|
Log-Analyse und Auswertung: Malwarefund Win32/Herz.BWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
18.11.2016, 13:17 | #1 | |
| Malwarefund Win32/Herz.B Hallo liebe Boarder Gestern meldete mir AVG einen Malwarefund Zitat:
http://www.trojaner-board.de/182238-...infektion.html Ich habe die betreffende Datei in Quarantäne geschoben - bin aber unsicher, ob das reicht. Ich habe Farbar's Recovery Scan Tool (FRST) durchlaufen lassen Es wäre nett, wenn Ihr Euch die Logs ansehen könnt und weitere Schritte vorschlagt. liebe Grüße + Vielen Dank schon mal Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 16-11-2016 durchgeführt von UK (Administrator) auf LAPTOP (18-11-2016 11:32:18) Gestartet von D:\Downloads\malware apps Geladene Profile: UK & Administrator (Verfügbare Profile: UK & Administrator) Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: "C:\Program Files (x86)\SeaMonkey\seamonkey.exe" -requestPending -osint -url "%1") Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe (NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe (Intel Corporation) C:\WINDOWS\System32\igfxCUIService.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\ProgramData\Avg_Update_1116av\AVG-Secure-Search-Update_1116av.exe () C:\ProgramData\Avg_Update_1116sp\AVG-Secure-Search-Update_1116sp.exe (Intel Corporation) C:\WINDOWS\System32\igfxEM.exe (Intel Corporation) C:\WINDOWS\System32\igfxHK.exe (Intel Corporation) C:\WINDOWS\System32\igfxTray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Wistron) C:\Program Files (x86)\Launch Manager\HotkeyApp.exe (Wistron Corp.) C:\Program Files (x86)\Launch Manager\OSD.exe (Wistron Corp.) C:\Program Files (x86)\Launch Manager\WButton.exe (Wistron Corp.) C:\Program Files (x86)\Launch Manager\WisLMSvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe () C:\ProgramData\Avg_Update_1116av\AVG-Secure-Search-Update_1116av.exe () C:\ProgramData\Avg_Update_1116sp\AVG-Secure-Search-Update_1116sp.exe (mozilla.org) C:\Program Files (x86)\SeaMonkey\seamonkey.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe (Microsoft Corporation) C:\WINDOWS\System32\InstallAgent.exe (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\Pub\PubMonitor.exe (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe (Microsoft Corporation) C:\WINDOWS\System32\SettingSyncHost.exe (Microsoft Corporation) C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe (Microsoft Corporation) C:\WINDOWS\splwow64.exe (FreeDownloadManager.ORG) C:\Program Files (x86)\Free Download Manager\fdm.exe (Microsoft Corporation) C:\WINDOWS\System32\WWAHost.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3951280 2016-01-07] (Synaptics Incorporated) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1795912 2015-07-23] (NVIDIA Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16475392 2016-11-06] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-11-06] (Realtek Semiconductor) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [258576 2012-11-05] (CyberLink Corp.) HKLM-x32\...\Run: [HotkeyApp] => C:\Program Files (x86)\Launch Manager\HotkeyApp.exe [320824 2012-08-16] (Wistron) HKLM-x32\...\Run: [LMgrVolOSD] => C:\Program Files (x86)\Launch Manager\OSD.exe [348960 2012-08-13] (Wistron Corp.) HKLM-x32\...\Run: [Wbutton] => C:\Program Files (x86)\Launch Manager\Wbutton.exe [388408 2012-08-13] (Wistron Corp.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Reader Application Helper] => C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2014-10-24] (Sony Corporation) HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [218896 2016-09-13] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [218896 2016-09-13] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [KMConfig] => "C:\Program Files (x86)\Multimedia Mouse Driver\V5\StartAutorun.exe" KMConfig.exe HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [6006560 2016-11-01] (IObit) HKLM Group Policy restriction on software: %appdata%\*.exe <====== ACHTUNG HKLM Group Policy restriction on software: %appdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ACHTUNG Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Run: [Dropbox Update] => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.) HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [176904 2015-07-23] (NVIDIA Corporation) AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [176904 2015-07-23] (NVIDIA Corporation) ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\FileSyncShell64.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\FileSyncShell64.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\FileSyncShell64.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Keine Datei ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileSyncShell.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileSyncShell.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileSyncShell.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt.3.0.dll [2016-11-07] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2014-08-19] ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-10-07] ShortcutTarget: Dropbox.lnk -> C:\Users\u\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) GroupPolicy: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{4344fcb4-282c-4464-86a8-73e16d20d65e}: [DhcpNameServer] 172.168.162.2 Tcpip\..\Interfaces\{4eeae347-f1dc-4b6d-9bfc-fec9118835a7}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2736805842-114790362-3470889979-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com HKU\S-1-5-21-2736805842-114790362-3470889979-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com SearchScopes: HKLM-x32 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKU\S-1-5-21-2736805842-114790362-3470889979-1002 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={AC253DE7-6601-433F-BA91-16375F6660FA}&mid=2ae03b1695df47d29d5bb17f9b50f6b7-05990095de2fd0dcb2ffe05a504540b90c1928bc&lang=de&ds=AVG&coid=avgtbavg&cmpid=0316tb&pr=fr&d=2016-03-12 13:58:07&v=4.2.8.608&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-2736805842-114790362-3470889979-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2736805842-114790362-3470889979-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear SearchScopes: HKU\S-1-5-21-2736805842-114790362-3470889979-1002 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={AC253DE7-6601-433F-BA91-16375F6660FA}&mid=2ae03b1695df47d29d5bb17f9b50f6b7-05990095de2fd0dcb2ffe05a504540b90c1928bc&lang=de&ds=AVG&coid=avgtbavg&cmpid=0316tb&pr=fr&d=2016-03-12 13:58:07&v=4.2.8.608&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-2736805842-114790362-3470889979-1002 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-10-22] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-10-22] (Oracle Corporation) BHO-x32: IObit Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2016-08-03] (IObit) BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2013-03-11] (FreeDownloadManager.ORG) BHO-x32: IObit Ads Removal -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll [2016-06-23] (IObit) Toolbar: HKLM - Kein Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Keine Datei Toolbar: HKLM - Kein Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Keine Datei DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.15.0.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-09-23] (Skype Technologies) FireFox: ======== FF DefaultProfile: Mozilla-Seamonkey FF DefaultProfile: yn4743c8.default FF ProfilePath: C:\Users\u\AppData\Roaming\Mozilla\SeaMonkey\Profiles\9o47yt72.default [2016-11-08] FF DefaultSearchEngine: Mozilla\SeaMonkey\Profiles\9o47yt72.default -> Google FF Homepage: Mozilla\SeaMonkey\Profiles\9o47yt72.default -> hxxp://www.windfinder.com/weatherforecast/hamburg_aussenalster FF NetworkProxy: Mozilla\SeaMonkey\Profiles\9o47yt72.default -> share_proxy_settings", true FF NetworkProxy: Mozilla\SeaMonkey\Profiles\9o47yt72.default -> type", 0 FF SearchPlugin: C:\Users\u\AppData\Roaming\Mozilla\SeaMonkey\Profiles\9o47yt72.default\searchplugins\otrkeyfindercom.xml [2013-04-30] FF ProfilePath: D:\Mozilla-Seamonkey [2016-11-18] FF DefaultSearchEngine: D:\Mozilla-Seamonkey -> Startpage HTTPS - Deutsch FF Homepage: D:\Mozilla-Seamonkey -> hxxp://www.windfinder.com/weatherforecast/hamburg_aussenalster FF NetworkProxy: D:\Mozilla-Seamonkey -> share_proxy_settings", true FF NetworkProxy: D:\Mozilla-Seamonkey -> type", 0 FF Extension: (DOM Inspector) - D:\Mozilla-Seamonkey\Extensions\inspector@mozilla.org [2016-05-03] FF Extension: (ChatZilla Deutsch (DE) Language Pack) - D:\Mozilla-Seamonkey\Extensions\langpack-de@chatzilla.mozilla.org [2015-09-21] FF Extension: (JavaScript Debugger Deutsch (DE) Language Pack) - D:\Mozilla-Seamonkey\Extensions\langpack-de@venkman.mozilla.org.xpi [2013-10-02] [ist nicht signiert] FF Extension: (Adblock Plus) - D:\Mozilla-Seamonkey\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-10-28] FF SearchPlugin: D:\Mozilla-Seamonkey\searchplugins\startpage-https---deutsch.xml [2016-11-16] FF ProfilePath: C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default [2016-11-18] FF user.js: detected! => C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\user.js [2016-04-17] FF DefaultSearchEngine: Mozilla\Firefox\Profiles\yn4743c8.default -> Google FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\yn4743c8.default -> Bing FF Keyword.URL: Mozilla\Firefox\Profiles\yn4743c8.default -> hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q= FF Extension: (IObit Surfing Protection & Ads Removal) - C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\Extensions\ascsurfingprotectionnew@iobit.com.xpi [2016-10-18] FF Extension: (Bing Search Engine) - C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\Extensions\bingsearch.full@microsoft.com [2015-03-18] [ist nicht signiert] FF Extension: (Multi YouTube mp3) - C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\Extensions\d.lehr@chello.at.xpi [2015-12-12] FF Extension: (Video DownloadHelper) - C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-10-11] FF Extension: (Adblock Plus) - C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-10-28] FF SearchPlugin: C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\searchplugins\startpage-ssl.xml [2015-01-30] FF Extension: (Application Update Service Helper) - C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi [2016-11-16] [ist nicht signiert] FF Extension: (Multi-process staged rollout) - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi [2016-11-16] [ist nicht signiert] FF Extension: (Pocket) - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi [2016-11-16] [ist nicht signiert] FF Extension: (Web Compat) - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi [2016-11-16] [ist nicht signiert] FF HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\u\AppData\Roaming\Cliqz\cliqz@cliqz.com FF Extension: (Cliqz Beta) - C:\Users\u\AppData\Roaming\Cliqz\cliqz@cliqz.com [2014-12-24] [ist nicht signiert] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-11-08] () FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-10-22] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-10-22] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-08] () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-07-12] (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-07-23] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-07-23] (NVIDIA Corporation) FF Plugin-x32: @sony.com/ReaderDesktop -> C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll [2014-10-24] (Sony Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-2736805842-114790362-3470889979-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\u\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-07-14] (Unity Technologies ApS) Chrome: ======= CHR Profile: C:\Users\u\AppData\Local\Google\Chrome\User Data\Default [2016-11-18] CHR Extension: (Google Präsentationen) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-15] CHR Extension: (Google Docs) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-15] CHR Extension: (Google Drive) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23] CHR Extension: (YouTube) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26] CHR Extension: (Adblock für Youtube™) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2016-11-03] CHR Extension: (Google-Suche) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28] CHR Extension: (Google Tabellen) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-15] CHR Extension: (Musixmatch Lyrics for YouTube) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfenjblodoldnbiddmggcbkcapiolbig [2016-11-03] CHR Extension: (Google Docs Offline) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02] CHR Extension: (Play Music Lyrics Fetcher) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\phnnoaooookpaffnminadcajmghibbbc [2016-11-03] CHR Extension: (Google Mail) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-15] CHR Extension: (Chrome Media Router) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-07] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AdvancedSystemCareService10; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [462624 2016-10-14] (IObit) S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [647864 2016-10-13] (AVG Technologies CZ, s.r.o.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5332384 2016-10-13] (AVG Technologies CZ, s.r.o.) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1149712 2016-09-13] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [727512 2016-10-13] (AVG Technologies CZ, s.r.o.) S3 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [168592 2013-04-10] (Microsoft Corp.) S3 BitBoxService; C:\Program Files (x86)\Sirrix AG\BitBox\bin\BitBoxService.exe [738304 2015-11-13] (Sirrix AG) [Datei ist nicht signiert] S3 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [70952 2011-04-13] (CyberLink) S3 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [312616 2011-04-13] (CyberLink) S3 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [37448 2014-08-13] (CHENGDU YIWO Tech Development Co., Ltd) [Datei ist nicht signiert] R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation) R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [1600800 2016-10-21] (IObit) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation) R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit) S3 PAExec; C:\WINDOWS\PAExec.exe [189112 2016-07-23] (Power Admin LLC) S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2010-08-19] () S3 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2014-04-25] (Sony Corporation) [Datei ist nicht signiert] S3 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246448 2016-01-07] (Synaptics Incorporated) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-10-25] (Microsoft Corporation) R3 WisLMSvc; C:\Program Files (x86)\Launch Manager\WisLMSvc.exe [118560 2012-08-13] (Wistron Corp.) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S0 Avgboota; C:\WINDOWS\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\WINDOWS\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdrivera.sys [311552 2016-09-22] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\WINDOWS\System32\DRIVERS\avgidsha.sys [272640 2016-07-27] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\WINDOWS\System32\DRIVERS\avgldx64.sys [265472 2016-09-20] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\WINDOWS\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\WINDOWS\System32\DRIVERS\avgmfx64.sys [254208 2016-09-26] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\WINDOWS\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.) R0 Avguniva; C:\WINDOWS\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\WINDOWS\system32\DRIVERS\avgwfpa.sys [313096 2016-08-04] (AVG Technologies CZ, s.r.o.) S3 btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [1448248 2016-04-18] (Motorola Solutions, Inc.) R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 cpuz138; C:\Users\u\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [27320 2016-11-17] (CPUID) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [129152 2016-04-24] (Samsung Electronics Co., Ltd.) S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [17480 2013-03-07] () [Datei ist nicht signiert] S3 epmntdrv; C:\WINDOWS\SysWOW64\epmntdrv.sys [13896 2013-03-07] () [Datei ist nicht signiert] R0 EUBAKUP; C:\WINDOWS\System32\drivers\eubakup.sys [61000 2014-08-13] (CHENGDU YIWO Tech Development Co., Ltd) [Datei ist nicht signiert] R0 EUBKMON; C:\WINDOWS\System32\drivers\EUBKMON.sys [48200 2014-08-13] () [Datei ist nicht signiert] R1 EUDSKACS; C:\WINDOWS\system32\drivers\eudskacs.sys [18504 2014-08-13] (CHENGDU YIWO Tech Development Co., Ltd) [Datei ist nicht signiert] R1 EUFDDISK; C:\WINDOWS\system32\drivers\EuFdDisk.sys [189000 2014-08-13] (CHENGDU YIWO Tech Development Co., Ltd) [Datei ist nicht signiert] S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [9800 2013-03-07] () [Datei ist nicht signiert] S3 EuGdiDrv; C:\WINDOWS\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () [Datei ist nicht signiert] R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-04-17] (REALiX(tm)) R3 IMFFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [22208 2016-04-01] (IObit) R3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3354384 2016-04-18] (Intel Corporation) R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2016-07-27] (IObit.com) S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [25504 2013-10-21] (Resplendence Software Projects Sp.) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [936192 2016-07-24] (Realtek ) R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [413912 2016-04-18] (Realsil Semiconductor Corporation) S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-16] (Synaptics Incorporated) S3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42664 2016-01-07] (Synaptics Incorporated) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [221824 2016-04-24] (Samsung Electronics Co., Ltd.) R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [47072 2012-11-29] (Windows (R) Win 7 DDK provider) R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [194816 2015-11-11] (Oracle Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) R3 XHCIPort; C:\WINDOWS\System32\drivers\XHCIPort.sys [188896 2012-11-29] (Windows (R) Win 7 DDK provider) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-11-18 11:31 - 2016-11-18 11:32 - 00000000 ____D C:\FRST 2016-11-17 03:07 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\WINDOWS\system32\IObitSmartDefragExtension.dll 2016-11-17 03:07 - 2016-03-22 11:02 - 00036824 _____ (IObit) C:\WINDOWS\system32\SmartDefragBootTime.exe 2016-11-17 03:03 - 2016-11-17 03:03 - 00000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705} 2016-11-17 02:56 - 2016-11-17 02:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter 2016-11-17 02:54 - 2016-11-17 03:10 - 00003084 _____ C:\WINDOWS\System32\Tasks\ASC10_PerformanceMonitor 2016-11-17 02:54 - 2016-11-17 02:54 - 00002872 _____ C:\WINDOWS\System32\Tasks\ASC10_SkipUac_UK 2016-11-17 02:54 - 2016-11-17 02:54 - 00000000 ____D C:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A} 2016-11-17 02:34 - 2016-11-17 02:34 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices 2016-11-17 02:34 - 2016-11-17 02:34 - 00000000 ____D C:\WINDOWS\system32\BestPractices 2016-11-17 02:12 - 2016-11-17 02:12 - 00003584 _____ C:\WINDOWS\System32\Tasks\AVG-SSU_1116av_DELETE 2016-11-17 02:12 - 2016-11-17 02:12 - 00003172 _____ C:\WINDOWS\System32\Tasks\AVG-SSU_1116av 2016-11-17 02:12 - 2016-11-17 02:12 - 00000000 ____D C:\ProgramData\Avg_Update_1116av 2016-11-16 01:48 - 2016-11-18 00:25 - 00000000 ____D C:\Users\u\AppData\LocalLow\Mozilla 2016-11-16 01:47 - 2016-11-17 02:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-11-14 18:05 - 2016-11-14 18:05 - 00003584 _____ C:\WINDOWS\System32\Tasks\AVG-SSU_1116sp_DELETE 2016-11-14 18:05 - 2016-11-14 18:05 - 00003188 _____ C:\WINDOWS\System32\Tasks\AVG-SSU_1116sp 2016-11-14 18:05 - 2016-11-14 18:05 - 00000000 ____D C:\ProgramData\Avg_Update_1116sp 2016-11-12 00:59 - 2016-11-12 00:59 - 00000000 ____D C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-11-09 16:41 - 2016-11-02 14:32 - 00316256 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-11-09 16:41 - 2016-11-02 14:31 - 00546968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-11-09 16:41 - 2016-10-25 10:34 - 00454496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys 2016-11-09 16:41 - 2016-10-25 09:32 - 01862000 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-11-09 16:41 - 2016-10-25 09:32 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-11-09 16:41 - 2016-10-25 09:32 - 00845568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2016-11-09 16:41 - 2016-10-25 09:32 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll 2016-11-09 16:41 - 2016-10-25 09:28 - 01083648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe 2016-11-09 16:41 - 2016-10-25 09:05 - 00712032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2016-11-09 16:41 - 2016-10-25 08:45 - 00032096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys 2016-11-09 16:41 - 2016-10-25 08:39 - 00306840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 01349632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 00709176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-11-09 16:41 - 2016-10-25 08:31 - 01824272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-11-09 16:41 - 2016-10-25 08:31 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-11-09 16:41 - 2016-10-25 08:30 - 02938920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-11-09 16:41 - 2016-10-25 08:30 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-11-09 16:41 - 2016-10-25 08:27 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-11-09 16:41 - 2016-10-25 08:27 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2016-11-09 16:41 - 2016-10-25 08:27 - 00256704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-11-09 16:41 - 2016-10-25 08:26 - 05240952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-11-09 16:41 - 2016-10-25 08:26 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-11-09 16:41 - 2016-10-25 08:26 - 01355344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll 2016-11-09 16:41 - 2016-10-25 08:26 - 00836752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2016-11-09 16:41 - 2016-10-25 08:26 - 00569752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll 2016-11-09 16:41 - 2016-10-25 08:22 - 00268040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2016-11-09 16:41 - 2016-10-25 08:19 - 00295776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-11-09 16:41 - 2016-10-25 08:18 - 01536088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2016-11-09 16:41 - 2016-10-25 07:56 - 02195640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2016-11-09 16:41 - 2016-10-25 07:56 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe 2016-11-09 16:41 - 2016-10-25 07:54 - 01522160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-11-09 16:41 - 2016-10-25 07:54 - 00273760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll 2016-11-09 16:41 - 2016-10-25 07:53 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-11-09 16:41 - 2016-10-25 07:27 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2016-11-09 16:41 - 2016-10-25 07:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2016-11-09 16:41 - 2016-10-25 07:21 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll 2016-11-09 16:41 - 2016-10-25 07:09 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2016-11-09 16:41 - 2016-10-25 07:08 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-11-09 16:41 - 2016-10-25 07:06 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-11-09 16:41 - 2016-10-25 07:00 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2016-11-09 16:41 - 2016-10-25 06:50 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2016-11-09 16:41 - 2016-10-25 06:49 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2016-11-09 16:41 - 2016-10-25 06:48 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll 2016-11-09 16:41 - 2016-10-25 06:45 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-11-09 16:41 - 2016-10-25 06:45 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll 2016-11-09 16:41 - 2016-10-25 06:44 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll 2016-11-09 16:41 - 2016-10-25 06:43 