-23 06:48 -------- d-----w- C:\AdwCleaner 2016-04-22 15:19 . 2016-03-21 17:43 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F57FDFC3-74A3-473A-8C73-953E4DB7128D}\gapaengine.dll 2016-04-22 13:09 . 2016-04-22 13:09 -------- d-sh--w- c:\windows\ftpcache 2016-04-22 08:06 . 2016-04-22 08:06 444416 ----a-w- c:\windows\system32\winhttp.dll 2016-04-22 08:06 . 2016-04-22 08:06 396800 ----a-w- c:\windows\system32\webio.dll 2016-04-22 08:06 . 2016-04-22 08:06 351744 ----a-w- c:\windows\SysWow64\winhttp.dll 2016-04-22 08:06 . 2016-04-22 08:06 316416 ----a-w- c:\windows\SysWow64\webio.dll 2016-04-22 08:04 . 2016-04-22 08:04 274944 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkDiv.dll 2016-04-22 08:04 . 2016-04-22 08:04 1416192 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkObj.dll 2016-04-22 08:04 . 2016-04-22 08:04 216064 ----a-w- c:\windows\SysWow64\InkEd.dll 2016-04-22 08:04 . 2016-04-22 08:04 353280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkDiv.dll 2016-04-22 08:04 . 2016-04-22 08:04 275456 ----a-w- c:\windows\system32\InkEd.dll 2016-04-22 08:04 . 2016-04-22 08:04 2104320 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll 2016-04-22 08:04 . 2016-04-22 08:04 18432 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2016-04-22 08:04 . 2016-04-22 08:04 169984 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\rtscom.dll 2016-04-22 08:04 . 2016-04-22 08:04 16384 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2016-04-22 08:04 . 2016-04-22 08:04 126464 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\rtscom.dll 2016-04-21 05:38 . 2016-04-21 05:38 -------- d-----w- c:\programdata\BlueStacks 2016-04-19 16:15 . 2016-04-19 16:15 1356512 ----a-w- c:\windows\system32\RTCOM64.dll 2016-04-19 16:14 . 2016-04-19 16:14 118600 ----a-w- c:\windows\system32\AERTAR64.dll 2016-04-19 16:14 . 2016-04-19 16:14 574760 ----a-w- c:\windows\system32\AERTAC64.dll 2016-04-19 16:14 . 2016-04-19 16:14 118600 ----a-w- c:\windows\system32\AcpiServiceVnA64.dll 2016-04-18 04:39 . 2016-04-23 05:40 -------- d-----w- C:\FRST 2016-04-15 13:37 . 2016-04-15 13:37 -------- d-----w- c:\programdata\blg 2016-04-14 15:38 . 2016-04-14 15:38 413912 ----a-w- c:\windows\system32\drivers\RtsUer.sys 2016-04-14 15:38 . 2016-04-14 15:38 4330200 ----a-w- c:\windows\RtCRU64.exe 2016-04-13 07:47 . 2016-03-06 18:53 1885696 ----a-w- c:\windows\system32\msxml3.dll 2016-04-13 07:47 . 2016-03-06 18:53 2048 ----a-w- c:\windows\system32\msxml3r.dll 2016-04-13 07:47 . 2016-03-06 18:38 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll 2016-04-13 07:47 . 2016-03-06 18:38 1240576 ----a-w- c:\windows\SysWow64\msxml3.dll 2016-04-13 07:47 . 2016-03-16 18:50 156672 ----a-w- c:\windows\system32\mtxoci.dll 2016-04-13 07:47 . 2016-03-16 18:28 111616 ----a-w- c:\windows\SysWow64\mtxoci.dll 2016-04-13 07:47 . 2016-03-16 18:28 176128 ----a-w- c:\windows\SysWow64\msorcl32.dll 2016-04-13 07:47 . 2016-03-16 18:27 286720 ----a-w- c:\program files (x86)\Common Files\System\Ole DB\msdaora.dll 2016-04-13 07:45 . 2016-03-31 00:21 34304 ----a-w- c:\windows\system32\iernonce.dll 2016-04-13 07:44 . 2016-03-31 00:36 10949120 ----a-w- c:\program files\Internet Explorer\F12Resources.dll 2016-04-12 13:21 . 2016-04-12 13:21 -------- d-----w- c:\programdata\LittleGamesCompany 2016-04-12 12:05 . 2016-04-12 12:07 -------- d-----w- c:\programdata\TheFallTrilogyEp3 2016-04-10 11:20 . 2016-04-11 04:17 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2016-03-30 05:28 . 2016-03-30 05:28 22704 ----a-w- c:\windows\system32\drivers\EsgScanner.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2016-04-22 07:57 . 2014-06-25 10:50 453288 ------w- c:\windows\system32\MpSigStub.exe 2016-04-14 15:40 . 2009-07-13 21:59 18634264 ----a-w- c:\windows\system32\nvwgf2umx.dll 2016-04-14 15:40 . 2015-12-22 08:09 14497568 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2016-04-10 05:50 . 2014-06-25 12:28 143659408 ----a-w- c:\windows\system32\MRT.exe 2016-03-21 17:43 . 2016-03-23 05:20 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2016-03-21 10:32 . 2016-03-21 10:32 70144 ----a-w- c:\windows\system32\appinfo.dll 2016-03-21 10:32 . 2016-03-21 10:32 504320 ----a-w- c:\windows\system32\msihnd.dll 2016-03-21 10:32 . 2016-03-21 10:32 337408 ----a-w- c:\windows\SysWow64\msihnd.dll 2016-03-21 10:32 . 2016-03-21 10:32 3243008 ----a-w- c:\windows\system32\msi.dll 2016-03-21 10:32 . 2016-03-21 10:32 25088 ----a-w- c:\windows\SysWow64\msimsg.dll 2016-03-21 10:32 . 2016-03-21 10:32 25088 ----a-w- c:\windows\system32\msimsg.dll 2016-03-21 10:32 . 2016-03-21 10:32 2364928 ----a-w- c:\windows\SysWow64\msi.dll 2016-03-21 10:32 . 2016-03-21 10:32 1940992 ----a-w- c:\windows\system32\authui.dll 2016-03-21 10:32 . 2016-03-21 10:32 1805824 ----a-w- c:\windows\SysWow64\authui.dll 2016-03-21 10:32 . 2016-03-21 10:32 114624 ----a-w- c:\windows\system32\consent.exe 2016-03-21 10:32 . 2016-03-21 10:32 511488 ----a-w- c:\windows\system32\rpcss.dll 2016-03-21 10:32 . 2016-03-21 10:32 73664 ----a-w- c:\windows\system32\drivers\disk.sys 2016-03-21 10:31 . 2016-03-21 10:31 451080 ----a-w- c:\windows\system32\fveapi.dll 2016-03-21 10:31 . 2016-03-21 10:31 312600 ----a-w- c:\windows\system32\wbem\Win32_Tpm.dll 2016-03-21 10:31 . 2016-03-21 10:31 257864 ----a-w- c:\windows\SysWow64\wbem\Win32_Tpm.dll 2016-03-21 10:31 . 2016-03-21 10:31 20480 ----a-w- c:\windows\system32\tbs.dll 2016-03-21 10:31 . 2016-03-21 10:31 15360 ----a-w- c:\windows\SysWow64\tbs.dll 2016-03-21 10:31 . 2016-03-21 10:31 109568 ----a-w- c:\windows\system32\fveapibase.dll 2016-03-17 22:24 . 2016-04-13 07:48 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2016-03-17 05:10 . 2016-02-07 15:53 60136 ------w- c:\windows\system32\drivers\MPCKpt.sys 2016-02-24 17:38 . 2016-02-24 17:38 1186160 ----a-w- c:\windows\system32\SET82D8.tmp 2016-02-24 17:23 . 2016-02-24 17:23 3052880 ----a-w- c:\windows\system32\SET688E.tmp 2016-02-24 17:23 . 2016-02-24 17:23 445408 ----a-w- c:\windows\system32\SET6B2A.tmp 2016-02-24 17:21 . 2016-02-24 17:21 501280 ----a-w- c:\windows\system32\nvusmb.exe 2016-02-24 17:21 . 2016-02-24 17:21 135680 ----a-w- c:\windows\system32\NVCOSMB.DLL 2016-02-19 01:53 . 2016-03-19 06:06 11249080 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DCBDA277-69F9-40DD-934E-280AF67DAEEF}\mpengine.dll 2016-02-18 11:29 . 2016-02-18 11:29 478128 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys 2016-02-15 09:36 . 2016-03-24 15:39 45992 ----a-w- c:\windows\system32\TURegOpt.exe 2016-02-15 09:30 . 2016-03-24 15:39 37288 ----a-w- c:\windows\system32\authuitu.dll 2016-02-15 09:30 . 2016-03-24 15:39 32680 ----a-w- c:\windows\SysWow64\authuitu.dll 2016-02-12 18:52 . 2016-03-09 08:46 3169792 ----a-w- c:\windows\system32\wucltux.dll 2016-02-12 18:52 . 2016-03-09 08:46 98816 ----a-w- c:\windows\system32\wudriver.dll 2016-02-12 18:52 . 2016-03-09 08:46 192512 ----a-w- c:\windows\system32\wuwebv.dll 2016-02-12 18:44 . 2016-03-09 08:46 91136 ----a-w- c:\windows\system32\WinSetupUI.dll 2016-02-12 18:39 . 2016-03-09 08:46 174080 ----a-w- c:\windows\SysWow64\wuwebv.dll 2016-02-12 18:22 . 2016-03-09 08:46 2610688 ----a-w- c:\windows\system32\wuaueng.dll 2016-02-12 18:19 . 2016-03-09 08:46 709120 ----a-w- c:\windows\system32\wuapi.dll 2016-02-12 18:18 . 2016-03-09 08:46 37888 ----a-w- c:\windows\system32\wuapp.exe 2016-02-12 18:18 . 2016-03-09 08:46 140288 ----a-w- c:\windows\system32\wuauclt.exe 2016-02-12 18:18 . 2016-03-09 08:46 36864 ----a-w- c:\windows\system32\wups.dll 2016-02-12 18:18 . 2016-03-09 08:46 37888 ----a-w- c:\windows\system32\wups2.dll 2016-02-12 18:18 . 2016-03-09 08:46 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll 2016-02-12 18:06 . 2016-03-09 08:46 573440 ----a-w- c:\windows\SysWow64\wuapi.dll 2016-02-12 18:05 . 2016-03-09 08:46 93696 ----a-w- c:\windows\SysWow64\wudriver.dll 2016-02-12 18:05 . 2016-03-09 08:46 30208 ----a-w- c:\windows\SysWow64\wups.dll 2016-02-12 18:05 . 2016-03-09 08:46 35328 ----a-w- c:\windows\SysWow64\wuapp.exe 2016-02-09 09:57 . 2016-03-09 08:41 12625920 ----a-w- c:\windows\system32\wmploc.DLL 2016-02-09 09:57 . 2016-03-09 08:41 14634496 ----a-w- c:\windows\system32\wmp.dll 2016-02-09 09:56 . 2016-03-09 08:41 5120 ----a-w- c:\windows\system32\msdxm.ocx 2016-02-09 09:56 . 2016-03-09 08:41 5120 ----a-w- c:\windows\system32\dxmasf.dll 2016-02-09 09:55 . 2016-03-09 08:46 30720 ----a-w- c:\windows\system32\seclogon.dll 2016-02-09 09:54 . 2016-03-09 08:41 9728 ----a-w- c:\windows\system32\spwmp.dll 2016-02-09 09:51 . 2016-03-09 08:41 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL 2016-02-09 09:13 . 2016-03-09 08:41 4096 ----a-w- c:\windows\SysWow64\msdxm.ocx 2016-02-09 09:13 . 2016-03-09 08:41 4096 ----a-w- c:\windows\SysWow64\dxmasf.dll 2016-02-09 09:13 . 2016-03-09 08:41 8192 ----a-w- c:\windows\SysWow64\spwmp.dll 2016-02-05 18:54 . 2016-03-09 08:41 41472 ----a-w- c:\windows\system32\lpk.dll 2016-02-05 18:54 . 2016-03-09 08:41 100864 ----a-w- c:\windows\system32\fontsub.dll 2016-02-05 18:53 . 2016-03-09 08:41 14336 ----a-w- c:\windows\system32\dciman32.dll 2016-02-05 18:53 . 2016-03-09 08:41 46080 ----a-w- c:\windows\system32\atmlib.dll 2016-02-05 18:50 . 2016-03-09 08:41 25600 ----a-w- c:\windows\SysWow64\lpk.dll 2016-02-05 18:44 . 2016-03-09 08:41 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2016-02-05 18:42 . 2016-03-09 08:41 10240 ----a-w- c:\windows\SysWow64\dciman32.dll 2016-02-05 17:48 . 2016-03-09 08:41 372736 ----a-w- c:\windows\system32\atmfd.dll 2016-02-05 17:43 . 2016-03-09 08:41 299520 ----a-w- c:\windows\SysWow64\atmfd.dll 2016-02-05 17:43 . 2016-03-09 08:41 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2016-02-05 01:19 . 2016-03-09 08:41 381440 ----a-w- c:\windows\system32\mfds.dll 2016-02-04 22:13 . 2016-02-04 22:13 875720 ----a-w- c:\windows\SysWow64\msvcr120_clr0400.dll 2016-02-04 22:13 . 2016-02-04 22:13 536776 ----a-w- c:\windows\SysWow64\msvcp120_clr0400.dll 2016-02-04 22:03 . 2016-02-04 22:03 869568 ----a-w- c:\windows\system32\msvcr120_clr0400.dll 2016-02-04 22:03 . 2016-02-04 22:03 678600 ----a-w- c:\windows\system32\msvcp120_clr0400.dll 2016-02-04 18:41 . 2016-03-09 08:41 296448 ----a-w- c:\windows\SysWow64\mfds.dll 2016-02-03 18:58 . 2016-03-09 08:45 862208 ----a-w- c:\windows\system32\oleaut32.dll 2016-02-03 18:52 . 2016-03-09 08:45 84992 ----a-w- c:\windows\system32\asycfilt.dll 2016-02-03 18:49 . 2016-03-09 08:45 572416 ----a-w- c:\windows\SysWow64\oleaut32.dll 2016-02-03 18:43 . 2016-03-09 08:45 67584 ----a-w- c:\windows\SysWow64\asycfilt.dll 2016-02-03 18:07 . 2016-03-09 08:45 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS 2016-01-29 10:49 . 2014-11-13 16:13 6791736 ----a-w- c:\windows\system32\nvcpl.dll 2016-01-29 10:49 . 2014-11-13 16:13 3529152 ----a-w- c:\windows\system32\nvsvc64.dll 2016-01-29 10:49 . 2015-03-19 10:42 2558328 ----a-w- c:\windows\system32\nvsvcr.dll 2016-01-29 10:49 . 2014-11-13 16:13 932728 ----a-w- c:\windows\system32\nvvsvc.exe 2016-01-29 10:49 . 2014-11-13 16:13 62512 ----a-w- c:\windows\system32\nvshext.dll 2016-01-29 10:49 . 2014-11-13 16:13 384888 ----a-w- c:\windows\system32\nvmctray.dll 2016-01-28 16:29 . 2014-11-13 16:13 6150607 ----a-w- c:\windows\system32\nvcoproc.bin . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "Advanced SystemCare 9"="c:\program files (x86)\IObit\Advanced SystemCare\ASCTray.exe" [2016-01-11 2019616] "CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2015-11-16 8591272] "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 1 (0x1) "NoSimpleNetIDList"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "PPort12reminder"="c:\program files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "c:\programdata\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x] R3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe;c:\program files (x86)\Browny02\BrYNSvc.exe [x] R3 cpuz134;cpuz134;c:\users\S-O\AppData\Local\Temp\cpuz134\cpuz134_x64.sys;c:\users\S-O\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x] R3 cpuz136;cpuz136;c:\users\S-O\AppData\Local\Temp\cpuz136\cpuz136_x64.sys;c:\users\S-O\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [x] R3 GamesAppIntegrationService;GamesAppIntegrationService;c:\program files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x] R3 ogmservice;Online Games Manager;c:\program files (x86)\Online Games Manager\ogmservice.exe;c:\program files (x86)\Online Games Manager\ogmservice.exe [x] R3 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [x] R3 RTSUER;Realtek USB Card Reader - UER;c:\windows\system32\Drivers\RtsUer.sys;c:\windows\SYSNATIVE\Drivers\RtsUer.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x] S1 MPCKpt;MPCKpt;c:\windows\system32\DRIVERS\MPCKpt.sys;c:\windows\SYSNATIVE\DRIVERS\MPCKpt.sys [x] S2 AdvancedSystemCareService9;Advanced SystemCare Service 9;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe [x] S2 MPCProtectService;MPC Core Protect Service;c:\program files (x86)\MPC Cleaner\MPCProtectService.exe;c:\program files (x86)\MPC Cleaner\MPCProtectService.exe [x] S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] S3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc . Inhalt des "geplante Tasks" Ordners . 2016-02-09 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-25 08:42] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2016-04-19 16418560] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2016-01-29 1340192] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = search.mpc.am/?geo=de uDefault_Page_URL = search.mpc.am/?geo=de mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Bar = https://www.google.com/?trackid=sp-006 mStart Page = search.mpc.am/?geo=de mDefault_Page_URL = search.mpc.am/?geo=de Trusted Zone: localhost Trusted Zone: webcompanion.com TCP: DhcpNameServer = 192.168.178.1 DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} - FF - ProfilePath - c:\users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841\ FF - prefs.js: browser.startup.homepage - google.de . - - - - Entfernte verwaiste Registrierungseinträge - - - - . ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_19_0_0_226_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_19_0_0_226_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_19_0_0_226_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_19_0_0_226_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_226.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.19" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_226.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_226.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_226.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\IObit\Advanced SystemCare\Monitor.exe c:\program files (x86)\MPC Cleaner\MPCTray.exe c:\program files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe . ************************************************************************** . Zeit der Fertigstellung: 2016-04-26 07:28:40 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2016-04-26 05:28 ComboFix2.txt 2016-04-25 06:33 . Vor Suchlauf: 21 Verzeichnis(se), 83.813.498.880 Bytes frei Nach Suchlauf: 22 Verzeichnis(se), 84.413.472.768 Bytes frei . - - End Of File - - 54FF27F10551C1FDB59D1D2CF9A893FC A36C5E4F47E84449FF07ED3517B43A31 |
26.04.2016, 16:06 | #19 |
/// Malwareteam | MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] Schritt: 1 Combofix-Skript
Schritt: 2 Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen.
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
26.04.2016, 17:18 | #20 |
| MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] *#*Combofix Logfile: Code:
ATTFilter ComboFix 16-04-22.01 - S-O 26.04.2016 17:47:17.4.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.1535.571 [GMT 2:00] ausgeführt von:: c:\users\S-O\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Updated* {768124D7-F5F7-6D2F-DDC2-94DFA4017C95} SP: Microsoft Security Essentials *Enabled/Updated* {CDE0C533-D3CD-62A1-E772-AFADDF863628} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2016-03-26 bis 2016-04-26 )))))))))))))))))))))))))))))) . . 2016-04-26 16:04 . 2016-04-26 16:04 -------- d-----w- c:\users\Default\AppData\Local\temp 2016-04-26 09:32 . 2016-04-26 15:25 -------- d---a-w- C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ......Z.ZZZZZ 2016-04-26 07:30 . 2016-04-26 09:32 -------- d-----w- C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ..Z.....ZZZZZ 2016-04-26 04:44 . 2016-04-26 04:47 -------- d-----w- c:\program files (x86)\Sea of Lies - In den Tiefen der Meere 2016-04-25 10:45 . 2016-03-17 01:45 11686560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C586A1D5-2587-4F8A-AAC7-9741B5DA5D38}\mpengine.dll 2016-04-25 10:23 . 2016-04-25 16:07 -------- d-----w- c:\programdata\Trymedia 2016-04-25 06:42 . 2016-04-25 06:47 -------- d-----w- c:\program files (x86)\Warlock - Der Fluch des Schamanen 2016-04-24 04:54 . 2016-03-17 01:45 11686560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2016-04-23 07:37 . 2016-04-23 07:39 -------- d-----w- c:\program files (x86)\Around the World in 80 Days 2016-04-23 05:49 . 2016-04-23 06:48 -------- d-----w- C:\AdwCleaner 2016-04-22 15:19 . 2016-03-21 17:43 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F57FDFC3-74A3-473A-8C73-953E4DB7128D}\gapaengine.dll 2016-04-22 13:09 . 2016-04-22 13:09 -------- d-sh--w- c:\windows\ftpcache 2016-04-22 08:06 . 2016-04-22 08:06 444416 ----a-w- c:\windows\system32\winhttp.dll 2016-04-22 08:06 . 2016-04-22 08:06 396800 ----a-w- c:\windows\system32\webio.dll 2016-04-22 08:06 . 2016-04-22 08:06 351744 ----a-w- c:\windows\SysWow64\winhttp.dll 2016-04-22 08:06 . 2016-04-22 08:06 316416 ----a-w- c:\windows\SysWow64\webio.dll 2016-04-22 08:04 . 2016-04-22 08:04 274944 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkDiv.dll 2016-04-22 08:04 . 2016-04-22 08:04 1416192 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkObj.dll 2016-04-22 08:04 . 2016-04-22 08:04 216064 ----a-w- c:\windows\SysWow64\InkEd.dll 2016-04-22 08:04 . 2016-04-22 08:04 353280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkDiv.dll 2016-04-22 08:04 . 2016-04-22 08:04 275456 ----a-w- c:\windows\system32\InkEd.dll 2016-04-22 08:04 . 2016-04-22 08:04 2104320 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll 2016-04-22 08:04 . 2016-04-22 08:04 18432 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2016-04-22 08:04 . 2016-04-22 08:04 169984 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\rtscom.dll 2016-04-22 08:04 . 2016-04-22 08:04 16384 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2016-04-22 08:04 . 2016-04-22 08:04 126464 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\rtscom.dll 2016-04-21 05:38 . 2016-04-21 05:38 -------- d-----w- c:\programdata\BlueStacks 2016-04-19 16:15 . 2016-04-19 16:15 1356512 ----a-w- c:\windows\system32\RTCOM64.dll 2016-04-19 16:14 . 2016-04-19 16:14 118600 ----a-w- c:\windows\system32\AERTAR64.dll 2016-04-19 16:14 . 2016-04-19 16:14 574760 ----a-w- c:\windows\system32\AERTAC64.dll 2016-04-19 16:14 . 2016-04-19 16:14 118600 ----a-w- c:\windows\system32\AcpiServiceVnA64.dll 2016-04-18 04:39 . 2016-04-23 05:40 -------- d-----w- C:\FRST 2016-04-15 13:37 . 2016-04-15 13:37 -------- d-----w- c:\programdata\blg 2016-04-14 15:38 . 2016-04-14 15:38 413912 ----a-w- c:\windows\system32\drivers\RtsUer.sys 2016-04-14 15:38 . 2016-04-14 15:38 4330200 ----a-w- c:\windows\RtCRU64.exe 2016-04-13 07:47 . 2016-03-06 18:53 1885696 ----a-w- c:\windows\system32\msxml3.dll 2016-04-13 07:47 . 2016-03-06 18:53 2048 ----a-w- c:\windows\system32\msxml3r.dll 2016-04-13 07:47 . 2016-03-06 18:38 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll 2016-04-13 07:47 . 2016-03-06 18:38 1240576 ----a-w- c:\windows\SysWow64\msxml3.dll 2016-04-13 07:47 . 2016-03-16 18:50 156672 ----a-w- c:\windows\system32\mtxoci.dll 2016-04-13 07:47 . 2016-03-16 18:28 111616 ----a-w- c:\windows\SysWow64\mtxoci.dll 2016-04-13 07:47 . 2016-03-16 18:28 176128 ----a-w- c:\windows\SysWow64\msorcl32.dll 2016-04-13 07:47 . 2016-03-16 18:27 286720 ----a-w- c:\program files (x86)\Common Files\System\Ole DB\msdaora.dll 2016-04-13 07:45 . 2016-03-31 00:21 34304 ----a-w- c:\windows\system32\iernonce.dll 2016-04-13 07:44 . 2016-03-31 00:36 10949120 ----a-w- c:\program files\Internet Explorer\F12Resources.dll 2016-04-12 13:21 . 2016-04-12 13:21 -------- d-----w- c:\programdata\LittleGamesCompany 2016-04-12 12:05 . 2016-04-12 12:07 -------- d-----w- c:\programdata\TheFallTrilogyEp3 2016-04-10 11:20 . 2016-04-11 04:17 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2016-03-30 05:28 . 2016-03-30 05:28 22704 ----a-w- c:\windows\system32\drivers\EsgScanner.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2016-04-22 07:57 . 2014-06-25 10:50 453288 ------w- c:\windows\system32\MpSigStub.exe 2016-04-14 15:40 . 2009-07-13 21:59 18634264 ----a-w- c:\windows\system32\nvwgf2umx.dll 2016-04-14 15:40 . 2015-12-22 08:09 14497568 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2016-04-10 05:50 . 2014-06-25 12:28 143659408 ----a-w- c:\windows\system32\MRT.exe 2016-03-21 17:43 . 2016-03-23 05:20 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2016-03-21 10:32 . 2016-03-21 10:32 70144 ----a-w- c:\windows\system32\appinfo.dll 2016-03-21 10:32 . 2016-03-21 10:32 504320 ----a-w- c:\windows\system32\msihnd.dll 2016-03-21 10:32 . 2016-03-21 10:32 337408 ----a-w- c:\windows\SysWow64\msihnd.dll 2016-03-21 10:32 . 2016-03-21 10:32 3243008 ----a-w- c:\windows\system32\msi.dll 2016-03-21 10:32 . 2016-03-21 10:32 25088 ----a-w- c:\windows\SysWow64\msimsg.dll 2016-03-21 10:32 . 2016-03-21 10:32 25088 ----a-w- c:\windows\system32\msimsg.dll 2016-03-21 10:32 . 2016-03-21 10:32 2364928 ----a-w- c:\windows\SysWow64\msi.dll 2016-03-21 10:32 . 2016-03-21 10:32 1940992 ----a-w- c:\windows\system32\authui.dll 2016-03-21 10:32 . 2016-03-21 10:32 1805824 ----a-w- c:\windows\SysWow64\authui.dll 2016-03-21 10:32 . 2016-03-21 10:32 114624 ----a-w- c:\windows\system32\consent.exe 2016-03-21 10:32 . 2016-03-21 10:32 511488 ----a-w- c:\windows\system32\rpcss.dll 2016-03-21 10:32 . 2016-03-21 10:32 73664 ----a-w- c:\windows\system32\drivers\disk.sys 2016-03-21 10:31 . 2016-03-21 10:31 451080 ----a-w- c:\windows\system32\fveapi.dll 2016-03-21 10:31 . 2016-03-21 10:31 312600 ----a-w- c:\windows\system32\wbem\Win32_Tpm.dll 2016-03-21 10:31 . 2016-03-21 10:31 257864 ----a-w- c:\windows\SysWow64\wbem\Win32_Tpm.dll 2016-03-21 10:31 . 2016-03-21 10:31 20480 ----a-w- c:\windows\system32\tbs.dll 2016-03-21 10:31 . 2016-03-21 10:31 15360 ----a-w- c:\windows\SysWow64\tbs.dll 2016-03-21 10:31 . 2016-03-21 10:31 109568 ----a-w- c:\windows\system32\fveapibase.dll 2016-03-17 22:24 . 2016-04-13 07:48 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2016-03-17 05:10 . 2016-02-07 15:53 60136 ------w- c:\windows\system32\drivers\MPCKpt.sys 2016-02-24 17:38 . 2016-02-24 17:38 1186160 ----a-w- c:\windows\system32\SET82D8.tmp 2016-02-24 17:23 . 2016-02-24 17:23 3052880 ----a-w- c:\windows\system32\SET688E.tmp 2016-02-24 17:23 . 2016-02-24 17:23 445408 ----a-w- c:\windows\system32\SET6B2A.tmp 2016-02-24 17:21 . 2016-02-24 17:21 501280 ----a-w- c:\windows\system32\nvusmb.exe 2016-02-24 17:21 . 2016-02-24 17:21 135680 ----a-w- c:\windows\system32\NVCOSMB.DLL 2016-02-19 01:53 . 2016-03-19 06:06 11249080 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DCBDA277-69F9-40DD-934E-280AF67DAEEF}\mpengine.dll 2016-02-18 11:29 . 2016-02-18 11:29 478128 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys 2016-02-15 09:36 . 2016-03-24 15:39 45992 ----a-w- c:\windows\system32\TURegOpt.exe 2016-02-15 09:30 . 2016-03-24 15:39 37288 ----a-w- c:\windows\system32\authuitu.dll 2016-02-15 09:30 . 2016-03-24 15:39 32680 ----a-w- c:\windows\SysWow64\authuitu.dll 2016-02-12 18:52 . 2016-03-09 08:46 3169792 ----a-w- c:\windows\system32\wucltux.dll 2016-02-12 18:52 . 2016-03-09 08:46 98816 ----a-w- c:\windows\system32\wudriver.dll 2016-02-12 18:52 . 2016-03-09 08:46 192512 ----a-w- c:\windows\system32\wuwebv.dll 2016-02-12 18:44 . 2016-03-09 08:46 91136 ----a-w- c:\windows\system32\WinSetupUI.dll 2016-02-12 18:39 . 2016-03-09 08:46 174080 ----a-w- c:\windows\SysWow64\wuwebv.dll 2016-02-12 18:22 . 2016-03-09 08:46 2610688 ----a-w- c:\windows\system32\wuaueng.dll 2016-02-12 18:19 . 2016-03-09 08:46 709120 ----a-w- c:\windows\system32\wuapi.dll 2016-02-12 18:18 . 2016-03-09 08:46 37888 ----a-w- c:\windows\system32\wuapp.exe 2016-02-12 18:18 . 2016-03-09 08:46 140288 ----a-w- c:\windows\system32\wuauclt.exe 2016-02-12 18:18 . 2016-03-09 08:46 36864 ----a-w- c:\windows\system32\wups.dll 2016-02-12 18:18 . 2016-03-09 08:46 37888 ----a-w- c:\windows\system32\wups2.dll 2016-02-12 18:18 . 2016-03-09 08:46 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll 2016-02-12 18:06 . 2016-03-09 08:46 573440 ----a-w- c:\windows\SysWow64\wuapi.dll 2016-02-12 18:05 . 2016-03-09 08:46 93696 ----a-w- c:\windows\SysWow64\wudriver.dll 2016-02-12 18:05 . 2016-03-09 08:46 30208 ----a-w- c:\windows\SysWow64\wups.dll 2016-02-12 18:05 . 2016-03-09 08:46 35328 ----a-w- c:\windows\SysWow64\wuapp.exe 2016-02-09 09:57 . 2016-03-09 08:41 12625920 ----a-w- c:\windows\system32\wmploc.DLL 2016-02-09 09:57 . 2016-03-09 08:41 14634496 ----a-w- c:\windows\system32\wmp.dll 2016-02-09 09:56 . 2016-03-09 08:41 5120 ----a-w- c:\windows\system32\msdxm.ocx 2016-02-09 09:56 . 2016-03-09 08:41 5120 ----a-w- c:\windows\system32\dxmasf.dll 2016-02-09 09:55 . 2016-03-09 08:46 30720 ----a-w- c:\windows\system32\seclogon.dll 2016-02-09 09:54 . 2016-03-09 08:41 9728 ----a-w- c:\windows\system32\spwmp.dll 2016-02-09 09:51 . 2016-03-09 08:41 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL 2016-02-09 09:13 . 2016-03-09 08:41 4096 ----a-w- c:\windows\SysWow64\msdxm.ocx 2016-02-09 09:13 . 2016-03-09 08:41 4096 ----a-w- c:\windows\SysWow64\dxmasf.dll 2016-02-09 09:13 . 2016-03-09 08:41 8192 ----a-w- c:\windows\SysWow64\spwmp.dll 2016-02-05 18:54 . 2016-03-09 08:41 41472 ----a-w- c:\windows\system32\lpk.dll 2016-02-05 18:54 . 2016-03-09 08:41 100864 ----a-w- c:\windows\system32\fontsub.dll 2016-02-05 18:53 . 2016-03-09 08:41 14336 ----a-w- c:\windows\system32\dciman32.dll 2016-02-05 18:53 . 2016-03-09 08:41 46080 ----a-w- c:\windows\system32\atmlib.dll 2016-02-05 18:50 . 2016-03-09 08:41 25600 ----a-w- c:\windows\SysWow64\lpk.dll 2016-02-05 18:44 . 2016-03-09 08:41 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2016-02-05 18:42 . 2016-03-09 08:41 10240 ----a-w- c:\windows\SysWow64\dciman32.dll 2016-02-05 17:48 . 2016-03-09 08:41 372736 ----a-w- c:\windows\system32\atmfd.dll 2016-02-05 17:43 . 2016-03-09 08:41 299520 ----a-w- c:\windows\SysWow64\atmfd.dll 2016-02-05 17:43 . 2016-03-09 08:41 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2016-02-05 01:19 . 2016-03-09 08:41 381440 ----a-w- c:\windows\system32\mfds.dll 2016-02-04 22:13 . 2016-02-04 22:13 875720 ----a-w- c:\windows\SysWow64\msvcr120_clr0400.dll 2016-02-04 22:13 . 2016-02-04 22:13 536776 ----a-w- c:\windows\SysWow64\msvcp120_clr0400.dll 2016-02-04 22:03 . 2016-02-04 22:03 869568 ----a-w- c:\windows\system32\msvcr120_clr0400.dll 2016-02-04 22:03 . 2016-02-04 22:03 678600 ----a-w- c:\windows\system32\msvcp120_clr0400.dll 2016-02-04 18:41 . 2016-03-09 08:41 296448 ----a-w- c:\windows\SysWow64\mfds.dll 2016-02-03 18:58 . 2016-03-09 08:45 862208 ----a-w- c:\windows\system32\oleaut32.dll 2016-02-03 18:52 . 2016-03-09 08:45 84992 ----a-w- c:\windows\system32\asycfilt.dll 2016-02-03 18:49 . 2016-03-09 08:45 572416 ----a-w- c:\windows\SysWow64\oleaut32.dll 2016-02-03 18:43 . 2016-03-09 08:45 67584 ----a-w- c:\windows\SysWow64\asycfilt.dll 2016-02-03 18:07 . 2016-03-09 08:45 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS 2016-01-29 10:49 . 2014-11-13 16:13 6791736 ----a-w- c:\windows\system32\nvcpl.dll 2016-01-29 10:49 . 2014-11-13 16:13 3529152 ----a-w- c:\windows\system32\nvsvc64.dll 2016-01-29 10:49 . 2015-03-19 10:42 2558328 ----a-w- c:\windows\system32\nvsvcr.dll 2016-01-29 10:49 . 2014-11-13 16:13 932728 ----a-w- c:\windows\system32\nvvsvc.exe 2016-01-29 10:49 . 2014-11-13 16:13 62512 ----a-w- c:\windows\system32\nvshext.dll 2016-01-29 10:49 . 2014-11-13 16:13 384888 ----a-w- c:\windows\system32\nvmctray.dll 2016-01-28 16:29 . 2014-11-13 16:13 6150607 ----a-w- c:\windows\system32\nvcoproc.bin . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "Advanced SystemCare 9"="c:\program files (x86)\IObit\Advanced SystemCare\ASCTray.exe" [2016-01-11 2019616] "CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2015-11-16 8591272] "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 1 (0x1) "NoSimpleNetIDList"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "PPort12reminder"="c:\program files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "c:\programdata\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x] R3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe;c:\program files (x86)\Browny02\BrYNSvc.exe [x] R3 cpuz134;cpuz134;c:\users\S-O\AppData\Local\Temp\cpuz134\cpuz134_x64.sys;c:\users\S-O\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x] R3 cpuz136;cpuz136;c:\users\S-O\AppData\Local\Temp\cpuz136\cpuz136_x64.sys;c:\users\S-O\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [x] R3 GamesAppIntegrationService;GamesAppIntegrationService;c:\program files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x] R3 ogmservice;Online Games Manager;c:\program files (x86)\Online Games Manager\ogmservice.exe;c:\program files (x86)\Online Games Manager\ogmservice.exe [x] R3 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [x] R3 RTSUER;Realtek USB Card Reader - UER;c:\windows\system32\Drivers\RtsUer.sys;c:\windows\SYSNATIVE\Drivers\RtsUer.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x] S1 MPCKpt;MPCKpt;c:\windows\system32\DRIVERS\MPCKpt.sys;c:\windows\SYSNATIVE\DRIVERS\MPCKpt.sys [x] S2 AdvancedSystemCareService9;Advanced SystemCare Service 9;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe [x] S2 MPCProtectService;MPC Core Protect Service;c:\program files (x86)\MPC Cleaner\MPCProtectService.exe;c:\program files (x86)\MPC Cleaner\MPCProtectService.exe [x] S3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] S3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc . Inhalt des "geplante Tasks" Ordners . 2016-02-09 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-25 08:42] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2016-04-19 16418560] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2016-01-29 1340192] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = search.mpc.am/?geo=de uDefault_Page_URL = search.mpc.am/?geo=de mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Bar = https://www.google.com/?trackid=sp-006 mStart Page = search.mpc.am/?geo=de mDefault_Page_URL = search.mpc.am/?geo=de Trusted Zone: localhost Trusted Zone: webcompanion.com TCP: DhcpNameServer = 192.168.178.1 DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} - FF - ProfilePath - c:\users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841\ FF - prefs.js: browser.startup.homepage - google.de . - - - - Entfernte verwaiste Registrierungseinträge - - - - . ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_19_0_0_226_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_19_0_0_226_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_19_0_0_226_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_19_0_0_226_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_226.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.19" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_226.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_226.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_226.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2016-04-26 18:12:08 ComboFix-quarantined-files.txt 2016-04-26 16:12 ComboFix2.txt 2016-04-26 05:28 ComboFix3.txt 2016-04-25 06:33 . Vor Suchlauf: 23 Verzeichnis(se), 83.971.371.008 Bytes frei Nach Suchlauf: 24 Verzeichnis(se), 83.912.486.912 Bytes frei . - - End Of File - - F0D0F25B34C81BF4AABB2F061A12E304 A36C5E4F47E84449FF07ED3517B43A31 |
26.04.2016, 17:23 | #21 |
/// Malwareteam | MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] Du hast die Anleitung nicht richtig gelesen, du hast das Skript nicht durchgeführt. Lies bitte noch einmal mein Posting genau durch und folge dieser Anleitung.
__________________ --> MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht |
26.04.2016, 17:25 | #22 |
| MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_226.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2016-04-26 18:12:08 ComboFix-quarantined-files.txt 2016-04-26 16:12 ComboFix2.txt 2016-04-26 05:28 ComboFix3.txt 2016-04-25 06:33 . Vor Suchlauf: 23 Verzeichnis(se), 83.971.371.008 Bytes frei Nach Suchlauf: 24 Verzeichnis(se), 83.912.486.912 Bytes frei FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:17-04-2016 01 durchgeführt von S-O (Administrator) auf S-O-PC (26-04-2016 18:19:13) Gestartet von C:\Users\S-O\Downloads Geladene Profile: S-O (Verfügbare Profile: S-O) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe (DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCTray.exe (DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCTray64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe (WildTangent, Inc.) C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16418560 2016-04-19] (Realtek Semiconductor) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Policies\Explorer: [NoInternetOpenWith] 1 HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Keine Datei ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{FF12AB65-EFBE-4417-B33C-1A72AD66D239}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = search.mpc.am/?geo=de HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = search.mpc.am/?geo=de HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = search.mpc.am/?geo=de HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = search.mpc.am/?geo=de HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\Software\Microsoft\Internet Explorer\Main,Start Page = search.mpc.am/?geo=de SearchScopes: HKLM -> DefaultScope {0644EE93-D778-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000 -> DefaultScope {0644EE93-D778-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.mpc.am/index/search?q={searchTerms}&cx=partner-pub-3796753109442372:3837783968&ie=UTF-8 SearchScopes: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000 -> Yahoo URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=oberhp&type=iplaygamestoolbar SearchScopes: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000 -> {0644EE93-D778-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.mpc.am/index/search?q={searchTerms}&cx=partner-pub-3796753109442372:3837783968&ie=UTF-8 SearchScopes: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation) DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095} FireFox: ======== FF ProfilePath: C:\Users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841 FF DefaultSearchEngine: Google FF Homepage: google.de FF Plugin-x32: @alawar.com/npapi -> C:\Windows\npapi.dll [2014-01-29] (Alawar) FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll [2012-05-31] (Oberon-Media ) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2016-04-01] () FF Extension: LottaDeals - C:\Users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841\Extensions\@lottadealsun.xpi [2016-02-02] FF Extension: Primary Color 1.0.1 - C:\Users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841\Extensions\{54e9b4e5-84c4-42a5-a254-fd1f8319fc98}.xpi [2016-02-06] [ist nicht signiert] FF Extension: Adblock Plus - C:\Users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-24] Chrome: ======= CHR Profile: C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Kein Name) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-05] CHR Extension: (Google Search) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-05] CHR Extension: (Startpage) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\mflpjdcmkggbacigfegaffogkkkkoiim [2014-11-17] CHR Extension: (Google Wallet) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-05] CHR Extension: (Gmail) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-05] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ijepgjdjkdbopbnaopmlmobimmhjklhd] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [mflpjdcmkggbacigfegaffogkkkkoiim] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\S-O\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx <nicht gefunden> ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit) S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [Datei ist nicht signiert] S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [350064 2016-04-01] (WildTangent) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit) R2 MPCProtectService; C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe [350688 2016-03-17] (DotC United Inc) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation) S3 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [581568 2014-03-27] (RealNetworks, Inc.) S3 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-01] (REALiX(tm)) R1 MPCKpt; C:\Windows\System32\DRIVERS\MPCKpt.sys [60136 2016-03-17] (DotC United Inc) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation) R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation) S3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [413912 2016-04-14] (Realsil Semiconductor Corporation) S3 StarOpen; kein ImagePath S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz134; \??\C:\Users\S-O\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 cpuz136; \??\C:\Users\S-O\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-26 18:15 - 2016-04-26 18:15 - 00025013 _____ C:\Users\S-O\Documents\cfscript.txt 2016-04-26 18:12 - 2016-04-26 18:12 - 00025015 _____ C:\ComboFix.txt 2016-04-26 17:44 - 2016-04-26 18:12 - 00000000 ____D C:\ComboFix 2016-04-26 17:23 - 2016-04-26 17:24 - 05660058 ____R (Swearware) C:\Users\S-O\Downloads\ComboFix.exe 2016-04-26 11:32 - 2016-04-26 17:25 - 00000000 ____D C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ......Z.ZZZZZ 2016-04-26 09:30 - 2016-04-26 11:32 - 00000000 ____D C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ..Z.....ZZZZZ 2016-04-26 07:16 - 2016-04-26 07:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC 2016-04-26 06:47 - 2016-04-26 06:47 - 00002204 _____ C:\Users\Public\Desktop\Spiel Sea of Lies - In den Tiefen der Meere.lnk 2016-04-26 06:47 - 2016-04-26 06:47 - 00001304 _____ C:\Users\Public\Desktop\Weitere fantastische Spiele.lnk 2016-04-26 06:44 - 2016-04-26 06:47 - 00000000 ____D C:\Program Files (x86)\Sea of Lies - In den Tiefen der Meere 2016-04-26 06:44 - 2016-04-26 06:44 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sea of Lies - In den Tiefen der Meere 2016-04-26 06:44 - 2016-04-26 06:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sea of Lies - In den Tiefen der Meere 2016-04-25 15:27 - 2016-04-26 05:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-04-25 12:23 - 2016-04-25 18:07 - 00000000 ____D C:\ProgramData\Trymedia 2016-04-25 08:53 - 2016-04-25 08:53 - 00003234 _____ C:\Windows\System32\Tasks\SidebarExecute 2016-04-25 08:47 - 2016-04-25 08:47 - 00002122 _____ C:\Users\Public\Desktop\Spiel Warlock - Der Fluch des Schamanen.lnk 2016-04-25 08:42 - 2016-04-25 08:47 - 00000000 ____D C:\Program Files (x86)\Warlock - Der Fluch des Schamanen 2016-04-25 08:42 - 2016-04-25 08:42 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warlock - Der Fluch des Schamanen 2016-04-25 08:42 - 2016-04-25 08:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warlock - Der Fluch des Schamanen 2016-04-25 07:28 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2016-04-25 07:28 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2016-04-25 07:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2016-04-25 07:25 - 2016-04-26 18:12 - 00000000 ____D C:\Qoobox 2016-04-25 07:17 - 2016-04-25 08:27 - 00000000 ____D C:\Windows\erdnt 2016-04-25 07:14 - 2016-04-26 17:23 - 00002896 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_S-O 2016-04-23 09:39 - 2016-04-23 09:39 - 00002108 _____ C:\Users\Public\Desktop\Spiel Around the World in 80 Days.lnk 2016-04-23 09:39 - 2016-04-23 09:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Around the World in 80 Days 2016-04-23 09:37 - 2016-04-23 09:39 - 00000000 ____D C:\Program Files (x86)\Around the World in 80 Days 2016-04-23 08:43 - 2016-04-23 08:56 - 00004681 _____ C:\mbam.txt 2016-04-23 07:49 - 2016-04-23 08:48 - 00000000 ____D C:\AdwCleaner 2016-04-22 15:09 - 2016-04-22 15:09 - 00000000 __SHD C:\Windows\ftpcache 2016-04-22 10:06 - 2016-04-22 10:06 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2016-04-22 10:06 - 2016-04-22 10:06 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2016-04-22 10:06 - 2016-04-22 10:06 - 00351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2016-04-22 10:06 - 2016-04-22 10:06 - 00316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2016-04-22 10:04 - 2016-04-22 10:04 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2016-04-22 10:04 - 2016-04-22 10:04 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2016-04-21 08:36 - 2016-04-21 08:44 - 00000255 _____ C:\Users\S-O\Downloads\Search.txt 2016-04-21 07:38 - 2016-04-21 07:38 - 00002694 ____N C:\Users\Public\Desktop\WildTangent Games App - wildgames.lnk 2016-04-21 07:38 - 2016-04-21 07:38 - 00000000 ____D C:\ProgramData\BlueStacks 2016-04-20 06:45 - 2016-04-20 06:45 - 02375680 _____ (Farbar) C:\Users\S-O\Downloads\FRST64(1).exe 2016-04-19 18:16 - 2016-04-19 18:16 - 04803840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2016-04-19 18:16 - 2016-04-19 18:16 - 03299832 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE2.