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\filemgmt.dll 2016-11-09 16:41 - 2016-10-25 06:41 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2016-11-09 16:41 - 2016-10-25 06:40 - 01336832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2016-11-09 16:41 - 2016-10-25 06:37 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-11-09 16:41 - 2016-10-25 06:36 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-11-09 16:41 - 2016-10-25 06:36 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2016-11-09 16:41 - 2016-10-25 06:36 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll 2016-11-09 16:41 - 2016-10-25 06:35 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll 2016-11-09 16:41 - 2016-10-25 06:32 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-11-09 16:41 - 2016-10-25 06:31 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-11-09 16:41 - 2016-10-25 06:30 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-11-09 16:41 - 2016-10-25 06:29 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe 2016-11-09 16:41 - 2016-10-25 06:29 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 02578432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 00885248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 00760320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2016-11-09 16:41 - 2016-10-25 06:27 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll 2016-11-09 16:41 - 2016-10-25 06:25 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll 2016-11-09 16:41 - 2016-10-25 06:25 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2016-11-09 16:41 - 2016-10-25 06:23 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll 2016-11-09 16:41 - 2016-10-25 06:23 - 00964096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2016-11-09 16:41 - 2016-10-25 06:22 - 01562624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe 2016-11-09 16:41 - 2016-10-25 06:21 - 03577344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2016-11-09 16:41 - 2016-10-25 06:21 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2016-11-09 16:41 - 2016-10-25 06:11 - 04078592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2016-11-09 16:41 - 2016-10-25 06:11 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2016-11-09 16:41 - 2016-10-25 06:09 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2016-11-09 16:41 - 2016-10-25 06:04 - 00835072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll 2016-11-09 16:41 - 2016-10-25 06:03 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-11-09 16:41 - 2016-10-25 06:01 - 02361856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 02555904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 01708032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-11-09 16:41 - 2016-10-25 05:59 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2016-11-09 16:41 - 2016-10-25 05:59 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll 2016-11-09 16:41 - 2016-10-25 05:58 - 09920512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-11-09 16:41 - 2016-10-25 05:57 - 06296064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-11-09 16:41 - 2016-10-25 05:56 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-11-09 16:41 - 2016-10-25 05:55 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2016-11-09 16:41 - 2016-10-25 05:55 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnfldr.dll 2016-11-09 16:41 - 2016-10-25 05:54 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2016-11-09 16:41 - 2016-10-25 05:53 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2016-11-09 16:41 - 2016-10-25 05:47 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-11-09 16:41 - 2016-10-25 05:46 - 02771968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2016-11-09 16:41 - 2016-10-25 05:44 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2016-11-09 16:41 - 2016-10-25 05:43 - 04404736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-11-09 16:41 - 2016-10-25 05:40 - 05325824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-11-09 16:41 - 2016-10-25 05:38 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-11-09 16:41 - 2016-10-25 05:37 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-11-09 16:41 - 2016-10-25 05:36 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2016-11-09 16:41 - 2016-10-25 05:35 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2016-11-09 16:41 - 2016-10-25 05:35 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll 2016-11-09 16:41 - 2016-10-25 05:34 - 02062336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-11-09 16:41 - 2016-10-25 05:34 - 01228800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll 2016-11-09 16:41 - 2016-10-25 05:32 - 06743040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2016-11-09 16:41 - 2016-10-25 05:27 - 03065344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2016-11-09 16:41 - 2016-10-25 05:23 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll 2016-11-09 16:41 - 2016-10-25 05:21 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll 2016-11-09 16:40 - 2016-11-02 13:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-11-09 16:40 - 2016-10-25 10:24 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2016-11-09 16:40 - 2016-10-25 10:18 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2016-11-09 16:40 - 2016-10-25 09:48 - 01554152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2016-11-09 16:40 - 2016-10-25 09:48 - 01552104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2016-11-09 16:40 - 2016-10-25 09:42 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-11-09 16:40 - 2016-10-25 09:38 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-11-09 16:40 - 2016-10-25 09:37 - 01040792 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2016-11-09 16:40 - 2016-10-25 09:35 - 06536248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2016-11-09 16:40 - 2016-10-25 09:30 - 00360288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-11-09 16:40 - 2016-10-25 08:47 - 00305808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll 2016-11-09 16:40 - 2016-10-25 08:30 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2016-11-09 16:40 - 2016-10-25 08:29 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2016-11-09 16:40 - 2016-10-25 08:26 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2016-11-09 16:40 - 2016-10-25 08:22 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys 2016-11-09 16:40 - 2016-10-25 08:14 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll 2016-11-09 16:40 - 2016-10-25 08:12 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\racpldlg.dll 2016-11-09 16:40 - 2016-10-25 08:12 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys 2016-11-09 16:40 - 2016-10-25 08:10 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceClassExtension.dll 2016-11-09 16:40 - 2016-10-25 08:06 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2016-11-09 16:40 - 2016-10-25 08:06 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceConnectApi.dll 2016-11-09 16:40 - 2016-10-25 08:01 - 00404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys 2016-11-09 16:40 - 2016-10-25 07:59 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2016-11-09 16:40 - 2016-10-25 07:52 - 00577536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll 2016-11-09 16:40 - 2016-10-25 07:51 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-11-09 16:40 - 2016-10-25 07:50 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll 2016-11-09 16:40 - 2016-10-25 07:49 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll 2016-11-09 16:40 - 2016-10-25 07:49 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll 2016-11-09 16:40 - 2016-10-25 07:48 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceApi.dll 2016-11-09 16:40 - 2016-10-25 07:43 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll 2016-11-09 16:40 - 2016-10-25 07:40 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll 2016-11-09 16:40 - 2016-10-25 07:39 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-11-09 16:40 - 2016-10-25 07:38 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll 2016-11-09 16:40 - 2016-10-25 07:38 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll 2016-11-09 16:40 - 2016-10-25 07:38 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-11-09 16:40 - 2016-10-25 07:37 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll 2016-11-09 16:40 - 2016-10-25 07:37 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll 2016-11-09 16:40 - 2016-10-25 07:33 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-11-09 16:40 - 2016-10-25 07:32 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-11-09 16:40 - 2016-10-25 07:28 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll 2016-11-09 16:40 - 2016-10-25 07:27 - 01466368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Pimstore.dll 2016-11-09 16:40 - 2016-10-25 07:27 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-11-09 16:40 - 2016-10-25 07:23 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2016-11-09 16:40 - 2016-10-25 07:22 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2016-11-09 16:40 - 2016-10-25 07:18 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll 2016-11-09 16:40 - 2016-10-25 07:12 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll 2016-11-09 16:40 - 2016-10-25 07:05 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll 2016-11-09 16:40 - 2016-10-25 07:05 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\StikyNot.exe 2016-11-09 16:40 - 2016-10-25 07:05 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2016-11-09 16:40 - 2016-10-25 07:03 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SCardDlg.dll 2016-11-09 16:40 - 2016-10-25 07:01 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2016-11-09 16:40 - 2016-10-25 07:00 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp 2016-11-09 16:40 - 2016-10-25 07:00 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceClassExtension.dll 2016-11-09 16:40 - 2016-10-25 06:59 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oemlicense.dll 2016-11-09 16:40 - 2016-10-25 06:56 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceConnectApi.dll 2016-11-09 16:40 - 2016-10-25 06:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll 2016-11-09 16:40 - 2016-10-25 06:53 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-11-09 16:40 - 2016-10-25 06:51 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll 2016-11-09 16:40 - 2016-10-25 06:50 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl 2016-11-09 16:40 - 2016-10-25 06:50 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll 2016-11-09 16:40 - 2016-10-25 06:50 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2016-11-09 16:40 - 2016-10-25 06:49 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3ui.dll 2016-11-09 16:40 - 2016-10-25 06:48 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2016-11-09 16:40 - 2016-10-25 06:45 - 07977984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-11-09 16:40 - 2016-10-25 06:45 - 00564736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\objsel.dll 2016-11-09 16:40 - 2016-10-25 06:45 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe 2016-11-09 16:40 - 2016-10-25 06:43 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceApi.dll 2016-11-09 16:40 - 2016-10-25 06:42 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2016-11-09 16:40 - 2016-10-25 06:41 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll 2016-11-09 16:40 - 2016-10-25 06:39 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2016-11-09 16:40 - 2016-10-25 06:39 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe 2016-11-09 16:40 - 2016-10-25 06:39 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-11-09 16:40 - 2016-10-25 06:37 - 04143104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll 2016-11-09 16:40 - 2016-10-25 06:37 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll 2016-11-09 16:40 - 2016-10-25 06:37 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 04646400 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe 2016-11-09 16:40 - 2016-10-25 06:36 - 00879616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wvc.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WLanConn.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll 2016-11-09 16:40 - 2016-10-25 06:35 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll 2016-11-09 16:40 - 2016-10-25 06:35 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll 2016-11-09 16:40 - 2016-10-25 06:34 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2016-11-09 16:40 - 2016-10-25 06:33 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll 2016-11-09 16:40 - 2016-10-25 06:33 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2016-11-09 16:40 - 2016-10-25 06:32 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl 2016-11-09 16:40 - 2016-10-25 06:32 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll 2016-11-09 16:40 - 2016-10-25 06:32 - 00645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll 2016-11-09 16:40 - 2016-10-25 06:29 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll 2016-11-09 16:40 - 2016-10-25 06:28 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-11-09 16:40 - 2016-10-25 06:27 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll 2016-11-09 16:40 - 2016-10-25 06:26 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2016-11-09 16:40 - 2016-10-25 06:25 - 03695104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2016-11-09 16:40 - 2016-10-25 06:25 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2016-11-09 16:40 - 2016-10-25 06:25 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2016-11-09 16:40 - 2016-10-25 06:24 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licensingdiag.exe 2016-11-09 16:40 - 2016-10-25 06:17 - 00581632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll 2016-11-09 16:40 - 2016-10-25 06:14 - 02911744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2016-11-09 16:40 - 2016-10-25 06:14 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2016-11-09 16:40 - 2016-10-25 06:11 - 06471168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2016-11-09 16:40 - 2016-10-25 06:09 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll 2016-11-09 16:40 - 2016-10-25 06:07 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2016-11-09 16:40 - 2016-10-25 05:59 - 14258688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-11-09 16:40 - 2016-10-25 05:58 - 07536128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2016-11-09 16:40 - 2016-10-25 05:53 - 03294208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2016-11-09 16:40 - 2016-10-25 05:52 - 03555840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe 2016-11-09 16:40 - 2016-10-25 05:51 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll 2016-11-09 16:40 - 2016-10-25 05:50 - 01487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll 2016-11-09 16:40 - 2016-10-25 05:45 - 02679808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2016-11-09 16:40 - 2016-10-25 05:41 - 02519552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll 2016-11-09 16:40 - 2016-10-25 05:34 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-11-09 16:40 - 2016-10-25 05:33 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll 2016-11-09 16:40 - 2016-10-25 05:32 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll 2016-11-09 16:40 - 2016-10-25 05:32 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2016-11-09 16:40 - 2016-10-25 05:30 - 12590080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-11-09 16:40 - 2016-10-25 05:07 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-11-09 16:39 - 2016-10-25 10:25 - 01637216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2016-11-09 16:39 - 2016-10-25 09:51 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll 2016-11-09 16:39 - 2016-10-25 09:49 - 00588328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmdev.dll 2016-11-09 16:39 - 2016-10-25 09:49 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 01017024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 00847648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-11-09 16:39 - 2016-10-25 09:41 - 03694088 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-11-09 16:39 - 2016-10-25 09:39 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2016-11-09 16:39 - 2016-10-25 09:37 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-11-09 16:39 - 2016-10-25 09:32 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-11-09 16:39 - 2016-10-25 08:47 - 28851216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll 2016-11-09 16:39 - 2016-10-25 08:47 - 02641928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL 2016-11-09 16:39 - 2016-10-25 08:46 - 00388896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2016-11-09 16:39 - 2016-10-25 08:40 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll 2016-11-09 16:39 - 2016-10-25 08:40 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2016-11-09 16:39 - 2016-10-25 08:35 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll 2016-11-09 16:39 - 2016-10-25 08:33 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\genericusbfn.sys 2016-11-09 16:39 - 2016-10-25 08:32 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2016-11-09 16:39 - 2016-10-25 08:31 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2016-11-09 16:39 - 2016-10-25 08:23 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll 2016-11-09 16:39 - 2016-10-25 08:20 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-11-09 16:39 - 2016-10-25 08:18 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-11-09 16:39 - 2016-10-25 08:13 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-11-09 16:39 - 2016-10-25 08:05 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-11-09 16:39 - 2016-10-25 08:04 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LegacyNetUXHost.exe 2016-11-09 16:39 - 2016-10-25 07:59 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2016-11-09 16:39 - 2016-10-25 07:56 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2016-11-09 16:39 - 2016-10-25 07:54 - 00752128 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll 2016-11-09 16:39 - 2016-10-25 07:53 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll 2016-11-09 16:39 - 2016-10-25 07:52 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2016-11-09 16:39 - 2016-10-25 07:51 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll 2016-11-09 16:39 - 2016-10-25 07:50 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll 2016-11-09 16:39 - 2016-10-25 07:50 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll 2016-11-09 16:39 - 2016-10-25 07:46 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll 2016-11-09 16:39 - 2016-10-25 07:43 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-11-09 16:39 - 2016-10-25 07:42 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2016-11-09 16:39 - 2016-10-25 07:41 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll 2016-11-09 16:39 - 2016-10-25 07:41 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll 2016-11-09 16:39 - 2016-10-25 07:40 - 02331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL 2016-11-09 16:39 - 2016-10-25 07:40 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll 2016-11-09 16:39 - 2016-10-25 07:40 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll 2016-11-09 16:39 - 2016-10-25 07:40 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2016-11-09 16:39 - 2016-10-25 07:39 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll 2016-11-09 16:39 - 2016-10-25 07:39 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll 2016-11-09 16:39 - 2016-10-25 07:39 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WLanConn.dll 2016-11-09 16:39 - 2016-10-25 07:38 - 00610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmsdk.dll 2016-11-09 16:39 - 2016-10-25 07:35 - 01434112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll 2016-11-09 16:39 - 2016-10-25 07:35 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-11-09 16:39 - 2016-10-25 07:35 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2016-11-09 16:39 - 2016-10-25 07:34 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2016-11-09 16:39 - 2016-10-25 07:33 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2016-11-09 16:39 - 2016-10-25 07:33 - 00817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll 2016-11-09 16:39 - 2016-10-25 07:29 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll 2016-11-09 16:39 - 2016-10-25 07:27 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll 2016-11-09 16:39 - 2016-10-25 07:27 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll 2016-11-09 16:39 - 2016-10-25 07:19 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2016-11-09 16:39 - 2016-10-25 07:16 - 01965568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe 2016-11-09 16:39 - 2016-10-25 07:07 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2016-11-09 16:39 - 2016-10-25 07:03 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2016-11-09 16:39 - 2016-10-25 07:03 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2016-11-09 16:39 - 2016-10-25 07:01 - 01121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2016-11-09 16:39 - 2016-10-25 06:59 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2016-11-09 16:39 - 2016-10-25 06:57 - 02285568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll 2016-11-09 16:39 - 2016-10-25 06:57 - 00833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\pmcsnap.dll 2016-11-09 16:39 - 2016-10-25 06:55 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll 2016-11-09 16:39 - 2016-10-25 06:53 - 01728000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-11-09 16:39 - 2016-10-25 06:49 - 03081216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-11-09 16:39 - 2016-10-25 06:46 - 00486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnfldr.dll 2016-11-09 16:39 - 2016-10-25 06:46 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2016-11-09 16:39 - 2016-10-25 06:42 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 2016-11-09 16:39 - 2016-10-25 06:35 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmsdk.dll 2016-11-09 16:39 - 2016-10-25 06:34 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2016-11-09 16:39 - 2016-10-25 06:32 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2016-11-09 16:39 - 2016-10-25 06:28 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2016-11-09 16:39 - 2016-10-25 06:28 - 01186816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll 2016-11-09 16:39 - 2016-10-25 06:28 - 00882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2016-11-09 16:39 - 2016-10-25 06:25 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll 2016-11-09 16:39 - 2016-10-25 06:24 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2016-11-09 16:39 - 2016-10-25 06:23 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2016-11-09 16:39 - 2016-10-25 06:19 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-11-09 16:39 - 2016-10-25 06:17 - 04895744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-11-09 16:39 - 2016-10-25 06:05 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-11-09 16:39 - 2016-10-25 06:05 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-11-09 16:39 - 2016-10-25 06:05 - 01385472 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-11-09 16:39 - 2016-10-25 05:55 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2016-11-09 16:39 - 2016-10-25 05:55 - 02217984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll 2016-11-09 16:39 - 2016-10-25 05:53 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr 2016-11-09 16:39 - 2016-10-25 05:52 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2016-11-09 16:39 - 2016-10-25 05:48 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll 2016-11-09 16:39 - 2016-10-25 05:45 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-11-09 16:39 - 2016-10-25 05:44 - 19348480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-11-09 16:39 - 2016-10-25 05:44 - 12134400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-11-09 16:39 - 2016-10-25 05:43 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-11-09 16:39 - 2016-10-25 05:29 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr 2016-11-09 16:39 - 2016-10-25 05:26 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-11-09 16:39 - 2016-10-25 02:47 - 00445873 _____ C:\WINDOWS\system32\ApnDatabase.xml 2016-11-09 16:38 - 2016-11-02 16:12 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-11-09 16:38 - 2016-11-02 16:08 - 00636296 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-11-09 16:38 - 2016-10-25 10:44 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-11-09 16:38 - 2016-10-25 10:44 - 00875480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-11-09 16:38 - 2016-10-25 10:42 - 07468384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-11-09 16:38 - 2016-10-25 10:42 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-11-09 16:38 - 2016-10-25 10:42 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-11-09 16:38 - 2016-10-25 10:42 - 01142560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-11-09 16:38 - 2016-10-25 10:42 - 01098648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2016-11-09 16:38 - 2016-10-25 10:42 - 00125280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys 2016-11-09 16:38 - 2016-10-25 10:41 - 01819208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-11-09 16:38 - 2016-10-25 10:40 - 00384864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2016-11-09 16:38 - 2016-10-25 10:39 - 01238584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe 2016-11-09 16:38 - 2016-10-25 10:19 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2016-11-09 16:38 - 2016-10-25 09:50 - 00439136 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll 2016-11-09 16:38 - 2016-10-25 09:42 - 02607336 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-11-09 16:38 - 2016-10-25 09:42 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-11-09 16:38 - 2016-10-25 09:39 - 00730352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2016-11-09 16:38 - 2016-10-25 09:39 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-11-09 16:38 - 2016-10-25 09:38 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2016-11-09 16:38 - 2016-10-25 09:37 - 04515256 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-11-09 16:38 - 2016-10-25 09:37 - 01603224 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll 2016-11-09 16:38 - 2016-10-25 09:33 - 00341936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2016-11-09 16:38 - 2016-10-25 09:30 - 01848072 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2016-11-09 16:38 - 2016-10-25 09:03 - 02549456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2016-11-09 16:38 - 2016-10-25 09:03 - 01988440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-11-09 16:38 - 2016-10-25 09:02 - 00577376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-11-09 16:38 - 2016-10-25 09:02 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-11-09 16:38 - 2016-10-25 09:01 - 01776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-11-09 16:38 - 2016-10-25 09:01 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-11-09 16:38 - 2016-10-25 08:45 - 00503600 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll 2016-11-09 16:38 - 2016-10-25 08:31 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll 2016-11-09 16:38 - 2016-10-25 08:30 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll 2016-11-09 16:38 - 2016-10-25 08:24 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys 2016-11-09 16:38 - 2016-10-25 08:21 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2016-11-09 16:38 - 2016-10-25 08:16 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2016-11-09 16:38 - 2016-10-25 08:12 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe 2016-11-09 16:38 - 2016-10-25 08:12 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-11-09 16:38 - 2016-10-25 08:10 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp 2016-11-09 16:38 - 2016-10-25 08:10 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll 2016-11-09 16:38 - 2016-10-25 08:08 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys 2016-11-09 16:38 - 2016-10-25 08:02 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2016-11-09 16:38 - 2016-10-25 08:02 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2016-11-09 16:38 - 2016-10-25 08:00 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2016-11-09 16:38 - 2016-10-25 07:58 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll 2016-11-09 16:38 - 2016-10-25 07:57 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll 2016-11-09 16:38 - 2016-10-25 07:56 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3ui.dll 2016-11-09 16:38 - 2016-10-25 07:56 - 00317952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll 2016-11-09 16:38 - 2016-10-25 07:55 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-11-09 16:38 - 2016-10-25 07:55 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2016-11-09 16:38 - 2016-10-25 07:55 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll 2016-11-09 16:38 - 2016-10-25 07:53 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2016-11-09 16:38 - 2016-10-25 07:53 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-11-09 16:38 - 2016-10-25 07:53 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll 2016-11-09 16:38 - 2016-10-25 07:52 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll 2016-11-09 16:38 - 2016-10-25 07:52 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll 2016-11-09 16:38 - 2016-10-25 07:52 - 00370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack_win.dll 2016-11-09 16:38 - 2016-10-25 07:51 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe 2016-11-09 16:38 - 2016-10-25 07:51 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2016-11-09 16:38 - 2016-10-25 07:51 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll 2016-11-09 16:38 - 2016-10-25 07:50 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll 2016-11-09 16:38 - 2016-10-25 07:50 - 00363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneOm.dll 2016-11-09 16:38 - 2016-10-25 07:49 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll 2016-11-09 16:38 - 2016-10-25 07:48 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll 2016-11-09 16:38 - 2016-10-25 07:47 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll 2016-11-09 16:38 - 2016-10-25 07:46 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll 2016-11-09 16:38 - 2016-10-25 07:46 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2016-11-09 16:38 - 2016-10-25 07:44 - 01479168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2016-11-09 16:38 - 2016-10-25 07:43 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2016-11-09 16:38 - 2016-10-25 07:42 - 01813504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2016-11-09 16:38 - 2016-10-25 07:42 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll 2016-11-09 16:38 - 2016-10-25 07:41 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll 2016-11-09 16:38 - 2016-10-25 07:40 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxApplicabilityEngine.dll 2016-11-09 16:38 - 2016-10-25 07:40 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll 2016-11-09 16:38 - 2016-10-25 07:40 - 00466944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll 2016-11-09 16:38 - 2016-10-25 07:39 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll 2016-11-09 16:38 - 2016-10-25 07:39 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2016-11-09 16:38 - 2016-10-25 07:39 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2016-11-09 16:38 - 2016-10-25 07:39 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll 2016-11-09 16:38 - 2016-10-25 07:38 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wvc.dll 2016-11-09 16:38 - 2016-10-25 07:36 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-11-09 16:38 - 2016-10-25 07:36 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll 2016-11-09 16:38 - 2016-10-25 07:36 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2016-11-09 16:38 - 2016-10-25 07:35 - 01132544 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll 2016-11-09 16:38 - 2016-10-25 07:34 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-11-09 16:38 - 2016-10-25 07:32 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-11-09 16:38 - 2016-10-25 07:32 - 01159168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll 2016-11-09 16:38 - 2016-10-25 07:32 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-11-09 16:38 - 2016-10-25 07:30 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2016-11-09 16:38 - 2016-10-25 07:30 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-11-09 16:38 - 2016-10-25 07:29 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe 2016-11-09 16:38 - 2016-10-25 07:29 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2016-11-09 16:38 - 2016-10-25 07:29 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-11-09 16:38 - 2016-10-25 07:28 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2016-11-09 16:38 - 2016-10-25 07:27 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2016-11-09 16:38 - 2016-10-25 07:27 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2016-11-09 16:38 - 2016-10-25 07:26 - 02103296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll 2016-11-09 16:38 - 2016-10-25 07:25 - 01872896 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2016-11-09 16:38 - 2016-10-25 07:25 - 01319424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2016-11-09 16:38 - 2016-10-25 07:25 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll 2016-11-09 16:38 - 2016-10-25 07:24 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2016-11-09 16:38 - 2016-10-25 07:24 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2016-11-09 16:38 - 2016-10-25 07:23 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-11-09 16:38 - 2016-10-25 07:22 - 01424384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll 2016-11-09 16:38 - 2016-10-25 07:22 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2016-11-09 16:38 - 2016-10-25 07:21 - 02054144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2016-11-09 16:38 - 2016-10-25 07:21 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-11-09 16:38 - 2016-10-25 07:20 - 03549696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll 2016-11-09 16:38 - 2016-10-25 07:17 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2016-11-09 16:38 - 2016-10-25 07:16 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2016-11-09 16:38 - 2016-10-25 07:05 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-11-09 16:38 - 2016-10-25 07:05 - 02610176 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-11-09 16:38 - 2016-10-25 07:03 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2016-11-09 16:38 - 2016-10-25 07:01 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2016-11-09 16:38 - 2016-10-25 06:54 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-11-09 16:38 - 2016-10-25 06:54 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-11-09 16:38 - 2016-10-25 06:54 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2016-11-09 16:38 - 2016-10-25 06:53 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2016-11-09 16:38 - 2016-10-25 06:52 - 04170240 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll 2016-11-09 16:38 - 2016-10-25 06:52 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2016-11-09 16:38 - 2016-10-25 06:51 - 02175488 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-11-09 16:38 - 2016-10-25 06:50 - 02874880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll 2016-11-09 16:38 - 2016-10-25 06:49 - 01997312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2016-11-09 16:38 - 2016-10-25 06:48 - 04826624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-11-09 16:38 - 2016-10-25 06:46 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll 2016-11-09 16:38 - 2016-10-25 06:43 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-11-09 16:38 - 2016-10-25 06:41 - 02444800 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2016-11-09 16:38 - 2016-10-25 06:40 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2016-11-09 16:38 - 2016-10-25 06:39 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2016-11-09 16:38 - 2016-10-25 06:38 - 03585536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-11-09 16:38 - 2016-10-25 06:37 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-11-09 16:38 - 2016-10-25 06:34 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-11-09 16:38 - 2016-10-25 06:34 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2016-11-09 16:38 - 2016-10-25 06:30 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-11-09 16:38 - 2016-10-25 06:28 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2016-11-09 16:38 - 2016-10-25 06:20 - 01797120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-11-09 16:38 - 2016-10-25 06:14 - 00651776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll 2016-11-09 16:38 - 2016-10-25 06:13 - 22375936 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-11-09 16:38 - 2016-10-25 06:12 - 11544576 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-11-09 16:38 - 2016-10-25 06:10 - 01568256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll 2016-11-09 16:38 - 2016-10-25 06:05 - 06312448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-11-09 16:38 - 2016-10-25 06:05 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2016-11-09 16:38 - 2016-10-25 06:02 - 24610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-11-09 16:38 - 2016-10-25 06:02 - 06976512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-11-09 16:38 - 2016-10-25 06:02 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-11-09 16:38 - 2016-10-25 06:02 - 03459584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll 2016-11-09 16:38 - 2016-10-25 06:01 - 13392384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-11-09 16:38 - 2016-10-25 05:48 - 07838208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-11-09 16:38 - 2016-10-25 03:19 - 00775336 _____ C:\WINDOWS\SysWOW64\locale.nls 2016-11-09 16:38 - 2016-10-25 03:19 - 00775336 _____ C:\WINDOWS\system32\locale.nls 2016-11-09 16:38 - 2016-09-07 06:22 - 00604920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-11-09 16:37 - 2016-11-02 15:25 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-11-09 16:37 - 2016-10-25 10:42 - 00037744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2016-11-09 16:37 - 2016-10-25 10:39 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2016-11-09 16:37 - 2016-10-25 10:26 - 00528736 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2016-11-09 16:37 - 2016-10-25 09:38 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-11-09 16:37 - 2016-10-25 09:37 - 00725776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll 2016-11-09 16:37 - 2016-10-25 09:36 - 01540216 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-11-09 16:37 - 2016-10-25 09:36 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-11-09 16:37 - 2016-10-25 09:34 - 01128104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2016-11-09 16:37 - 2016-10-25 09:34 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2016-11-09 16:37 - 2016-10-25 09:34 - 00106928 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe 2016-11-09 16:37 - 2016-10-25 09:01 - 00324448 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll 2016-11-09 16:37 - 2016-10-25 08:46 - 00376528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll 2016-11-09 16:37 - 2016-10-25 08:32 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll 2016-11-09 16:37 - 2016-10-25 08:31 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll 2016-11-09 16:37 - 2016-10-25 08:21 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2016-11-09 16:37 - 2016-10-25 08:19 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys 2016-11-09 16:37 - 2016-10-25 08:13 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll 2016-11-09 16:37 - 2016-10-25 08:13 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2016-11-09 16:37 - 2016-10-25 08:12 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2016-11-09 16:37 - 2016-10-25 08:10 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2016-11-09 16:37 - 2016-10-25 08:09 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oemlicense.dll 2016-11-09 16:37 - 2016-10-25 08:05 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FingerprintEnrollment.dll 2016-11-09 16:37 - 2016-10-25 08:02 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-11-09 16:37 - 2016-10-25 07:59 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2016-11-09 16:37 - 2016-10-25 07:59 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll 2016-11-09 16:37 - 2016-10-25 07:59 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsvc.dll 2016-11-09 16:37 - 2016-10-25 07:59 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll 2016-11-09 16:37 - 2016-10-25 07:58 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl 2016-11-09 16:37 - 2016-10-25 07:58 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2016-11-09 16:37 - 2016-10-25 07:57 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2016-11-09 16:37 - 2016-10-25 07:56 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dxpserver.exe 2016-11-09 16:37 - 2016-10-25 07:55 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2016-11-09 16:37 - 2016-10-25 07:55 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll 2016-11-09 16:37 - 2016-10-25 07:54 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll 2016-11-09 16:37 - 2016-10-25 07:53 - 00714240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2016-11-09 16:37 - 2016-10-25 07:53 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll 2016-11-09 16:37 - 2016-10-25 07:52 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2016-11-09 16:37 - 2016-10-25 07:52 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll 2016-11-09 16:37 - 2016-10-25 07:51 - 00469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll 2016-11-09 16:37 - 2016-10-25 07:51 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll 2016-11-09 16:37 - 2016-10-25 07:50 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2016-11-09 16:37 - 2016-10-25 07:47 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2016-11-09 16:37 - 2016-10-25 07:47 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2016-11-09 16:37 - 2016-10-25 07:47 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll 2016-11-09 16:37 - 2016-10-25 07:45 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-11-09 16:37 - 2016-10-25 07:44 - 00602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll 2016-11-09 16:37 - 2016-10-25 07:43 - 00440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe 2016-11-09 16:37 - 2016-10-25 07:42 - 00656896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll 2016-11-09 16:37 - 2016-10-25 07:41 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll 2016-11-09 16:37 - 2016-10-25 07:41 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-11-09 16:37 - 2016-10-25 07:41 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2016-11-09 16:37 - 2016-10-25 07:38 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll 2016-11-09 16:37 - 2016-10-25 07:38 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2016-11-09 16:37 - 2016-10-25 07:38 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll 2016-11-09 16:37 - 2016-10-25 07:37 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll 2016-11-09 16:37 - 2016-10-25 07:37 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2016-11-09 16:37 - 2016-10-25 07:35 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2016-11-09 16:37 - 2016-10-25 07:34 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-11-09 16:37 - 2016-10-25 07:33 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl 2016-11-09 16:37 - 2016-10-25 07:32 - 01037824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll 2016-11-09 16:37 - 2016-10-25 07:32 - 00990208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2016-11-09 16:37 - 2016-10-25 07:32 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-11-09 16:37 - 2016-10-25 07:32 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll 2016-11-09 16:37 - 2016-10-25 07:27 - 02731008 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2016-11-09 16:37 - 2016-10-25 07:24 - 04456448 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2016-11-09 16:37 - 2016-10-25 07:21 - 01570816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe 2016-11-09 16:37 - 2016-10-25 07:21 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\licensingdiag.exe 2016-11-09 16:37 - 2016-10-25 07:16 - 03415040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2016-11-09 16:37 - 2016-10-25 07:11 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll 2016-11-09 16:37 - 2016-10-25 07:09 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2016-11-09 16:37 - 2016-10-25 07:03 - 06675968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2016-11-09 16:37 - 2016-10-25 07:01 - 01755648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll 2016-11-09 16:37 - 2016-10-25 06:52 - 00693760 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll 2016-11-09 16:37 - 2016-10-25 06:47 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2016-11-09 16:37 - 2016-10-25 06:47 - 00453632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AdmTmpl.dll 2016-11-09 16:37 - 2016-10-25 06:35 - 02902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll 2016-11-09 16:37 - 2016-10-25 06:26 - 02563584 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll 2016-11-09 16:37 - 2016-10-25 06:13 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2016-11-09 16:37 - 2016-10-25 06:10 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll 2016-11-09 16:37 - 2016-10-25 06:03 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll 2016-11-09 16:37 - 2016-10-25 05:44 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2016-11-09 16:37 - 2016-10-25 05:43 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll 2016-11-06 04:15 - 2016-11-06 04:15 - 95043584 _____ C:\WINDOWS\system32\config\SOFTWARE.iobit 2016-11-06 04:15 - 2016-11-06 04:15 - 06832128 _____ C:\WINDOWS\system32\config\DRIVERS.iobit 2016-11-06 04:15 - 2016-11-06 04:15 - 00434176 _____ C:\WINDOWS\system32\config\DEFAULT.iobit 2016-11-06 04:15 - 2016-11-06 04:15 - 00069632 _____ C:\WINDOWS\system32\config\SAM.iobit 2016-11-06 04:15 - 2016-11-06 04:15 - 00032768 _____ C:\WINDOWS\system32\config\SECURITY.iobit 2016-11-06 04:07 - 2016-11-06 04:07 - 72520720 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat 2016-11-06 04:07 - 2016-11-06 04:07 - 07172920 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 07096192 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 06264640 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 05664483 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT 2016-11-06 04:07 - 2016-11-06 04:07 - 05339560 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 03283248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 03282544 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 03199232 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 02895104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl 2016-11-06 04:07 - 2016-11-06 04:07 - 02058496 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 02050184 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01965816 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01959608 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01780624 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01591064 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01508936 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01355616 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01061120 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00965032 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00743968 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00727440 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00708320 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00689888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00678192 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00677680 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00574760 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00532384 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00504312 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00445408 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00441272 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00387320 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00371456 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00362064 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00330568 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00327464 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00310432 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00272720 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00253904 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00253872 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00252880 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00231920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00221976 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00214840 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00209544 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00166208 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00134208 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00122328 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00118600 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00110992 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00090920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00088352 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00088328 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00084624 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll 2016-11-06 04:00 - 2016-11-08 14:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4 2016-11-06 04:00 - 2016-11-06 04:00 - 00003370 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler 2016-11-03 15:13 - 2016-11-03 15:13 - 00680212 _____ C:\WINDOWS\ProcessedPackets.KTL 2016-11-03 15:13 - 2016-11-03 15:13 - 00576091 _____ C:\WINDOWS\Packet.KTL 2016-11-03 15:13 - 2016-11-03 15:13 - 00288104 _____ C:\WINDOWS\SentOSPackets.KTL 2016-11-03 15:13 - 2016-11-03 15:13 - 00288088 _____ C:\WINDOWS\Control.KTL 2016-11-03 15:13 - 2016-11-03 15:13 - 00004123 _____ C:\WINDOWS\NGIControl.KTL 2016-10-23 13:47 - 2016-11-08 14:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ElsterFormular |