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 03283248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 03198720 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 02894976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2016-04-19 18:16 - 2016-04-19 18:16 - 02190992 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 02110600 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01943624 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01435152 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01382240 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01330072 _____ (DTS, Inc.) C:\Windows\system32\slcnt64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01022872 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00965032 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00927424 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00888480 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaeapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00873472 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00716104 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00689888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00596120 _____ (TOSHIBA Corporation) C:\Windows\system32\tosasfapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00589080 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SECOMN32.DLL 2016-04-19 18:16 - 2016-04-19 18:16 - 00532384 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00467168 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00450128 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00387320 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00381416 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00343712 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00341160 _____ (Synopsys, Inc.) C:\Windows\SysWOW64\SRCOM.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00341160 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00258504 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00231920 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00224264 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaemaxapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00221976 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00214840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00209536 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00192992 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00172584 _____ (TOSHIBA Corporation) C:\Windows\system32\toseaeapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00166208 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00158704 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00110984 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00090920 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00088352 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00088328 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00075544 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00023704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 72203792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2016-04-19 18:15 - 2016-04-19 18:15 - 14057256 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 13120760 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 12986528 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO4064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 10521552 _____ (Intel Corporation) C:\Windows\system32\IntelSSTAPO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 07172920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 07096192 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 06343320 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV3apo.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 06264640 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64AF3.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 05777704 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 05576400 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2016-04-19 18:15 - 2016-04-19 18:15 - 05338936 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 05289952 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 03282032 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 03081808 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02823280 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO7064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02714568 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RltkAPO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02437144 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02050184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02049664 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01965816 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01959608 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64AF3.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01780624 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01601952 _____ (Conexant Systems Inc.) C:\Windows\system32\CX64APO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01591064 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01508936 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01421104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01356512 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01334384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01211840 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01186168 _____ (Intel Corporation) C:\Windows\system32\IntelSstCApoPropPage.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01164336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01060504 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01003864 _____ (Nahimic Inc) C:\Windows\system32\NahimicAPONSControl.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00998032 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00931624 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00923752 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00743968 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00727440 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00708320 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00678192 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00677680 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00618192 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00514528 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00504312 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00500560 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00471336 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00447720 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00445408 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00441272 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00428232 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00416512 _____ (Harman) C:\Windows\system32\HMUI.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00370840 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00366128 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\HMAPO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00362056 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64AF3.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00360352 _____ (Harman) C:\Windows\system32\HMClariFi.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00330568 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00327464 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00310424 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64F3.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00272720 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00253904 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00253872 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00252880 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00203848 _____ (Harman) C:\Windows\system32\HMHVS.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00190944 _____ (Harman) C:\Windows\system32\HMEQ_Voice.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00190944 _____ (Harman) C:\Windows\system32\HMEQ.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00179608 _____ (Harman) C:\Windows\system32\HMLimiter.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00151792 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00134208 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00122328 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00105312 _____ C:\Windows\system32\audioLibVc.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00084624 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00065792 _____ (Harman) C:\Windows\system32\HarmanAudioInterface.dll 2016-04-19 18:14 - 2016-04-19 18:14 - 00574760 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2016-04-19 18:14 - 2016-04-19 18:14 - 00118600 _____ C:\Windows\system32\AcpiServiceVnA64.dll 2016-04-19 18:14 - 2016-04-19 18:14 - 00118600 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2016-04-18 15:14 - 2016-04-18 15:14 - 00000000 ____D C:\Users\S-O\Documents\The Lonely Hearts Murders SE 2016-04-18 06:56 - 2016-04-23 07:40 - 00055891 _____ C:\Users\S-O\Downloads\Addition.txt 2016-04-18 06:41 - 2016-04-26 18:20 - 00012337 _____ C:\Users\S-O\Downloads\FRST.txt 2016-04-18 06:39 - 2016-04-26 18:19 - 00000000 ____D C:\FRST 2016-04-18 06:38 - 2016-04-18 06:38 - 02375680 _____ (Farbar) C:\Users\S-O\Downloads\FRST64.exe 2016-04-17 10:21 - 2016-04-17 10:21 - 00001328 _____ C:\Users\Public\Desktop\More Great Games.lnk 2016-04-15 15:37 - 2016-04-15 15:37 - 00000000 ____D C:\ProgramData\blg 2016-04-14 17:40 - 2016-04-14 17:40 - 31523896 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 24207296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 23000000 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 17559240 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 16128576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 15302712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 13916600 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 13828032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 12911160 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2016-04-14 17:40 - 2016-04-14 17:40 - 11272240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 11209376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 04252608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 03996216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 03210784 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 02825016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 01908272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434195.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 01557552 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434195.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 00952256 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 00915392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 00911928 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 00878648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2016-04-14 17:38 - 2016-04-14 17:38 - 04330200 _____ (TODO: <Company name>) C:\Windows\RtCRU64.exe 2016-04-14 17:38 - 2016-04-14 17:38 - 00413912 _____ (Realsil Semiconductor Corporation) C:\Windows\system32\Drivers\RtsUer.sys 2016-04-13 09:48 - 2016-03-18 01:04 - 05551336 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-04-13 09:48 - 2016-03-18 01:04 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2016-04-13 09:48 - 2016-03-18 01:04 - 00154344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-04-13 09:48 - 2016-03-18 01:04 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-04-13 09:48 - 2016-03-18 01:01 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-04-13 09:48 - 2016-03-18 01:01 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2016-04-13 09:48 - 2016-03-18 00:58 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-04-13 09:48 - 2016-03-18 00:56 - 02084864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2016-04-13 09:48 - 2016-03-18 00:56 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2016-04-13 09:48 - 2016-03-18 00:54 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-04-13 09:48 - 2016-03-18 00:54 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-04-13 09:48 - 2016-03-18 00:54 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-04-13 09:48 - 2016-03-18 00:54 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-04-13 09:48 - 2016-03-18 00:53 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-04-13 09:48 - 2016-03-18 00:53 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-04-13 09:48 - 2016-03-18 00:53 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-04-13 09:48 - 2016-03-18 00:53 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-04-13 09:48 - 2016-03-18 00:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-04-13 09:48 - 2016-03-18 00:33 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-04-13 09:48 - 2016-03-18 00:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-04-13 09:48 - 2016-03-18 00:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-04-13 09:48 - 2016-03-18 00:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-04-13 09:48 - 2016-03-18 00:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-04-13 09:48 - 2016-03-18 00:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2016-04-13 09:48 - 2016-03-18 00:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-04-13 09:48 - 2016-03-18 00:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2016-04-13 09:48 - 2016-03-18 00:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-04-13 09:48 - 2016-03-18 00:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-04-13 09:48 - 2016-03-18 00:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-04-13 09:48 - 2016-03-18 00:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-04-13 09:48 - 2016-03-18 00:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-04-13 09:48 - 2016-03-18 00:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-04-13 09:48 - 2016-03-17 23:53 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2016-04-13 09:48 - 2016-03-17 23:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2016-04-13 09:48 - 2016-03-17 23:52 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2016-04-13 09:48 - 2016-03-17 23:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-04-13 09:48 - 2016-03-17 23:44 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-04-13 09:48 - 2016-03-17 23:43 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-04-13 09:48 - 2016-03-17 23:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-04-13 09:48 - 2016-03-17 23:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-04-13 09:48 - 2016-03-17 23:37 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-04-13 09:48 - 2016-03-17 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-04-13 09:48 - 2016-03-17 23:35 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-04-13 09:48 - 2016-03-17 23:35 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-04-13 09:48 - 2016-03-17 23:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-04-13 09:48 - 2016-03-17 23:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-04-13 09:48 - 2016-03-17 23:30 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-04-13 09:48 - 2016-03-17 23:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-04-13 09:48 - 2016-03-17 23:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-04-13 09:48 - 2016-03-17 23:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-04-13 09:48 - 2016-03-17 23:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-04-13 09:48 - 2016-03-17 23:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-04-13 09:48 - 2016-03-17 23:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-04-13 09:47 - 2016-03-16 20:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2016-04-13 09:47 - 2016-03-16 20:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2016-04-13 09:47 - 2016-03-16 20:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2016-04-13 09:47 - 2016-03-06 20:53 - 01885696 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2016-04-13 09:47 - 2016-03-06 20:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2016-04-13 09:47 - 2016-03-06 20:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2016-04-13 09:47 - 2016-03-06 20:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2016-04-13 09:46 - 2016-04-04 20:14 - 00038120 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-04-13 09:46 - 2016-04-04 20:02 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-04-13 09:46 - 2016-04-02 15:08 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-04-13 09:46 - 2016-03-29 19:53 - 03216896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-04-13 09:46 - 2016-03-23 16:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2016-04-13 09:46 - 2016-03-17 20:04 - 00698368 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-04-13 09:46 - 2016-03-17 20:04 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-04-13 09:46 - 2016-03-17 20:04 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-04-13 09:46 - 2016-03-17 20:04 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-04-13 09:46 - 2016-03-16 02:16 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2016-04-13 09:46 - 2016-03-16 02:16 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2016-04-13 09:46 - 2016-03-16 01:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2016-04-13 09:46 - 2016-03-11 20:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2016-04-13 09:46 - 2016-03-11 20:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2016-04-13 09:45 - 2016-03-31 21:25 - 00394952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-04-13 09:45 - 2016-03-31 20:41 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-04-13 09:45 - 2016-03-31 02:54 - 25817600 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-04-13 09:45 - 2016-03-31 02:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2016-04-13 09:45 - 2016-03-31 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2016-04-13 09:45 - 2016-03-31 02:31 - 02892800 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-04-13 09:45 - 2016-03-31 02:28 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-04-13 09:45 - 2016-03-31 02:28 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2016-04-13 09:45 - 2016-03-31 02:27 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2016-04-13 09:45 - 2016-03-31 02:27 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2016-04-13 09:45 - 2016-03-31 02:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2016-04-13 09:45 - 2016-03-31 02:25 - 06052352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-04-13 09:45 - 2016-03-31 02:22 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2016-04-13 09:45 - 2016-03-31 02:21 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2016-04-13 09:45 - 2016-03-31 02:19 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-04-13 09:45 - 2016-03-31 02:17 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-04-13 09:45 - 2016-03-31 02:17 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2016-04-13 09:45 - 2016-03-31 02:17 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2016-04-13 09:45 - 2016-03-31 02:17 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2016-04-13 09:45 - 2016-03-31 02:11 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2016-04-13 09:45 - 2016-03-31 02:08 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2016-04-13 09:45 - 2016-03-31 02:03 - 20352512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-04-13 09:45 - 2016-03-31 02:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2016-04-13 09:45 - 2016-03-31 02:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-04-13 09:45 - 2016-03-31 01:59 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2016-04-13 09:45 - 2016-03-31 01:57 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2016-04-13 09:45 - 2016-03-31 01:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-04-13 09:45 - 2016-03-31 01:55 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-04-13 09:45 - 2016-03-31 01:53 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-04-13 09:45 - 2016-03-31 01:53 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2016-04-13 09:45 - 2016-03-31 01:52 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2016-04-13 09:45 - 2016-03-31 01:52 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-04-13 09:45 - 2016-03-31 01:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2016-04-13 09:45 - 2016-03-31 01:52 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2016-04-13 09:45 - 2016-03-31 01:51 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-04-13 09:45 - 2016-03-31 01:48 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2016-04-13 09:45 - 2016-03-31 01:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2016-04-13 09:45 - 2016-03-31 01:46 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-04-13 09:45 - 2016-03-31 01:45 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-04-13 09:45 - 2016-03-31 01:45 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2016-04-13 09:45 - 2016-03-31 01:45 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-04-13 09:45 - 2016-03-31 01:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2016-04-13 09:45 - 2016-03-31 01:43 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-04-13 09:45 - 2016-03-31 01:43 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-04-13 09:45 - 2016-03-31 01:42 - 02131968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-04-13 09:45 - 2016-03-31 01:42 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2016-04-13 09:45 - 2016-03-31 01:39 - 15415808 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-04-13 09:45 - 2016-03-31 01:38 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2016-04-13 09:45 - 2016-03-31 01:34 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-04-13 09:45 - 2016-03-31 01:33 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2016-04-13 09:45 - 2016-03-31 01:31 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2016-04-13 09:45 - 2016-03-31 01:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2016-04-13 09:45 - 2016-03-31 01:30 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-04-13 09:45 - 2016-03-31 01:30 - 02596864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-04-13 09:45 - 2016-03-31 01:30 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-04-13 09:45 - 2016-03-31 01:29 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2016-04-13 09:45 - 2016-03-31 01:24 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-04-13 09:45 - 2016-03-31 01:23 - 02056192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-04-13 09:45 - 2016-03-31 01:23 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-04-13 09:45 - 2016-03-31 01:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2016-04-13 09:45 - 2016-03-31 01:21 - 13811712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-04-13 09:45 - 2016-03-31 01:18 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-04-13 09:45 - 2016-03-31 01:06 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-04-13 09:45 - 2016-03-31 01:05 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-04-13 09:45 - 2016-03-31 01:02 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-04-13 09:45 - 2016-03-31 01:00 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-04-12 15:21 - 2016-04-12 15:21 - 00000000 ____D C:\ProgramData\LittleGamesCompany 2016-04-12 14:05 - 2016-04-12 14:07 - 00000000 ____D C:\ProgramData\TheFallTrilogyEp3 2016-04-10 13:20 - 2016-04-11 06:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2016-04-09 07:52 - 2016-04-09 07:52 - 00000000 ____D C:\Users\S-O\Documents\My Games 2016-03-30 16:17 - 2016-03-30 16:17 - 00000000 ____D C:\Users\S-O\AppData\LocalLow\phime studio 2016-03-30 07:28 - 2016-03-30 07:28 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-26 18:04 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2016-04-26 17:19 - 2014-11-21 15:13 - 00013214 _____ C:\Users\S-O\Documents\Lottogeld Gerhilde.ods 2016-04-26 17:14 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2016-04-26 12:31 - 2009-07-14 06:45 - 00015136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-04-26 12:31 - 2009-07-14 06:45 - 00015136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-04-26 11:42 - 2015-11-20 19:23 - 00000000 ____D C:\ProgramData\TEMP 2016-04-26 08:56 - 2014-06-26 08:04 - 00000000 ____D C:\BigFishCache 2016-04-26 07:19 - 2015-11-24 22:53 - 00003234 _____ C:\Windows\System32\Tasks\Driver Booster Scheduler 2016-04-26 07:19 - 2014-11-13 17:36 - 00002866 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (S-O) 2016-04-26 07:16 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-04-26 05:53 - 2014-06-25 11:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-04-25 18:09 - 2014-12-25 19:06 - 00000000 ____D C:\Zylom Games 2016-04-25 18:09 - 2014-08-17 17:56 - 00000000 ____D C:\Users\S-O\AppData\Local\com.gamehouse.acid 2016-04-25 18:09 - 2014-06-26 17:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zylom 2016-04-25 17:36 - 2016-03-12 18:27 - 00000000 ____D C:\Program Files (x86)\Alawar.de 2016-04-25 17:27 - 2016-02-05 11:31 - 00000000 ____D C:\ProgramData\AlawarWrapper 2016-04-25 16:15 - 2014-07-09 11:42 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Natural Threat.Ominous Shores 2016-04-25 11:20 - 2014-07-12 07:16 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Eipix 2016-04-25 10:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2016-04-23 13:14 - 2014-09-11 12:18 - 00000000 ____D C:\ProgramData\WildTangent 2016-04-23 07:06 - 2016-02-08 14:19 - 00000000 ____D C:\Program Files (x86)\OXXOGames 2016-04-22 19:01 - 2016-02-12 11:41 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT 2016-04-22 19:01 - 2016-01-08 18:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT 2016-04-22 19:00 - 2016-02-08 14:19 - 00000000 ____D C:\Program Files (x86)\DEUTSCHLAND SPIELT 2016-04-22 11:39 - 2014-06-27 10:05 - 00000000 ____D C:\Users\S-O\AppData\Roaming\ERS Game Studios 2016-04-22 09:57 - 2014-06-25 12:50 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-04-22 04:55 - 2015-09-02 11:30 - 00000000 ____D C:\ProgramData\ProductData 2016-04-21 07:38 - 2014-09-11 12:18 - 00000000 ____D C:\Users\S-O\AppData\Roaming\WildTangent 2016-04-21 07:38 - 2014-09-11 12:18 - 00000000 ____D C:\Program Files (x86)\WildTangent Games 2016-04-19 18:21 - 2015-11-24 22:53 - 00002168 _____ C:\Users\Public\Desktop\Driver Booster 3.lnk 2016-04-19 18:20 - 2015-07-17 10:41 - 00000000 ____D C:\Windows\system32\DAX2 2016-04-19 18:18 - 2014-11-13 18:06 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2016-04-19 12:15 - 2014-07-12 08:09 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Mad Head Games 2016-04-19 06:49 - 2014-08-17 17:58 - 00000000 ____D C:\Users\S-O\AppData\Roaming\rokapublish 2016-04-18 13:50 - 2014-07-19 17:42 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Gogii 2016-04-17 17:51 - 2016-03-16 11:47 - 00000000 ____D C:\Program Files (x86)\ToomkyGames.com 2016-04-17 12:52 - 2014-12-25 12:27 - 00000000 ____D C:\Users\S-O\AppData\Roaming\FGS 2016-04-16 17:05 - 2015-11-27 17:51 - 00000000 ____D C:\ProgramData\Alawar Stargaze 2016-04-16 16:02 - 2016-02-25 14:58 - 00000000 ____D C:\ProgramData\Floodlight Games 2016-04-16 15:22 - 2014-10-27 18:19 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Casual Arts 2016-04-16 13:31 - 2016-02-01 09:27 - 00000000 ____D C:\ProgramData\MumboJumbo 2016-04-16 05:47 - 2009-07-14 19:58 - 00707430 _____ C:\Windows\system32\perfh007.dat 2016-04-16 05:47 - 2009-07-14 19:58 - 00152492 _____ C:\Windows\system32\perfc007.dat 2016-04-16 05:47 - 2009-07-14 07:13 - 01678350 _____ C:\Windows\system32\PerfStringBackup.INI 2016-04-15 11:55 - 2014-12-13 12:39 - 00000000 ____D C:\Users\S-O\AppData\Roaming\JoyBits 2016-04-14 17:46 - 2016-01-22 15:55 - 00000000 ____D C:\Temp 2016-04-14 17:46 - 2014-11-13 18:13 - 00000000 ____D C:\ProgramData\NVIDIA 2016-04-14 17:45 - 2014-11-13 18:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-04-14 17:40 - 2015-12-22 10:09 - 14497568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2016-04-14 17:40 - 2014-11-13 18:11 - 00026157 _____ C:\Windows\system32\nvinfo.pb 2016-04-14 17:40 - 2009-07-13 23:59 - 18634264 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2016-04-14 06:03 - 2009-07-14 06:45 - 00301992 _____ C:\Windows\system32\FNTCACHE.DAT 2016-04-14 06:01 - 2015-11-12 06:52 - 00000000 ____D C:\Windows\system32\appraiser 2016-04-12 13:03 - 2014-06-30 09:44 - 00000000 ____D C:\Users\S-O\AppData\Roaming\DominiGames 2016-04-10 17:26 - 2015-11-27 14:09 - 00000000 ____D C:\ProgramData\DailyMagic 2016-04-10 17:26 - 2014-07-16 08:06 - 00000000 ____D C:\Users\S-O\AppData\Roaming\DailyMagic 2016-04-10 07:50 - 2014-06-25 14:28 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-04-09 15:35 - 2014-07-02 06:57 - 00000000 ____D C:\Users\S-O\AppData\Roaming\AlawarEntertainment 2016-04-06 17:56 - 2014-07-08 09:43 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Brave Giant 2016-04-06 12:09 - 2015-10-23 15:03 - 00000000 ____D C:\ProgramData\Playrix Entertainment 2016-04-05 15:17 - 2016-03-10 16:21 - 00000000 ____D C:\ProgramData\Cateia Games 2016-04-04 17:02 - 2014-09-28 12:37 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Friday's games 2016-04-02 15:36 - 2014-08-26 17:54 - 00000000 ____D C:\Users\S-O\AppData\Roaming\GrandMA Studios 2016-03-30 14:50 - 2015-12-16 13:09 - 00000000 ____D C:\ProgramData\Elephant Games 2016-03-30 14:50 - 2014-07-19 08:14 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Elephant Games 2016-03-30 10:43 - 2014-08-31 09:27 - 00000000 ___RD C:\Users\S-O\Documents\Scanned Documents 2016-03-30 06:24 - 2016-03-26 18:08 - 00000000 ____D C:\searchplugins 2016-03-30 06:23 - 2016-03-26 18:06 - 00000000 ____D C:\ProgramData\Lavasoft 2016-03-30 06:23 - 2016-03-26 18:06 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2016-03-29 15:53 - 2014-07-29 12:15 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Alawar Entertainment 2016-03-29 14:15 - 2016-02-21 15:52 - 00000000 ____D C:\ProgramData\Meridian93 2016-03-28 13:35 - 2016-02-25 15:14 - 00000000 ____D C:\Program Files (x86)\Purplehills 2016-03-28 12:44 - 2014-09-08 11:04 - 00000000 ____D C:\Users\S-O\AppData\Local\Downloaded Installations 2016-03-27 18:13 - 2016-03-26 18:07 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Lavasoft ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-02-06 10:01 - 2016-02-06 10:01 - 0003072 _____ () C:\Users\S-O\AppData\Roaming\.spark_db 2015-09-23 14:07 - 2015-09-23 15:07 - 0579338 _____ () C:\Users\S-O\AppData\Roaming\log.sflog 2016-03-30 06:52 - 2016-03-30 07:03 - 0000115 _____ () C:\Users\S-O\AppData\Roaming\LogFile.txt 2015-04-06 13:26 - 2015-04-06 13:26 - 0000239 _____ () C:\Users\S-O\AppData\Roaming\prefsdb.dat 2015-03-11 13:28 - 2015-03-16 18:20 - 0001156 _____ () C:\Users\S-O\AppData\Roaming\rrr.xml 2015-01-01 18:27 - 2015-03-16 18:47 - 0005056 _____ () C:\Users\S-O\AppData\Roaming\tt.xml 2015-01-01 18:21 - 2015-03-16 18:47 - 0001069 _____ () C:\Users\S-O\AppData\Roaming\users.xml 2014-06-28 15:30 - 2014-06-28 15:30 - 0033193 _____ () C:\Users\S-O\AppData\Roaming\UserTile.png 2016-03-09 10:32 - 2016-03-09 11:32 - 167257409 _____ () C:\Users\S-O\AppData\Roaming\VGEngineDX.log 2016-02-21 13:31 - 2016-02-21 13:31 - 0003072 _____ () C:\Users\S-O\AppData\Local\file__0.localstorage 2016-02-21 13:31 - 2016-02-21 13:31 - 0003072 _____ () C:\Users\S-O\AppData\Local\https_drm.youdagames.com_0.localstorage 2015-01-26 18:08 - 2015-01-26 18:50 - 0006700 _____ () C:\Users\S-O\AppData\Local\slot1.mm1 2016-03-17 13:49 - 2016-03-17 13:51 - 0003896 _____ () C:\ProgramData\doicrane_save.log 2014-11-13 18:07 - 2014-11-13 18:07 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-04-18 11:52 ==================== Ende von FRST.txt ============================ |
27.04.2016, 06:01 | #23 |
| MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] FRST Additions Logfile: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:17-04-2016 01 durchgeführt von S-O (2016-04-26 18:22:23) Gestartet von C:\Users\S-O\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2014-06-25 09:29:16) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3482151743-2939713798-2738295144-500 - Administrator - Disabled) Gast (S-1-5-21-3482151743-2939713798-2738295144-501 - Limited - Enabled) S-O (S-1-5-21-3482151743-2939713798-2738295144-1000 - Administrator - Enabled) => C:\Users\S-O ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95} AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.226 - Adobe Systems Incorporated) Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated) Around the World in 80 Days (HKLM-x32\...\BFG-Around the World in 80 Days) (Version: - ) Avalon Legends Solitaire (HKLM-x32\...\BFG-Avalon Legends Solitaire) (Version: - ) AVG Zen (Version: 1.41.29 - AVG Technologies) Hidden Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.3.0.2 - ) Brother MFL-Pro Suite DCP-7070DW (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.) CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform) Cradle of Rome (HKLM-x32\...\BFG-Cradle of Rome) (Version: - ) Die Chroniken von Emerland Solitär (HKLM-x32\...\BFG-Die Chroniken von Emerland Solitaer) (Version: - ) Emerland Solitaire: Endless Journey (HKLM-x32\...\BFG-Emerland Solitaire - Endless Journey) (Version: - ) Ferne Königreiche - Wintersolitaire (HKLM-x32\...\BFG-Ferne Koenigreiche - Wintersolitaire) (Version: - ) FMW 1 (Version: 1.62.2 - AVG Technologies) Hidden Heartwild Solitaire (HKLM-x32\...\BFG-Heartwild Solitaire) (Version: - ) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.2.1.126 - IObit) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Mozilla Firefox 46.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 46.0 (x86 de)) (Version: 46.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 46.0.0.5955 - Mozilla) Mozilla Thunderbird 38.7.2 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 38.7.2 (x86 de)) (Version: 38.7.2 - Mozilla) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.) Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation) Online Games Manager v1.30 (HKLM-x32\...\Online Games Manager) (Version: 1.30.14 - Real Networks, Inc.) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7746 - Realtek Semiconductor Corp.) Sea of Lies: In den Tiefen der Meere (HKLM-x32\...\BFG-Sea of Lies - In den Tiefen der Meere) (Version: - ) The Path of Hercules (HKLM-x32\...\BFG-The Path of Hercules) (Version: - ) The Rise of Atlantis (HKLM-x32\...\BFG-The Rise of Atlantis) (Version: - ) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) VLC media player 2.0.5 (HKLM-x32\...\VLC media player) (Version: 2.0.5 - VideoLAN) Warlock - Der Fluch des Schamanen (HKLM-x32\...\BFG-Warlock - Der Fluch des Schamanen) (Version: - ) WildTangent Games App (x32 Version: 4.0.10.25 - WildTangent) Hidden WildTangent-Spiele (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.1.0.28 - WildTangent) WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - ) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {07436B16-FE19-4A5A-B231-1FA1349AC5EF} - System32\Tasks\{3CC89BB3-4254-4F39-BA00-AD99D04AF8DF} => pcalua.exe -a C:\Users\S-O\Downloads\RoyalMahjongDieReiseDesKoenigs.exe -d C:\Users\S-O\Downloads\ Task: {10133C68-9491-4A78-BDEA-F512E1FD16BB} - System32\Tasks\{506D09E9-D93C-4BF6-A657-F6C2B5E03AF0} => pcalua.exe -a C:\Users\S-O\Downloads\riseofatlantis_setup(1).exe -d C:\Users\S-O\Downloads Task: {1D4101B7-F9A4-4E0E-93A1-2C330CF07C95} - System32\Tasks\{1AE9A7D5-233E-4AD5-B509-214EF6C6DC8E} => C:\Program Files (x86)\bfgclient\bfgclient.exe [2014-03-05] () Task: {20647033-E6A7-4E70-8468-3C1F3326736E} - System32\Tasks\Uninstaller_SkipUac_S-O => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-01-12] (IObit) Task: {30589647-360D-47DB-BF15-540632B71C1B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-17] (Adobe Systems Incorporated) Task: {356B815F-C9E1-45BD-899E-E675E5AC0CFD} - System32\Tasks\{41598AD5-A86B-455F-A093-D7532BFD8843} => pcalua.exe -a "C:\Program Files (x86)\Columbus - Der Geist im Stein\Uninstall.exe" Task: {381568B0-BBB8-4081-B124-99D343D11D7B} - System32\Tasks\{A64CC72B-1794-4CFA-9C10-241D4F1EBCE7} => pcalua.exe -a C:\Users\S-O\Downloads\BigCityAdventureTokyo(2).exe -d C:\Users\S-O\Downloads Task: {3A60A4D6-A943-47FE-9E9F-13F5B0B400C6} - System32\Tasks\{E072B913-E166-4B57-B4FA-85B80C2640BF} => pcalua.exe -a "C:\Program Files (x86)\Myths of the World - Der Elfenfaenger Sammleredition\Uninstall.exe" Task: {3D0E39D1-1865-4F2E-B384-D3BA8B28F465} - System32\Tasks\{369F9E9C-F685-49FF-A8E0-61B2F37F8882} => pcalua.exe -a "C:\Remote Programs\The Treasures of Montezuma\GPlrLanc.exe" -c -LOpCode 2 /RemoveContent cid=466552;name=The Treasures of Montezuma;dir=C:\Remote Programs\The Treasures of Montezuma\;PrvId=148;cmdid=1;prvdir=Default Task: {410EBFAB-09E9-4E99-AC51-E52E05873707} - System32\Tasks\{24C8089B-057D-436C-94A4-4C523DBB839D} => pcalua.exe -a C:\Users\S-O\Downloads\GreedVerrueckteWissenschaftler.exe -d C:\Users\S-O\Downloads Task: {4428B58C-4DF7-4071-BAAE-CDAAD8E3F4F2} - \SafeZone scheduled Autoupdate 1455795784 -> Keine Datei <==== ACHTUNG Task: {447D502B-0F22-4B79-80AC-7698505B5F75} - System32\Tasks\{5722FF3E-723E-4232-AEFC-FDD1C4F25C22} => pcalua.exe -a "C:\Program Files (x86)\Mystery Case Files - Die Druiden von Dire Grove Sammleredition\Uninstall.exe" Task: {494D2AFA-7FA8-4D21-AD31-EEABDE444A54} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-01-20] (AVAST Software) Task: {4CEB1302-8A54-4096-9273-822229C57A1D} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3482151743-2939713798-2738295144-1000 Task: {4FDAF9DC-117B-4B1D-9D66-BC42A797726C} - System32\Tasks\{DAE36A89-A9B9-4926-8B4B-CD237745AD61} => pcalua.exe -a "C:\Users\S-O\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33ZVHNKV\Setup[1].exe" -d "c:\program files (x86)\wildtangent games\app" Task: {517F29B3-976F-4EDA-B7CE-8667CA6662ED} - System32\Tasks\{F4D1B90F-6073-458F-9D52-C0E6AFC912B9} => pcalua.exe -a C:\Users\S-O\Downloads\BigCityAdventureRioDeJaneiro(1).exe -d C:\Users\S-O\Downloads Task: {57A0DF26-EA4B-44AC-B96E-67134C96ADA6} - System32\Tasks\{8C7932EF-A79E-4138-80FC-93D1C05A05F1} => pcalua.exe -a "C:\Program Files (x86)\GameTop.com\Egyptian Ball\unins000.exe" Task: {6A7D2A96-B9D7-4E60-A6C7-93CEBE7EE361} - \Opera scheduled Autoupdate 1459857045 -> Keine Datei <==== ACHTUNG Task: {6BEF2A4E-A7D5-487C-A6BD-1A3E7C1EEB8D} - System32\Tasks\{D2FF64D8-63B6-4301-84BC-D6063989E5A9} => pcalua.exe -a C:\Users\S-O\Downloads\DarkParablesRotkaeppchenSammler.exe -d C:\Users\S-O\Downloads Task: {77003A9D-9E13-475F-9C47-9725C60DB521} - System32\Tasks\{67D81E6A-289D-467C-BD0A-E0DE556FAF0F} => C:\Program Files (x86)\bfgclient\bfgclient.exe [2014-03-05] () Task: {7F6C97E7-38D2-4146-BD93-D57942C30DD0} - System32\Tasks\{8D2627E4-D89B-4596-9795-0399E2CC9548} => pcalua.exe -a "C:\Program Files (x86)\Nevertales - Die innere Schoenheit Sammleredition\Uninstall.exe" Task: {8365884E-C068-4169-836B-932DA69593E8} - System32\Tasks\{AAF2DBFC-1B56-4566-B35D-875B4ED76BE9} => pcalua.exe -a C:\Users\S-O\Downloads\MordIstIhrHobby2.exe -d C:\Users\S-O\Downloads Task: {8C9AF501-8A02-4AE6-A46A-0D2C08E4A3C8} - \Opera scheduled Autoupdate 1460460240 -> Keine Datei <==== ACHTUNG Task: {9333A1EC-2DA8-4C5F-B717-4FF76BCA969D} - System32\Tasks\{7A2A58A8-149B-45E8-A37A-91227BCF91B0} => pcalua.exe -a "C:\Program Files (x86)\GameTop.com\The Rise Of Atlantis\unins000.exe" Task: {98C1B123-31FB-42DC-B804-EBA903D9DD95} - System32\Tasks\Driver Booster SkipUAC (S-O) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2016-01-18] (IObit) Task: {A28CC4BA-38F1-4102-85FD-10EA175BCF15} - System32\Tasks\{D04B8E65-A67E-43A6-B02C-16CB2ABAC5B7} => pcalua.exe -a "C:\Program Files (x86)\OXXOGames\GPlayer\\MyInstall.exe" -c ScriptUInst "C:\Program Files (x86)\OXXOGames\GPlayer\Install\\Game_BigCityAdventureParis.log" Task: {A2B06C45-661F-4BE3-85AF-6C9DBB258B14} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2016-01-13] (IObit) Task: {BBBA7ED5-1F61-4DC2-BE04-3F8E5D687C41} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {D2DD889E-EC62-4BBD-AD3A-B63B59565014} - System32\Tasks\{37137159-462D-459D-BA48-0715F5A42CE0} => pcalua.exe -a C:\Users\S-O\Downloads\NewYorkMysteriesHochspannungSE.exe -d C:\Users\S-O\Downloads Task: {D4E0BA10-7D52-4EF3-B176-E2A635540216} - System32\Tasks\ASC9_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-01-15] (IObit) Task: {DFF4575A-1AD5-4131-B007-9033EE081693} - System32\Tasks\{7A3E63D9-54E3-44E8-81FC-17FA9B21559C} => C:\Program Files (x86)\bfgclient\bfgclient.exe [2014-03-05] () Task: {E4D264EE-CCD0-452B-B948-0EC52672ED63} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd) Task: {EA6A2FA2-F26A-4F62-83F5-C245D45F1754} - System32\Tasks\ASC9_SkipUac_S-O => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-01-18] (IObit) Task: {EAAE3B23-F16C-4D7F-8EB6-68D1A727FF45} - System32\Tasks\{171EFD58-163A-4405-9707-16647CCF3B7D} => C:\Program Files (x86)\bfgclient\bfgclient.exe [2014-03-05] () Task: {F0180014-9DB4-459F-986F-BB29038B3BA2} - \Opera scheduled Autoupdate 1460715966 -> Keine Datei <==== ACHTUNG Task: {F787742B-CFC5-43DB-8C81-0C55CC64A7B6} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {F89BC92B-B7CA-416F-A42A-4C9E28C5660A} - System32\Tasks\{010F5115-9A1B-4724-BAD9-9F6C2D5EB0E9} => pcalua.exe -a C:\Users\S-O\Downloads\DerVerborgeneKontinent.exe -d C:\Users\S-O\Downloads (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2014-11-13 18:13 - 2016-01-29 12:49 - 00135224 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-11-16 18:55 - 2015-11-16 18:55 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2016-02-17 20:07 - 2015-12-23 19:32 - 00355616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madExcept_.bpl 2016-02-17 20:07 - 2015-12-23 19:32 - 00190240 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madBasic_.bpl 2016-02-17 20:07 - 2015-12-23 19:32 - 00057632 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madDisAsm_.bpl 2016-01-28 06:46 - 2015-12-23 19:32 - 00355616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl 2016-01-28 06:46 - 2015-12-23 19:32 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl 2016-01-28 06:46 - 2015-12-23 19:32 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl 2016-02-17 20:07 - 2015-12-28 14:50 - 00899872 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\webres.dll 2016-02-17 20:07 - 2015-12-28 14:50 - 01293088 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\Scan.dll 2016-02-17 20:07 - 2015-12-28 14:49 - 00629536 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\ProductStatistics.dll 2016-04-10 13:20 - 2016-04-10 13:20 - 00153032 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2016-04-10 13:20 - 2016-04-10 13:20 - 00022472 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ......Z.ZZZZZ:1 [882] AlternateDataStreams: C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ..Z.....ZZZZZ:1 [882] AlternateDataStreams: C:\ProgramData:gs5sys [2560] AlternateDataStreams: C:\Users\All Users:gs5sys [2560] AlternateDataStreams: C:\Users\S-O:gs5sys [3074] AlternateDataStreams: C:\ProgramData\Anwendungsdaten:gs5sys [2560] AlternateDataStreams: C:\ProgramData\Application Data:gs5sys [2560] AlternateDataStreams: C:\ProgramData\TEMP:008FE370 [134] AlternateDataStreams: C:\ProgramData\TEMP:00A3C892 [134] AlternateDataStreams: C:\ProgramData\TEMP:0205B36B [127] AlternateDataStreams: C:\ProgramData\TEMP:02166498 [145] AlternateDataStreams: C:\ProgramData\TEMP:024B9CC7 [137] AlternateDataStreams: C:\ProgramData\TEMP:02AAE472 [124] AlternateDataStreams: C:\ProgramData\TEMP:0452501D [286] AlternateDataStreams: C:\ProgramData\TEMP:070D9534 [117] AlternateDataStreams: C:\ProgramData\TEMP:076F9EF8 [128] AlternateDataStreams: C:\ProgramData\TEMP:08767DE0 [128] AlternateDataStreams: C:\ProgramData\TEMP:08F9E829 [290] AlternateDataStreams: C:\ProgramData\TEMP:092BD83A [272] AlternateDataStreams: C:\ProgramData\TEMP:097C4B7D [136] AlternateDataStreams: C:\ProgramData\TEMP:099BA123 [296] AlternateDataStreams: C:\ProgramData\TEMP:09D92173 [256] AlternateDataStreams: C:\ProgramData\TEMP:0A719894 [143] AlternateDataStreams: C:\ProgramData\TEMP:0B9DC6BB [132] AlternateDataStreams: C:\ProgramData\TEMP:0BCD47A5 [149] AlternateDataStreams: C:\ProgramData\TEMP:0BFBB93D [254] AlternateDataStreams: C:\ProgramData\TEMP:0C1258F3 [131] AlternateDataStreams: C:\ProgramData\TEMP:0C2A17F2 [139] AlternateDataStreams: C:\ProgramData\TEMP:0C363260 [151] AlternateDataStreams: C:\ProgramData\TEMP:0C8F16BF [146] AlternateDataStreams: C:\ProgramData\TEMP:0C98AF11 [146] AlternateDataStreams: C:\ProgramData\TEMP:0CEE6109 [131] AlternateDataStreams: C:\ProgramData\TEMP:0D060666 [132] AlternateDataStreams: C:\ProgramData\TEMP:0EE45B2D [141] AlternateDataStreams: C:\ProgramData\TEMP:0EFDD299 [266] AlternateDataStreams: C:\ProgramData\TEMP:0FA1EAA7 [131] AlternateDataStreams: C:\ProgramData\TEMP:1130B726 [143] AlternateDataStreams: C:\ProgramData\TEMP:120B3AFD [136] AlternateDataStreams: C:\ProgramData\TEMP:1239BE94 [135] AlternateDataStreams: C:\ProgramData\TEMP:123A86B5 [141] AlternateDataStreams: C:\ProgramData\TEMP:12D2EB9C [125] AlternateDataStreams: C:\ProgramData\TEMP:1309637A [294] AlternateDataStreams: C:\ProgramData\TEMP:1322DDBD [130] AlternateDataStreams: C:\ProgramData\TEMP:132B1756 [152] AlternateDataStreams: C:\ProgramData\TEMP:1345C9DC [121] AlternateDataStreams: C:\ProgramData\TEMP:1392F09D [126] AlternateDataStreams: C:\ProgramData\TEMP:14B3C0A8 [124] AlternateDataStreams: C:\ProgramData\TEMP:14D4993F [266] AlternateDataStreams: C:\ProgramData\TEMP:164561C8 [148] AlternateDataStreams: C:\ProgramData\TEMP:16F4BC64 [119] AlternateDataStreams: C:\ProgramData\TEMP:177313FB [125] AlternateDataStreams: C:\ProgramData\TEMP:186F8A82 [149] AlternateDataStreams: C:\ProgramData\TEMP:18A6D2CC [134] AlternateDataStreams: C:\ProgramData\TEMP:18E35126 [130] AlternateDataStreams: C:\ProgramData\TEMP:19474103 [264] AlternateDataStreams: C:\ProgramData\TEMP:1999DD0A [133] AlternateDataStreams: C:\ProgramData\TEMP:1A14B3AF [140] AlternateDataStreams: C:\ProgramData\TEMP:1A259A13 [282] AlternateDataStreams: C:\ProgramData\TEMP:1B506EA3 [150] AlternateDataStreams: C:\ProgramData\TEMP:1BD320E3 [143] AlternateDataStreams: C:\ProgramData\TEMP:1C211903 [286] AlternateDataStreams: C:\ProgramData\TEMP:1C662800 [137] AlternateDataStreams: C:\ProgramData\TEMP:1CCE0A1A [140] AlternateDataStreams: C:\ProgramData\TEMP:1D5FADCD [300] AlternateDataStreams: C:\ProgramData\TEMP:1F4F2F80 [127] AlternateDataStreams: C:\ProgramData\TEMP:1F9D647F [146] AlternateDataStreams: C:\ProgramData\TEMP:20ABE827 [286] AlternateDataStreams: C:\ProgramData\TEMP:2187A2BB [126] AlternateDataStreams: C:\ProgramData\TEMP:219DB32E [131] AlternateDataStreams: C:\ProgramData\TEMP:229564F1 [120] AlternateDataStreams: C:\ProgramData\TEMP:2313511A [128] AlternateDataStreams: C:\ProgramData\TEMP:244E4E3A [146] AlternateDataStreams: C:\ProgramData\TEMP:25F31665 [141] AlternateDataStreams: C:\ProgramData\TEMP:260575F1 [119] AlternateDataStreams: C:\ProgramData\TEMP:2680DDD5 [151] AlternateDataStreams: C:\ProgramData\TEMP:282A4C88 [136] AlternateDataStreams: C:\ProgramData\TEMP:29EA7E22 [0] AlternateDataStreams: C:\ProgramData\TEMP:2B1EA607 [118] AlternateDataStreams: C:\ProgramData\TEMP:2B5C4773 [155] AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F [134] AlternateDataStreams: C:\ProgramData\TEMP:2D2A0FC2 [122] AlternateDataStreams: C:\ProgramData\TEMP:2E5508DE [122] AlternateDataStreams: C:\ProgramData\TEMP:2EAD4F23 [148] AlternateDataStreams: C:\ProgramData\TEMP:2EFCCD2A [280] AlternateDataStreams: C:\ProgramData\TEMP:2F70C0B4 [145] AlternateDataStreams: C:\ProgramData\TEMP:2F9BD5B3 [127] AlternateDataStreams: C:\ProgramData\TEMP:3086B95F [123] AlternateDataStreams: C:\ProgramData\TEMP:308F8D8D [278] AlternateDataStreams: C:\ProgramData\TEMP:30A9192A [129] AlternateDataStreams: C:\ProgramData\TEMP:30EDFEBE [118] AlternateDataStreams: C:\ProgramData\TEMP:313F7672 [150] AlternateDataStreams: C:\ProgramData\TEMP:316EAAE9 [102] AlternateDataStreams: C:\ProgramData\TEMP:31C9BA96 [284] AlternateDataStreams: C:\ProgramData\TEMP:31CE65F3 [127] AlternateDataStreams: C:\ProgramData\TEMP:32414169 [145] AlternateDataStreams: C:\ProgramData\TEMP:32FFF2D1 [119] AlternateDataStreams: C:\ProgramData\TEMP:331B7520 [155] AlternateDataStreams: C:\ProgramData\TEMP:3393A1CA [270] AlternateDataStreams: C:\ProgramData\TEMP:33E58057 [144] AlternateDataStreams: C:\ProgramData\TEMP:341C1FBD [282] AlternateDataStreams: C:\ProgramData\TEMP:346337E3 [133] AlternateDataStreams: C:\ProgramData\TEMP:34FBEA36 [134] AlternateDataStreams: C:\ProgramData\TEMP:36AAD0E5 [135] AlternateDataStreams: C:\ProgramData\TEMP:36E7847A [126] AlternateDataStreams: C:\ProgramData\TEMP:36ED5C45 [140] AlternateDataStreams: C:\ProgramData\TEMP:371C5214 [276] AlternateDataStreams: C:\ProgramData\TEMP:37207201 [148] AlternateDataStreams: C:\ProgramData\TEMP:39743F39 [125] AlternateDataStreams: C:\ProgramData\TEMP:39BD98E5 [135] AlternateDataStreams: C:\ProgramData\TEMP:39CB2031 [366] AlternateDataStreams: C:\ProgramData\TEMP:3A133158 [140] AlternateDataStreams: C:\ProgramData\TEMP:3ADE134E [290] AlternateDataStreams: C:\ProgramData\TEMP:3B622E21 [155] AlternateDataStreams: C:\ProgramData\TEMP:3BDF57F4 [144] AlternateDataStreams: C:\ProgramData\TEMP:3C18D47C [130] AlternateDataStreams: C:\ProgramData\TEMP:3D186293 [145] AlternateDataStreams: C:\ProgramData\TEMP:3D4B733E [296] AlternateDataStreams: C:\ProgramData\TEMP:3E1EE95E [130] AlternateDataStreams: C:\ProgramData\TEMP:3FD496E1 [115] AlternateDataStreams: C:\ProgramData\TEMP:3FE64CFC [129] AlternateDataStreams: C:\ProgramData\TEMP:406E0034 [130] AlternateDataStreams: C:\ProgramData\TEMP:413177C4 [151] AlternateDataStreams: C:\ProgramData\TEMP:4157BB05 [132] AlternateDataStreams: C:\ProgramData\TEMP:415E77AB [152] AlternateDataStreams: C:\ProgramData\TEMP:41CB6858 [276] AlternateDataStreams: C:\ProgramData\TEMP:424D7CFE [131] AlternateDataStreams: C:\ProgramData\TEMP:426D1496 [123] AlternateDataStreams: C:\ProgramData\TEMP:447856CD [131] AlternateDataStreams: C:\ProgramData\TEMP:44A0FEC3 [140] AlternateDataStreams: C:\ProgramData\TEMP:44ABD37A [135] AlternateDataStreams: C:\ProgramData\TEMP:4548E058 [138] AlternateDataStreams: C:\ProgramData\TEMP:45936E12 [129] AlternateDataStreams: C:\ProgramData\TEMP:46EF121E [122] AlternateDataStreams: C:\ProgramData\TEMP:474022C7 [146] AlternateDataStreams: C:\ProgramData\TEMP:4762F1D2 [148] AlternateDataStreams: C:\ProgramData\TEMP:490B67EC [125] AlternateDataStreams: C:\ProgramData\TEMP:498B5975 [141] AlternateDataStreams: C:\ProgramData\TEMP:4A8EB1C4 [149] AlternateDataStreams: C:\ProgramData\TEMP:4B7C28B1 [137] AlternateDataStreams: C:\ProgramData\TEMP:4C235DA4 [290] AlternateDataStreams: C:\ProgramData\TEMP:4CF76F21 [121] AlternateDataStreams: C:\ProgramData\TEMP:4DDBE3DC [130] AlternateDataStreams: C:\ProgramData\TEMP:4E07A403 [147] AlternateDataStreams: C:\ProgramData\TEMP:4FA837B4 [128] AlternateDataStreams: C:\ProgramData\TEMP:4FD3435F [155] AlternateDataStreams: C:\ProgramData\TEMP:4FE3FB06 [140] AlternateDataStreams: C:\ProgramData\TEMP:506698B2 [138] AlternateDataStreams: C:\ProgramData\TEMP:50868536 [260] AlternateDataStreams: C:\ProgramData\TEMP:512E1728 [136] AlternateDataStreams: C:\ProgramData\TEMP:5167543E [145] AlternateDataStreams: C:\ProgramData\TEMP:51A20D23 [286] AlternateDataStreams: C:\ProgramData\TEMP:52641FBE [126] AlternateDataStreams: C:\ProgramData\TEMP:5430D891 [153] AlternateDataStreams: C:\ProgramData\TEMP:5545792B [140] AlternateDataStreams: C:\ProgramData\TEMP:5559517D [138] AlternateDataStreams: C:\ProgramData\TEMP:55BB2521 [101] AlternateDataStreams: C:\ProgramData\TEMP:55E1514E [268] AlternateDataStreams: C:\ProgramData\TEMP:565D4B03 [298] AlternateDataStreams: C:\ProgramData\TEMP:566B9179 [264] AlternateDataStreams: C:\ProgramData\TEMP:569CEE83 [127] AlternateDataStreams: C:\ProgramData\TEMP:570ED58C [300] AlternateDataStreams: C:\ProgramData\TEMP:58158478 [131] AlternateDataStreams: C:\ProgramData\TEMP:58306E4C [137] AlternateDataStreams: C:\ProgramData\TEMP:5986FE1C [141] AlternateDataStreams: C:\ProgramData\TEMP:598BD055 [139] AlternateDataStreams: C:\ProgramData\TEMP:59CA329D [119] AlternateDataStreams: C:\ProgramData\TEMP:5A1E97C7 [134] AlternateDataStreams: C:\ProgramData\TEMP:5A437AC3 [408] AlternateDataStreams: C:\ProgramData\TEMP:5AF17798 [280] AlternateDataStreams: C:\ProgramData\TEMP:5C717402 [274] AlternateDataStreams: C:\ProgramData\TEMP:5E7551D4 [128] AlternateDataStreams: C:\ProgramData\TEMP:5E8C18F1 [276] AlternateDataStreams: C:\ProgramData\TEMP:5E9B629B [97] AlternateDataStreams: C:\ProgramData\TEMP:5F56E7C1 [286] AlternateDataStreams: C:\ProgramData\TEMP:5FEBCE9C [128] AlternateDataStreams: C:\ProgramData\TEMP:623E564B [124] AlternateDataStreams: C:\ProgramData\TEMP:629A9591 [145] AlternateDataStreams: C:\ProgramData\TEMP:629F8518 [143] AlternateDataStreams: C:\ProgramData\TEMP:634EA293 [137] AlternateDataStreams: C:\ProgramData\TEMP:63BA523E [138] AlternateDataStreams: C:\ProgramData\TEMP:63C48B80 [288] AlternateDataStreams: C:\ProgramData\TEMP:64E05835 [145] AlternateDataStreams: C:\ProgramData\TEMP:65949863 [141] AlternateDataStreams: C:\ProgramData\TEMP:660BDAE1 [310] AlternateDataStreams: C:\ProgramData\TEMP:667D4A95 [133] AlternateDataStreams: C:\ProgramData\TEMP:66F19688 [147] AlternateDataStreams: C:\ProgramData\TEMP:675F9A63 [141] AlternateDataStreams: C:\ProgramData\TEMP:68899984 [145] AlternateDataStreams: C:\ProgramData\TEMP:6A0A47E7 [136] AlternateDataStreams: C:\ProgramData\TEMP:6A6D4AF4 [286] AlternateDataStreams: C:\ProgramData\TEMP:6A936202 [105] AlternateDataStreams: C:\ProgramData\TEMP:6BB32FFE [286] AlternateDataStreams: C:\ProgramData\TEMP:6D208D7A [130] AlternateDataStreams: C:\ProgramData\TEMP:6DA9822F [140] AlternateDataStreams: C:\ProgramData\TEMP:6E90EDD7 [256] AlternateDataStreams: C:\ProgramData\TEMP:6F3BEBA5 [128] AlternateDataStreams: C:\ProgramData\TEMP:70AD58E0 [136] AlternateDataStreams: C:\ProgramData\TEMP:70E897B5 [117] AlternateDataStreams: C:\ProgramData\TEMP:72449E7D [140] AlternateDataStreams: C:\ProgramData\TEMP:72C99D4E [294] AlternateDataStreams: C:\ProgramData\TEMP:72DDC498 [145] AlternateDataStreams: C:\ProgramData\TEMP:72E5CC07 [286] AlternateDataStreams: C:\ProgramData\TEMP:74615EBC [119] AlternateDataStreams: C:\ProgramData\TEMP:75765D7B [144] AlternateDataStreams: C:\ProgramData\TEMP:75CC0165 [112] AlternateDataStreams: C:\ProgramData\TEMP:75CF6AF0 [286] AlternateDataStreams: C:\ProgramData\TEMP:78395CE2 [266] AlternateDataStreams: C:\ProgramData\TEMP:7929462F [135] AlternateDataStreams: C:\ProgramData\TEMP:797D4F54 [139] AlternateDataStreams: C:\ProgramData\TEMP:79A7F369 [137] AlternateDataStreams: C:\ProgramData\TEMP:79EAEF54 [135] AlternateDataStreams: C:\ProgramData\TEMP:7A3AAF2E [121] AlternateDataStreams: C:\ProgramData\TEMP:7A530D80 [144] AlternateDataStreams: C:\ProgramData\TEMP:7C1271A7 [147] AlternateDataStreams: C:\ProgramData\TEMP:7C27C41C [148] AlternateDataStreams: C:\ProgramData\TEMP:7CF96AD4 [128] AlternateDataStreams: C:\ProgramData\TEMP:7D9B1030 [148] AlternateDataStreams: C:\ProgramData\TEMP:7DB43890 [138] AlternateDataStreams: C:\ProgramData\TEMP:7E1E8D30 [135] AlternateDataStreams: C:\ProgramData\TEMP:7F477B0D [139] AlternateDataStreams: C:\ProgramData\TEMP:7F4D8125 [124] AlternateDataStreams: C:\ProgramData\TEMP:8029E75F [129] AlternateDataStreams: C:\ProgramData\TEMP:808420C9 [129] AlternateDataStreams: C:\ProgramData\TEMP:80974241 [131] AlternateDataStreams: C:\ProgramData\TEMP:80EA2EA3 [135] AlternateDataStreams: C:\ProgramData\TEMP:80FA23CA [154] AlternateDataStreams: C:\ProgramData\TEMP:819394CC [146] AlternateDataStreams: C:\ProgramData\TEMP:82756AB7 [150] AlternateDataStreams: C:\ProgramData\TEMP:830725A7 [127] AlternateDataStreams: C:\ProgramData\TEMP:8318A814 [124] AlternateDataStreams: C:\ProgramData\TEMP:839A89FC [145] AlternateDataStreams: C:\ProgramData\TEMP:841E05D6 [124] AlternateDataStreams: C:\ProgramData\TEMP:8435AD8C [135] AlternateDataStreams: C:\ProgramData\TEMP:86A7B7DD [140] AlternateDataStreams: C:\ProgramData\TEMP:86B7FDDB [120] AlternateDataStreams: C:\ProgramData\TEMP:87A3A233 [121] AlternateDataStreams: C:\ProgramData\TEMP:88C5973F [133] AlternateDataStreams: C:\ProgramData\TEMP:89B7A4D9 [144] AlternateDataStreams: C:\ProgramData\TEMP:89CF6F9C [141] AlternateDataStreams: C:\ProgramData\TEMP:8B4B9596 [144] AlternateDataStreams: C:\ProgramData\TEMP:8B4DEB15 [148] AlternateDataStreams: C:\ProgramData\TEMP:8C3C65BE [136] AlternateDataStreams: C:\ProgramData\TEMP:8DBCF585 [132] AlternateDataStreams: C:\ProgramData\TEMP:8DC85A87 [126] AlternateDataStreams: C:\ProgramData\TEMP:8E5EA40F [138] AlternateDataStreams: C:\ProgramData\TEMP:8E761650 [135] AlternateDataStreams: C:\ProgramData\TEMP:8F6B75BF [148] AlternateDataStreams: C:\ProgramData\TEMP:900EBAFA [130] AlternateDataStreams: C:\ProgramData\TEMP:90865A6D [130] AlternateDataStreams: C:\ProgramData\TEMP:90C320E1 [128] AlternateDataStreams: C:\ProgramData\TEMP:91742C9B [128] AlternateDataStreams: C:\ProgramData\TEMP:918A387B [137] AlternateDataStreams: C:\ProgramData\TEMP:919D5A07 [128] AlternateDataStreams: C:\ProgramData\TEMP:91B663FA [138] AlternateDataStreams: C:\ProgramData\TEMP:91FE43FF [144] AlternateDataStreams: C:\ProgramData\TEMP:92A815D8 [105] AlternateDataStreams: C:\ProgramData\TEMP:92B49D9A [151] AlternateDataStreams: C:\ProgramData\TEMP:94B08D9A [131] AlternateDataStreams: C:\ProgramData\TEMP:94B25DF5 [144] AlternateDataStreams: C:\ProgramData\TEMP:950E98CE [266] AlternateDataStreams: C:\ProgramData\TEMP:9510DF8F [132] AlternateDataStreams: C:\ProgramData\TEMP:9524D821 [128] AlternateDataStreams: C:\ProgramData\TEMP:956AE390 [149] AlternateDataStreams: C:\ProgramData\TEMP:97AAB7F2 [258] AlternateDataStreams: C:\ProgramData\TEMP:982B9800 [147] AlternateDataStreams: C:\ProgramData\TEMP:99A29126 [420] AlternateDataStreams: C:\ProgramData\TEMP:9A60A5B3 [125] AlternateDataStreams: C:\ProgramData\TEMP:9BAC4211 [141] AlternateDataStreams: C:\ProgramData\TEMP:9C435C94 [127] AlternateDataStreams: C:\ProgramData\TEMP:9DD01D6C [150] AlternateDataStreams: C:\ProgramData\TEMP:9E5EA7A3 [124] AlternateDataStreams: C:\ProgramData\TEMP:9EE6560D [125] AlternateDataStreams: C:\ProgramData\TEMP:9FC58CBB [148] AlternateDataStreams: C:\ProgramData\TEMP:A19DFC74 [150] AlternateDataStreams: C:\ProgramData\TEMP:A291068E [135] AlternateDataStreams: C:\ProgramData\TEMP:A3B8F70C [116] AlternateDataStreams: C:\ProgramData\TEMP:A3D9016F [126] AlternateDataStreams: C:\ProgramData\TEMP:A42B5698 [276] AlternateDataStreams: C:\ProgramData\TEMP:A441D13F [120] AlternateDataStreams: C:\ProgramData\TEMP:A52D07E2 [128] AlternateDataStreams: C:\ProgramData\TEMP:A594A11A [129] AlternateDataStreams: C:\ProgramData\TEMP:A694F56D [258] AlternateDataStreams: C:\ProgramData\TEMP:A745DB5D [200] AlternateDataStreams: C:\ProgramData\TEMP:A89DF5BD [132] AlternateDataStreams: C:\ProgramData\TEMP:A9056F42 [129] AlternateDataStreams: C:\ProgramData\TEMP:A9EBEE99 [134] AlternateDataStreams: C:\ProgramData\TEMP:AA5A61B2 [130] AlternateDataStreams: C:\ProgramData\TEMP:AB0A5A80 [130] AlternateDataStreams: C:\ProgramData\TEMP:AC9F291E [282] AlternateDataStreams: C:\ProgramData\TEMP:AD450465 [129] AlternateDataStreams: C:\ProgramData\TEMP:AD7BB754 [278] AlternateDataStreams: C:\ProgramData\TEMP:AE324BE5 [140] AlternateDataStreams: C:\ProgramData\TEMP:AE75CCC8 [247] AlternateDataStreams: C:\ProgramData\TEMP:AE7FB2F5 [137] AlternateDataStreams: C:\ProgramData\TEMP:AED33A42 [135] AlternateDataStreams: C:\ProgramData\TEMP:AF465248 [137] AlternateDataStreams: C:\ProgramData\TEMP:B0456F0C [148] AlternateDataStreams: C:\ProgramData\TEMP:B097AC8A [152] AlternateDataStreams: C:\ProgramData\TEMP:B0BE4B3D [284] AlternateDataStreams: C:\ProgramData\TEMP:B190BE3A [114] AlternateDataStreams: C:\ProgramData\TEMP:B39AFC9E [284] AlternateDataStreams: C:\ProgramData\TEMP:B3A139F8 [126] AlternateDataStreams: C:\ProgramData\TEMP:B3C7433B [141] AlternateDataStreams: C:\ProgramData\TEMP:B3D50E25 [133] AlternateDataStreams: C:\ProgramData\TEMP:B4DFBFB7 [120] AlternateDataStreams: C:\ProgramData\TEMP:B53339FE [151] AlternateDataStreams: C:\ProgramData\TEMP:B65E763D [260] AlternateDataStreams: C:\ProgramData\TEMP:B68B34BE [125] AlternateDataStreams: C:\ProgramData\TEMP:B6FBC05A [153] AlternateDataStreams: C:\ProgramData\TEMP:B74BD6BF [150] AlternateDataStreams: C:\ProgramData\TEMP:B7505DCD [153] AlternateDataStreams: C:\ProgramData\TEMP:B8408597 [129] AlternateDataStreams: C:\ProgramData\TEMP:B845F669 [131] AlternateDataStreams: C:\ProgramData\TEMP:B863466F [286] AlternateDataStreams: C:\ProgramData\TEMP:B961095A [152] AlternateDataStreams: C:\ProgramData\TEMP:BA9CDA91 [134] AlternateDataStreams: C:\ProgramData\TEMP:BAD046B8 [140] AlternateDataStreams: C:\ProgramData\TEMP:BCFEA004 [112] AlternateDataStreams: C:\ProgramData\TEMP:BE40C8A2 [124] AlternateDataStreams: C:\ProgramData\TEMP:BF4319E5 [136] AlternateDataStreams: C:\ProgramData\TEMP:C00AB302 [298] AlternateDataStreams: C:\ProgramData\TEMP:C11BB4F1 [304] AlternateDataStreams: C:\ProgramData\TEMP:C1616CD9 [129] AlternateDataStreams: C:\ProgramData\TEMP:C178954A [288] AlternateDataStreams: C:\ProgramData\TEMP:C1D3D9A3 [127] AlternateDataStreams: C:\ProgramData\TEMP:C25E505B [298] AlternateDataStreams: C:\ProgramData\TEMP:C36D0DFD [120] AlternateDataStreams: C:\ProgramData\TEMP:C3D26A8A [260] AlternateDataStreams: C:\ProgramData\TEMP:C49A5AD1 [130] AlternateDataStreams: C:\ProgramData\TEMP:C55217E2 [140] AlternateDataStreams: C:\ProgramData\TEMP:C5D38708 [147] AlternateDataStreams: C:\ProgramData\TEMP:C617C0F6 [139] AlternateDataStreams: C:\ProgramData\TEMP:C6275D37 [154] AlternateDataStreams: C:\ProgramData\TEMP:C64957DF [150] AlternateDataStreams: C:\ProgramData\TEMP:C6EB7815 [135] AlternateDataStreams: C:\ProgramData\TEMP:C7684F3C [130] AlternateDataStreams: C:\ProgramData\TEMP:C76D8487 [155] AlternateDataStreams: C:\ProgramData\TEMP:C7D35E8C [136] AlternateDataStreams: C:\ProgramData\TEMP:C7F75BDD [138] AlternateDataStreams: C:\ProgramData\TEMP:CB08ED9D [145] AlternateDataStreams: C:\ProgramData\TEMP:CB3667AF [304] AlternateDataStreams: C:\ProgramData\TEMP:CC8B36B2 [145] AlternateDataStreams: C:\ProgramData\TEMP:CD09F4F2 [125] AlternateDataStreams: C:\ProgramData\TEMP:CDCDE97C [114] AlternateDataStreams: C:\ProgramData\TEMP:CE506F23 [149] AlternateDataStreams: C:\ProgramData\TEMP:CF82DADF [252] AlternateDataStreams: C:\ProgramData\TEMP:CF8AEC6E [140] AlternateDataStreams: C:\ProgramData\TEMP:D21C1CCC [134] AlternateDataStreams: C:\ProgramData\TEMP:D4E62FA9 [151] AlternateDataStreams: C:\ProgramData\TEMP:D57DCBA2 [126] AlternateDataStreams: C:\ProgramData\TEMP:D5C946C5 [144] AlternateDataStreams: C:\ProgramData\TEMP:D6A43EB0 [139] AlternateDataStreams: C:\ProgramData\TEMP:D92485C9 [104] AlternateDataStreams: C:\ProgramData\TEMP:D92A5893 [148] AlternateDataStreams: C:\ProgramData\TEMP:DADACE5D [152] AlternateDataStreams: C:\ProgramData\TEMP:DB2748F7 [145] AlternateDataStreams: C:\ProgramData\TEMP:DB77E2C4 [136] AlternateDataStreams: C:\ProgramData\TEMP:DB8C5FF1 [143] AlternateDataStreams: C:\ProgramData\TEMP:DBC28EB1 [121] AlternateDataStreams: C:\ProgramData\TEMP:DBC3D477 [137] AlternateDataStreams: C:\ProgramData\TEMP:DBE046F5 [132] AlternateDataStreams: C:\ProgramData\TEMP:DC0B1070 [143] AlternateDataStreams: C:\ProgramData\TEMP:DC7EDF41 [143] AlternateDataStreams: C:\ProgramData\TEMP:DC8E5CD4 [284] AlternateDataStreams: C:\ProgramData\TEMP:DD04902E [127] AlternateDataStreams: C:\ProgramData\TEMP:DDA730F9 [91] AlternateDataStreams: C:\ProgramData\TEMP:DDE3F219 [149] AlternateDataStreams: C:\ProgramData\TEMP:DDF112BD [276] AlternateDataStreams: C:\ProgramData\TEMP:DE007F2F [140] AlternateDataStreams: C:\ProgramData\TEMP:DEE38664 [146] AlternateDataStreams: C:\ProgramData\TEMP:DF5ABA3D [152] AlternateDataStreams: C:\ProgramData\TEMP:DFDBC05C [278] AlternateDataStreams: C:\ProgramData\TEMP:E18702AE [131] AlternateDataStreams: C:\ProgramData\TEMP:E2295807 [251] AlternateDataStreams: C:\ProgramData\TEMP:E31EDFDE [146] AlternateDataStreams: C:\ProgramData\TEMP:E3B0ACE0 [133] AlternateDataStreams: C:\ProgramData\TEMP:E3C06B97 [130] AlternateDataStreams: C:\ProgramData\TEMP:E446CB48 [122] AlternateDataStreams: C:\ProgramData\TEMP:E4996D81 [136] AlternateDataStreams: C:\ProgramData\TEMP:E4B4E556 [152] AlternateDataStreams: C:\ProgramData\TEMP:E4FD113F [296] AlternateDataStreams: C:\ProgramData\TEMP:E5AF754F [131] AlternateDataStreams: C:\ProgramData\TEMP:E6708F08 [117] AlternateDataStreams: C:\ProgramData\TEMP:E690114B [147] AlternateDataStreams: C:\ProgramData\TEMP:E71BB809 [298] AlternateDataStreams: C:\ProgramData\TEMP:E81603BC [145] AlternateDataStreams: C:\ProgramData\TEMP:E8AEB2BF [128] AlternateDataStreams: C:\ProgramData\TEMP:E94FA418 [286] AlternateDataStreams: C:\ProgramData\TEMP:E9C2F553 [268] AlternateDataStreams: C:\ProgramData\TEMP:EA2D3047 [141] AlternateDataStreams: C:\ProgramData\TEMP:EAF0C571 [137] AlternateDataStreams: C:\ProgramData\TEMP:EE2DD6CC [126] AlternateDataStreams: C:\ProgramData\TEMP:EF0BD3A1 [127] AlternateDataStreams: C:\ProgramData\TEMP:EF123AF6 [134] AlternateDataStreams: C:\ProgramData\TEMP:EF53A5CA [134] AlternateDataStreams: C:\ProgramData\TEMP:F074840B [136] AlternateDataStreams: C:\ProgramData\TEMP:F0F90DC6 [518] AlternateDataStreams: C:\ProgramData\TEMP:F1373816 [149] AlternateDataStreams: C:\ProgramData\TEMP:F176B6C6 [144] AlternateDataStreams: C:\ProgramData\TEMP:F2F0A8AC [138] AlternateDataStreams: C:\ProgramData\TEMP:F39A1A9B [129] AlternateDataStreams: C:\ProgramData\TEMP:F4B7CBB2 [152] AlternateDataStreams: C:\ProgramData\TEMP:F55F0EF6 [129] AlternateDataStreams: C:\ProgramData\TEMP:F5E90ED3 [454] AlternateDataStreams: C:\ProgramData\TEMP:F610C203 [129] AlternateDataStreams: C:\ProgramData\TEMP:F66F0A25 [143] AlternateDataStreams: C:\ProgramData\TEMP:F67808F2 [128] AlternateDataStreams: C:\ProgramData\TEMP:F6A712DD [132] AlternateDataStreams: C:\ProgramData\TEMP:F816645E [130] AlternateDataStreams: C:\ProgramData\TEMP:F83E8359 [125] AlternateDataStreams: C:\ProgramData\TEMP:F92E1E4B [122] AlternateDataStreams: C:\ProgramData\TEMP:FA66F86F [155] AlternateDataStreams: C:\ProgramData\TEMP:FAB64002 [144] AlternateDataStreams: C:\ProgramData\TEMP:FAFEC4B9 [114] AlternateDataStreams: C:\ProgramData\TEMP:FC97DEBC [148] AlternateDataStreams: C:\ProgramData\TEMP:FCECE156 [127] AlternateDataStreams: C:\ProgramData\TEMP:FD6D11C9 [128] AlternateDataStreams: C:\ProgramData\TEMP:FD8BCF62 [286] AlternateDataStreams: C:\ProgramData\TEMP:FDB03735 [136] AlternateDataStreams: C:\ProgramData\TEMP:FE61B3F6 [148] AlternateDataStreams: C:\ProgramData\TEMP:FF869361 [130] AlternateDataStreams: C:\Users\Public\Documents\desktop.ini:gs5sys [2048] AlternateDataStreams: C:\Users\S-O\Anwendungsdaten:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Cookies:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Lokale Einstellungen:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Vorlagen:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Desktop\desktop.ini:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\AppData\Local:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\AppData\Roaming:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\AppData\Local\Anwendungsdaten:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\AppData\Local\Verlauf:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Documents\desktop.ini:gs5sys [3074] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\webcompanion.com -> hxxp://webcompanion.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1001movie.com -> 1001movie.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1001night.biz -> 1001night.biz IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\100gal.net -> 100gal.net IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\100sexlinks.com -> 100sexlinks.com Da befinden sich 4788 mehr Seiten. ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2016-04-26 07:17 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\S-O\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: LiveUpdateSvc => 2 MSCONFIG\Services: MBAMScheduler => 2 MSCONFIG\Services: MBAMService => 2 ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{8CB37AA2-4647-4254-A2ED-03A48ADABC3C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{B8A0DA5A-F4AF-4DF5-A575-F92F96A0385B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{8569C3D1-1154-40BE-80C8-F4D232B15F87}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{10C7D8E6-1113-4D0E-B6E8-8A43833FB6F8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{3A976A67-A5AB-4F20-8D7B-13FFBBFC4340}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3EB9616D-29DC-477E-A200-7771617E6A9D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{A6F913EE-5E14-4E38-9E99-0B2ED5B556A1}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{DDDE07BD-22DF-412B-A2F2-FAF4CA561A13}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{F3421429-9323-44E7-9E3C-856BA0F298CF}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe FirewallRules: [{1970EEB2-5F54-40DC-AC17-BAEF479C1A28}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe FirewallRules: [{6C11389D-2BFA-4CA4-A191-F9A140F518AF}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe FirewallRules: [{F44E652C-E4F2-4434-AE5B-5785CCD4B0FB}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe ==================== Wiederherstellungspunkte ========================= 25-04-2016 06:23:15 Windows-Sicherung 25-04-2016 19:22:21 Windows Update ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (04/26/2016 05:26:31 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm CCleaner64.exe, Version 5.12.0.5431 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 98c Startzeit: 01d19f8cf7cbf600 Endzeit: 203 Anwendungspfad: C:\Program Files\CCleaner\CCleaner64.exe Berichts-ID: 3a6d59c1-0bc3-11e6-94b3-001d72a78854 Error: (04/26/2016 10:41:16 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: EmerlandSolitaireEndlessJourney.exe, Version: 0.0.0.0, Zeitstempel: 0x56c33513 Name des fehlerhaften Moduls: EmerlandSolitaireEndlessJourney.exe, Version: 0.0.0.0, Zeitstempel: 0x56c33513 Ausnahmecode: 0xc0000417 Fehleroffset: 0x002028f3 ID des fehlerhaften Prozesses: 0xb28 Startzeit der fehlerhaften Anwendung: 0xEmerlandSolitaireEndlessJourney.exe0 Pfad der fehlerhaften Anwendung: EmerlandSolitaireEndlessJourney.exe1 Pfad des fehlerhaften Moduls: EmerlandSolitaireEndlessJourney.exe2 Berichtskennung: EmerlandSolitaireEndlessJourney.exe3 Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 3058) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 3028) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 9002) (User: ) Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 7042) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 7040) (User: ) Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=4700} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Systemfehler: ============= Error: (04/26/2016 06:04:40 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/26/2016 05:56:43 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/26/2016 07:14:44 AM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/26/2016 07:07:10 AM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/26/2016 05:55:17 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (04/26/2016 05:54:47 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/26/2016 05:54:47 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Error: (04/25/2016 07:33:02 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070490 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB3071756) Error: (04/25/2016 07:32:18 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070490 fehlgeschlagen: Update für Windows 7 für x64-basierte Systeme (KB3068708) Error: (04/25/2016 07:31:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070490 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB3033929) CodeIntegrity: =================================== Date: 2016-04-25 08:14:53.092 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-04-25 08:14:52.967 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Prozessor: Athlon(tm) Dual Core Processor 4450e Prozentuale Nutzung des RAM: 95% Installierter physikalischer RAM: 1534.55 MB Verfügbarer physikalischer RAM: 76.12 MB Summe virtueller Speicher: 3069.1 MB Verfügbarer virtueller Speicher: 1053.36 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:155.05 GB) (Free:78.23 GB) NTFS Drive d: (DATA) (Fixed) (Total:142.94 GB) (Free:48.11 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 27F6989C) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=155 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=142.9 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ Um die Frage auf deinen Hinweis zu benatworten, der Upload scheint nicht geklappt zu haben. Hallo Raphael, entweder bin ich zu blöd oder ich verstehe irgend etwas nicht, ich kann den Log nicht in Combofix ziehen. Es tut mit leid dir soviel Arbeit zu machen, aber ich bin auch keine Computerfachfrau. Bitte sei nicht böse und melde dich. Danke aria |
27.04.2016, 08:49 | #24 |
/// Malwareteam | MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] Hallo Aria, Du erstellst eine Textdatei auf dem Desktop - der Inhalt dieser Datei steht in meinem Posting. Dann schließt und speicherst du diese Datei. Im Anschluss daran klickst du mit der linken Maustaste auf diese Textdatei und hälst die taste gedrückt, so als wenn du sie verschieben wolltest - dann ziehst du diese Datei in “Combofix“ rein und lässt die Maustaste los...
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
28.04.2016, 06:09 | #25 |
| MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] Hallo, ich glaube ich weiss jetzt woran es liegt, ich kann machen was ich will ich bekomme die Dateien nicht auf den Desktop sonder sie bleiben im Download hängen. Also kann ich diese Dateien immer wieder neu starten und nicht dahin verschieben. |
28.04.2016, 09:06 | #26 | |
/// Malwareteam | MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] ?? Zitat:
Kopiere Combofix und die Anweisungsliste auf den Desktop und führe das was oben steht aus - dass das nicht geht, kann ich schwer glauben.
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
28.04.2016, 10:31 | #27 |
| MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] Hallo, ich bin mit meinem Latein am Ende, vielleicht kannst Du mir mit Teamviewer weiterhelfen. Wenn ja melde dich bitte wieder. |
28.04.2016, 17:01 | #28 |
/// Malwareteam | MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] so jetzt poste mal die beiden FRST Logs die auf deinem Desktop sind.
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
28.04.2016, 17:11 | #29 |
| MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] FRST Additions Logfile: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016 durchgeführt von S-O (2016-04-28 16:04:38) Gestartet von C:\Users\S-O\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2014-06-25 09:29:16) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3482151743-2939713798-2738295144-500 - Administrator - Disabled) Gast (S-1-5-21-3482151743-2939713798-2738295144-501 - Limited - Enabled) S-O (S-1-5-21-3482151743-2939713798-2738295144-1000 - Administrator - Enabled) => C:\Users\S-O ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95} AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.226 - Adobe Systems Incorporated) Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated) Around the World in 80 Days (HKLM-x32\...\BFG-Around the World in 80 Days) (Version: - ) Avalon Legends Solitaire (HKLM-x32\...\BFG-Avalon Legends Solitaire) (Version: - ) AVG Zen (Version: 1.41.29 - AVG Technologies) Hidden Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.3.0.2 - ) Brother MFL-Pro Suite DCP-7070DW (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.) CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform) Cradle of Rome (HKLM-x32\...\BFG-Cradle of Rome) (Version: - ) Die Chroniken von Emerland Solitär (HKLM-x32\...\BFG-Die Chroniken von Emerland Solitaer) (Version: - ) Emerland Solitaire: Endless Journey (HKLM-x32\...\BFG-Emerland Solitaire - Endless Journey) (Version: - ) Ferne Königreiche - Wintersolitaire (HKLM-x32\...\BFG-Ferne Koenigreiche - Wintersolitaire) (Version: - ) FMW 1 (Version: 1.62.2 - AVG Technologies) Hidden Heartwild Solitaire (HKLM-x32\...\BFG-Heartwild Solitaire) (Version: - ) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.2.1.126 - IObit) Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Mozilla Firefox 46.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 46.0 (x86 de)) (Version: 46.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 46.0.0.5955 - Mozilla) Mozilla Thunderbird 38.7.2 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 38.7.2 (x86 de)) (Version: 38.7.2 - Mozilla) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Mystery Tales: Durch ihre Augen Sammleredition (HKLM-x32\...\BFG-Mystery Tales - Durch ihre Augen Sammleredition) (Version: - ) Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.) Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation) Online Games Manager v1.30 (HKLM-x32\...\Online Games Manager) (Version: 1.30.14 - Real Networks, Inc.) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7746 - Realtek Semiconductor Corp.) TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.56083 - TeamViewer) The Path of Hercules (HKLM-x32\...\BFG-The Path of Hercules) (Version: - ) The Rise of Atlantis (HKLM-x32\...\BFG-The Rise of Atlantis) (Version: - ) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) VLC media player 2.0.5 (HKLM-x32\...\VLC media player) (Version: 2.0.5 - VideoLAN) Warlock - Der Fluch des Schamanen (HKLM-x32\...\BFG-Warlock - Der Fluch des Schamanen) (Version: - ) WildTangent Games App (x32 Version: 4.0.10.25 - WildTangent) Hidden WildTangent-Spiele (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.1.0.28 - WildTangent) WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - ) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {07436B16-FE19-4A5A-B231-1FA1349AC5EF} - System32\Tasks\{3CC89BB3-4254-4F39-BA00-AD99D04AF8DF} => pcalua.exe -a C:\Users\S-O\Downloads\RoyalMahjongDieReiseDesKoenigs.exe -d C:\Users\S-O\Downloads\ Task: {10133C68-9491-4A78-BDEA-F512E1FD16BB} - System32\Tasks\{506D09E9-D93C-4BF6-A657-F6C2B5E03AF0} => pcalua.exe -a C:\Users\S-O\Downloads\riseofatlantis_setup(1).exe -d C:\Users\S-O\Downloads Task: {1D4101B7-F9A4-4E0E-93A1-2C330CF07C95} - System32\Tasks\{1AE9A7D5-233E-4AD5-B509-214EF6C6DC8E} => C:\Program Files (x86)\bfgclient\bfgclient.exe [2014-03-05] () Task: {30589647-360D-47DB-BF15-540632B71C1B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-17] (Adobe Systems Incorporated) Task: {356B815F-C9E1-45BD-899E-E675E5AC0CFD} - System32\Tasks\{41598AD5-A86B-455F-A093-D7532BFD8843} => pcalua.exe -a "C:\Program Files (x86)\Columbus - Der Geist im Stein\Uninstall.exe" Task: {381568B0-BBB8-4081-B124-99D343D11D7B} - System32\Tasks\{A64CC72B-1794-4CFA-9C10-241D4F1EBCE7} => pcalua.exe -a C:\Users\S-O\Downloads\BigCityAdventureTokyo(2).exe -d C:\Users\S-O\Downloads Task: {3A60A4D6-A943-47FE-9E9F-13F5B0B400C6} - System32\Tasks\{E072B913-E166-4B57-B4FA-85B80C2640BF} => pcalua.exe -a "C:\Program Files (x86)\Myths of the World - Der Elfenfaenger Sammleredition\Uninstall.exe" Task: {3D0E39D1-1865-4F2E-B384-D3BA8B28F465} - System32\Tasks\{369F9E9C-F685-49FF-A8E0-61B2F37F8882} => pcalua.exe -a "C:\Remote Programs\The Treasures of Montezuma\GPlrLanc.exe" -c -LOpCode 2 /RemoveContent cid=466552;name=The Treasures of Montezuma;dir=C:\Remote Programs\The Treasures of Montezuma\;PrvId=148;cmdid=1;prvdir=Default Task: {410EBFAB-09E9-4E99-AC51-E52E05873707} - System32\Tasks\{24C8089B-057D-436C-94A4-4C523DBB839D} => pcalua.exe -a C:\Users\S-O\Downloads\GreedVerrueckteWissenschaftler.exe -d C:\Users\S-O\Downloads Task: {4428B58C-4DF7-4071-BAAE-CDAAD8E3F4F2} - \SafeZone scheduled Autoupdate 1455795784 -> Keine Datei <==== ACHTUNG Task: {447D502B-0F22-4B79-80AC-7698505B5F75} - System32\Tasks\{5722FF3E-723E-4232-AEFC-FDD1C4F25C22} => pcalua.exe -a "C:\Program Files (x86)\Mystery Case Files - Die Druiden von Dire Grove Sammleredition\Uninstall.exe" Task: {494D2AFA-7FA8-4D21-AD31-EEABDE444A54} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-01-20] (AVAST Software) Task: {4CEB1302-8A54-4096-9273-822229C57A1D} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3482151743-2939713798-2738295144-1000 Task: {4FDAF9DC-117B-4B1D-9D66-BC42A797726C} - System32\Tasks\{DAE36A89-A9B9-4926-8B4B-CD237745AD61} => pcalua.exe -a "C:\Users\S-O\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33ZVHNKV\Setup[1].exe" -d "c:\program files (x86)\wildtangent games\app" Task: {517F29B3-976F-4EDA-B7CE-8667CA6662ED} - System32\Tasks\{F4D1B90F-6073-458F-9D52-C0E6AFC912B9} => pcalua.exe -a C:\Users\S-O\Downloads\BigCityAdventureRioDeJaneiro(1).exe -d C:\Users\S-O\Downloads Task: {57A0DF26-EA4B-44AC-B96E-67134C96ADA6} - System32\Tasks\{8C7932EF-A79E-4138-80FC-93D1C05A05F1} => pcalua.exe -a "C:\Program Files (x86)\GameTop.com\Egyptian Ball\unins000.exe" Task: {5E362B45-8FD0-4950-A564-270C2A028F9E} - System32\Tasks\Uninstaller_SkipUac_S-O => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-01-12] (IObit) Task: {6A7D2A96-B9D7-4E60-A6C7-93CEBE7EE361} - \Opera scheduled Autoupdate 1459857045 -> Keine Datei <==== ACHTUNG Task: {6BEF2A4E-A7D5-487C-A6BD-1A3E7C1EEB8D} - System32\Tasks\{D2FF64D8-63B6-4301-84BC-D6063989E5A9} => pcalua.exe -a C:\Users\S-O\Downloads\DarkParablesRotkaeppchenSammler.exe -d C:\Users\S-O\Downloads Task: {77003A9D-9E13-475F-9C47-9725C60DB521} - System32\Tasks\{67D81E6A-289D-467C-BD0A-E0DE556FAF0F} => C:\Program Files (x86)\bfgclient\bfgclient.exe [2014-03-05] () Task: {7F6C97E7-38D2-4146-BD93-D57942C30DD0} - System32\Tasks\{8D2627E4-D89B-4596-9795-0399E2CC9548} => pcalua.exe -a "C:\Program Files (x86)\Nevertales - Die innere Schoenheit Sammleredition\Uninstall.exe" Task: {8365884E-C068-4169-836B-932DA69593E8} - System32\Tasks\{AAF2DBFC-1B56-4566-B35D-875B4ED76BE9} => pcalua.exe -a C:\Users\S-O\Downloads\MordIstIhrHobby2.exe -d C:\Users\S-O\Downloads Task: {8C9AF501-8A02-4AE6-A46A-0D2C08E4A3C8} - \Opera scheduled Autoupdate 1460460240 -> Keine Datei <==== ACHTUNG Task: {9333A1EC-2DA8-4C5F-B717-4FF76BCA969D} - System32\Tasks\{7A2A58A8-149B-45E8-A37A-91227BCF91B0} => pcalua.exe -a "C:\Program Files (x86)\GameTop.com\The Rise Of Atlantis\unins000.exe" Task: {98C1B123-31FB-42DC-B804-EBA903D9DD95} - System32\Tasks\Driver Booster SkipUAC (S-O) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2016-01-18] (IObit) Task: {A28CC4BA-38F1-4102-85FD-10EA175BCF15} - System32\Tasks\{D04B8E65-A67E-43A6-B02C-16CB2ABAC5B7} => pcalua.exe -a "C:\Program Files (x86)\OXXOGames\GPlayer\\MyInstall.exe" -c ScriptUInst "C:\Program Files (x86)\OXXOGames\GPlayer\Install\\Game_BigCityAdventureParis.log" Task: {A2B06C45-661F-4BE3-85AF-6C9DBB258B14} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2016-01-13] (IObit) Task: {BBBA7ED5-1F61-4DC2-BE04-3F8E5D687C41} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {D2DD889E-EC62-4BBD-AD3A-B63B59565014} - System32\Tasks\{37137159-462D-459D-BA48-0715F5A42CE0} => pcalua.exe -a C:\Users\S-O\Downloads\NewYorkMysteriesHochspannungSE.exe -d C:\Users\S-O\Downloads Task: {D4E0BA10-7D52-4EF3-B176-E2A635540216} - System32\Tasks\ASC9_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-01-15] (IObit) Task: {DFF4575A-1AD5-4131-B007-9033EE081693} - System32\Tasks\{7A3E63D9-54E3-44E8-81FC-17FA9B21559C} => C:\Program Files (x86)\bfgclient\bfgclient.exe [2014-03-05] () Task: {E4D264EE-CCD0-452B-B948-0EC52672ED63} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd) Task: {EA6A2FA2-F26A-4F62-83F5-C245D45F1754} - System32\Tasks\ASC9_SkipUac_S-O => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-01-18] (IObit) Task: {EAAE3B23-F16C-4D7F-8EB6-68D1A727FF45} - System32\Tasks\{171EFD58-163A-4405-9707-16647CCF3B7D} => C:\Program Files (x86)\bfgclient\bfgclient.exe [2014-03-05] () Task: {F0180014-9DB4-459F-986F-BB29038B3BA2} - \Opera scheduled Autoupdate 1460715966 -> Keine Datei <==== ACHTUNG Task: {F787742B-CFC5-43DB-8C81-0C55CC64A7B6} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {F89BC92B-B7CA-416F-A42A-4C9E28C5660A} - System32\Tasks\{010F5115-9A1B-4724-BAD9-9F6C2D5EB0E9} => pcalua.exe -a C:\Users\S-O\Downloads\DerVerborgeneKontinent.exe -d C:\Users\S-O\Downloads (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2014-11-13 18:13 - 2016-01-29 12:49 - 00135224 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-11-16 18:55 - 2015-11-16 18:55 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2016-02-17 20:07 - 2015-12-23 19:32 - 00355616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madExcept_.bpl 2016-02-17 20:07 - 2015-12-23 19:32 - 00190240 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madBasic_.bpl 2016-02-17 20:07 - 2015-12-23 19:32 - 00057632 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madDisAsm_.bpl 2016-02-17 20:07 - 2015-12-28 14:50 - 00899872 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\webres.dll 2016-02-17 20:07 - 2015-12-28 14:49 - 00629536 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\ProductStatistics.dll 2016-01-28 06:46 - 2015-12-23 19:32 - 00355616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl 2016-01-28 06:46 - 2015-12-23 19:32 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl 2016-01-28 06:46 - 2015-12-23 19:32 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData:gs5sys [2560] AlternateDataStreams: C:\Users\All Users:gs5sys [2560] AlternateDataStreams: C:\Users\S-O:gs5sys [3074] AlternateDataStreams: C:\ProgramData\Anwendungsdaten:gs5sys [2560] AlternateDataStreams: C:\ProgramData\Application Data:gs5sys [2560] AlternateDataStreams: C:\ProgramData\TEMP:008FE370 [134] AlternateDataStreams: C:\ProgramData\TEMP:00A3C892 [134] AlternateDataStreams: C:\ProgramData\TEMP:0205B36B [127] AlternateDataStreams: C:\ProgramData\TEMP:02166498 [145] AlternateDataStreams: C:\ProgramData\TEMP:024B9CC7 [137] AlternateDataStreams: C:\ProgramData\TEMP:02AAE472 [124] AlternateDataStreams: C:\ProgramData\TEMP:0452501D [286] AlternateDataStreams: C:\ProgramData\TEMP:070D9534 [117] AlternateDataStreams: C:\ProgramData\TEMP:076F9EF8 [128] AlternateDataStreams: C:\ProgramData\TEMP:08767DE0 [128] AlternateDataStreams: C:\ProgramData\TEMP:08F9E829 [290] AlternateDataStreams: C:\ProgramData\TEMP:092BD83A [272] AlternateDataStreams: C:\ProgramData\TEMP:097C4B7D [136] AlternateDataStreams: C:\ProgramData\TEMP:099BA123 [296] AlternateDataStreams: C:\ProgramData\TEMP:09D92173 [256] AlternateDataStreams: C:\ProgramData\TEMP:0A719894 [143] AlternateDataStreams: C:\ProgramData\TEMP:0B9DC6BB [132] AlternateDataStreams: C:\ProgramData\TEMP:0BCD47A5 [149] AlternateDataStreams: C:\ProgramData\TEMP:0BFBB93D [254] AlternateDataStreams: C:\ProgramData\TEMP:0C1258F3 [131] AlternateDataStreams: C:\ProgramData\TEMP:0C2A17F2 [139] AlternateDataStreams: C:\ProgramData\TEMP:0C363260 [151] AlternateDataStreams: C:\ProgramData\TEMP:0C8F16BF [146] AlternateDataStreams: C:\ProgramData\TEMP:0C98AF11 [146] AlternateDataStreams: C:\ProgramData\TEMP:0CEE6109 [131] AlternateDataStreams: C:\ProgramData\TEMP:0D060666 [132] AlternateDataStreams: C:\ProgramData\TEMP:0EE45B2D [141] AlternateDataStreams: C:\ProgramData\TEMP:0EFDD299 [266] AlternateDataStreams: C:\ProgramData\TEMP:0FA1EAA7 [131] AlternateDataStreams: C:\ProgramData\TEMP:1130B726 [143] AlternateDataStreams: C:\ProgramData\TEMP:120B3AFD [136] AlternateDataStreams: C:\ProgramData\TEMP:1239BE94 [135] AlternateDataStreams: C:\ProgramData\TEMP:123A86B5 [141] AlternateDataStreams: C:\ProgramData\TEMP:12D2EB9C [125] AlternateDataStreams: C:\ProgramData\TEMP:1309637A [294] AlternateDataStreams: C:\ProgramData\TEMP:1322DDBD [130] AlternateDataStreams: C:\ProgramData\TEMP:132B1756 [152] AlternateDataStreams: C:\ProgramData\TEMP:1345C9DC [121] AlternateDataStreams: C:\ProgramData\TEMP:1392F09D [126] AlternateDataStreams: C:\ProgramData\TEMP:14B3C0A8 [124] AlternateDataStreams: C:\ProgramData\TEMP:14D4993F [266] AlternateDataStreams: C:\ProgramData\TEMP:164561C8 [148] AlternateDataStreams: C:\ProgramData\TEMP:16F4BC64 [119] AlternateDataStreams: C:\ProgramData\TEMP:177313FB [125] AlternateDataStreams: C:\ProgramData\TEMP:186F8A82 [149] AlternateDataStreams: C:\ProgramData\TEMP:18A6D2CC [134] AlternateDataStreams: C:\ProgramData\TEMP:18E35126 [130] AlternateDataStreams: C:\ProgramData\TEMP:19474103 [264] AlternateDataStreams: C:\ProgramData\TEMP:1999DD0A [133] AlternateDataStreams: C:\ProgramData\TEMP:1A14B3AF [140] AlternateDataStreams: C:\ProgramData\TEMP:1A259A13 [282] AlternateDataStreams: C:\ProgramData\TEMP:1B506EA3 [150] AlternateDataStreams: C:\ProgramData\TEMP:1BD320E3 [143] AlternateDataStreams: C:\ProgramData\TEMP:1C211903 [286] AlternateDataStreams: C:\ProgramData\TEMP:1C662800 [137] AlternateDataStreams: C:\ProgramData\TEMP:1CCE0A1A [140] AlternateDataStreams: C:\ProgramData\TEMP:1D5FADCD [300] AlternateDataStreams: C:\ProgramData\TEMP:1F4F2F80 [127] AlternateDataStreams: C:\ProgramData\TEMP:1F9D647F [146] AlternateDataStreams: C:\ProgramData\TEMP:20ABE827 [286] AlternateDataStreams: C:\ProgramData\TEMP:2187A2BB [126] AlternateDataStreams: C:\ProgramData\TEMP:219DB32E [131] AlternateDataStreams: C:\ProgramData\TEMP:229564F1 [120] AlternateDataStreams: C:\ProgramData\TEMP:2313511A [128] AlternateDataStreams: C:\ProgramData\TEMP:244E4E3A [146] AlternateDataStreams: C:\ProgramData\TEMP:25F31665 [141] AlternateDataStreams: C:\ProgramData\TEMP:260575F1 [119] AlternateDataStreams: C:\ProgramData\TEMP:2680DDD5 [151] AlternateDataStreams: C:\ProgramData\TEMP:282A4C88 [136] AlternateDataStreams: C:\ProgramData\TEMP:29EA7E22 [0] AlternateDataStreams: C:\ProgramData\TEMP:2B1EA607 [118] AlternateDataStreams: C:\ProgramData\TEMP:2B5C4773 [155] AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F [134] AlternateDataStreams: C:\ProgramData\TEMP:2D2A0FC2 [122] AlternateDataStreams: C:\ProgramData\TEMP:2E5508DE [122] AlternateDataStreams: C:\ProgramData\TEMP:2EAD4F23 [148] AlternateDataStreams: C:\ProgramData\TEMP:2EFCCD2A [280] AlternateDataStreams: C:\ProgramData\TEMP:2F70C0B4 [145] AlternateDataStreams: C:\ProgramData\TEMP:2F9BD5B3 [127] AlternateDataStreams: C:\ProgramData\TEMP:3086B95F [123] AlternateDataStreams: C:\ProgramData\TEMP:308F8D8D [278] AlternateDataStreams: C:\ProgramData\TEMP:30A9192A [129] AlternateDataStreams: C:\ProgramData\TEMP:30EDFEBE [118] AlternateDataStreams: C:\ProgramData\TEMP:313F7672 [150] AlternateDataStreams: C:\ProgramData\TEMP:316EAAE9 [102] AlternateDataStreams: C:\ProgramData\TEMP:31C9BA96 [284] AlternateDataStreams: C:\ProgramData\TEMP:31CE65F3 [133] AlternateDataStreams: C:\ProgramData\TEMP:32414169 [145] AlternateDataStreams: C:\ProgramData\TEMP:32FFF2D1 [119] AlternateDataStreams: C:\ProgramData\TEMP:331B7520 [155] AlternateDataStreams: C:\ProgramData\TEMP:3393A1CA [270] AlternateDataStreams: C:\ProgramData\TEMP:33E58057 [144] AlternateDataStreams: C:\ProgramData\TEMP:341C1FBD [282] AlternateDataStreams: C:\ProgramData\TEMP:346337E3 [133] AlternateDataStreams: C:\ProgramData\TEMP:34FBEA36 [134] AlternateDataStreams: C:\ProgramData\TEMP:36AAD0E5 [135] AlternateDataStreams: C:\ProgramData\TEMP:36E7847A [126] AlternateDataStreams: C:\ProgramData\TEMP:36ED5C45 [140] AlternateDataStreams: C:\ProgramData\TEMP:371C5214 [276] AlternateDataStreams: C:\ProgramData\TEMP:37207201 [148] AlternateDataStreams: C:\ProgramData\TEMP:39743F39 [125] AlternateDataStreams: C:\ProgramData\TEMP:39BD98E5 [135] AlternateDataStreams: C:\ProgramData\TEMP:39CB2031 [366] AlternateDataStreams: C:\ProgramData\TEMP:3A133158 [140] AlternateDataStreams: C:\ProgramData\TEMP:3ADE134E [290] AlternateDataStreams: C:\ProgramData\TEMP:3B622E21 [155] AlternateDataStreams: C:\ProgramData\TEMP:3BDF57F4 [144] AlternateDataStreams: C:\ProgramData\TEMP:3C18D47C [130] AlternateDataStreams: C:\ProgramData\TEMP:3D186293 [145] AlternateDataStreams: C:\ProgramData\TEMP:3D4B733E [296] AlternateDataStreams: C:\ProgramData\TEMP:3E1EE95E [130] AlternateDataStreams: C:\ProgramData\TEMP:3FD496E1 [115] AlternateDataStreams: C:\ProgramData\TEMP:3FE64CFC [129] AlternateDataStreams: C:\ProgramData\TEMP:406E0034 [130] AlternateDataStreams: C:\ProgramData\TEMP:413177C4 [151] AlternateDataStreams: C:\ProgramData\TEMP:4157BB05 [132] AlternateDataStreams: C:\ProgramData\TEMP:415E77AB [152] AlternateDataStreams: C:\ProgramData\TEMP:41CB6858 [276] AlternateDataStreams: C:\ProgramData\TEMP:424D7CFE [131] AlternateDataStreams: C:\ProgramData\TEMP:426D1496 [123] AlternateDataStreams: C:\ProgramData\TEMP:447856CD [131] AlternateDataStreams: C:\ProgramData\TEMP:44A0FEC3 [140] AlternateDataStreams: C:\ProgramData\TEMP:44ABD37A [135] AlternateDataStreams: C:\ProgramData\TEMP:4548E058 [138] AlternateDataStreams: C:\ProgramData\TEMP:45936E12 [129] AlternateDataStreams: C:\ProgramData\TEMP:46EF121E [122] AlternateDataStreams: C:\ProgramData\TEMP:474022C7 [146] AlternateDataStreams: C:\ProgramData\TEMP:4762F1D2 [148] AlternateDataStreams: C:\ProgramData\TEMP:490B67EC [125] AlternateDataStreams: C:\ProgramData\TEMP:498B5975 [141] AlternateDataStreams: C:\ProgramData\TEMP:4A8EB1C4 [149] AlternateDataStreams: C:\ProgramData\TEMP:4B7C28B1 [137] AlternateDataStreams: C:\ProgramData\TEMP:4C235DA4 [290] AlternateDataStreams: C:\ProgramData\TEMP:4CF76F21 [121] AlternateDataStreams: C:\ProgramData\TEMP:4DDBE3DC [130] AlternateDataStreams: C:\ProgramData\TEMP:4E07A403 [147] AlternateDataStreams: C:\ProgramData\TEMP:4FA837B4 [128] AlternateDataStreams: C:\ProgramData\TEMP:4FD3435F [155] AlternateDataStreams: C:\ProgramData\TEMP:4FE3FB06 [140] AlternateDataStreams: C:\ProgramData\TEMP:506698B2 [138] AlternateDataStreams: C:\ProgramData\TEMP:50868536 [260] AlternateDataStreams: C:\ProgramData\TEMP:512E1728 [136] AlternateDataStreams: C:\ProgramData\TEMP:5167543E [145] AlternateDataStreams: C:\ProgramData\TEMP:51A20D23 [286] AlternateDataStreams: C:\ProgramData\TEMP:52641FBE [126] AlternateDataStreams: C:\ProgramData\TEMP:5430D891 [153] AlternateDataStreams: C:\ProgramData\TEMP:5545792B [140] AlternateDataStreams: C:\ProgramData\TEMP:5559517D [138] AlternateDataStreams: C:\ProgramData\TEMP:55BB2521 [101] AlternateDataStreams: C:\ProgramData\TEMP:55E1514E [268] AlternateDataStreams: C:\ProgramData\TEMP:565D4B03 [298] AlternateDataStreams: C:\ProgramData\TEMP:566B9179 [264] AlternateDataStreams: C:\ProgramData\TEMP:569CEE83 [127] AlternateDataStreams: C:\ProgramData\TEMP:570ED58C [300] AlternateDataStreams: C:\ProgramData\TEMP:58158478 [131] AlternateDataStreams: C:\ProgramData\TEMP:58306E4C [137] AlternateDataStreams: C:\ProgramData\TEMP:5986FE1C [141] AlternateDataStreams: C:\ProgramData\TEMP:598BD055 [139] AlternateDataStreams: C:\ProgramData\TEMP:59CA329D [119] AlternateDataStreams: C:\ProgramData\TEMP:5A1E97C7 [134] AlternateDataStreams: C:\ProgramData\TEMP:5A437AC3 [408] AlternateDataStreams: C:\ProgramData\TEMP:5AF17798 [280] AlternateDataStreams: C:\ProgramData\TEMP:5C717402 [274] AlternateDataStreams: C:\ProgramData\TEMP:5E7551D4 [128] AlternateDataStreams: C:\ProgramData\TEMP:5E8C18F1 [276] AlternateDataStreams: C:\ProgramData\TEMP:5E9B629B [97] AlternateDataStreams: C:\ProgramData\TEMP:5F56E7C1 [286] AlternateDataStreams: C:\ProgramData\TEMP:5FEBCE9C [128] AlternateDataStreams: C:\ProgramData\TEMP:623E564B [124] AlternateDataStreams: C:\ProgramData\TEMP:629A9591 [145] AlternateDataStreams: C:\ProgramData\TEMP:629F8518 [143] AlternateDataStreams: C:\ProgramData\TEMP:634EA293 [137] AlternateDataStreams: C:\ProgramData\TEMP:63BA523E [138] AlternateDataStreams: C:\ProgramData\TEMP:63C48B80 [288] AlternateDataStreams: C:\ProgramData\TEMP:64E05835 [145] AlternateDataStreams: C:\ProgramData\TEMP:65949863 [141] AlternateDataStreams: C:\ProgramData\TEMP:660BDAE1 [310] AlternateDataStreams: C:\ProgramData\TEMP:667D4A95 [133] AlternateDataStreams: C:\ProgramData\TEMP:66F19688 [147] AlternateDataStreams: C:\ProgramData\TEMP:675F9A63 [141] AlternateDataStreams: C:\ProgramData\TEMP:68899984 [145] AlternateDataStreams: C:\ProgramData\TEMP:6A0A47E7 [136] AlternateDataStreams: C:\ProgramData\TEMP:6A6D4AF4 [286] AlternateDataStreams: C:\ProgramData\TEMP:6A936202 [105] AlternateDataStreams: C:\ProgramData\TEMP:6BB32FFE [286] AlternateDataStreams: C:\ProgramData\TEMP:6D208D7A [130] AlternateDataStreams: C:\ProgramData\TEMP:6DA9822F [140] AlternateDataStreams: C:\ProgramData\TEMP:6E90EDD7 [256] AlternateDataStreams: C:\ProgramData\TEMP:6F3BEBA5 [128] AlternateDataStreams: C:\ProgramData\TEMP:70AD58E0 [136] AlternateDataStreams: C:\ProgramData\TEMP:70E897B5 [117] AlternateDataStreams: C:\ProgramData\TEMP:72449E7D [140] AlternateDataStreams: C:\ProgramData\TEMP:72C99D4E [294] AlternateDataStreams: C:\ProgramData\TEMP:72DDC498 [145] AlternateDataStreams: C:\ProgramData\TEMP:72E5CC07 [286] AlternateDataStreams: C:\ProgramData\TEMP:74615EBC [119] AlternateDataStreams: C:\ProgramData\TEMP:75765D7B [144] AlternateDataStreams: C:\ProgramData\TEMP:75CC0165 [112] AlternateDataStreams: C:\ProgramData\TEMP:75CF6AF0 [286] AlternateDataStreams: C:\ProgramData\TEMP:78395CE2 [266] AlternateDataStreams: C:\ProgramData\TEMP:7929462F [135] AlternateDataStreams: C:\ProgramData\TEMP:797D4F54 [139] AlternateDataStreams: C:\ProgramData\TEMP:79A7F369 [137] AlternateDataStreams: C:\ProgramData\TEMP:79EAEF54 [135] AlternateDataStreams: C:\ProgramData\TEMP:7A3AAF2E [121] AlternateDataStreams: C:\ProgramData\TEMP:7A530D80 [144] AlternateDataStreams: C:\ProgramData\TEMP:7C1271A7 [147] AlternateDataStreams: C:\ProgramData\TEMP:7C27C41C [148] AlternateDataStreams: C:\ProgramData\TEMP:7CF96AD4 [128] AlternateDataStreams: C:\ProgramData\TEMP:7D9B1030 [148] AlternateDataStreams: C:\ProgramData\TEMP:7DB43890 [138] AlternateDataStreams: C:\ProgramData\TEMP:7E1E8D30 [135] AlternateDataStreams: C:\ProgramData\TEMP:7F477B0D [139] AlternateDataStreams: C:\ProgramData\TEMP:7F4D8125 [124] AlternateDataStreams: C:\ProgramData\TEMP:8029E75F [129] AlternateDataStreams: C:\ProgramData\TEMP:808420C9 [129] AlternateDataStreams: C:\ProgramData\TEMP:80974241 [131] AlternateDataStreams: C:\ProgramData\TEMP:80EA2EA3 [135] AlternateDataStreams: C:\ProgramData\TEMP:80FA23CA [154] AlternateDataStreams: C:\ProgramData\TEMP:819394CC [146] AlternateDataStreams: C:\ProgramData\TEMP:82756AB7 [150] AlternateDataStreams: C:\ProgramData\TEMP:830725A7 [127] AlternateDataStreams: C:\ProgramData\TEMP:8318A814 [124] AlternateDataStreams: C:\ProgramData\TEMP:839A89FC [145] AlternateDataStreams: C:\ProgramData\TEMP:841E05D6 [124] AlternateDataStreams: C:\ProgramData\TEMP:8435AD8C [135] AlternateDataStreams: C:\ProgramData\TEMP:86A7B7DD [140] AlternateDataStreams: C:\ProgramData\TEMP:86B7FDDB [120] AlternateDataStreams: C:\ProgramData\TEMP:87A3A233 [121] AlternateDataStreams: C:\ProgramData\TEMP:88C5973F [133] AlternateDataStreams: C:\ProgramData\TEMP:89B7A4D9 [144] AlternateDataStreams: C:\ProgramData\TEMP:89CF6F9C [141] AlternateDataStreams: C:\ProgramData\TEMP:8B4B9596 [144] AlternateDataStreams: C:\ProgramData\TEMP:8B4DEB15 [148] AlternateDataStreams: C:\ProgramData\TEMP:8C3C65BE [136] AlternateDataStreams: C:\ProgramData\TEMP:8DBCF585 [132] AlternateDataStreams: C:\ProgramData\TEMP:8DC85A87 [126] AlternateDataStreams: C:\ProgramData\TEMP:8E5EA40F [138] AlternateDataStreams: C:\ProgramData\TEMP:8E761650 [135] AlternateDataStreams: C:\ProgramData\TEMP:8F6B75BF [148] AlternateDataStreams: C:\ProgramData\TEMP:900EBAFA [130] AlternateDataStreams: C:\ProgramData\TEMP:90865A6D [130] AlternateDataStreams: C:\ProgramData\TEMP:90C320E1 [128] AlternateDataStreams: C:\ProgramData\TEMP:91742C9B [128] AlternateDataStreams: C:\ProgramData\TEMP:918A387B [137] AlternateDataStreams: C:\ProgramData\TEMP:919D5A07 [128] AlternateDataStreams: C:\ProgramData\TEMP:91B663FA [138] AlternateDataStreams: C:\ProgramData\TEMP:91FE43FF [144] AlternateDataStreams: C:\ProgramData\TEMP:92A815D8 [105] AlternateDataStreams: C:\ProgramData\TEMP:92B49D9A [151] AlternateDataStreams: C:\ProgramData\TEMP:94B08D9A [131] AlternateDataStreams: C:\ProgramData\TEMP:94B25DF5 [144] AlternateDataStreams: C:\ProgramData\TEMP:950E98CE [266] AlternateDataStreams: C:\ProgramData\TEMP:9510DF8F [132] AlternateDataStreams: C:\ProgramData\TEMP:9524D821 [128] AlternateDataStreams: C:\ProgramData\TEMP:956AE390 [149] AlternateDataStreams: C:\ProgramData\TEMP:97AAB7F2 [258] AlternateDataStreams: C:\ProgramData\TEMP:982B9800 [147] AlternateDataStreams: C:\ProgramData\TEMP:99A29126 [420] AlternateDataStreams: C:\ProgramData\TEMP:9A60A5B3 [125] AlternateDataStreams: C:\ProgramData\TEMP:9BAC4211 [141] AlternateDataStreams: C:\ProgramData\TEMP:9C435C94 [127] AlternateDataStreams: C:\ProgramData\TEMP:9DD01D6C [150] AlternateDataStreams: C:\ProgramData\TEMP:9E5EA7A3 [124] AlternateDataStreams: C:\ProgramData\TEMP:9EE6560D [125] AlternateDataStreams: C:\ProgramData\TEMP:9FC58CBB [148] AlternateDataStreams: C:\ProgramData\TEMP:A19DFC74 [150] AlternateDataStreams: C:\ProgramData\TEMP:A291068E [135] AlternateDataStreams: C:\ProgramData\TEMP:A3B8F70C [116] AlternateDataStreams: C:\ProgramData\TEMP:A3D9016F [126] AlternateDataStreams: C:\ProgramData\TEMP:A42B5698 [276] AlternateDataStreams: C:\ProgramData\TEMP:A441D13F [120] AlternateDataStreams: C:\ProgramData\TEMP:A52D07E2 [128] AlternateDataStreams: C:\ProgramData\TEMP:A594A11A [129] AlternateDataStreams: C:\ProgramData\TEMP:A694F56D [258] AlternateDataStreams: C:\ProgramData\TEMP:A745DB5D [200] AlternateDataStreams: C:\ProgramData\TEMP:A89DF5BD [132] AlternateDataStreams: C:\ProgramData\TEMP:A9056F42 [129] AlternateDataStreams: C:\ProgramData\TEMP:A9EBEE99 [134] AlternateDataStreams: C:\ProgramData\TEMP:A9F877BF [133] AlternateDataStreams: C:\ProgramData\TEMP:AA5A61B2 [130] AlternateDataStreams: C:\ProgramData\TEMP:AB0A5A80 [130] AlternateDataStreams: C:\ProgramData\TEMP:AC9F291E [282] AlternateDataStreams: C:\ProgramData\TEMP:AD450465 [129] AlternateDataStreams: C:\ProgramData\TEMP:AD7BB754 [278] AlternateDataStreams: C:\ProgramData\TEMP:AE324BE5 [140] AlternateDataStreams: C:\ProgramData\TEMP:AE75CCC8 [247] AlternateDataStreams: C:\ProgramData\TEMP:AE7FB2F5 [137] AlternateDataStreams: C:\ProgramData\TEMP:AED33A42 [135] AlternateDataStreams: C:\ProgramData\TEMP:AF465248 [137] AlternateDataStreams: C:\ProgramData\TEMP:B0456F0C [148] AlternateDataStreams: C:\ProgramData\TEMP:B097AC8A [152] AlternateDataStreams: C:\ProgramData\TEMP:B0BE4B3D [284] AlternateDataStreams: C:\ProgramData\TEMP:B190BE3A [114] AlternateDataStreams: C:\ProgramData\TEMP:B39AFC9E [284] AlternateDataStreams: C:\ProgramData\TEMP:B3A139F8 [126] AlternateDataStreams: C:\ProgramData\TEMP:B3C7433B [141] AlternateDataStreams: C:\ProgramData\TEMP:B3D50E25 [133] AlternateDataStreams: C:\ProgramData\TEMP:B4DFBFB7 [120] AlternateDataStreams: C:\ProgramData\TEMP:B53339FE [151] AlternateDataStreams: C:\ProgramData\TEMP:B65E763D [260] AlternateDataStreams: C:\ProgramData\TEMP:B68B34BE [125] AlternateDataStreams: C:\ProgramData\TEMP:B6A93D80 [134] AlternateDataStreams: C:\ProgramData\TEMP:B6FBC05A [153] AlternateDataStreams: C:\ProgramData\TEMP:B74BD6BF [150] AlternateDataStreams: C:\ProgramData\TEMP:B7505DCD [153] AlternateDataStreams: C:\ProgramData\TEMP:B8408597 [129] AlternateDataStreams: C:\ProgramData\TEMP:B845F669 [131] AlternateDataStreams: C:\ProgramData\TEMP:B863466F [286] AlternateDataStreams: C:\ProgramData\TEMP:B961095A [152] AlternateDataStreams: C:\ProgramData\TEMP:BA9CDA91 [134] AlternateDataStreams: C:\ProgramData\TEMP:BAD046B8 [140] AlternateDataStreams: C:\ProgramData\TEMP:BCFEA004 [112] AlternateDataStreams: C:\ProgramData\TEMP:BDE56C1E [150] AlternateDataStreams: C:\ProgramData\TEMP:BE40C8A2 [124] AlternateDataStreams: C:\ProgramData\TEMP:BF4319E5 [136] AlternateDataStreams: C:\ProgramData\TEMP:C00AB302 [298] AlternateDataStreams: C:\ProgramData\TEMP:C11BB4F1 [304] AlternateDataStreams: C:\ProgramData\TEMP:C1616CD9 [129] AlternateDataStreams: C:\ProgramData\TEMP:C178954A [288] AlternateDataStreams: C:\ProgramData\TEMP:C1D3D9A3 [127] AlternateDataStreams: C:\ProgramData\TEMP:C25E505B [298] AlternateDataStreams: C:\ProgramData\TEMP:C36D0DFD [120] AlternateDataStreams: C:\ProgramData\TEMP:C3D26A8A [260] AlternateDataStreams: C:\ProgramData\TEMP:C49A5AD1 [130] AlternateDataStreams: C:\ProgramData\TEMP:C55217E2 [140] AlternateDataStreams: C:\ProgramData\TEMP:C5D38708 [147] AlternateDataStreams: C:\ProgramData\TEMP:C617C0F6 [139] AlternateDataStreams: C:\ProgramData\TEMP:C6275D37 [154] AlternateDataStreams: C:\ProgramData\TEMP:C64957DF [150] AlternateDataStreams: C:\ProgramData\TEMP:C6EB7815 [135] AlternateDataStreams: C:\ProgramData\TEMP:C7684F3C [130] AlternateDataStreams: C:\ProgramData\TEMP:C76D8487 [155] AlternateDataStreams: C:\ProgramData\TEMP:C7D35E8C [136] AlternateDataStreams: C:\ProgramData\TEMP:C7F75BDD [138] AlternateDataStreams: C:\ProgramData\TEMP:CB08ED9D [145] AlternateDataStreams: C:\ProgramData\TEMP:CB3667AF [304] AlternateDataStreams: C:\ProgramData\TEMP:CC8B36B2 [145] AlternateDataStreams: C:\ProgramData\TEMP:CD09F4F2 [125] AlternateDataStreams: C:\ProgramData\TEMP:CDCDE97C [114] AlternateDataStreams: C:\ProgramData\TEMP:CE506F23 [149] AlternateDataStreams: C:\ProgramData\TEMP:CF82DADF [252] AlternateDataStreams: C:\ProgramData\TEMP:CF8AEC6E [140] AlternateDataStreams: C:\ProgramData\TEMP:D21C1CCC [134] AlternateDataStreams: C:\ProgramData\TEMP:D3D28FA2 [260] AlternateDataStreams: C:\ProgramData\TEMP:D4E62FA9 [151] AlternateDataStreams: C:\ProgramData\TEMP:D57DCBA2 [126] AlternateDataStreams: C:\ProgramData\TEMP:D5C946C5 [144] AlternateDataStreams: C:\ProgramData\TEMP:D6A43EB0 [139] AlternateDataStreams: C:\ProgramData\TEMP:D92485C9 [104] AlternateDataStreams: C:\ProgramData\TEMP:D92A5893 [148] AlternateDataStreams: C:\ProgramData\TEMP:DADACE5D [152] AlternateDataStreams: C:\ProgramData\TEMP:DB2748F7 [145] AlternateDataStreams: C:\ProgramData\TEMP:DB77E2C4 [136] AlternateDataStreams: C:\ProgramData\TEMP:DB8C5FF1 [143] AlternateDataStreams: C:\ProgramData\TEMP:DBC28EB1 [121] AlternateDataStreams: C:\ProgramData\TEMP:DBC3D477 [137] AlternateDataStreams: C:\ProgramData\TEMP:DBE046F5 [132] AlternateDataStreams: C:\ProgramData\TEMP:DC0B1070 [143] AlternateDataStreams: C:\ProgramData\TEMP:DC7EDF41 [143] AlternateDataStreams: C:\ProgramData\TEMP:DC8E5CD4 [284] AlternateDataStreams: C:\ProgramData\TEMP:DD04902E [127] AlternateDataStreams: C:\ProgramData\TEMP:DDA730F9 [91] AlternateDataStreams: C:\ProgramData\TEMP:DDE3F219 [149] AlternateDataStreams: C:\ProgramData\TEMP:DDF112BD [276] AlternateDataStreams: C:\ProgramData\TEMP:DE007F2F [140] AlternateDataStreams: C:\ProgramData\TEMP:DEE38664 [146] AlternateDataStreams: C:\ProgramData\TEMP:DF5ABA3D [152] AlternateDataStreams: C:\ProgramData\TEMP:DFDBC05C [278] AlternateDataStreams: C:\ProgramData\TEMP:E18702AE [131] AlternateDataStreams: C:\ProgramData\TEMP:E2295807 [251] AlternateDataStreams: C:\ProgramData\TEMP:E31EDFDE [146] AlternateDataStreams: C:\ProgramData\TEMP:E3B0ACE0 [133] AlternateDataStreams: C:\ProgramData\TEMP:E3C06B97 [130] AlternateDataStreams: C:\ProgramData\TEMP:E446CB48 [122] AlternateDataStreams: C:\ProgramData\TEMP:E4996D81 [136] AlternateDataStreams: C:\ProgramData\TEMP:E4B4E556 [152] AlternateDataStreams: C:\ProgramData\TEMP:E4FD113F [296] AlternateDataStreams: C:\ProgramData\TEMP:E5AF754F [131] AlternateDataStreams: C:\ProgramData\TEMP:E6708F08 [117] AlternateDataStreams: C:\ProgramData\TEMP:E690114B [147] AlternateDataStreams: C:\ProgramData\TEMP:E71BB809 [298] AlternateDataStreams: C:\ProgramData\TEMP:E81603BC [145] AlternateDataStreams: C:\ProgramData\TEMP:E8AEB2BF [128] AlternateDataStreams: C:\ProgramData\TEMP:E94FA418 [286] AlternateDataStreams: C:\ProgramData\TEMP:E9C2F553 [268] AlternateDataStreams: C:\ProgramData\TEMP:EA2D3047 [141] AlternateDataStreams: C:\ProgramData\TEMP:EAF0C571 [137] AlternateDataStreams: C:\ProgramData\TEMP:EE2DD6CC [126] AlternateDataStreams: C:\ProgramData\TEMP:EF0BD3A1 [127] AlternateDataStreams: C:\ProgramData\TEMP:EF123AF6 [134] AlternateDataStreams: C:\ProgramData\TEMP:EF53A5CA [134] AlternateDataStreams: C:\ProgramData\TEMP:F074840B [136] AlternateDataStreams: C:\ProgramData\TEMP:F0F90DC6 [518] AlternateDataStreams: C:\ProgramData\TEMP:F1373816 [149] AlternateDataStreams: C:\ProgramData\TEMP:F176B6C6 [144] AlternateDataStreams: C:\ProgramData\TEMP:F2F0A8AC [138] AlternateDataStreams: C:\ProgramData\TEMP:F39A1A9B [129] AlternateDataStreams: C:\ProgramData\TEMP:F4B7CBB2 [152] AlternateDataStreams: C:\ProgramData\TEMP:F55F0EF6 [129] AlternateDataStreams: C:\ProgramData\TEMP:F5E90ED3 [454] AlternateDataStreams: C:\ProgramData\TEMP:F610C203 [129] AlternateDataStreams: C:\ProgramData\TEMP:F66F0A25 [143] AlternateDataStreams: C:\ProgramData\TEMP:F67808F2 [128] AlternateDataStreams: C:\ProgramData\TEMP:F6A712DD [132] AlternateDataStreams: C:\ProgramData\TEMP:F816645E [130] AlternateDataStreams: C:\ProgramData\TEMP:F83E8359 [125] AlternateDataStreams: C:\ProgramData\TEMP:F92E1E4B [122] AlternateDataStreams: C:\ProgramData\TEMP:FA66F86F [155] AlternateDataStreams: C:\ProgramData\TEMP:FAB64002 [144] AlternateDataStreams: C:\ProgramData\TEMP:FAFEC4B9 [114] AlternateDataStreams: C:\ProgramData\TEMP:FC97DEBC [148] AlternateDataStreams: C:\ProgramData\TEMP:FCECE156 [127] AlternateDataStreams: C:\ProgramData\TEMP:FD6D11C9 [128] AlternateDataStreams: C:\ProgramData\TEMP:FD8BCF62 [286] AlternateDataStreams: C:\ProgramData\TEMP:FDB03735 [136] AlternateDataStreams: C:\ProgramData\TEMP:FE61B3F6 [148] AlternateDataStreams: C:\ProgramData\TEMP:FF869361 [130] AlternateDataStreams: C:\Users\Public\Documents\desktop.ini:gs5sys [2048] AlternateDataStreams: C:\Users\S-O\Anwendungsdaten:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Cookies:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Lokale Einstellungen:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Vorlagen:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Desktop\desktop.ini:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\AppData\Local:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\AppData\Roaming:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\AppData\Local\Anwendungsdaten:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\AppData\Local\Verlauf:gs5sys [3074] AlternateDataStreams: C:\Users\S-O\Documents\desktop.ini:gs5sys [3074] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\webcompanion.com -> hxxp://webcompanion.