18.11.2016, 13:22 | #2 |
| Malwarefund Win32/Herz.B Teil 2 Frst.txt
__________________Code:
ATTFilter ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-11-18 11:15 - 2013-05-01 00:06 - 00000000 ____D C:\Users\u\AppData\Roaming\Free Download Manager 2016-11-18 11:13 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-11-18 11:13 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-11-18 11:02 - 2016-04-26 23:22 - 00000000 ____D C:\Users\u\AppData\Roaming\Wise Uninstaller 2016-11-18 11:00 - 2016-04-17 13:05 - 00002460 _____ C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_UK 2016-11-18 11:00 - 2016-04-17 13:05 - 00000286 _____ C:\WINDOWS\Tasks\Uninstaller_SkipUac_UK.job 2016-11-18 11:00 - 2016-04-17 13:05 - 00000000 ____D C:\ProgramData\ProductData 2016-11-18 11:00 - 2016-04-17 13:05 - 00000000 ____D C:\Program Files (x86)\IObit 2016-11-18 10:59 - 2013-04-25 21:16 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-11-18 10:57 - 2015-06-23 19:08 - 00001222 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002UA.job 2016-11-18 10:57 - 2015-06-23 19:08 - 00001170 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002Core.job 2016-11-18 10:50 - 2015-07-29 01:24 - 00000000 ____D C:\ProgramData\MFAData 2016-11-17 23:26 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF 2016-11-17 12:25 - 2016-04-17 13:05 - 00000000 ____D C:\Users\u\AppData\Roaming\IObit 2016-11-17 03:49 - 2016-04-17 13:05 - 00000000 ____D C:\Users\u\AppData\LocalLow\IObit 2016-11-17 03:42 - 2013-05-14 13:34 - 00000000 __RDO C:\Users\u\SkyDrive 2016-11-17 03:41 - 2016-07-23 03:08 - 00000000 ___DC C:\WINDOWS\Panther 2016-11-17 03:34 - 2016-07-24 11:19 - 00000000 ____D C:\Users\Administrator 2016-11-17 03:24 - 2016-04-17 14:55 - 00003008 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (UK) 2016-11-17 03:07 - 2016-04-17 13:05 - 00000000 ____D C:\ProgramData\IObit 2016-11-17 02:54 - 2016-05-12 11:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 2016-11-17 02:47 - 2016-07-23 02:33 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-11-17 02:47 - 2016-04-27 06:13 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat 2016-11-17 02:47 - 2016-04-27 06:13 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat 2016-11-17 02:44 - 2016-07-23 02:15 - 00000000 ____D C:\Users\u 2016-11-17 02:44 - 2016-04-27 06:55 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-11-17 02:40 - 2016-07-23 13:21 - 00000000 ____D C:\ProgramData\NVIDIA 2016-11-17 02:40 - 2016-04-27 06:48 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-11-17 02:39 - 2016-04-26 21:44 - 00410448 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-11-17 02:39 - 2015-04-13 02:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-11-17 02:38 - 2015-10-30 07:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI 2016-11-17 02:35 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\F12 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PrintDialog 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\migwiz 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Provisioning 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Defender 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2016-11-16 15:01 - 2016-09-21 03:28 - 00003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task 2016-11-16 01:45 - 2015-10-30 07:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2016-11-14 21:48 - 2015-09-15 23:05 - 00002268 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-11-14 20:16 - 2013-05-14 15:06 - 00000000 ____D C:\Users\u\AppData\LocalLow\Temp 2016-11-14 20:12 - 2013-07-30 17:59 - 00000000 ____D C:\Users\u\AppData\Roaming\Spotify 2016-11-14 20:05 - 2013-07-30 17:59 - 00000000 ____D C:\Users\u\AppData\Local\Spotify 2016-11-14 15:55 - 2013-04-26 00:09 - 00000000 ____D C:\Users\u\AppData\Roaming\Skype 2016-11-12 01:00 - 2013-06-17 11:51 - 00000000 ____D C:\Users\u\AppData\Roaming\Dropbox 2016-11-10 14:29 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-11-10 14:29 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-11-10 10:52 - 2015-06-23 19:08 - 00004334 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002UA 2016-11-10 10:52 - 2015-06-23 19:08 - 00003958 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002Core 2016-11-09 18:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-11-09 18:04 - 2013-07-24 19:22 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-11-09 17:58 - 2013-02-01 06:09 - 141011376 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-11-09 15:48 - 2016-04-27 06:17 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-11-09 11:11 - 2016-07-17 00:55 - 00000000 ___HD C:\$WINDOWS.~BT 2016-11-09 03:33 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Registration 2016-11-09 03:32 - 2013-10-17 18:12 - 00022863 _____ C:\WINDOWS\diagwrn.xml 2016-11-09 03:32 - 2013-10-17 18:12 - 00022863 _____ C:\WINDOWS\diagerr.xml 2016-11-08 19:13 - 2016-07-23 03:48 - 00000000 ____D C:\WINDOWS\Minidump 2016-11-08 19:12 - 2013-12-08 18:52 - 00000000 ____D C:\Users\u\AppData\Local\Foxit Reader 2016-11-08 14:20 - 2016-07-23 13:19 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-11-08 14:20 - 2016-04-27 06:13 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2016-11-08 14:20 - 2016-04-26 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Program Uninstaller 2016-11-08 14:20 - 2016-04-15 13:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 2016-11-08 14:20 - 2016-04-12 10:54 - 00000000 ____D C:\WINDOWS\de 2016-11-08 14:20 - 2016-03-22 14:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\winahnen 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\spool 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\InputMethod 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\IME 2016-11-08 14:20 - 2015-01-30 14:36 - 00000000 ____D C:\WINDOWS\system32\appmgmt 2016-11-08 14:20 - 2014-11-11 18:19 - 00000000 ____D C:\WINDOWS\SysWOW64\vbox 2016-11-08 14:20 - 2014-11-11 18:19 - 00000000 ____D C:\WINDOWS\system32\vbox 2016-11-08 14:20 - 2014-08-19 21:42 - 00000000 ____D C:\WINDOWS\SysWOW64\Adobe 2016-11-08 14:20 - 2014-07-16 17:39 - 00000000 ____D C:\WINDOWS\SysWOW64\SafeMonk 2016-11-08 14:20 - 2013-11-06 22:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2016-11-08 14:20 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared 2016-11-08 14:20 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared 2016-11-08 14:20 - 2013-02-01 08:43 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\sl 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\nl 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\it 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\hu 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\fr 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\da 2016-11-08 14:20 - 2012-07-26 10:43 - 00000000 ____D C:\WINDOWS\en-GB 2016-11-08 14:19 - 2016-10-18 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-11-08 14:19 - 2016-10-02 19:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow 2016-11-08 14:19 - 2016-10-02 19:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ColdCut 2016-11-08 14:19 - 2016-07-23 13:19 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-11-08 14:19 - 2016-07-23 13:19 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-11-08 14:19 - 2016-05-25 13:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-11-08 14:19 - 2016-05-11 11:19 - 00000000 ____D C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Multimedia Mouse Driver 2016-11-08 14:19 - 2016-05-10 16:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader 2016-11-08 14:19 - 2016-01-06 16:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity 2016-11-08 14:19 - 2015-12-25 14:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-11-08 14:19 - 2015-12-20 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser in the Box 2016-11-08 14:19 - 2015-12-07 20:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiCryptoWall 2016-11-08 14:19 - 2015-11-13 12:51 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2 2016-11-08 14:19 - 2015-11-05 00:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2016-11-08 14:19 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-11-08 14:19 - 2015-09-05 16:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc 2016-11-08 14:19 - 2015-07-23 01:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2016-11-08 14:19 - 2015-05-10 12:18 - 00000000 ____D C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2016-11-08 14:19 - 2015-05-02 01:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon 2016-11-08 14:19 - 2014-12-15 15:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Audio 2016-11-08 14:19 - 2014-10-06 12:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo Backup Free 7.5 2016-11-08 14:19 - 2014-10-06 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 10.1 2016-11-08 14:19 - 2014-07-10 17:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlightGear 2.4.0 2016-11-08 14:19 - 2014-07-10 16:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex 2016-11-08 14:19 - 2013-11-02 19:03 - 00000000 ____D C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DirSync 2016-11-08 14:19 - 2013-10-27 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3Gain 2016-11-08 14:19 - 2013-10-02 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SeaMonkey 2016-11-08 14:19 - 2013-09-06 13:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 2016-11-08 14:19 - 2013-08-22 16:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy 2016-11-08 14:19 - 2013-08-21 22:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MediaMonkey 2016-11-08 14:19 - 2013-07-20 13:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2016-11-08 14:19 - 2013-07-03 17:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solid Edge 2D Drafting ST5 2016-11-08 14:19 - 2013-05-14 13:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva 2016-11-08 14:19 - 2013-05-01 00:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager 2016-11-08 14:19 - 2013-04-28 18:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bing-Desktop 2016-11-08 14:19 - 2013-04-26 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup 2016-11-08 14:19 - 2013-04-26 18:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Maustreiber 2016-11-08 14:19 - 2013-04-26 18:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-11-08 14:19 - 2013-04-25 23:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler 2016-11-08 14:19 - 2013-04-25 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView 2016-11-08 14:19 - 2013-02-01 08:13 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2016-11-08 14:19 - 2013-02-01 08:10 - 00000000 ____D C:\Program Files\Intel 2016-11-08 14:19 - 2013-02-01 08:06 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PhotoDirector 3 2016-11-08 14:19 - 2013-02-01 08:00 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HomeCinema 2016-11-08 14:19 - 2013-02-01 07:57 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover 2016-11-08 14:19 - 2013-02-01 07:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medion MediaPack 3 2016-11-08 11:59 - 2013-04-25 21:16 - 00003870 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-11-06 04:09 - 2016-07-23 02:12 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2016-11-06 04:09 - 2016-07-23 02:12 - 00000000 ____D C:\WINDOWS\system32\DAX2 2016-11-06 04:07 - 2016-07-24 15:51 - 05200128 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys 2016-11-06 04:07 - 2016-07-24 15:51 - 03087472 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll 2016-11-06 04:07 - 2016-07-24 15:51 - 00447728 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll 2016-11-06 04:07 - 2016-07-24 15:51 - 00192992 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll 2016-11-06 04:07 - 2016-07-24 15:51 - 00151792 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll 2016-11-06 04:07 - 2016-07-24 15:51 - 00023696 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll 2016-11-02 11:09 - 2013-07-20 13:19 - 00000000 ____D C:\Users\u\AppData\Local\Google 2016-10-30 17:05 - 2013-06-15 19:24 - 00000000 ____D C:\Users\u\AppData\Roaming\vlc 2016-10-28 22:48 - 2015-10-30 08:26 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-10-28 22:48 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-10-28 21:37 - 2013-02-01 07:52 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-10-28 21:37 - 2013-02-01 07:52 - 00000000 ____D C:\ProgramData\Skype 2016-10-25 09:58 - 2016-04-27 06:48 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2016-10-23 13:49 - 2014-05-24 22:43 - 00000000 ____D C:\ProgramData\elsterformular 2016-10-23 13:47 - 2014-05-24 22:42 - 00000000 ____D C:\Program Files (x86)\ElsterFormular 2016-10-22 01:38 - 2015-01-30 14:41 - 00000000 ____D C:\Program Files\Java 2016-10-22 01:38 - 2013-09-26 21:34 - 00000000 ____D C:\ProgramData\Oracle 2016-10-22 01:37 - 2016-05-25 13:46 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2016-10-20 19:00 - 2013-04-27 11:27 - 00074752 _____ C:\Users\u\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-10-19 09:35 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2004-01-21 18:29 - 2004-01-21 14:52 - 2863868 _____ () C:\Program Files (x86)\CADtools.aip 2016-04-26 23:22 - 2016-04-26 23:22 - 0000376 _____ () C:\Users\u\AppData\Roaming\wpulog.txt 2013-04-27 11:27 - 2016-10-20 19:00 - 0074752 _____ () C:\Users\u\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-04-26 00:22 - 2015-12-08 12:38 - 0007652 _____ () C:\Users\u\AppData\Local\resmon.resmoncfg 2016-07-23 02:12 - 2016-07-23 02:12 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-11-13 17:39 ==================== Ende von FRST.txt ============================ |
18.11.2016, 13:24 | #3 |
| Malwarefund Win32/Herz.B Addition.txt
__________________Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 16-11-2016 durchgeführt von UK (18-11-2016 11:34:10) Gestartet von D:\Downloads\malware apps Windows 10 Pro Version 1511 (X64) (2016-07-23 02:06:14) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2736805842-114790362-3470889979-500 - Administrator - Enabled) => C:\Users\Administrator BitBox (S-1-5-21-2736805842-114790362-3470889979-1036 - Limited - Enabled) DefaultAccount (S-1-5-21-2736805842-114790362-3470889979-503 - Limited - Disabled) Gast (S-1-5-21-2736805842-114790362-3470889979-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2736805842-114790362-3470889979-1039 - Limited - Enabled) UK (S-1-5-21-2736805842-114790362-3470889979-1002 - Administrator - Enabled) => C:\Users\u ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: IObit Malware Fighter (Disabled - Out of date) {4D381C57-3C7A-6F22-07EB-639F49E836D4} AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} AS: IObit Malware Fighter (Enabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated) Adobe Illustrator 10.0.3 (HKLM-x32\...\{412033BC-44CF-48D9-B813-4B835101F4D3}) (Version: 10.0.3 - Adobe Systems, Inc.) Adobe Photoshop 7.0 (HKLM-x32\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.) Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version: 3.0 - Adobe Systems, Inc.) Advanced SystemCare 10 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 10.0.3 - IObit) Amazon Kindle (HKLM-x32\...\Amazon Kindle) (Version: - Amazon) Amazon Kindle (HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Amazon Kindle) (Version: 1.14.0.43019 - Amazon) AntiCryptoWall (HKLM\...\{BE40AB1F-558F-4434-B72F-461EF97E7796}_is1) (Version: 1.0.9.1 - Bitdefender) Ashampoo AppLauncher (Medion) v.1.0.0 (HKLM-x32\...\Ashampoo AppLauncher (Medion)_is1) (Version: 1.0.0 - Ashampoo GmbH & Co. KG) Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team) Autodesk 3ds Max 2011 64-Bit (HKLM\...\{39BFB02A-9692-0407-A808-3F5C7B1F8953}) (Version: 13.0 - Autodesk) AVG (Version: 16.121.7859 - AVG Technologies) Hidden AVG 2016 (Version: 16.0.4664 - AVG Technologies) Hidden AVG Protection (HKLM\...\AVG) (Version: 2016.121.7859 - AVG Technologies) Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.2.126.0 - Microsoft Corporation) Browser in the Box (HKLM-x32\...\BitBox) (Version: 4.1.4-r150 - Sirrix AG) CCleaner (HKLM\...\CCleaner) (Version: 5.22 - Piriform) CDex - Open Source Digital Audio CD Extractor (HKLM-x32\...\CDex) (Version: 1.70.5.2014 - Georgy Berdyshev) Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.53 - Cliqz.com) ColdCut (HKLM-x32\...\{8944ED10-DBF2-4FA9-8B5D-D7E1B046C761}_is1) (Version: ColdCut - © Jan Brummelte) CyberLink PhotoNow (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.7717 - CyberLink Corp.) CyberLink PowerDirector (Version: 9.0.0.3815c - CyberLink Corp.) Hidden CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.7.0.0913 - CyberLink Corp.) CyberLink PowerRecover (Version: 5.7.0.0913 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DC Magic Audio (HKLM-x32\...\DCMaUnInstall) (Version: - ) Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform) DirSync 2.96 (HKLM-x32\...\DirSync) (Version: - Stephen Kalisch) Driver Booster 4.0 (HKLM-x32\...\Driver Booster_is1) (Version: 4.0.4 - IObit) Dropbox (HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Dropbox) (Version: 14.4.19 - Dropbox, Inc.) EaseUS Partition Master 10.1 (HKLM-x32\...\EaseUS Partition Master_is1) (Version: - EaseUS) EaseUS Todo Backup Free 7.5 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 7.5 - CHENGDU YIWO Tech Development Co., Ltd) ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 17.4.19695 - Landesfinanzdirektion Thüringen) EPSON BX535WD Series Printer Uninstall (HKLM\...\EPSON BX535WD Series) (Version: - SEIKO EPSON Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EpsonNet Config V4 (HKLM-x32\...\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.1.1 - SEIKO EPSON CORPORATION) EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) ffdshow [rev 2946] [2009-05-15] (HKLM-x32\...\ffdshow_is1) (Version: 1.0 - ) FlightGear 2.4.0 (HKLM-x32\...\FlightGear 2.4.0_is1) (Version: - The FlightGear Team) FMW 1 (Version: 1.132.1 - AVG Technologies) Hidden FormatFactory 3.6.0.0 (HKLM-x32\...\FormatFactory) (Version: 3.6.0.0 - Format Factory) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.3.6.321 - Foxit Software Inc.) Free Download Manager 3.9.3 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG) Free YouTube to MP3 Converter version 3.12.60.713 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.60.713 - DVDVideoSoft Ltd.) Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden GIMP 2.8.4 (HKLM\...\GIMP-2_is1) (Version: 2.8.4 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.99 - Google Inc.) Google Earth (HKLM-x32\...\{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}) (Version: 7.1.1.1888 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{DA2600C1-6BDF-4FD1-1212-148929CC1385}) (Version: 2.6.1212.0302 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.7.0.1013 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel(R) WiDi (HKLM\...\{23D486D4-FBE0-40F3-A245-E4D56D094764}) (Version: 3.5.41.0 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{2b83a547-7e0f-4dca-8990-97ff818fa3d8}) (Version: 15.6.0 - Intel Corporation) IObit Malware Fighter 4 (HKLM-x32\...\IObit Malware Fighter_is1) (Version: 4.4 - IObit) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) KRISTAL Audio Engine (HKLM-x32\...\KRISTAL Audio Engine) (Version: - ) LatencyMon 6.00 (HKLM\...\LatencyMon_is1) (Version: - Resplendence Software Projects Sp.) Launch Manager (HKLM-x32\...\{D0846526-66DD-4DC9-A02C-98F9A2806812}) (Version: 1.5.1.8 - Wistron Corp.) MediaMonkey 4.1 (HKLM-x32\...\MediaMonkey_is1) (Version: 4.1 - Ventis Media Inc.) Mediathek (HKLM-x32\...\{EFFED0C0-5299-422E-AFE6-8B8066D18A2A}) (Version: 1.4.0 - Medion) Medion Home Cinema 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) Medion Home Cinema 10 (x32 Version: 10.1924 - CyberLink Corp.) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{e6e75766-da0f-4ba2-9788-6ea593ce702d}) (Version: 12.0.30501.0 - Microsoft Corporation) MouseDriver (HKLM-x32\...\{643E1970-324F-474C-8610-55F3F053BC01}) (Version: 1.00.0000 - ) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek) Mozilla Firefox 50.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.0 (x86 de)) (Version: 50.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.0.0.6152 - Mozilla) Multimedia Mouse Driver (HKLM-x32\...\InstallShield_{A9495514-098A-4869-A464-C455857BC464}) (Version: 2.0 - Ihr Firmenname) Multimedia Mouse Driver (x32 Version: 2.0 - Ihr Firmenname) Hidden MyFreeCodec (HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\MyFreeCodec) (Version: - ) NVIDIA 3D Vision Treiber 353.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.62 - NVIDIA Corporation) NVIDIA Grafiktreiber 353.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.62 - NVIDIA Corporation) NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation) OpenOffice 4.1.2 (HKLM-x32\...\{E6AD67BB-1C33-4AB3-A387-E0D48137AB70}) (Version: 4.12.9782 - Apache Software Foundation) OpenOffice 4.1.2 Language Pack (German) (HKLM-x32\...\{E0E6DB8D-D2B1-4A0B-A09C-44DBC09BF499}) (Version: 4.12.9782 - Apache Software Foundation) Oracle VM VirtualBox 5.0.10_Sirrix (HKLM\...\{15DB0BEC-4D4B-4471-9E37-2FB454965C05}) (Version: 5.0.10 - Sirrix AG) paint.net (HKLM\...\{F509C1F4-0029-49F9-B145-A4C4E8DF481A}) (Version: 4.0.3 - dotPDN LLC) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.) Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Reader for PC (HKLM-x32\...\{D279DFB7-97A3-439D-8BE9-95D8AFA68562}) (Version: 2.4.01.10241 - Sony Corporation) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7794 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.46 - Piriform) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.) Hidden Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.) SeaMonkey 2.40 (x86 de) (HKLM-x32\...\SeaMonkey 2.40 (x86 de)) (Version: 2.40 - Mozilla) Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.16034.4 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.1.16034.4 - Samsung Electronics Co., Ltd.) Hidden Solid Edge 2D Drafting ST5 (HKLM-x32\...\{6AE4221E-7BB6-4D22-A157-5AA0F206EF30}) (Version: 105.00.01015 - Siemens) Spotify (HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Spotify) (Version: 1.0.42.151.g19de0aa6 - Spotify AB) Sweet Home 3D version 4.6 (HKLM\...\Sweet Home 3D_is1) (Version: - eTeks) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.19.1 - Synaptics Incorporated) Unity (HKLM-x32\...\Unity) (Version: - Unity Technologies ApS) Unity Web Player (HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\UnityWebPlayer) (Version: 5.3.6f1 - Unity Technologies ApS) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Vulkan Run Time Libraries 1.0.5.1 (HKLM\...\VulkanRT1.0.5.1) (Version: 1.0.5.1 - LunarG, Inc.) Winahnen 6.51 (HKLM-x32\...\Winahnen) (Version: 6.51 - Cyberlab GmbH) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Wise Program Uninstaller 1.96 (HKLM-x32\...\Wise Program Uninstaller_is1) (Version: 1.96 - WiseCleaner.com, Inc.) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll () CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0BD5A988-59E8-49BB-9365-4E1725064C36} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {214D3269-76F4-4291-B9E5-7525B5B3FCBE} - System32\Tasks\ASC10_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-11-10] (IObit) Task: {247308E9-66CE-4324-B318-3ED1EBB0ECF8} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002Core => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {2C74D5F8-22E0-4A30-A58C-4462427CA7D0} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-11-09] (Microsoft Corporation) Task: {2FB4CFDF-3396-4702-BD4F-C1C371F43971} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-09-22] (Oracle Corporation) Task: {3802260F-4C4B-4948-8980-03EF66E049CF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {4B1BFEF3-AA86-4DD7-A4E8-A675A283752E} - System32\Tasks\Uninstaller_SkipUac_UK => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe Task: {500250FB-2304-49FF-B3D3-15DA6D2E338A} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG Task: {569AF090-9860-4BD5-A4CF-A91B7CF1FE83} - System32\Tasks\Defraggler Volume C Task => C:\Program Files\Defraggler\df64.exe [2016-03-08] (Piriform Ltd) Task: {5B3A3A2A-B5C5-4ADC-9A8C-6EA6EB1EDC90} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {606A4DE5-12F6-455C-A32C-1B203E403503} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Keine Datei <==== ACHTUNG Task: {640E7F00-9D80-4AAA-A0AA-E62828580740} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {6AD5537A-83EA-4E26-86D0-2F7FBEF13D71} - System32\Tasks\ASC10_SkipUac_UK => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-11-11] (IObit) Task: {6D3DFBB8-08BE-4544-BC25-6F8EC54BC860} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> Keine Datei <==== ACHTUNG Task: {6DAC5A9A-A3DF-46AE-9C33-416F3191CA51} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {6DC35D43-D1FB-428B-98B6-4058DA64BE3D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {77985C08-6D66-46E5-88EB-6CEE7604899B} - \Microsoft\Windows\Setup\gwx\rundetector -> Keine Datei <==== ACHTUNG Task: {87721D04-8D72-4F96-AC0C-EA284D9B9F71} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {905FB805-E39D-4CF4-835F-829B8907356F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {98A2E36E-6902-4350-BB0C-B0DBBB4F8159} - System32\Tasks\AVG-SSU_1116av_DELETE => C:\ProgramData\Avg_Update_1116av\AVG-Secure-Search-Update_1116av.exe [2016-06-27] () Task: {9A17E40C-5123-43F9-BA94-AD68160A9458} - System32\Tasks\AVG-SSU_1116sp_DELETE => C:\ProgramData\Avg_Update_1116sp\AVG-Secure-Search-Update_1116sp.exe [2016-11-08] () Task: {9BC69F5F-77BC-4BAC-9651-0B346EA4A320} - System32\Tasks\Synaptics TouchPad Enhancements => Program Files\Synaptics\SynTP\SynTPEnh.exe Task: {A2104205-7A54-472D-ABFC-AE12D9BB6B90} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {ABD0E0FE-32B4-48E1-82EB-D8B34E0728F0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {AD2C4855-CAB9-420C-8B53-4E7AE96479C4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-26] (Piriform Ltd) Task: {B3473A15-8F0E-48DF-93D3-499B8BEECCD8} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG Task: {BB82A172-7AA9-4CFC-9932-DE373FE3E9D5} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002UA => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {BDDBCBA1-6C7F-4D79-BA99-E5D6AE466E1E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {C3CB5C01-A5A4-4D89-9483-1FFFAAEE19C6} - System32\Tasks\AVG-SSU_1116av => C:\ProgramData\Avg_Update_1116av\AVG-Secure-Search-Update_1116av.exe [2016-06-27] () Task: {C5A8771C-782B-4082-B79A-FB8E3ADCD3F2} - System32\Tasks\{5043C671-56F2-4441-BD17-E62D27136F46} => pcalua.exe -a "C:\Program Files (x86)\pazera-software\MOV_to_AVI_Converter\unins000.exe" -d "C:\Program Files (x86)\pazera-software\MOV_to_AVI_Converter" Task: {C87E602A-82BA-4025-87C8-0BF70E0062B6} - System32\Tasks\{4E86AB65-D547-4799-BFA7-96F9D06FD3D7} => pcalua.exe -a "J:\backup\Downloads\GRAFIK\illustrator10\CADtools 3\Install Hot Door CADtools.exe" -d "J:\backup\Downloads\GRAFIK\illustrator10\CADtools 3" Task: {DC0EB0F0-2991-4968-AAD8-FCDFA9444125} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {E23EA3DC-6853-494B-9B8C-A7F113B1B65A} - System32\Tasks\Driver Booster SkipUAC (UK) => C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DriverBooster.exe [2016-10-09] (IObit) Task: {EBE2E9D9-E35D-46E3-BBA5-ED2F6CDC96F5} - System32\Tasks\AVG-SSU_1116sp => C:\ProgramData\Avg_Update_1116sp\AVG-Secure-Search-Update_1116sp.exe [2016-11-08] () Task: {F24B0DCE-7E54-4C06-88CD-03FC83A4120D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-08] (Adobe Systems Incorporated) Task: {F3AE50C8-80D6-46F8-9793-5B3D2F2CB57E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {FD77217B-EA1D-4D9D-A217-274FFEF19337} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\4.0.4\Scheduler.exe [2016-09-20] (IObit) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\Defraggler Volume C Task.job => Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002Core.job => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002UA.job => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_UK.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MEDIONhome.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.medion.com ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Welcome.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.aldi-essen.de ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 08:17 - 2015-10-30 08:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-07-23 13:20 - 2015-07-23 02:10 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-11-09 16:38 - 2016-10-25 10:42 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-11-09 16:38 - 2016-10-25 10:42 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-07-23 03:11 - 2016-07-23 03:11 - 00959168 _____ () C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\ClientTelemetry.dll 2016-11-17 02:12 - 2016-06-27 08:04 - 02049096 _____ () C:\ProgramData\Avg_Update_1116av\AVG-Secure-Search-Update_1116av.exe 2016-11-14 18:05 - 2016-11-08 15:39 - 01863752 _____ () C:\ProgramData\Avg_Update_1116sp\AVG-Secure-Search-Update_1116sp.exe 2016-04-27 06:17 - 2016-04-27 06:17 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-23 13:16 - 2016-07-01 04:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-11-09 16:39 - 2016-10-25 05:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-09 16:38 - 2016-10-25 05:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-09 16:39 - 2016-10-25 05:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-09 16:39 - 2016-10-25 05:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-08-26 19:25 - 2016-08-26 19:25 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2016-07-23 13:32 - 2016-07-23 13:32 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-11-05 00:47 - 2016-04-07 14:15 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll 2013-02-01 08:10 - 2012-06-25 09:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-05-01 00:06 - 2013-01-11 02:17 - 00105984 _____ () C:\Program Files (x86)\Free Download Manager\fdmumsp.dll 2016-07-23 13:32 - 2016-07-23 13:32 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-07-23 13:32 - 2016-07-23 13:32 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-11-17 02:54 - 2016-08-18 18:43 - 00442144 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madExcept_.bpl 2016-11-17 02:54 - 2016-08-18 18:43 - 00210720 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madBasic_.bpl 2016-11-17 02:54 - 2016-08-18 18:43 - 00059680 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madDisAsm_.bpl 2016-11-17 02:54 - 2016-11-01 10:11 - 00078624 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\GetProcessDLL.dll 2016-11-17 02:56 - 2016-03-31 17:57 - 00899872 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\webres.dll 2016-11-17 02:56 - 2016-03-31 17:57 - 00188704 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\unrar.dll 2016-11-17 02:56 - 2016-03-31 17:57 - 00151840 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\zlibwapi.dll 2016-11-17 02:56 - 2016-03-31 17:57 - 00625440 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\ProductStatistics.dll 2016-11-17 02:56 - 2016-03-31 17:57 - 00625440 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll 2016-11-17 02:56 - 2016-03-31 17:57 - 00355616 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\madExcept_.bpl 2016-11-17 02:56 - 2016-03-31 17:57 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\madBasic_.bpl 2016-11-17 02:56 - 2016-03-31 17:57 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\madDisAsm_.bpl 2013-05-01 00:06 - 2013-10-04 13:38 - 03560960 _____ () C:\Program Files (x86)\Free Download Manager\fdmbtsupp.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PAexec => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1001movie.com -> 1001movie.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1001night.biz -> 1001night.biz IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\100gal.net -> 100gal.net IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\100sexlinks.com -> 100sexlinks.com Da befinden sich 4788 mehr Seiten. ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\u\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\irfanview_wallpaper.bmp HKU\S-1-5-21-2736805842-114790362-3470889979-500\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\startupreg: BingDesktop => c:\program files (x86)\microsoft\bingdesktop\bingdesktop.exe /fromkey MSCONFIG\startupreg: EaseUS EPM tray => c:\program files (x86)\easeus\easeus partition master 10.1\bin\epmnews.exe MSCONFIG\startupreg: iWareV3 => c:\program files (x86)\hamamousedriver\officemouse.exe HKLM\...\StartupApproved\Run: => "BTMTrayAgent" HKLM\...\StartupApproved\Run: => "NvBackend" HKLM\...\StartupApproved\Run32: => "CLMLServer_For_P2G8" HKLM\...\StartupApproved\Run32: => "CLVirtualDrive" HKLM\...\StartupApproved\Run32: => "RemoteControl10" HKLM\...\StartupApproved\Run32: => "YouCam Service" HKLM\...\StartupApproved\Run32: => "BingDesktop" HKLM\...\StartupApproved\Run32: => "EaseUS EPM tray" HKLM\...\StartupApproved\Run32: => "Reader Application Helper" HKLM\...\StartupApproved\Run32: => "KMConfig" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\StartupFolder: => "Dropbox.lnk" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\StartupFolder: => "An OneNote senden.lnk" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "SkyDrive" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "Power2GoExpress8" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "Spotify Web Helper" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "OKAYFREEDOM_Agent" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "Dropbox Update" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{4D4C9AD9-356F-4BFA-97FA-16244E817834}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{146E9894-E3CE-47DC-A95B-8FC9E0ECA636}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{047977D7-43F7-41D0-A3EC-BB1CF97D5B61}] => (Allow) LPort=1900 FirewallRules: [{F5FF2534-1B73-4E39-AC75-2E59DCE4FEBB}] => (Allow) LPort=2869 FirewallRules: [{343B8EF5-AD71-40DC-BAB7-AFD84845CC2E}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [UDP Query User{3821B853-4841-4163-A0D3-6FB2B599D721}C:\program files (x86)\freetime\formatfactory\formatfactory.exe] => (Allow) C:\program files (x86)\freetime\formatfactory\formatfactory.exe FirewallRules: [TCP Query User{D365C419-7280-4005-9EAC-659970EAF00A}C:\program files (x86)\freetime\formatfactory\formatfactory.exe] => (Allow) C:\program files (x86)\freetime\formatfactory\formatfactory.exe FirewallRules: [{245055FD-A157-44DB-B4FC-A996A22E088C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{C294BFF7-DCAB-4B69-A38B-02D3C528607A}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{DFBF42E0-4C71-430B-B1CE-8062419FED92}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{D2066F37-5662-48B8-A689-FB1EE3F82333}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{AC814D30-FA2E-44E0-8DB7-A5AB7EF33C54}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe FirewallRules: [{AF45708B-A877-49FD-9560-E963E09EEC5D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{04C2C747-A2F8-4774-9348-F8691706677A}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [UDP Query User{C1A9CAD9-5997-4419-A652-5B7F453CD2BA}C:\users\u\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\u\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{6CFCC5B2-469F-4E8D-A8A4-BD6D3B04D2FF}C:\users\u\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\u\appdata\roaming\spotify\spotify.exe FirewallRules: [{1CC73DFC-D009-450A-9092-AA8020FB8074}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{989D5291-5062-4C9D-A812-8641CC7AD9AD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5E3F33AC-D82E-4500-B331-F89B63496553}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{B9033C8B-5CD6-431F-A3BF-82429B1DE042}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{7CCAC3FE-9832-4310-889D-70EF859CD487}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe FirewallRules: [{4C03A924-1E11-4002-8202-1D0D4B495167}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{5D8C0ED3-DEB5-40E9-9F36-C777624753A8}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{8BCA876E-C56A-4407-9A8D-856517AA77C1}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{1E78C583-9717-4244-84DB-76BCFC22C833}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{EF944702-B94D-45F2-9B0E-5811E40E5989}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{CE0966CA-B266-46CC-984C-CBF587451532}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{09887BFF-029C-403B-8B53-08E54CFFA49E}] => (Allow) C:\Program Files (x86)\ElsterFormular\bin\pica.exe FirewallRules: [{3224EFAA-5BAA-42F6-AB8D-D467E8C9CB6D}] => (Allow) C:\Program Files (x86)\ElsterFormular\bin\pica.exe FirewallRules: [{932E0581-99ED-4E1C-B0BA-DCA7C35FB7E8}] => (Allow) C:\Program Files (x86)\ElsterFormular\bin\pica.exe FirewallRules: [{3CA21043-CBBF-46DC-BCC0-28050F77FBCC}] => (Allow) C:\Program Files (x86)\ElsterFormular\bin\pica.exe FirewallRules: [UDP Query User{A8229A15-0C45-42BD-8FC2-5C1D458E213D}C:\program files (x86)\mediamonkey\mediamonkey.exe] => (Allow) C:\program files (x86)\mediamonkey\mediamonkey.exe FirewallRules: [TCP Query User{517092E8-B102-48CE-A4D1-5B4009E2DDEB}C:\program files (x86)\mediamonkey\mediamonkey.exe] => (Allow) C:\program files (x86)\mediamonkey\mediamonkey.exe FirewallRules: [UDP Query User{C6C09EC6-0D7B-451B-9661-2A0E694BACCA}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [TCP Query User{AA849031-F27A-4B9F-A99D-F0144DC08DF3}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [{5257C427-CFFC-49FD-972D-AF35E0A1C61C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{13D13049-ACB6-44B8-96BB-FCF92AEBAB24}] => (Allow) C:\Program Files\CyberLink\PowerDirector\PDR9.EXE FirewallRules: [{07914CAC-C34D-4187-BBAE-D1CAA6D2ABDC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{1CD9D222-A437-4DAE-A8CB-DFB885ED5E95}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{FD060A25-41C1-4BE2-B90C-92DA496DD612}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe FirewallRules: [{783FF671-AE0D-4A75-AA01-2BB9E3FC8FE3}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe FirewallRules: [{E3E045E5-F501-4BE2-AA27-5C0170451BFE}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Config V4\ENConfig.exe FirewallRules: [{65A8A1C7-4F46-4F9B-8B4E-C08958F7B12E}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Config V4\ENConfig.exe FirewallRules: [{B7B03170-9F92-43BD-9485-D9BC379E4AA4}] => (Allow) C:\Users\u\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{E7D90FBE-CD4E-46D3-8E3F-DDA8F84EB824}] => (Allow) C:\Users\u\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{C3503FD4-1AD0-4650-A170-28953E966FF5}C:\users\u\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\u\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{BC410B7C-5F94-423A-A0E9-C3A9FFCCE769}C:\users\u\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\u\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{0C5ACE68-BB7C-43F3-A1EF-E0AEE4193A36}C:\users\u\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\u\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{F16CD45C-B296-4C92-AEDD-30EA494D1E35}C:\users\u\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\u\appdata\roaming\spotify\spotify.exe FirewallRules: [{A67E3198-4406-451C-BA3E-3F9BB9BC6BFA}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DriverBooster.exe FirewallRules: [{CA9D6CD5-736D-4896-9161-52532E6796C9}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DriverBooster.exe FirewallRules: [{C9C2CFE4-A6FD-4DDE-BFD4-7AE8A00756CA}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DBDownloader.exe FirewallRules: [{4DA1B66E-98F2-4BD5-8A45-16DF159B13D8}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DBDownloader.exe FirewallRules: [{7ABD4256-E2CA-4B27-85BC-1577429DC96A}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\AutoUpdate.exe FirewallRules: [{B28718EC-D135-4C0D-8698-2485438D9072}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\AutoUpdate.exe FirewallRules: [{8B10A2D3-224F-43CD-8990-E2531D2C2182}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{C4CF1696-8AF6-431F-9671-1E385FAE5A94}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe FirewallRules: [{925B148B-3F9E-4FE0-BAA1-64E31AA2C506}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe ==================== Wiederherstellungspunkte ========================= 09-11-2016 17:52:23 Windows Update 09-11-2016 17:53:19 Windows Update ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (11/17/2016 07:26:18 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Laptop) Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (11/12/2016 07:33:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Laptop) Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (11/09/2016 05:53:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (11/09/2016 05:52:40 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (11/08/2016 07:29:09 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (11/08/2016 07:12:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FoxitReader.exe, Version: 7.3.6.321, Zeitstempel: 0x56f0c322 Name des fehlerhaften Moduls: FoxitReader.exe, Version: 7.3.6.321, Zeitstempel: 0x56f0c322 Ausnahmecode: 0xc000041d Fehleroffset: 0x002b8f92 ID des fehlerhaften Prozesses: 0x1df4 Startzeit der fehlerhaften Anwendung: 0x01d239c6ce600a6f Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe Berichtskennung: cfd7912c-5387-4405-a309-1a866260512a Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (11/08/2016 07:12:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FoxitReader.exe, Version: 7.3.6.321, Zeitstempel: 0x56f0c322 Name des fehlerhaften Moduls: FoxitReader.exe, Version: 7.3.6.321, Zeitstempel: 0x56f0c322 Ausnahmecode: 0xc0000005 Fehleroffset: 0x002b8f92 ID des fehlerhaften Prozesses: 0x1df4 Startzeit der fehlerhaften Anwendung: 0x01d239c6ce600a6f Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe Berichtskennung: a624d073-4bf8-4778-9d7d-5cb5719ee551 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (11/08/2016 07:12:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 43.0.1.5863, Zeitstempel: 0x56a06dda Name des fehlerhaften Moduls: mozglue.dll, Version: 43.0.1.5863, Zeitstempel: 0x56a06c6c Ausnahmecode: 0x80000003 Fehleroffset: 0x000025ff ID des fehlerhaften Prozesses: 0x1af0 Startzeit der fehlerhaften Anwendung: 0x01d239c6ce46b456 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\SeaMonkey\plugin-container.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\SeaMonkey\mozglue.dll Berichtskennung: 86c136a4-5094-4ebe-b657-9cd4cf35e037 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (11/07/2016 01:54:24 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (11/07/2016 02:46:17 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Laptop) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Systemfehler: ============= Error: (11/18/2016 11:01:45 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "IObit Uninstaller Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/17/2016 02:54:26 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Advanced SystemCare Service 9" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/17/2016 02:54:26 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "LiveUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/17/2016 02:46:25 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Speicherdienst" wurde nicht richtig gestartet. Error: (11/17/2016 02:45:19 AM) (Source: DCOM) (EventID: 10016) (User: Laptop) Description: Durch die Berechtigungseinstellungen für "Computerstandard" wird dem Benutzer "Laptop\UK" (SID: S-1-5-21-2736805842-114790362-3470889979-1002) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} und der APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} im Anwendungscontainer "Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy" (SID: S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (11/17/2016 02:45:19 AM) (Source: DCOM) (EventID: 10016) (User: Laptop) Description: Durch die Berechtigungseinstellungen für "Computerstandard" wird dem Benutzer "Laptop\UK" (SID: S-1-5-21-2736805842-114790362-3470889979-1002) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} und der APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} im Anwendungscontainer "Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy" (SID: S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (11/17/2016 02:41:58 AM) (Source: Microsoft-Windows-Eventlog) (EventID: 30) (User: NT-AUTORITÄT) Description: Der Ereignisprotokollierungsdienst hat beim Aktivieren des Herausgebers "{0BF2FB94-7B60-4B4D-9766-E82F658DF540}" für den Kanal "Microsoft-Windows-Kernel-ShimEngine/Operational" einen Fehler (5) erkannt. Dieser Fehler hat keinen Einfluss auf den Betrieb des Kanals, beeinträchtigt jedoch die Fähigkeit des Herausgebers, Ereignisse für den Kanal auszulösen. Dieser Fehler ist oft darauf zurückzuführen, dass der Anbieter die ETW-Anbietersicherheit verwendet und der Ereignisprotokoll-Dienstidentität keine Berechtigungen zum Aktivieren gewährt hat. Error: (11/17/2016 02:37:23 AM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: Zugriff verweigert Error: (11/17/2016 02:30:11 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_27671c" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (11/17/2016 02:30:11 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _27671c" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2016-11-17 23:23:34.164 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-17 02:42:59.309 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-11 10:22:26.997 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-10 10:35:56.723 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-29 20:30:56.210 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-18 17:34:33.045 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-18 12:02:10.098 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-13 19:06:30.756 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-09-22 09:57:25.275 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-09-21 04:18:21.889 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz Prozentuale Nutzung des RAM: 38% Installierter physikalischer RAM: 8054.82 MB Verfügbarer physikalischer RAM: 4961.11 MB Summe virtueller Speicher: 12627.82 MB Verfügbarer virtueller Speicher: 9351.28 MB ==================== Laufwerke ================================ Drive c: (Boot) (Fixed) (Total:134.05 GB) (Free:57.14 GB) NTFS Drive d: (Daten) (Fixed) (Total:719.95 GB) (Free:488.93 GB) NTFS Drive x: (Recover) (Fixed) (Total:60 GB) (Free:38.54 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: CEAAD2D8) Partition: GPT. ==================== Ende von Addition.txt ============================ |
21.11.2016, 09:46 | #4 |
/// TB-Ausbilder /// Anleitungs-Guru | Malwarefund Win32/Herz.BMein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...