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1001movie.com -> 1001movie.com IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\1001night.biz -> 1001night.biz IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\100gal.net -> 100gal.net IE restricted site: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\100sexlinks.com -> 100sexlinks.com Da befinden sich 4788 mehr Seiten. ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2016-04-28 11:14 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\S-O\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: LiveUpdateSvc => 2 MSCONFIG\Services: MBAMScheduler => 2 MSCONFIG\Services: MBAMService => 2 ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{8CB37AA2-4647-4254-A2ED-03A48ADABC3C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{B8A0DA5A-F4AF-4DF5-A575-F92F96A0385B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{8569C3D1-1154-40BE-80C8-F4D232B15F87}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{10C7D8E6-1113-4D0E-B6E8-8A43833FB6F8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{3A976A67-A5AB-4F20-8D7B-13FFBBFC4340}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3EB9616D-29DC-477E-A200-7771617E6A9D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{A6F913EE-5E14-4E38-9E99-0B2ED5B556A1}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{DDDE07BD-22DF-412B-A2F2-FAF4CA561A13}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{F3421429-9323-44E7-9E3C-856BA0F298CF}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe FirewallRules: [{1970EEB2-5F54-40DC-AC17-BAEF479C1A28}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe FirewallRules: [{6C11389D-2BFA-4CA4-A191-F9A140F518AF}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe FirewallRules: [{F44E652C-E4F2-4434-AE5B-5785CCD4B0FB}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe FirewallRules: [{A3913B88-96A2-4E26-93FE-592E84359157}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{5665F45E-A29B-496A-ABC8-38BF346156F7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{08484B7A-A9E2-410D-B566-381BB7C8C2F5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{B80A1368-F587-4600-A485-21F795B300AD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ==================== Wiederherstellungspunkte ========================= 27-04-2016 19:21:06 Windows Update ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (04/27/2016 07:05:07 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: EmerlandSolitaireEndlessJourney.exe, Version: 0.0.0.0, Zeitstempel: 0x56c33513 Name des fehlerhaften Moduls: EmerlandSolitaireEndlessJourney.exe, Version: 0.0.0.0, Zeitstempel: 0x56c33513 Ausnahmecode: 0xc0000417 Fehleroffset: 0x002020e3 ID des fehlerhaften Prozesses: 0x17f4 Startzeit der fehlerhaften Anwendung: 0xEmerlandSolitaireEndlessJourney.exe0 Pfad der fehlerhaften Anwendung: EmerlandSolitaireEndlessJourney.exe1 Pfad des fehlerhaften Moduls: EmerlandSolitaireEndlessJourney.exe2 Berichtskennung: EmerlandSolitaireEndlessJourney.exe3 Error: (04/27/2016 12:35:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: ) Description: Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -550. Error: (04/26/2016 05:26:31 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm CCleaner64.exe, Version 5.12.0.5431 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 98c Startzeit: 01d19f8cf7cbf600 Endzeit: 203 Anwendungspfad: C:\Program Files\CCleaner\CCleaner64.exe Berichts-ID: 3a6d59c1-0bc3-11e6-94b3-001d72a78854 Error: (04/26/2016 10:41:16 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: EmerlandSolitaireEndlessJourney.exe, Version: 0.0.0.0, Zeitstempel: 0x56c33513 Name des fehlerhaften Moduls: EmerlandSolitaireEndlessJourney.exe, Version: 0.0.0.0, Zeitstempel: 0x56c33513 Ausnahmecode: 0xc0000417 Fehleroffset: 0x002028f3 ID des fehlerhaften Prozesses: 0xb28 Startzeit der fehlerhaften Anwendung: 0xEmerlandSolitaireEndlessJourney.exe0 Pfad der fehlerhaften Anwendung: EmerlandSolitaireEndlessJourney.exe1 Pfad des fehlerhaften Moduls: EmerlandSolitaireEndlessJourney.exe2 Berichtskennung: EmerlandSolitaireEndlessJourney.exe3 Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 3058) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 3028) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (04/26/2016 05:54:47 AM) (Source: Windows Search Service) (EventID: 9002) (User: ) Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Systemfehler: ============= Error: (04/28/2016 04:00:40 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (04/28/2016 12:29:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "LiveUpdate" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/28/2016 12:29:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst LiveUpdate erreicht. Error: (04/28/2016 11:15:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/28/2016 11:15:59 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (04/28/2016 11:15:59 AM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error: (04/28/2016 11:15:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/28/2016 11:15:29 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (04/28/2016 11:15:29 AM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (04/28/2016 11:12:15 AM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. CodeIntegrity: =================================== Date: 2016-04-25 08:14:53.092 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-04-25 08:14:52.967 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Prozessor: Athlon(tm) Dual Core Processor 4450e Prozentuale Nutzung des RAM: 87% Installierter physikalischer RAM: 1534.55 MB Verfügbarer physikalischer RAM: 195.26 MB Summe virtueller Speicher: 3069.1 MB Verfügbarer virtueller Speicher: 1038.98 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:155.05 GB) (Free:78.39 GB) NTFS Drive d: (DATA) (Fixed) (Total:142.94 GB) (Free:52.34 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 27F6989C) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=155 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=142.9 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
28.04.2016, 17:21 | #30 |
| MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht [gelöst] FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016 durchgeführt von S-O (Administrator) auf S-O-PC (28-04-2016 15:59:36) Gestartet von C:\Users\S-O\Desktop Geladene Profile: S-O (Verfügbare Profile: S-O) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe (Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (IObit) C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe (Farbar) C:\Users\S-O\Desktop\FRST64(1).exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16418560 2016-04-19] (Realtek Semiconductor) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation) HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Policies\Explorer: [NoInternetOpenWith] 1 HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Keine Datei ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{FF12AB65-EFBE-4417-B33C-1A72AD66D239}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-3482151743-2939713798-2738295144-1000\Software\Microsoft\Internet Explorer\Main,Start Page = search.mpc.am/?geo=de SearchScopes: HKLM -> DefaultScope {0644EE93-D778-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000 -> DefaultScope {0644EE93-D778-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.mpc.am/index/search?q={searchTerms}&cx=partner-pub-3796753109442372:3837783968&ie=UTF-8 SearchScopes: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000 -> Yahoo URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=oberhp&type=iplaygamestoolbar SearchScopes: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000 -> {0644EE93-D778-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.mpc.am/index/search?q={searchTerms}&cx=partner-pub-3796753109442372:3837783968&ie=UTF-8 SearchScopes: HKU\S-1-5-21-3482151743-2939713798-2738295144-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation) DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095} FireFox: ======== FF ProfilePath: C:\Users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841 FF DefaultSearchEngine: Google FF Homepage: google.de FF Plugin-x32: @alawar.com/npapi -> C:\Windows\npapi.dll [2014-01-29] (Alawar) FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll [2012-05-31] (Oberon-Media ) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2016-04-01] () FF SearchPlugin: C:\Users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841\searchplugins\bing-lavasoft.xml [2016-04-27] FF Extension: LottaDeals - C:\Users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841\Extensions\@lottadealsun.xpi [2016-02-02] FF Extension: Primary Color 1.0.1 - C:\Users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841\Extensions\{54e9b4e5-84c4-42a5-a254-fd1f8319fc98}.xpi [2016-02-06] [ist nicht signiert] FF Extension: Adblock Plus - C:\Users\S-O\AppData\Roaming\Mozilla\Firefox\Profiles\kf5cpuj4.default-1449910348841\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-24] Chrome: ======= CHR Profile: C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Kein Name) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-05] CHR Extension: (Google Search) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-05] CHR Extension: (Startpage) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\mflpjdcmkggbacigfegaffogkkkkoiim [2014-11-17] CHR Extension: (Google Wallet) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-05] CHR Extension: (Gmail) - C:\Users\S-O\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-05] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [mflpjdcmkggbacigfegaffogkkkkoiim] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\S-O\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx <nicht gefunden> ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit) S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [Datei ist nicht signiert] S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [350064 2016-04-01] (WildTangent) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation) S3 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [581568 2014-03-27] (RealNetworks, Inc.) S3 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-01] (REALiX(tm)) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-28] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation) R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation) S3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [413912 2016-04-14] (Realsil Semiconductor Corporation) S3 StarOpen; kein ImagePath S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz134; \??\C:\Users\S-O\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 cpuz136; \??\C:\Users\S-O\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-28 15:59 - 2016-04-28 16:02 - 00013306 _____ C:\Users\S-O\Desktop\FRST.txt 2016-04-28 14:54 - 2016-04-28 15:56 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-04-28 14:53 - 2016-04-28 14:53 - 00001106 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2016-04-28 14:53 - 2016-04-28 14:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-04-28 14:52 - 2016-04-28 14:53 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-04-28 14:52 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-04-28 14:52 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-04-28 14:52 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-04-28 14:51 - 2016-04-28 14:51 - 22851472 _____ (Malwarebytes ) C:\Users\S-O\Downloads\mbam-setup-2.2.1.1043.exe 2016-04-28 12:55 - 2016-04-28 12:55 - 00002122 _____ C:\Users\Public\Desktop\Spiel Warlock - Der Fluch des Schamanen.lnk 2016-04-28 12:55 - 2016-04-28 12:55 - 00001296 _____ C:\Users\Public\Desktop\Weitere fantastische Spiele.lnk 2016-04-28 12:54 - 2016-04-28 12:55 - 00000000 ____D C:\Program Files (x86)\Warlock - Der Fluch des Schamanen 2016-04-28 12:54 - 2016-04-28 12:54 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warlock - Der Fluch des Schamanen 2016-04-28 12:54 - 2016-04-28 12:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warlock - Der Fluch des Schamanen 2016-04-28 11:34 - 2016-04-28 11:34 - 00001047 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk 2016-04-28 11:34 - 2016-04-28 11:34 - 00001035 _____ C:\Users\Public\Desktop\TeamViewer 11.lnk 2016-04-28 11:34 - 2016-04-28 11:34 - 00000000 ____D C:\Users\S-O\AppData\Roaming\TeamViewer 2016-04-28 11:33 - 2016-04-28 15:53 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-04-28 11:32 - 2016-04-28 11:33 - 09786224 _____ (TeamViewer GmbH) C:\Users\S-O\Downloads\TeamViewer_Setup_de.exe 2016-04-28 11:28 - 2016-04-28 06:56 - 00000743 _____ C:\Users\S-O\Desktop\ComboFix NSIS Installer (2).lnk 2016-04-28 11:25 - 2016-04-28 11:25 - 00025521 _____ C:\ComboFix.txt 2016-04-28 11:11 - 2016-04-27 06:51 - 00025411 _____ C:\Users\S-O\Desktop\cfscript.txt 2016-04-28 10:43 - 2016-04-26 17:24 - 05660058 ____R (Swearware) C:\Users\S-O\Desktop\ComboFix.exe 2016-04-28 08:03 - 2016-04-28 08:03 - 00001350 _____ C:\Users\Public\Desktop\More Great Games.lnk 2016-04-28 07:06 - 2016-04-28 07:06 - 00002286 _____ C:\Users\Public\Desktop\Spiel Mystery Tales - Durch ihre Augen Sammleredition.lnk 2016-04-28 06:55 - 2016-04-28 07:06 - 00000000 ____D C:\Program Files (x86)\Mystery Tales - Durch ihre Augen Sammleredition 2016-04-28 06:55 - 2016-04-28 06:55 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mystery Tales - Durch ihre Augen Sammleredition 2016-04-28 06:55 - 2016-04-28 06:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mystery Tales - Durch ihre Augen Sammleredition 2016-04-28 06:41 - 2016-04-28 06:42 - 00237568 _____ (Big Fish Games) C:\Users\S-O\Downloads\mystery-tales-her-own-eyes-collectors-edition_s2_l2_gF11386T1L2_d2600150040.exe 2016-04-27 14:31 - 2016-04-27 14:31 - 00000000 ____D C:\ProgramData\REXARD 2016-04-26 18:15 - 2016-04-27 06:51 - 00025411 _____ C:\Users\S-O\Downloads\cfscript.txt 2016-04-26 17:23 - 2016-04-26 17:24 - 05660058 ____R (Swearware) C:\Users\S-O\Downloads\ComboFix.exe 2016-04-25 15:27 - 2016-04-26 05:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-04-25 12:23 - 2016-04-25 18:07 - 00000000 ____D C:\ProgramData\Trymedia 2016-04-25 08:53 - 2016-04-28 11:37 - 00003234 _____ C:\Windows\System32\Tasks\SidebarExecute 2016-04-25 07:28 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2016-04-25 07:28 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2016-04-25 07:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2016-04-25 07:28 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2016-04-25 07:25 - 2016-04-28 11:25 - 00000000 ____D C:\Qoobox 2016-04-25 07:17 - 2016-04-28 07:20 - 00000000 ____D C:\Windows\erdnt 2016-04-25 07:14 - 2016-04-28 14:14 - 00002896 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_S-O 2016-04-23 09:39 - 2016-04-23 09:39 - 00002108 _____ C:\Users\Public\Desktop\Spiel Around the World in 80 Days.lnk 2016-04-23 09:39 - 2016-04-23 09:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Around the World in 80 Days 2016-04-23 09:37 - 2016-04-23 09:39 - 00000000 ____D C:\Program Files (x86)\Around the World in 80 Days 2016-04-23 08:43 - 2016-04-23 08:56 - 00004681 _____ C:\mbam.txt 2016-04-23 07:49 - 2016-04-23 08:48 - 00000000 ____D C:\AdwCleaner 2016-04-22 15:09 - 2016-04-22 15:09 - 00000000 __SHD C:\Windows\ftpcache 2016-04-22 10:06 - 2016-04-22 10:06 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2016-04-22 10:06 - 2016-04-22 10:06 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2016-04-22 10:06 - 2016-04-22 10:06 - 00351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2016-04-22 10:06 - 2016-04-22 10:06 - 00316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2016-04-22 10:04 - 2016-04-22 10:04 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2016-04-22 10:04 - 2016-04-22 10:04 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2016-04-21 08:36 - 2016-04-21 08:44 - 00000255 _____ C:\Users\S-O\Downloads\Search.txt 2016-04-21 07:38 - 2016-04-21 07:38 - 00002694 ____N C:\Users\Public\Desktop\WildTangent Games App - wildgames.lnk 2016-04-21 07:38 - 2016-04-21 07:38 - 00000000 ____D C:\ProgramData\BlueStacks 2016-04-20 06:45 - 2016-04-20 06:45 - 02375680 _____ (Farbar) C:\Users\S-O\Desktop\FRST64(1).exe 2016-04-19 18:16 - 2016-04-19 18:16 - 04803840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2016-04-19 18:16 - 2016-04-19 18:16 - 03299832 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE2.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 03283248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 03198720 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 02894976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2016-04-19 18:16 - 2016-04-19 18:16 - 02190992 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 02110600 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01943624 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01435152 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01382240 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01330072 _____ (DTS, Inc.) C:\Windows\system32\slcnt64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 01022872 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00965032 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00927424 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00888480 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaeapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00873472 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00716104 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00689888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00596120 _____ (TOSHIBA Corporation) C:\Windows\system32\tosasfapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00589080 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SECOMN32.DLL 2016-04-19 18:16 - 2016-04-19 18:16 - 00532384 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00467168 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00450128 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00387320 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00381416 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00343712 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00341160 _____ (Synopsys, Inc.) C:\Windows\SysWOW64\SRCOM.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00341160 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00258504 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00231920 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00224264 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaemaxapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00221976 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00214840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00209536 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00192992 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00172584 _____ (TOSHIBA Corporation) C:\Windows\system32\toseaeapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00166208 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00158704 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00110984 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00090920 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00088352 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00088328 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00075544 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll 2016-04-19 18:16 - 2016-04-19 18:16 - 00023704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 72203792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2016-04-19 18:15 - 2016-04-19 18:15 - 14057256 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 13120760 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 12986528 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO4064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 10521552 _____ (Intel Corporation) C:\Windows\system32\IntelSSTAPO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 07172920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 07096192 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 06343320 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV3apo.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 06264640 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64AF3.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 05777704 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 05576400 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2016-04-19 18:15 - 2016-04-19 18:15 - 05338936 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 05289952 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 03282032 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 03081808 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02823280 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO7064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02714568 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RltkAPO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02437144 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02050184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 02049664 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01965816 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01959608 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64AF3.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01780624 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01601952 _____ (Conexant Systems Inc.) C:\Windows\system32\CX64APO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01591064 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01508936 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01421104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01356512 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01334384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01211840 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01186168 _____ (Intel Corporation) C:\Windows\system32\IntelSstCApoPropPage.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01164336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01060504 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 01003864 _____ (Nahimic Inc) C:\Windows\system32\NahimicAPONSControl.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00998032 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00931624 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00923752 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00743968 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00727440 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00708320 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00678192 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00677680 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00618192 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00514528 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00504312 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00500560 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00471336 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00447720 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00445408 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00441272 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00428232 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00416512 _____ (Harman) C:\Windows\system32\HMUI.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00370840 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00366128 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\HMAPO.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00362056 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64AF3.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00360352 _____ (Harman) C:\Windows\system32\HMClariFi.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00330568 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00327464 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00310424 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64F3.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00272720 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00253904 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00253872 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00252880 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00203848 _____ (Harman) C:\Windows\system32\HMHVS.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00190944 _____ (Harman) C:\Windows\system32\HMEQ_Voice.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00190944 _____ (Harman) C:\Windows\system32\HMEQ.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00179608 _____ (Harman) C:\Windows\system32\HMLimiter.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00151792 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00134208 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00122328 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00105312 _____ C:\Windows\system32\audioLibVc.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00084624 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll 2016-04-19 18:15 - 2016-04-19 18:15 - 00065792 _____ (Harman) C:\Windows\system32\HarmanAudioInterface.dll 2016-04-19 18:14 - 2016-04-19 18:14 - 00574760 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2016-04-19 18:14 - 2016-04-19 18:14 - 00118600 _____ C:\Windows\system32\AcpiServiceVnA64.dll 2016-04-19 18:14 - 2016-04-19 18:14 - 00118600 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2016-04-18 15:14 - 2016-04-18 15:14 - 00000000 ____D C:\Users\S-O\Documents\The Lonely Hearts Murders SE 2016-04-18 06:56 - 2016-04-26 18:24 - 00057104 _____ C:\Users\S-O\Downloads\Addition.txt 2016-04-18 06:41 - 2016-04-26 18:24 - 00070301 _____ C:\Users\S-O\Downloads\FRST.txt 2016-04-18 06:39 - 2016-04-28 15:59 - 00000000 ____D C:\FRST 2016-04-18 06:38 - 2016-04-18 06:38 - 02375680 _____ (Farbar) C:\Users\S-O\Downloads\FRST64.exe 2016-04-15 15:37 - 2016-04-15 15:37 - 00000000 ____D C:\ProgramData\blg 2016-04-14 17:40 - 2016-04-14 17:40 - 31523896 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 24207296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 23000000 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 17559240 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 16128576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 15302712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 13916600 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 13828032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 12911160 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2016-04-14 17:40 - 2016-04-14 17:40 - 11272240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 11209376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 04252608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 03996216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 03210784 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 02825016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 01908272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434195.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 01557552 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434195.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 00952256 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 00915392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 00911928 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2016-04-14 17:40 - 2016-04-14 17:40 - 00878648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2016-04-14 17:38 - 2016-04-14 17:38 - 04330200 _____ (TODO: <Company name>) C:\Windows\RtCRU64.exe 2016-04-14 17:38 - 2016-04-14 17:38 - 00413912 _____ (Realsil Semiconductor Corporation) C:\Windows\system32\Drivers\RtsUer.sys 2016-04-13 09:48 - 2016-03-18 01:04 - 05551336 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-04-13 09:48 - 2016-03-18 01:04 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2016-04-13 09:48 - 2016-03-18 01:04 - 00154344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-04-13 09:48 - 2016-03-18 01:04 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-04-13 09:48 - 2016-03-18 01:01 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-04-13 09:48 - 2016-03-18 01:01 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2016-04-13 09:48 - 2016-03-18 00:58 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-04-13 09:48 - 2016-03-18 00:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2016-04-13 09:48 - 2016-03-18 00:57 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-04-13 09:48 - 2016-03-18 00:56 - 02084864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2016-04-13 09:48 - 2016-03-18 00:56 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2016-04-13 09:48 - 2016-03-18 00:54 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-04-13 09:48 - 2016-03-18 00:54 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-04-13 09:48 - 2016-03-18 00:54 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-04-13 09:48 - 2016-03-18 00:54 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-04-13 09:48 - 2016-03-18 00:53 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-04-13 09:48 - 2016-03-18 00:53 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-04-13 09:48 - 2016-03-18 00:53 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-04-13 09:48 - 2016-03-18 00:53 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-04-13 09:48 - 2016-03-18 00:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-04-13 09:48 - 2016-03-18 00:33 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-04-13 09:48 - 2016-03-18 00:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-04-13 09:48 - 2016-03-18 00:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-04-13 09:48 - 2016-03-18 00:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-04-13 09:48 - 2016-03-18 00:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-04-13 09:48 - 2016-03-18 00:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-04-13 09:48 - 2016-03-18 00:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2016-04-13 09:48 - 2016-03-18 00:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-04-13 09:48 - 2016-03-18 00:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2016-04-13 09:48 - 2016-03-18 00:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-04-13 09:48 - 2016-03-18 00:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-04-13 09:48 - 2016-03-18 00:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-04-13 09:48 - 2016-03-18 00:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-04-13 09:48 - 2016-03-18 00:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-04-13 09:48 - 2016-03-18 00:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-04-13 09:48 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-04-13 09:48 - 2016-03-17 23:53 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2016-04-13 09:48 - 2016-03-17 23:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2016-04-13 09:48 - 2016-03-17 23:52 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2016-04-13 09:48 - 2016-03-17 23:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-04-13 09:48 - 2016-03-17 23:44 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-04-13 09:48 - 2016-03-17 23:43 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-04-13 09:48 - 2016-03-17 23:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-04-13 09:48 - 2016-03-17 23:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-04-13 09:48 - 2016-03-17 23:37 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-04-13 09:48 - 2016-03-17 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-04-13 09:48 - 2016-03-17 23:35 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-04-13 09:48 - 2016-03-17 23:35 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-04-13 09:48 - 2016-03-17 23:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-04-13 09:48 - 2016-03-17 23:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-04-13 09:48 - 2016-03-17 23:30 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-04-13 09:48 - 2016-03-17 23:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-04-13 09:48 - 2016-03-17 23:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-04-13 09:48 - 2016-03-17 23:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-04-13 09:48 - 2016-03-17 23:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-04-13 09:48 - 2016-03-17 23:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-04-13 09:48 - 2016-03-17 23:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-04-13 09:47 - 2016-03-16 20:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2016-04-13 09:47 - 2016-03-16 20:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2016-04-13 09:47 - 2016-03-16 20:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2016-04-13 09:47 - 2016-03-06 20:53 - 01885696 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2016-04-13 09:47 - 2016-03-06 20:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2016-04-13 09:47 - 2016-03-06 20:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2016-04-13 09:47 - 2016-03-06 20:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2016-04-13 09:46 - 2016-04-04 20:14 - 00038120 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-04-13 09:46 - 2016-04-04 20:02 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-04-13 09:46 - 2016-04-02 15:08 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-04-13 09:46 - 2016-03-29 19:53 - 03216896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-04-13 09:46 - 2016-03-23 16:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2016-04-13 09:46 - 2016-03-17 20:04 - 00698368 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-04-13 09:46 - 2016-03-17 20:04 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-04-13 09:46 - 2016-03-17 20:04 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-04-13 09:46 - 2016-03-17 20:04 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-04-13 09:46 - 2016-03-16 02:16 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2016-04-13 09:46 - 2016-03-16 02:16 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2016-04-13 09:46 - 2016-03-16 01:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2016-04-13 09:46 - 2016-03-11 20:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2016-04-13 09:46 - 2016-03-11 20:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2016-04-13 09:45 - 2016-03-31 21:25 - 00394952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-04-13 09:45 - 2016-03-31 20:41 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-04-13 09:45 - 2016-03-31 02:54 - 25817600 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-04-13 09:45 - 2016-03-31 02:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2016-04-13 09:45 - 2016-03-31 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2016-04-13 09:45 - 2016-03-31 02:31 - 02892800 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-04-13 09:45 - 2016-03-31 02:28 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-04-13 09:45 - 2016-03-31 02:28 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2016-04-13 09:45 - 2016-03-31 02:27 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2016-04-13 09:45 - 2016-03-31 02:27 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2016-04-13 09:45 - 2016-03-31 02:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2016-04-13 09:45 - 2016-03-31 02:25 - 06052352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-04-13 09:45 - 2016-03-31 02:22 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2016-04-13 09:45 - 2016-03-31 02:21 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2016-04-13 09:45 - 2016-03-31 02:19 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-04-13 09:45 - 2016-03-31 02:17 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-04-13 09:45 - 2016-03-31 02:17 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2016-04-13 09:45 - 2016-03-31 02:17 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2016-04-13 09:45 - 2016-03-31 02:17 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2016-04-13 09:45 - 2016-03-31 02:11 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2016-04-13 09:45 - 2016-03-31 02:08 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2016-04-13 09:45 - 2016-03-31 02:03 - 20352512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-04-13 09:45 - 2016-03-31 02:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2016-04-13 09:45 - 2016-03-31 02:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-04-13 09:45 - 2016-03-31 01:59 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2016-04-13 09:45 - 2016-03-31 01:57 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2016-04-13 09:45 - 2016-03-31 01:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-04-13 09:45 - 2016-03-31 01:55 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-04-13 09:45 - 2016-03-31 01:53 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-04-13 09:45 - 2016-03-31 01:53 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2016-04-13 09:45 - 2016-03-31 01:52 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2016-04-13 09:45 - 2016-03-31 01:52 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-04-13 09:45 - 2016-03-31 01:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2016-04-13 09:45 - 2016-03-31 01:52 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2016-04-13 09:45 - 2016-03-31 01:51 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-04-13 09:45 - 2016-03-31 01:48 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2016-04-13 09:45 - 2016-03-31 01:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2016-04-13 09:45 - 2016-03-31 01:46 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-04-13 09:45 - 2016-03-31 01:45 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-04-13 09:45 - 2016-03-31 01:45 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2016-04-13 09:45 - 2016-03-31 01:45 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-04-13 09:45 - 2016-03-31 01:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2016-04-13 09:45 - 2016-03-31 01:43 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-04-13 09:45 - 2016-03-31 01:43 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-04-13 09:45 - 2016-03-31 01:42 - 02131968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-04-13 09:45 - 2016-03-31 01:42 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2016-04-13 09:45 - 2016-03-31 01:39 - 15415808 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-04-13 09:45 - 2016-03-31 01:38 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2016-04-13 09:45 - 2016-03-31 01:34 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-04-13 09:45 - 2016-03-31 01:33 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2016-04-13 09:45 - 2016-03-31 01:31 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2016-04-13 09:45 - 2016-03-31 01:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2016-04-13 09:45 - 2016-03-31 01:30 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-04-13 09:45 - 2016-03-31 01:30 - 02596864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-04-13 09:45 - 2016-03-31 01:30 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-04-13 09:45 - 2016-03-31 01:29 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2016-04-13 09:45 - 2016-03-31 01:24 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-04-13 09:45 - 2016-03-31 01:23 - 02056192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-04-13 09:45 - 2016-03-31 01:23 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-04-13 09:45 - 2016-03-31 01:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2016-04-13 09:45 - 2016-03-31 01:21 - 13811712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-04-13 09:45 - 2016-03-31 01:18 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-04-13 09:45 - 2016-03-31 01:06 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-04-13 09:45 - 2016-03-31 01:05 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-04-13 09:45 - 2016-03-31 01:02 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-04-13 09:45 - 2016-03-31 01:00 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-04-12 15:21 - 2016-04-12 15:21 - 00000000 ____D C:\ProgramData\LittleGamesCompany 2016-04-12 14:05 - 2016-04-12 14:07 - 00000000 ____D C:\ProgramData\TheFallTrilogyEp3 2016-04-10 13:20 - 2016-04-11 06:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2016-04-09 07:52 - 2016-04-09 07:52 - 00000000 ____D C:\Users\S-O\Documents\My Games 2016-03-30 16:17 - 2016-03-30 16:17 - 00000000 ____D C:\Users\S-O\AppData\LocalLow\phime studio 2016-03-30 07:28 - 2016-03-30 07:28 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-28 16:00 - 2015-11-24 22:53 - 00003234 _____ C:\Windows\System32\Tasks\Driver Booster Scheduler 2016-04-28 16:00 - 2014-11-13 17:36 - 00002866 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (S-O) 2016-04-28 15:55 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-04-28 14:52 - 2015-11-20 19:23 - 00000000 ____D C:\ProgramData\TEMP 2016-04-28 14:27 - 2014-06-30 09:44 - 00000000 ____D C:\Users\S-O\AppData\Roaming\DominiGames 2016-04-28 14:16 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2016-04-28 13:13 - 2014-07-19 08:14 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Elephant Games 2016-04-28 12:38 - 2014-06-26 08:04 - 00000000 ____D C:\BigFishCache 2016-04-28 12:38 - 2009-07-14 06:45 - 00015136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-04-28 12:38 - 2009-07-14 06:45 - 00015136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-04-28 12:29 - 2009-07-14 06:45 - 00302736 _____ C:\Windows\system32\FNTCACHE.DAT 2016-04-28 12:11 - 2016-02-17 20:07 - 00002260 _____ C:\Users\Public\Desktop\Advanced SystemCare 9.lnk 2016-04-28 11:48 - 2016-03-03 12:37 - 00067456 _____ C:\Users\S-O\AppData\Local\GDIPFONTCACHEV1.DAT 2016-04-28 11:14 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2016-04-28 08:41 - 2014-07-26 16:53 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Mariaglorum 2016-04-28 07:20 - 2016-03-26 18:06 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2016-04-28 07:20 - 2015-11-12 06:52 - 00000000 ___SD C:\Windows\system32\GWX 2016-04-28 07:20 - 2015-09-02 11:30 - 00000000 ____D C:\ProgramData\ProductData 2016-04-28 07:20 - 2014-11-13 17:40 - 00000000 ____D C:\Users\S-O\AppData\Roaming\ProductData 2016-04-28 07:20 - 2014-11-13 17:36 - 00000000 ____D C:\Users\S-O\AppData\Roaming\IObit 2016-04-28 07:20 - 2014-11-13 17:36 - 00000000 ____D C:\ProgramData\IObit 2016-04-28 07:20 - 2014-08-17 17:56 - 00000000 ____D C:\Users\S-O\AppData\Local\com.gamehouse.acid 2016-04-28 07:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2016-04-28 06:21 - 2014-06-25 11:29 - 00000000 ____D C:\Users\S-O 2016-04-27 18:36 - 2016-03-16 11:47 - 00000000 ____D C:\Program Files (x86)\ToomkyGames.com 2016-04-27 18:33 - 2016-03-26 18:07 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Lavasoft 2016-04-27 16:44 - 2016-03-26 18:08 - 00000000 ____D C:\searchplugins 2016-04-27 16:41 - 2016-03-26 18:06 - 00000000 ____D C:\ProgramData\Lavasoft 2016-04-26 17:19 - 2014-11-21 15:13 - 00013214 _____ C:\Users\S-O\Documents\Lottogeld Gerhilde.ods 2016-04-26 05:53 - 2014-06-25 11:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-04-25 18:09 - 2014-12-25 19:06 - 00000000 ____D C:\Zylom Games 2016-04-25 18:09 - 2014-06-26 17:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zylom 2016-04-25 17:36 - 2016-03-12 18:27 - 00000000 ____D C:\Program Files (x86)\Alawar.de 2016-04-25 17:27 - 2016-02-05 11:31 - 00000000 ____D C:\ProgramData\AlawarWrapper 2016-04-25 16:15 - 2014-07-09 11:42 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Natural Threat.Ominous Shores 2016-04-25 11:20 - 2014-07-12 07:16 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Eipix 2016-04-25 10:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2016-04-23 13:14 - 2014-09-11 12:18 - 00000000 ____D C:\ProgramData\WildTangent 2016-04-23 07:06 - 2016-02-08 14:19 - 00000000 ____D C:\Program Files (x86)\OXXOGames 2016-04-22 19:01 - 2016-02-12 11:41 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT 2016-04-22 19:01 - 2016-01-08 18:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT 2016-04-22 19:00 - 2016-02-08 14:19 - 00000000 ____D C:\Program Files (x86)\DEUTSCHLAND SPIELT 2016-04-22 11:39 - 2014-06-27 10:05 - 00000000 ____D C:\Users\S-O\AppData\Roaming\ERS Game Studios 2016-04-22 09:57 - 2014-06-25 12:50 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-04-21 07:38 - 2014-09-11 12:18 - 00000000 ____D C:\Users\S-O\AppData\Roaming\WildTangent 2016-04-21 07:38 - 2014-09-11 12:18 - 00000000 ____D C:\Program Files (x86)\WildTangent Games 2016-04-19 18:21 - 2015-11-24 22:53 - 00002168 _____ C:\Users\Public\Desktop\Driver Booster 3.lnk 2016-04-19 18:20 - 2015-07-17 10:41 - 00000000 ____D C:\Windows\system32\DAX2 2016-04-19 18:18 - 2014-11-13 18:06 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2016-04-19 12:15 - 2014-07-12 08:09 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Mad Head Games 2016-04-19 06:49 - 2014-08-17 17:58 - 00000000 ____D C:\Users\S-O\AppData\Roaming\rokapublish 2016-04-18 13:50 - 2014-07-19 17:42 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Gogii 2016-04-17 12:52 - 2014-12-25 12:27 - 00000000 ____D C:\Users\S-O\AppData\Roaming\FGS 2016-04-16 17:05 - 2015-11-27 17:51 - 00000000 ____D C:\ProgramData\Alawar Stargaze 2016-04-16 16:02 - 2016-02-25 14:58 - 00000000 ____D C:\ProgramData\Floodlight Games 2016-04-16 15:22 - 2014-10-27 18:19 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Casual Arts 2016-04-16 13:31 - 2016-02-01 09:27 - 00000000 ____D C:\ProgramData\MumboJumbo 2016-04-16 05:47 - 2009-07-14 19:58 - 00707430 _____ C:\Windows\system32\perfh007.dat 2016-04-16 05:47 - 2009-07-14 19:58 - 00152492 _____ C:\Windows\system32\perfc007.dat 2016-04-16 05:47 - 2009-07-14 07:13 - 01678350 _____ C:\Windows\system32\PerfStringBackup.INI 2016-04-15 11:55 - 2014-12-13 12:39 - 00000000 ____D C:\Users\S-O\AppData\Roaming\JoyBits 2016-04-14 17:46 - 2016-01-22 15:55 - 00000000 ____D C:\Temp 2016-04-14 17:46 - 2014-11-13 18:13 - 00000000 ____D C:\ProgramData\NVIDIA 2016-04-14 17:45 - 2014-11-13 18:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-04-14 17:40 - 2015-12-22 10:09 - 14497568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2016-04-14 17:40 - 2014-11-13 18:11 - 00026157 _____ C:\Windows\system32\nvinfo.pb 2016-04-14 17:40 - 2009-07-13 23:59 - 18634264 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2016-04-14 06:01 - 2015-11-12 06:52 - 00000000 ____D C:\Windows\system32\appraiser 2016-04-10 17:26 - 2015-11-27 14:09 - 00000000 ____D C:\ProgramData\DailyMagic 2016-04-10 17:26 - 2014-07-16 08:06 - 00000000 ____D C:\Users\S-O\AppData\Roaming\DailyMagic 2016-04-10 07:50 - 2014-06-25 14:28 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-04-09 15:35 - 2014-07-02 06:57 - 00000000 ____D C:\Users\S-O\AppData\Roaming\AlawarEntertainment 2016-04-06 17:56 - 2014-07-08 09:43 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Brave Giant 2016-04-06 12:09 - 2015-10-23 15:03 - 00000000 ____D C:\ProgramData\Playrix Entertainment 2016-04-05 15:17 - 2016-03-10 16:21 - 00000000 ____D C:\ProgramData\Cateia Games 2016-04-04 17:02 - 2014-09-28 12:37 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Friday's games 2016-04-02 15:36 - 2014-08-26 17:54 - 00000000 ____D C:\Users\S-O\AppData\Roaming\GrandMA Studios 2016-03-30 14:50 - 2015-12-16 13:09 - 00000000 ____D C:\ProgramData\Elephant Games 2016-03-30 10:43 - 2014-08-31 09:27 - 00000000 ___RD C:\Users\S-O\Documents\Scanned Documents 2016-03-29 15:53 - 2014-07-29 12:15 - 00000000 ____D C:\Users\S-O\AppData\Roaming\Alawar Entertainment 2016-03-29 14:15 - 2016-02-21 15:52 - 00000000 ____D C:\ProgramData\Meridian93 ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-02-06 10:01 - 2016-02-06 10:01 - 0003072 _____ () C:\Users\S-O\AppData\Roaming\.spark_db 2015-09-23 14:07 - 2015-09-23 15:07 - 0579338 _____ () C:\Users\S-O\AppData\Roaming\log.sflog 2016-03-30 06:52 - 2016-03-30 07:03 - 0000115 _____ () C:\Users\S-O\AppData\Roaming\LogFile.txt 2015-04-06 13:26 - 2015-04-06 13:26 - 0000239 _____ () C:\Users\S-O\AppData\Roaming\prefsdb.dat 2015-03-11 13:28 - 2015-03-16 18:20 - 0001156 _____ () C:\Users\S-O\AppData\Roaming\rrr.xml 2015-01-01 18:27 - 2015-03-16 18:47 - 0005056 _____ () C:\Users\S-O\AppData\Roaming\tt.xml 2015-01-01 18:21 - 2015-03-16 18:47 - 0001069 _____ () C:\Users\S-O\AppData\Roaming\users.xml 2014-06-28 15:30 - 2014-06-28 15:30 - 0033193 _____ () C:\Users\S-O\AppData\Roaming\UserTile.png 2016-03-09 10:32 - 2016-03-09 11:32 - 167257409 _____ () C:\Users\S-O\AppData\Roaming\VGEngineDX.log 2016-02-21 13:31 - 2016-02-21 13:31 - 0003072 _____ () C:\Users\S-O\AppData\Local\file__0.localstorage 2016-02-21 13:31 - 2016-02-21 13:31 - 0003072 _____ () C:\Users\S-O\AppData\Local\https_drm.youdagames.com_0.localstorage 2015-01-26 18:08 - 2015-01-26 18:50 - 0006700 _____ () C:\Users\S-O\AppData\Local\slot1.mm1 2016-03-17 13:49 - 2016-03-17 13:51 - 0003896 _____ () C:\ProgramData\doicrane_save.log 2014-11-13 18:07 - 2014-11-13 18:07 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-04-18 11:52 ==================== Ende von FRST.txt ============================ Hallo Raphael, ich danke dir von ganzem Herzen für deine bisherige Hilfe. Weißt du ich bin mitlerweile 65 Jahre alt und kann natürlich nicht in den Dimensionen denken wie du. Nach Beendigung unserer Arbeit möchte ich Dir auch eine kleine Spende zukommen lassen, bitte teile mir mit wie. Ich hoffe, wenn ich mal wieder ein Problem habe kann ich mich wieder an dich wenden. Einen schönen Abend noch und nochmals vielen Dank. Mein bürgerlicher Name ist Silvia und diese grüßt dich. |
Themen zu MPC Cleaner hat sich einfach manifestiert, wie bekomme ich ihn weg, löschen geht nicht |
cleaner, deinstallation, einfach, einiger, entferne, entfernen, geht nicht, gen, installer, iobit, löschen, meinem, melde, melden, mpc cleaner, neustart, nicht, nicht löschen, programme, uninstaller, versuch, versucht |