Hinweis: Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co. können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean bekommst. Los geht's: Bitte erstmal IObit Malwarefighter deinstallieren.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
21.11.2016, 12:31 | #5 |
| Malwarefund Win32/Herz.B Moin Jürgen, vielen Dank, dass Du Dich meiner annimmst Habe ich soeben gemacht |
21.11.2016, 17:26 | #6 |
/// TB-Ausbilder /// Anleitungs-Guru | Malwarefund Win32/Herz.B Gut. Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2
Schritt 3 Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Untersuchen. Bitte poste mir den Inhalt der beiden Logs die erstellt werden.
__________________ --> Malwarefund Win32/Herz.B |
22.11.2016, 02:35 | #7 |
| Malwarefund Win32/Herz.B Hallo Jürgen, soo, hier nun die logs Code:
ATTFilter # AdwCleaner v6.030 - Bericht erstellt am 22/11/2016 um 01:09:33 # Aktualisiert am 19/10/2016 von Malwarebytes # Datenbank : 2016-11-21.2 [Server] # Betriebssystem : Windows 10 Pro (X64) # Benutzername : UK - LAPTOP # Gestartet von : D:\Desktop\malware apps\AdwCleaner_6.030.exe # Modus: Löschen # Unterstützung : hxxps://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner gelöscht: C:\ProgramData\Avg_Update_1116av [-] Ordner gelöscht: C:\ProgramData\apn [-] Ordner gelöscht: C:\ProgramData\AVG Security Toolbar [-] Ordner gelöscht: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec [-] Ordner gelöscht: C:\Program Files (x86)\myfree codec ***** [ Dateien ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} [-] Schlüssel gelöscht: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [-] Schlüssel gelöscht: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\APN PIP [-] Schlüssel gelöscht: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Conduit [-] Schlüssel gelöscht: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Myfree Codec [-] Schlüssel gelöscht: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Softonic [-] Schlüssel gelöscht: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec [#] Schlüssel mit Neustart gelöscht: HKCU\Software\APN PIP [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Conduit [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Myfree Codec [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Softonic [-] Schlüssel gelöscht: HKLM\SOFTWARE\Myfree Codec [-] Schlüssel gelöscht: HKLM\SOFTWARE\PIP [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\APN PIP [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Conduit [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Myfree Codec [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Softonic [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec [-] Daten wiederhergestellt: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Microsoft\Internet Explorer\Main [Search Page] [-] Daten wiederhergestellt: HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] [-] Daten wiederhergestellt: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] [-] Schlüssel gelöscht: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} [-] Daten wiederhergestellt: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [-] Schlüssel gelöscht: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB} [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} [-] Daten wiederhergestellt: HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB} [-] Daten wiederhergestellt: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} [-] Daten wiederhergestellt: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB} [-] Wert gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [vProt] ***** [ Browser ] ***** ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: Proxy Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [5397 Bytes] - [22/11/2016 01:09:33] C:\AdwCleaner\AdwCleaner[S0].txt - [5422 Bytes] - [22/11/2016 01:05:37] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5543 Bytes] ########## Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 22.11.2016 Suchlaufzeit: 01:29 Protokolldatei: malwarebytes.txt Administrator: Ja Version: 2.2.1.1043 Malware-Datenbank: v2016.11.21.17 Rootkit-Datenbank: v2016.11.20.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 10 CPU: x64 Dateisystem: NTFS Benutzer: UK Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 388076 Abgelaufene Zeit: 28 Min., 8 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswerte: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 0 (keine bösartigen Elemente erkannt) Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 20-11-2016 01 durchgeführt von UK (Administrator) auf LAPTOP (22-11-2016 02:23:56) Gestartet von D:\Desktop\malware apps Geladene Profile: UK (Verfügbare Profile: UK & Administrator) Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: "C:\Program Files (x86)\SeaMonkey\seamonkey.exe" -requestPending -osint -url "%1") Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe (NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe (Intel Corporation) C:\WINDOWS\System32\igfxCUIService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Intel Corporation) C:\WINDOWS\System32\igfxEM.exe (Intel Corporation) C:\WINDOWS\System32\igfxHK.exe (Intel Corporation) C:\WINDOWS\System32\igfxTray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Wistron) C:\Program Files (x86)\Launch Manager\HotkeyApp.exe (Wistron Corp.) C:\Program Files (x86)\Launch Manager\OSD.exe (Wistron Corp.) C:\Program Files (x86)\Launch Manager\WisLMSvc.exe (Wistron Corp.) C:\Program Files (x86)\Launch Manager\WButton.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe (mozilla.org) C:\Program Files (x86)\SeaMonkey\seamonkey.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Microsoft Corporation) C:\WINDOWS\System32\SettingSyncHost.exe (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe (Microsoft Corporation) C:\WINDOWS\System32\InstallAgent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe (Microsoft Corporation) C:\WINDOWS\System32\NetworkUXBroker.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe (Microsoft Corporation) C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3951280 2016-01-07] (Synaptics Incorporated) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1795912 2015-07-23] (NVIDIA Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16475392 2016-11-06] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-11-06] (Realtek Semiconductor) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [258576 2012-11-05] (CyberLink Corp.) HKLM-x32\...\Run: [HotkeyApp] => C:\Program Files (x86)\Launch Manager\HotkeyApp.exe [320824 2012-08-16] (Wistron) HKLM-x32\...\Run: [LMgrVolOSD] => C:\Program Files (x86)\Launch Manager\OSD.exe [348960 2012-08-13] (Wistron Corp.) HKLM-x32\...\Run: [Wbutton] => C:\Program Files (x86)\Launch Manager\Wbutton.exe [388408 2012-08-13] (Wistron Corp.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Reader Application Helper] => C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2014-10-24] (Sony Corporation) HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [218896 2016-09-13] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [218896 2016-09-13] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [KMConfig] => "C:\Program Files (x86)\Multimedia Mouse Driver\V5\StartAutorun.exe" KMConfig.exe HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Run: [Dropbox Update] => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.) HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [176904 2015-07-23] (NVIDIA Corporation) AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [176904 2015-07-23] (NVIDIA Corporation) ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\FileSyncShell64.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\FileSyncShell64.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\FileSyncShell64.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Keine Datei ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileSyncShell.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileSyncShell.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileSyncShell.dll [2016-07-23] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt.3.0.dll [2016-11-07] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt.3.0.dll [2016-11-07] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2014-08-19] ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-10-07] ShortcutTarget: Dropbox.lnk -> C:\Users\u\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{4344fcb4-282c-4464-86a8-73e16d20d65e}: [DhcpNameServer] 172.168.162.2 Tcpip\..\Interfaces\{4eeae347-f1dc-4b6d-9bfc-fec9118835a7}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\S-1-5-21-2736805842-114790362-3470889979-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2736805842-114790362-3470889979-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2736805842-114790362-3470889979-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-10-22] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-10-22] (Oracle Corporation) BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2013-03-11] (FreeDownloadManager.ORG) BHO-x32: IObit Ads Removal -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll [2016-06-23] (IObit) Toolbar: HKLM - Kein Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Keine Datei Toolbar: HKLM - Kein Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Keine Datei DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.15.0.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-09-23] (Skype Technologies) FireFox: ======== FF DefaultProfile: Mozilla-Seamonkey FF DefaultProfile: yn4743c8.default FF ProfilePath: C:\Users\u\AppData\Roaming\Mozilla\SeaMonkey\Profiles\9o47yt72.default [2016-11-20] FF DefaultSearchEngine: Mozilla\SeaMonkey\Profiles\9o47yt72.default -> Google FF Homepage: Mozilla\SeaMonkey\Profiles\9o47yt72.default -> hxxp://www.windfinder.com/weatherforecast/hamburg_aussenalster FF NetworkProxy: Mozilla\SeaMonkey\Profiles\9o47yt72.default -> share_proxy_settings", true FF NetworkProxy: Mozilla\SeaMonkey\Profiles\9o47yt72.default -> type", 0 FF SearchPlugin: C:\Users\u\AppData\Roaming\Mozilla\SeaMonkey\Profiles\9o47yt72.default\searchplugins\otrkeyfindercom.xml [2013-04-30] FF ProfilePath: D:\Mozilla-Seamonkey [2016-11-22] FF DefaultSearchEngine: D:\Mozilla-Seamonkey -> Startpage HTTPS - Deutsch FF Homepage: D:\Mozilla-Seamonkey -> hxxp://www.windfinder.com/weatherforecast/hamburg_aussenalster FF NetworkProxy: D:\Mozilla-Seamonkey -> share_proxy_settings", true FF NetworkProxy: D:\Mozilla-Seamonkey -> type", 0 FF Extension: (DOM Inspector) - D:\Mozilla-Seamonkey\Extensions\inspector@mozilla.org [2016-05-03] FF Extension: (ChatZilla Deutsch (DE) Language Pack) - D:\Mozilla-Seamonkey\Extensions\langpack-de@chatzilla.mozilla.org [2015-09-21] FF Extension: (JavaScript Debugger Deutsch (DE) Language Pack) - D:\Mozilla-Seamonkey\Extensions\langpack-de@venkman.mozilla.org.xpi [2013-10-02] [ist nicht signiert] FF Extension: (Adblock Plus) - D:\Mozilla-Seamonkey\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-10-28] FF SearchPlugin: D:\Mozilla-Seamonkey\searchplugins\startpage-https---deutsch.xml [2016-11-19] FF ProfilePath: C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default [2016-11-21] FF user.js: detected! => C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\user.js [2016-04-17] FF DefaultSearchEngine: Mozilla\Firefox\Profiles\yn4743c8.default -> Google FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\yn4743c8.default -> Bing FF Keyword.URL: Mozilla\Firefox\Profiles\yn4743c8.default -> hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q= FF Extension: (IObit Surfing Protection & Ads Removal) - C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\Extensions\ascsurfingprotectionnew@iobit.com.xpi [2016-10-18] FF Extension: (Multi YouTube mp3) - C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\Extensions\d.lehr@chello.at.xpi [2015-12-12] FF Extension: (Video DownloadHelper) - C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-10-11] FF Extension: (Adblock Plus) - C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-10-28] FF SearchPlugin: C:\Users\u\AppData\Roaming\Mozilla\Firefox\Profiles\yn4743c8.default\searchplugins\startpage-ssl.xml [2015-01-30] FF HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\u\AppData\Roaming\Cliqz\cliqz@cliqz.com FF Extension: (Cliqz Beta) - C:\Users\u\AppData\Roaming\Cliqz\cliqz@cliqz.com [2014-12-24] [ist nicht signiert] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-11-08] () FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-10-22] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-10-22] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-08] () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-07-12] (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-07-23] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-07-23] (NVIDIA Corporation) FF Plugin-x32: @sony.com/ReaderDesktop -> C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll [2014-10-24] (Sony Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-2736805842-114790362-3470889979-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\u\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-07-14] (Unity Technologies ApS) Chrome: ======= CHR Profile: C:\Users\u\AppData\Local\Google\Chrome\User Data\Default [2016-11-22] CHR Extension: (Google Präsentationen) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-15] CHR Extension: (Google Docs) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-15] CHR Extension: (Google Drive) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23] CHR Extension: (YouTube) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26] CHR Extension: (Adblock für Youtube™) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2016-11-03] CHR Extension: (Google-Suche) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28] CHR Extension: (Google Tabellen) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-15] CHR Extension: (Google Docs Offline) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02] CHR Extension: (Play Music Lyrics Fetcher) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\phnnoaooookpaffnminadcajmghibbbc [2016-11-03] CHR Extension: (Google Mail) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-15] CHR Extension: (Chrome Media Router) - C:\Users\u\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-07] CHR HKU\S-1-5-21-2736805842-114790362-3470889979-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AdvancedSystemCareService10; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [462624 2016-10-14] (IObit) S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [647864 2016-11-02] (AVG Technologies CZ, s.r.o.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5337696 2016-11-02] (AVG Technologies CZ, s.r.o.) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1149712 2016-09-13] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [727512 2016-11-02] (AVG Technologies CZ, s.r.o.) S3 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [168592 2013-04-10] (Microsoft Corp.) S3 BitBoxService; C:\Program Files (x86)\Sirrix AG\BitBox\bin\BitBoxService.exe [738304 2015-11-13] (Sirrix AG) [Datei ist nicht signiert] S3 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [70952 2011-04-13] (CyberLink) S3 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [312616 2011-04-13] (CyberLink) S3 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [37448 2014-08-13] (CHENGDU YIWO Tech Development Co., Ltd) [Datei ist nicht signiert] R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation) R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit) S3 PAExec; C:\WINDOWS\PAExec.exe [189112 2016-07-23] (Power Admin LLC) S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2010-08-19] () S3 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2014-04-25] (Sony Corporation) [Datei ist nicht signiert] S3 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246448 2016-01-07] (Synaptics Incorporated) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-10-25] (Microsoft Corporation) R3 WisLMSvc; C:\Program Files (x86)\Launch Manager\WisLMSvc.exe [118560 2012-08-13] (Wistron Corp.) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S0 Avgboota; C:\WINDOWS\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\WINDOWS\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdrivera.sys [312576 2016-10-17] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\WINDOWS\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\WINDOWS\System32\DRIVERS\avgldx64.sys [267520 2016-10-19] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\WINDOWS\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\WINDOWS\System32\DRIVERS\avgmfx64.sys [254208 2016-09-26] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\WINDOWS\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.) R0 Avguniva; C:\WINDOWS\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\WINDOWS\system32\DRIVERS\avgwfpa.sys [313096 2016-08-04] (AVG Technologies CZ, s.r.o.) S3 btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [1448248 2016-04-18] (Motorola Solutions, Inc.) R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 cpuz138; C:\Users\u\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [27320 2016-11-22] (CPUID) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [129152 2016-04-24] (Samsung Electronics Co., Ltd.) S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [17480 2013-03-07] () [Datei ist nicht signiert] S3 epmntdrv; C:\WINDOWS\SysWOW64\epmntdrv.sys [13896 2013-03-07] () [Datei ist nicht signiert] R0 EUBAKUP; C:\WINDOWS\System32\drivers\eubakup.sys [61000 2014-08-13] (CHENGDU YIWO Tech Development Co., Ltd) [Datei ist nicht signiert] R0 EUBKMON; C:\WINDOWS\System32\drivers\EUBKMON.sys [48200 2014-08-13] () [Datei ist nicht signiert] R1 EUDSKACS; C:\WINDOWS\system32\drivers\eudskacs.sys [18504 2014-08-13] (CHENGDU YIWO Tech Development Co., Ltd) [Datei ist nicht signiert] R1 EUFDDISK; C:\WINDOWS\system32\drivers\EuFdDisk.sys [189000 2014-08-13] (CHENGDU YIWO Tech Development Co., Ltd) [Datei ist nicht signiert] S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [9800 2013-03-07] () [Datei ist nicht signiert] S3 EuGdiDrv; C:\WINDOWS\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () [Datei ist nicht signiert] R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-04-17] (REALiX(tm)) R3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3354384 2016-04-18] (Intel Corporation) S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [25504 2013-10-21] (Resplendence Software Projects Sp.) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [936192 2016-07-24] (Realtek ) R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [413912 2016-04-18] (Realsil Semiconductor Corporation) S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-16] (Synaptics Incorporated) S3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42664 2016-01-07] (Synaptics Incorporated) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [221824 2016-04-24] (Samsung Electronics Co., Ltd.) R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [47072 2012-11-29] (Windows (R) Win 7 DDK provider) R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [194816 2015-11-11] (Oracle Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) R3 XHCIPort; C:\WINDOWS\System32\drivers\XHCIPort.sys [188896 2012-11-29] (Windows (R) Win 7 DDK provider) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-11-22 01:25 - 2016-11-22 01:29 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-11-22 01:24 - 2016-11-22 01:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-11-22 01:24 - 2016-11-22 01:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-11-22 01:24 - 2016-11-22 01:24 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-11-22 01:24 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2016-11-22 01:24 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2016-11-22 01:24 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-11-22 01:01 - 2016-11-22 01:09 - 00000000 ____D C:\AdwCleaner 2016-11-18 11:31 - 2016-11-22 02:23 - 00000000 ____D C:\FRST 2016-11-17 03:07 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\WINDOWS\system32\IObitSmartDefragExtension.dll 2016-11-17 03:07 - 2016-03-22 11:02 - 00036824 _____ (IObit) C:\WINDOWS\system32\SmartDefragBootTime.exe 2016-11-17 03:03 - 2016-11-17 03:03 - 00000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705} 2016-11-17 02:54 - 2016-11-17 03:10 - 00003084 _____ C:\WINDOWS\System32\Tasks\ASC10_PerformanceMonitor 2016-11-17 02:54 - 2016-11-17 02:54 - 00002872 _____ C:\WINDOWS\System32\Tasks\ASC10_SkipUac_UK 2016-11-17 02:54 - 2016-11-17 02:54 - 00000000 ____D C:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A} 2016-11-17 02:34 - 2016-11-17 02:34 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices 2016-11-17 02:34 - 2016-11-17 02:34 - 00000000 ____D C:\WINDOWS\system32\BestPractices 2016-11-17 02:12 - 2016-11-17 02:12 - 00003584 _____ C:\WINDOWS\System32\Tasks\AVG-SSU_1116av_DELETE 2016-11-17 02:12 - 2016-11-17 02:12 - 00003172 _____ C:\WINDOWS\System32\Tasks\AVG-SSU_1116av 2016-11-16 01:48 - 2016-11-21 23:25 - 00000000 ____D C:\Users\u\AppData\LocalLow\Mozilla 2016-11-16 01:47 - 2016-11-17 02:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-11-14 18:05 - 2016-11-14 18:05 - 00000000 ____D C:\ProgramData\Avg_Update_1116sp 2016-11-12 00:59 - 2016-11-12 00:59 - 00000000 ____D C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-11-09 16:41 - 2016-11-02 14:32 - 00316256 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-11-09 16:41 - 2016-11-02 14:31 - 00546968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-11-09 16:41 - 2016-10-25 10:34 - 00454496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys 2016-11-09 16:41 - 2016-10-25 09:32 - 01862000 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-11-09 16:41 - 2016-10-25 09:32 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-11-09 16:41 - 2016-10-25 09:32 - 00845568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2016-11-09 16:41 - 2016-10-25 09:32 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll 2016-11-09 16:41 - 2016-10-25 09:28 - 01083648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe 2016-11-09 16:41 - 2016-10-25 09:05 - 00712032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2016-11-09 16:41 - 2016-10-25 08:45 - 00032096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys 2016-11-09 16:41 - 2016-10-25 08:39 - 00306840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 01349632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-11-09 16:41 - 2016-10-25 08:37 - 00709176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-11-09 16:41 - 2016-10-25 08:31 - 01824272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-11-09 16:41 - 2016-10-25 08:31 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-11-09 16:41 - 2016-10-25 08:30 - 02938920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-11-09 16:41 - 2016-10-25 08:30 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-11-09 16:41 - 2016-10-25 08:27 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-11-09 16:41 - 2016-10-25 08:27 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2016-11-09 16:41 - 2016-10-25 08:27 - 00256704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-11-09 16:41 - 2016-10-25 08:26 - 05240952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-11-09 16:41 - 2016-10-25 08:26 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-11-09 16:41 - 2016-10-25 08:26 - 01355344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll 2016-11-09 16:41 - 2016-10-25 08:26 - 00836752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2016-11-09 16:41 - 2016-10-25 08:26 - 00569752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll 2016-11-09 16:41 - 2016-10-25 08:22 - 00268040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2016-11-09 16:41 - 2016-10-25 08:19 - 00295776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-11-09 16:41 - 2016-10-25 08:18 - 01536088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2016-11-09 16:41 - 2016-10-25 07:56 - 02195640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2016-11-09 16:41 - 2016-10-25 07:56 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe 2016-11-09 16:41 - 2016-10-25 07:54 - 01522160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-11-09 16:41 - 2016-10-25 07:54 - 00273760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll 2016-11-09 16:41 - 2016-10-25 07:53 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-11-09 16:41 - 2016-10-25 07:27 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2016-11-09 16:41 - 2016-10-25 07:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2016-11-09 16:41 - 2016-10-25 07:21 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll 2016-11-09 16:41 - 2016-10-25 07:09 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2016-11-09 16:41 - 2016-10-25 07:08 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-11-09 16:41 - 2016-10-25 07:06 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-11-09 16:41 - 2016-10-25 07:00 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2016-11-09 16:41 - 2016-10-25 06:50 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2016-11-09 16:41 - 2016-10-25 06:49 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2016-11-09 16:41 - 2016-10-25 06:48 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll 2016-11-09 16:41 - 2016-10-25 06:45 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-11-09 16:41 - 2016-10-25 06:45 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll 2016-11-09 16:41 - 2016-10-25 06:44 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll 2016-11-09 16:41 - 2016-10-25 06:43 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\filemgmt.dll 2016-11-09 16:41 - 2016-10-25 06:41 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2016-11-09 16:41 - 2016-10-25 06:40 - 01336832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2016-11-09 16:41 - 2016-10-25 06:37 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-11-09 16:41 - 2016-10-25 06:36 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-11-09 16:41 - 2016-10-25 06:36 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2016-11-09 16:41 - 2016-10-25 06:36 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll 2016-11-09 16:41 - 2016-10-25 06:35 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll 2016-11-09 16:41 - 2016-10-25 06:32 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-11-09 16:41 - 2016-10-25 06:31 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-11-09 16:41 - 2016-10-25 06:30 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-11-09 16:41 - 2016-10-25 06:29 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe 2016-11-09 16:41 - 2016-10-25 06:29 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 02578432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 00885248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll 2016-11-09 16:41 - 2016-10-25 06:28 - 00760320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2016-11-09 16:41 - 2016-10-25 06:27 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll 2016-11-09 16:41 - 2016-10-25 06:25 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll 2016-11-09 16:41 - 2016-10-25 06:25 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2016-11-09 16:41 - 2016-10-25 06:23 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll 2016-11-09 16:41 - 2016-10-25 06:23 - 00964096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2016-11-09 16:41 - 2016-10-25 06:22 - 01562624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe 2016-11-09 16:41 - 2016-10-25 06:21 - 03577344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2016-11-09 16:41 - 2016-10-25 06:21 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2016-11-09 16:41 - 2016-10-25 06:11 - 04078592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2016-11-09 16:41 - 2016-10-25 06:11 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2016-11-09 16:41 - 2016-10-25 06:09 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2016-11-09 16:41 - 2016-10-25 06:04 - 00835072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll 2016-11-09 16:41 - 2016-10-25 06:03 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-11-09 16:41 - 2016-10-25 06:01 - 02361856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 02555904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2016-11-09 16:41 - 2016-10-25 06:00 - 01708032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-11-09 16:41 - 2016-10-25 05:59 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2016-11-09 16:41 - 2016-10-25 05:59 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll 2016-11-09 16:41 - 2016-10-25 05:58 - 09920512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-11-09 16:41 - 2016-10-25 05:57 - 06296064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-11-09 16:41 - 2016-10-25 05:56 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-11-09 16:41 - 2016-10-25 05:55 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2016-11-09 16:41 - 2016-10-25 05:55 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnfldr.dll 2016-11-09 16:41 - 2016-10-25 05:54 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2016-11-09 16:41 - 2016-10-25 05:53 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2016-11-09 16:41 - 2016-10-25 05:47 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-11-09 16:41 - 2016-10-25 05:46 - 02771968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2016-11-09 16:41 - 2016-10-25 05:44 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2016-11-09 16:41 - 2016-10-25 05:43 - 04404736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-11-09 16:41 - 2016-10-25 05:40 - 05325824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-11-09 16:41 - 2016-10-25 05:38 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-11-09 16:41 - 2016-10-25 05:37 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-11-09 16:41 - 2016-10-25 05:36 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2016-11-09 16:41 - 2016-10-25 05:35 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2016-11-09 16:41 - 2016-10-25 05:35 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll 2016-11-09 16:41 - 2016-10-25 05:34 - 02062336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-11-09 16:41 - 2016-10-25 05:34 - 01228800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll 2016-11-09 16:41 - 2016-10-25 05:32 - 06743040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2016-11-09 16:41 - 2016-10-25 05:27 - 03065344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2016-11-09 16:41 - 2016-10-25 05:23 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll 2016-11-09 16:41 - 2016-10-25 05:21 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll 2016-11-09 16:40 - 2016-11-02 13:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-11-09 16:40 - 2016-10-25 10:24 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2016-11-09 16:40 - 2016-10-25 10:18 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2016-11-09 16:40 - 2016-10-25 09:48 - 01554152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2016-11-09 16:40 - 2016-10-25 09:48 - 01552104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2016-11-09 16:40 - 2016-10-25 09:42 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-11-09 16:40 - 2016-10-25 09:38 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-11-09 16:40 - 2016-10-25 09:37 - 01040792 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2016-11-09 16:40 - 2016-10-25 09:35 - 06536248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2016-11-09 16:40 - 2016-10-25 09:30 - 00360288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-11-09 16:40 - 2016-10-25 08:47 - 00305808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll 2016-11-09 16:40 - 2016-10-25 08:30 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2016-11-09 16:40 - 2016-10-25 08:29 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2016-11-09 16:40 - 2016-10-25 08:26 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2016-11-09 16:40 - 2016-10-25 08:22 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys 2016-11-09 16:40 - 2016-10-25 08:14 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll 2016-11-09 16:40 - 2016-10-25 08:12 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\racpldlg.dll 2016-11-09 16:40 - 2016-10-25 08:12 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys 2016-11-09 16:40 - 2016-10-25 08:10 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceClassExtension.dll 2016-11-09 16:40 - 2016-10-25 08:06 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2016-11-09 16:40 - 2016-10-25 08:06 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceConnectApi.dll 2016-11-09 16:40 - 2016-10-25 08:01 - 00404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys 2016-11-09 16:40 - 2016-10-25 07:59 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2016-11-09 16:40 - 2016-10-25 07:52 - 00577536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll 2016-11-09 16:40 - 2016-10-25 07:51 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-11-09 16:40 - 2016-10-25 07:50 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll 2016-11-09 16:40 - 2016-10-25 07:49 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll 2016-11-09 16:40 - 2016-10-25 07:49 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll 2016-11-09 16:40 - 2016-10-25 07:48 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceApi.dll 2016-11-09 16:40 - 2016-10-25 07:43 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll 2016-11-09 16:40 - 2016-10-25 07:40 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll 2016-11-09 16:40 - 2016-10-25 07:39 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-11-09 16:40 - 2016-10-25 07:38 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll 2016-11-09 16:40 - 2016-10-25 07:38 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll 2016-11-09 16:40 - 2016-10-25 07:38 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-11-09 16:40 - 2016-10-25 07:37 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll 2016-11-09 16:40 - 2016-10-25 07:37 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll 2016-11-09 16:40 - 2016-10-25 07:33 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-11-09 16:40 - 2016-10-25 07:32 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-11-09 16:40 - 2016-10-25 07:28 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll 2016-11-09 16:40 - 2016-10-25 07:27 - 01466368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Pimstore.dll 2016-11-09 16:40 - 2016-10-25 07:27 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-11-09 16:40 - 2016-10-25 07:23 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2016-11-09 16:40 - 2016-10-25 07:22 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2016-11-09 16:40 - 2016-10-25 07:18 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll 2016-11-09 16:40 - 2016-10-25 07:12 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll 2016-11-09 16:40 - 2016-10-25 07:05 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll 2016-11-09 16:40 - 2016-10-25 07:05 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\StikyNot.exe 2016-11-09 16:40 - 2016-10-25 07:05 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2016-11-09 16:40 - 2016-10-25 07:03 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SCardDlg.dll 2016-11-09 16:40 - 2016-10-25 07:01 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2016-11-09 16:40 - 2016-10-25 07:00 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp 2016-11-09 16:40 - 2016-10-25 07:00 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceClassExtension.dll 2016-11-09 16:40 - 2016-10-25 06:59 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oemlicense.dll 2016-11-09 16:40 - 2016-10-25 06:56 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceConnectApi.dll 2016-11-09 16:40 - 2016-10-25 06:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll 2016-11-09 16:40 - 2016-10-25 06:53 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-11-09 16:40 - 2016-10-25 06:51 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll 2016-11-09 16:40 - 2016-10-25 06:50 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl 2016-11-09 16:40 - 2016-10-25 06:50 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll 2016-11-09 16:40 - 2016-10-25 06:50 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2016-11-09 16:40 - 2016-10-25 06:49 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3ui.dll 2016-11-09 16:40 - 2016-10-25 06:48 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2016-11-09 16:40 - 2016-10-25 06:45 - 07977984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-11-09 16:40 - 2016-10-25 06:45 - 00564736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\objsel.dll 2016-11-09 16:40 - 2016-10-25 06:45 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe 2016-11-09 16:40 - 2016-10-25 06:43 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceApi.dll 2016-11-09 16:40 - 2016-10-25 06:42 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2016-11-09 16:40 - 2016-10-25 06:41 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll 2016-11-09 16:40 - 2016-10-25 06:39 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2016-11-09 16:40 - 2016-10-25 06:39 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe 2016-11-09 16:40 - 2016-10-25 06:39 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-11-09 16:40 - 2016-10-25 06:37 - 04143104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll 2016-11-09 16:40 - 2016-10-25 06:37 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll 2016-11-09 16:40 - 2016-10-25 06:37 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 04646400 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe 2016-11-09 16:40 - 2016-10-25 06:36 - 00879616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wvc.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WLanConn.dll 2016-11-09 16:40 - 2016-10-25 06:36 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll 2016-11-09 16:40 - 2016-10-25 06:35 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll 2016-11-09 16:40 - 2016-10-25 06:35 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll 2016-11-09 16:40 - 2016-10-25 06:34 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2016-11-09 16:40 - 2016-10-25 06:33 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll 2016-11-09 16:40 - 2016-10-25 06:33 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2016-11-09 16:40 - 2016-10-25 06:32 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl 2016-11-09 16:40 - 2016-10-25 06:32 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll 2016-11-09 16:40 - 2016-10-25 06:32 - 00645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll 2016-11-09 16:40 - 2016-10-25 06:29 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll 2016-11-09 16:40 - 2016-10-25 06:28 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-11-09 16:40 - 2016-10-25 06:27 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll 2016-11-09 16:40 - 2016-10-25 06:26 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2016-11-09 16:40 - 2016-10-25 06:25 - 03695104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2016-11-09 16:40 - 2016-10-25 06:25 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2016-11-09 16:40 - 2016-10-25 06:25 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2016-11-09 16:40 - 2016-10-25 06:24 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licensingdiag.exe 2016-11-09 16:40 - 2016-10-25 06:17 - 00581632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll 2016-11-09 16:40 - 2016-10-25 06:14 - 02911744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2016-11-09 16:40 - 2016-10-25 06:14 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2016-11-09 16:40 - 2016-10-25 06:11 - 06471168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2016-11-09 16:40 - 2016-10-25 06:09 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll 2016-11-09 16:40 - 2016-10-25 06:07 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2016-11-09 16:40 - 2016-10-25 05:59 - 14258688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-11-09 16:40 - 2016-10-25 05:58 - 07536128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2016-11-09 16:40 - 2016-10-25 05:53 - 03294208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2016-11-09 16:40 - 2016-10-25 05:52 - 03555840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe 2016-11-09 16:40 - 2016-10-25 05:51 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll 2016-11-09 16:40 - 2016-10-25 05:50 - 01487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll 2016-11-09 16:40 - 2016-10-25 05:45 - 02679808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2016-11-09 16:40 - 2016-10-25 05:41 - 02519552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll 2016-11-09 16:40 - 2016-10-25 05:34 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-11-09 16:40 - 2016-10-25 05:33 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll 2016-11-09 16:40 - 2016-10-25 05:32 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll 2016-11-09 16:40 - 2016-10-25 05:32 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2016-11-09 16:40 - 2016-10-25 05:30 - 12590080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-11-09 16:40 - 2016-10-25 05:07 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-11-09 16:39 - 2016-10-25 10:25 - 01637216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2016-11-09 16:39 - 2016-10-25 09:51 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll 2016-11-09 16:39 - 2016-10-25 09:49 - 00588328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmdev.dll 2016-11-09 16:39 - 2016-10-25 09:49 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 01017024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2016-11-09 16:39 - 2016-10-25 09:48 - 00847648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-11-09 16:39 - 2016-10-25 09:41 - 03694088 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-11-09 16:39 - 2016-10-25 09:39 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2016-11-09 16:39 - 2016-10-25 09:37 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-11-09 16:39 - 2016-10-25 09:32 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-11-09 16:39 - 2016-10-25 08:47 - 28851216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll 2016-11-09 16:39 - 2016-10-25 08:47 - 02641928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL 2016-11-09 16:39 - 2016-10-25 08:46 - 00388896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2016-11-09 16:39 - 2016-10-25 08:40 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll 2016-11-09 16:39 - 2016-10-25 08:40 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2016-11-09 16:39 - 2016-10-25 08:35 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll 2016-11-09 16:39 - 2016-10-25 08:33 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\genericusbfn.sys 2016-11-09 16:39 - 2016-10-25 08:32 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2016-11-09 16:39 - 2016-10-25 08:31 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2016-11-09 16:39 - 2016-10-25 08:23 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll 2016-11-09 16:39 - 2016-10-25 08:20 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-11-09 16:39 - 2016-10-25 08:18 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-11-09 16:39 - 2016-10-25 08:13 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-11-09 16:39 - 2016-10-25 08:05 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-11-09 16:39 - 2016-10-25 08:04 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LegacyNetUXHost.exe 2016-11-09 16:39 - 2016-10-25 07:59 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2016-11-09 16:39 - 2016-10-25 07:56 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2016-11-09 16:39 - 2016-10-25 07:54 - 00752128 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll 2016-11-09 16:39 - 2016-10-25 07:53 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll 2016-11-09 16:39 - 2016-10-25 07:52 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2016-11-09 16:39 - 2016-10-25 07:51 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll 2016-11-09 16:39 - 2016-10-25 07:50 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll 2016-11-09 16:39 - 2016-10-25 07:50 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll 2016-11-09 16:39 - 2016-10-25 07:46 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll 2016-11-09 16:39 - 2016-10-25 07:43 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-11-09 16:39 - 2016-10-25 07:42 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2016-11-09 16:39 - 2016-10-25 07:41 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll 2016-11-09 16:39 - 2016-10-25 07:41 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll 2016-11-09 16:39 - 2016-10-25 07:40 - 02331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL 2016-11-09 16:39 - 2016-10-25 07:40 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll 2016-11-09 16:39 - 2016-10-25 07:40 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll 2016-11-09 16:39 - 2016-10-25 07:40 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2016-11-09 16:39 - 2016-10-25 07:39 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll 2016-11-09 16:39 - 2016-10-25 07:39 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll 2016-11-09 16:39 - 2016-10-25 07:39 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WLanConn.dll 2016-11-09 16:39 - 2016-10-25 07:38 - 00610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmsdk.dll 2016-11-09 16:39 - 2016-10-25 07:35 - 01434112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll 2016-11-09 16:39 - 2016-10-25 07:35 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-11-09 16:39 - 2016-10-25 07:35 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2016-11-09 16:39 - 2016-10-25 07:34 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2016-11-09 16:39 - 2016-10-25 07:33 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2016-11-09 16:39 - 2016-10-25 07:33 - 00817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll 2016-11-09 16:39 - 2016-10-25 07:29 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll 2016-11-09 16:39 - 2016-10-25 07:27 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll 2016-11-09 16:39 - 2016-10-25 07:27 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll 2016-11-09 16:39 - 2016-10-25 07:19 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2016-11-09 16:39 - 2016-10-25 07:16 - 01965568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe 2016-11-09 16:39 - 2016-10-25 07:07 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2016-11-09 16:39 - 2016-10-25 07:03 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2016-11-09 16:39 - 2016-10-25 07:03 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2016-11-09 16:39 - 2016-10-25 07:01 - 01121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2016-11-09 16:39 - 2016-10-25 06:59 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2016-11-09 16:39 - 2016-10-25 06:57 - 02285568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll 2016-11-09 16:39 - 2016-10-25 06:57 - 00833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\pmcsnap.dll 2016-11-09 16:39 - 2016-10-25 06:55 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll 2016-11-09 16:39 - 2016-10-25 06:53 - 01728000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-11-09 16:39 - 2016-10-25 06:49 - 03081216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-11-09 16:39 - 2016-10-25 06:46 - 00486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnfldr.dll 2016-11-09 16:39 - 2016-10-25 06:46 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2016-11-09 16:39 - 2016-10-25 06:42 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 2016-11-09 16:39 - 2016-10-25 06:35 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmsdk.dll 2016-11-09 16:39 - 2016-10-25 06:34 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2016-11-09 16:39 - 2016-10-25 06:32 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2016-11-09 16:39 - 2016-10-25 06:28 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2016-11-09 16:39 - 2016-10-25 06:28 - 01186816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll 2016-11-09 16:39 - 2016-10-25 06:28 - 00882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2016-11-09 16:39 - 2016-10-25 06:25 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll 2016-11-09 16:39 - 2016-10-25 06:24 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2016-11-09 16:39 - 2016-10-25 06:23 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2016-11-09 16:39 - 2016-10-25 06:19 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-11-09 16:39 - 2016-10-25 06:17 - 04895744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-11-09 16:39 - 2016-10-25 06:05 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-11-09 16:39 - 2016-10-25 06:05 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-11-09 16:39 - 2016-10-25 06:05 - 01385472 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-11-09 16:39 - 2016-10-25 05:55 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2016-11-09 16:39 - 2016-10-25 05:55 - 02217984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll 2016-11-09 16:39 - 2016-10-25 05:53 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr 2016-11-09 16:39 - 2016-10-25 05:52 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2016-11-09 16:39 - 2016-10-25 05:48 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll 2016-11-09 16:39 - 2016-10-25 05:45 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-11-09 16:39 - 2016-10-25 05:44 - 19348480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-11-09 16:39 - 2016-10-25 05:44 - 12134400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-11-09 16:39 - 2016-10-25 05:43 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-11-09 16:39 - 2016-10-25 05:29 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr 2016-11-09 16:39 - 2016-10-25 05:26 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-11-09 16:39 - 2016-10-25 02:47 - 00445873 _____ C:\WINDOWS\system32\ApnDatabase.xml 2016-11-09 16:38 - 2016-11-02 16:12 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-11-09 16:38 - 2016-11-02 16:08 - 00636296 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-11-09 16:38 - 2016-10-25 10:44 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-11-09 16:38 - 2016-10-25 10:44 - 00875480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-11-09 16:38 - 2016-10-25 10:42 - 07468384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-11-09 16:38 - 2016-10-25 10:42 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-11-09 16:38 - 2016-10-25 10:42 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-11-09 16:38 - 2016-10-25 10:42 - 01142560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-11-09 16:38 - 2016-10-25 10:42 - 01098648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2016-11-09 16:38 - 2016-10-25 10:42 - 00125280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys 2016-11-09 16:38 - 2016-10-25 10:41 - 01819208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-11-09 16:38 - 2016-10-25 10:40 - 00384864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2016-11-09 16:38 - 2016-10-25 10:39 - 01238584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe 2016-11-09 16:38 - 2016-10-25 10:19 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2016-11-09 16:38 - 2016-10-25 09:50 - 00439136 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll 2016-11-09 16:38 - 2016-10-25 09:42 - 02607336 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-11-09 16:38 - 2016-10-25 09:42 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-11-09 16:38 - 2016-10-25 09:39 - 00730352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2016-11-09 16:38 - 2016-10-25 09:39 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-11-09 16:38 - 2016-10-25 09:38 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2016-11-09 16:38 - 2016-10-25 09:37 - 04515256 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-11-09 16:38 - 2016-10-25 09:37 - 01603224 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll 2016-11-09 16:38 - 2016-10-25 09:33 - 00341936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2016-11-09 16:38 - 2016-10-25 09:30 - 01848072 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2016-11-09 16:38 - 2016-10-25 09:03 - 02549456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2016-11-09 16:38 - 2016-10-25 09:03 - 01988440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-11-09 16:38 - 2016-10-25 09:02 - 00577376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-11-09 16:38 - 2016-10-25 09:02 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-11-09 16:38 - 2016-10-25 09:01 - 01776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-11-09 16:38 - 2016-10-25 09:01 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-11-09 16:38 - 2016-10-25 08:45 - 00503600 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll 2016-11-09 16:38 - 2016-10-25 08:31 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll 2016-11-09 16:38 - 2016-10-25 08:30 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll 2016-11-09 16:38 - 2016-10-25 08:24 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys 2016-11-09 16:38 - 2016-10-25 08:21 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2016-11-09 16:38 - 2016-10-25 08:16 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2016-11-09 16:38 - 2016-10-25 08:12 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe 2016-11-09 16:38 - 2016-10-25 08:12 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-11-09 16:38 - 2016-10-25 08:10 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp 2016-11-09 16:38 - 2016-10-25 08:10 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll 2016-11-09 16:38 - 2016-10-25 08:08 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys 2016-11-09 16:38 - 2016-10-25 08:02 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2016-11-09 16:38 - 2016-10-25 08:02 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2016-11-09 16:38 - 2016-10-25 08:00 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2016-11-09 16:38 - 2016-10-25 07:58 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll 2016-11-09 16:38 - 2016-10-25 07:57 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll 2016-11-09 16:38 - 2016-10-25 07:56 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3ui.dll 2016-11-09 16:38 - 2016-10-25 07:56 - 00317952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll 2016-11-09 16:38 - 2016-10-25 07:55 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-11-09 16:38 - 2016-10-25 07:55 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2016-11-09 16:38 - 2016-10-25 07:55 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll 2016-11-09 16:38 - 2016-10-25 07:53 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2016-11-09 16:38 - 2016-10-25 07:53 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-11-09 16:38 - 2016-10-25 07:53 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll 2016-11-09 16:38 - 2016-10-25 07:52 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll 2016-11-09 16:38 - 2016-10-25 07:52 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll 2016-11-09 16:38 - 2016-10-25 07:52 - 00370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack_win.dll 2016-11-09 16:38 - 2016-10-25 07:51 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe 2016-11-09 16:38 - 2016-10-25 07:51 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2016-11-09 16:38 - 2016-10-25 07:51 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll 2016-11-09 16:38 - 2016-10-25 07:50 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll 2016-11-09 16:38 - 2016-10-25 07:50 - 00363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneOm.dll 2016-11-09 16:38 - 2016-10-25 07:49 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll 2016-11-09 16:38 - 2016-10-25 07:48 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll 2016-11-09 16:38 - 2016-10-25 07:47 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll 2016-11-09 16:38 - 2016-10-25 07:46 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll 2016-11-09 16:38 - 2016-10-25 07:46 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2016-11-09 16:38 - 2016-10-25 07:44 - 01479168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2016-11-09 16:38 - 2016-10-25 07:43 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2016-11-09 16:38 - 2016-10-25 07:42 - 01813504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2016-11-09 16:38 - 2016-10-25 07:42 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll 2016-11-09 16:38 - 2016-10-25 07:41 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll 2016-11-09 16:38 - 2016-10-25 07:40 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxApplicabilityEngine.dll 2016-11-09 16:38 - 2016-10-25 07:40 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll 2016-11-09 16:38 - 2016-10-25 07:40 - 00466944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll 2016-11-09 16:38 - 2016-10-25 07:39 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll 2016-11-09 16:38 - 2016-10-25 07:39 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2016-11-09 16:38 - 2016-10-25 07:39 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2016-11-09 16:38 - 2016-10-25 07:39 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll 2016-11-09 16:38 - 2016-10-25 07:38 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wvc.dll 2016-11-09 16:38 - 2016-10-25 07:36 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-11-09 16:38 - 2016-10-25 07:36 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll 2016-11-09 16:38 - 2016-10-25 07:36 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2016-11-09 16:38 - 2016-10-25 07:35 - 01132544 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll 2016-11-09 16:38 - 2016-10-25 07:34 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-11-09 16:38 - 2016-10-25 07:32 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-11-09 16:38 - 2016-10-25 07:32 - 01159168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll 2016-11-09 16:38 - 2016-10-25 07:32 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-11-09 16:38 - 2016-10-25 07:30 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2016-11-09 16:38 - 2016-10-25 07:30 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-11-09 16:38 - 2016-10-25 07:29 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe 2016-11-09 16:38 - 2016-10-25 07:29 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2016-11-09 16:38 - 2016-10-25 07:29 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-11-09 16:38 - 2016-10-25 07:28 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2016-11-09 16:38 - 2016-10-25 07:27 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2016-11-09 16:38 - 2016-10-25 07:27 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2016-11-09 16:38 - 2016-10-25 07:26 - 02103296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll 2016-11-09 16:38 - 2016-10-25 07:25 - 01872896 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2016-11-09 16:38 - 2016-10-25 07:25 - 01319424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2016-11-09 16:38 - 2016-10-25 07:25 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll 2016-11-09 16:38 - 2016-10-25 07:24 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2016-11-09 16:38 - 2016-10-25 07:24 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2016-11-09 16:38 - 2016-10-25 07:23 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-11-09 16:38 - 2016-10-25 07:22 - 01424384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll 2016-11-09 16:38 - 2016-10-25 07:22 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2016-11-09 16:38 - 2016-10-25 07:21 - 02054144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2016-11-09 16:38 - 2016-10-25 07:21 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-11-09 16:38 - 2016-10-25 07:20 - 03549696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll 2016-11-09 16:38 - 2016-10-25 07:17 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2016-11-09 16:38 - 2016-10-25 07:16 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2016-11-09 16:38 - 2016-10-25 07:05 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-11-09 16:38 - 2016-10-25 07:05 - 02610176 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-11-09 16:38 - 2016-10-25 07:03 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2016-11-09 16:38 - 2016-10-25 07:01 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2016-11-09 16:38 - 2016-10-25 06:54 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-11-09 16:38 - 2016-10-25 06:54 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-11-09 16:38 - 2016-10-25 06:54 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2016-11-09 16:38 - 2016-10-25 06:53 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2016-11-09 16:38 - 2016-10-25 06:52 - 04170240 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll 2016-11-09 16:38 - 2016-10-25 06:52 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2016-11-09 16:38 - 2016-10-25 06:51 - 02175488 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-11-09 16:38 - 2016-10-25 06:50 - 02874880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll 2016-11-09 16:38 - 2016-10-25 06:49 - 01997312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2016-11-09 16:38 - 2016-10-25 06:48 - 04826624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-11-09 16:38 - 2016-10-25 06:46 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll 2016-11-09 16:38 - 2016-10-25 06:43 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-11-09 16:38 - 2016-10-25 06:41 - 02444800 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2016-11-09 16:38 - 2016-10-25 06:40 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2016-11-09 16:38 - 2016-10-25 06:39 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2016-11-09 16:38 - 2016-10-25 06:38 - 03585536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-11-09 16:38 - 2016-10-25 06:37 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-11-09 16:38 - 2016-10-25 06:34 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-11-09 16:38 - 2016-10-25 06:34 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2016-11-09 16:38 - 2016-10-25 06:30 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-11-09 16:38 - 2016-10-25 06:28 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2016-11-09 16:38 - 2016-10-25 06:20 - 01797120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-11-09 16:38 - 2016-10-25 06:14 - 00651776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll 2016-11-09 16:38 - 2016-10-25 06:13 - 22375936 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-11-09 16:38 - 2016-10-25 06:12 - 11544576 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-11-09 16:38 - 2016-10-25 06:10 - 01568256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll 2016-11-09 16:38 - 2016-10-25 06:05 - 06312448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-11-09 16:38 - 2016-10-25 06:05 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2016-11-09 16:38 - 2016-10-25 06:02 - 24610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-11-09 16:38 - 2016-10-25 06:02 - 06976512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-11-09 16:38 - 2016-10-25 06:02 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-11-09 16:38 - 2016-10-25 06:02 - 03459584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll 2016-11-09 16:38 - 2016-10-25 06:01 - 13392384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-11-09 16:38 - 2016-10-25 05:48 - 07838208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-11-09 16:38 - 2016-10-25 03:19 - 00775336 _____ C:\WINDOWS\SysWOW64\locale.nls 2016-11-09 16:38 - 2016-10-25 03:19 - 00775336 _____ C:\WINDOWS\system32\locale.nls 2016-11-09 16:38 - 2016-09-07 06:22 - 00604920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-11-09 16:37 - 2016-11-02 15:25 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-11-09 16:37 - 2016-10-25 10:42 - 00037744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2016-11-09 16:37 - 2016-10-25 10:39 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2016-11-09 16:37 - 2016-10-25 10:26 - 00528736 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2016-11-09 16:37 - 2016-10-25 09:38 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-11-09 16:37 - 2016-10-25 09:37 - 00725776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll 2016-11-09 16:37 - 2016-10-25 09:36 - 01540216 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-11-09 16:37 - 2016-10-25 09:36 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-11-09 16:37 - 2016-10-25 09:34 - 01128104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2016-11-09 16:37 - 2016-10-25 09:34 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2016-11-09 16:37 - 2016-10-25 09:34 - 00106928 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe 2016-11-09 16:37 - 2016-10-25 09:01 - 00324448 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll 2016-11-09 16:37 - 2016-10-25 08:46 - 00376528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll 2016-11-09 16:37 - 2016-10-25 08:32 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll 2016-11-09 16:37 - 2016-10-25 08:31 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll 2016-11-09 16:37 - 2016-10-25 08:21 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2016-11-09 16:37 - 2016-10-25 08:19 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys 2016-11-09 16:37 - 2016-10-25 08:13 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll 2016-11-09 16:37 - 2016-10-25 08:13 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2016-11-09 16:37 - 2016-10-25 08:12 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2016-11-09 16:37 - 2016-10-25 08:10 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2016-11-09 16:37 - 2016-10-25 08:09 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oemlicense.dll 2016-11-09 16:37 - 2016-10-25 08:05 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FingerprintEnrollment.dll 2016-11-09 16:37 - 2016-10-25 08:02 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-11-09 16:37 - 2016-10-25 07:59 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2016-11-09 16:37 - 2016-10-25 07:59 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll 2016-11-09 16:37 - 2016-10-25 07:59 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsvc.dll 2016-11-09 16:37 - 2016-10-25 07:59 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll 2016-11-09 16:37 - 2016-10-25 07:58 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl 2016-11-09 16:37 - 2016-10-25 07:58 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2016-11-09 16:37 - 2016-10-25 07:57 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2016-11-09 16:37 - 2016-10-25 07:56 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dxpserver.exe 2016-11-09 16:37 - 2016-10-25 07:55 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2016-11-09 16:37 - 2016-10-25 07:55 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll 2016-11-09 16:37 - 2016-10-25 07:54 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll 2016-11-09 16:37 - 2016-10-25 07:53 - 00714240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2016-11-09 16:37 - 2016-10-25 07:53 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll 2016-11-09 16:37 - 2016-10-25 07:52 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2016-11-09 16:37 - 2016-10-25 07:52 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll 2016-11-09 16:37 - 2016-10-25 07:51 - 00469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll 2016-11-09 16:37 - 2016-10-25 07:51 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll 2016-11-09 16:37 - 2016-10-25 07:50 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2016-11-09 16:37 - 2016-10-25 07:47 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2016-11-09 16:37 - 2016-10-25 07:47 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2016-11-09 16:37 - 2016-10-25 07:47 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll 2016-11-09 16:37 - 2016-10-25 07:45 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-11-09 16:37 - 2016-10-25 07:44 - 00602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll 2016-11-09 16:37 - 2016-10-25 07:43 - 00440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe 2016-11-09 16:37 - 2016-10-25 07:42 - 00656896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll 2016-11-09 16:37 - 2016-10-25 07:41 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll 2016-11-09 16:37 - 2016-10-25 07:41 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-11-09 16:37 - 2016-10-25 07:41 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2016-11-09 16:37 - 2016-10-25 07:38 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll 2016-11-09 16:37 - 2016-10-25 07:38 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2016-11-09 16:37 - 2016-10-25 07:38 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll 2016-11-09 16:37 - 2016-10-25 07:37 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll 2016-11-09 16:37 - 2016-10-25 07:37 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2016-11-09 16:37 - 2016-10-25 07:35 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2016-11-09 16:37 - 2016-10-25 07:34 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-11-09 16:37 - 2016-10-25 07:33 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl 2016-11-09 16:37 - 2016-10-25 07:32 - 01037824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll 2016-11-09 16:37 - 2016-10-25 07:32 - 00990208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2016-11-09 16:37 - 2016-10-25 07:32 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-11-09 16:37 - 2016-10-25 07:32 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll 2016-11-09 16:37 - 2016-10-25 07:27 - 02731008 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2016-11-09 16:37 - 2016-10-25 07:24 - 04456448 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2016-11-09 16:37 - 2016-10-25 07:21 - 01570816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe 2016-11-09 16:37 - 2016-10-25 07:21 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\licensingdiag.exe 2016-11-09 16:37 - 2016-10-25 07:16 - 03415040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2016-11-09 16:37 - 2016-10-25 07:11 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll 2016-11-09 16:37 - 2016-10-25 07:09 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2016-11-09 16:37 - 2016-10-25 07:03 - 06675968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2016-11-09 16:37 - 2016-10-25 07:01 - 01755648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll 2016-11-09 16:37 - 2016-10-25 06:52 - 00693760 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll 2016-11-09 16:37 - 2016-10-25 06:47 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2016-11-09 16:37 - 2016-10-25 06:47 - 00453632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AdmTmpl.dll 2016-11-09 16:37 - 2016-10-25 06:35 - 02902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll 2016-11-09 16:37 - 2016-10-25 06:26 - 02563584 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll 2016-11-09 16:37 - 2016-10-25 06:13 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2016-11-09 16:37 - 2016-10-25 06:10 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll 2016-11-09 16:37 - 2016-10-25 06:03 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll 2016-11-09 16:37 - 2016-10-25 05:44 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2016-11-09 16:37 - 2016-10-25 05:43 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll 2016-11-06 04:15 - 2016-11-06 04:15 - 95043584 _____ C:\WINDOWS\system32\config\SOFTWARE.iobit 2016-11-06 04:15 - 2016-11-06 04:15 - 06832128 _____ C:\WINDOWS\system32\config\DRIVERS.iobit 2016-11-06 04:15 - 2016-11-06 04:15 - 00434176 _____ C:\WINDOWS\system32\config\DEFAULT.iobit 2016-11-06 04:15 - 2016-11-06 04:15 - 00069632 _____ C:\WINDOWS\system32\config\SAM.iobit 2016-11-06 04:15 - 2016-11-06 04:15 - 00032768 _____ C:\WINDOWS\system32\config\SECURITY.iobit 2016-11-06 04:07 - 2016-11-06 04:07 - 72520720 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat 2016-11-06 04:07 - 2016-11-06 04:07 - 07172920 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 07096192 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 06264640 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 05664483 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT 2016-11-06 04:07 - 2016-11-06 04:07 - 05339560 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 03283248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 03282544 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 03199232 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 02895104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl 2016-11-06 04:07 - 2016-11-06 04:07 - 02058496 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 02050184 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01965816 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01959608 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01780624 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01591064 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01508936 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01355616 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 01061120 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00965032 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00743968 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00727440 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00708320 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00689888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00678192 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00677680 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00574760 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00532384 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00504312 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00445408 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00441272 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00387320 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00371456 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00362064 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00330568 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00327464 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00310432 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00272720 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00253904 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00253872 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00252880 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00231920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00221976 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00214840 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00209544 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00166208 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00134208 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00122328 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00118600 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00110992 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00090920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00088352 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00088328 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00084624 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll 2016-11-06 04:07 - 2016-11-06 04:07 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll 2016-11-06 04:00 - 2016-11-08 14:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4 2016-11-06 04:00 - 2016-11-06 04:00 - 00003370 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler 2016-11-03 15:13 - 2016-11-03 15:13 - 00680212 _____ C:\WINDOWS\ProcessedPackets.KTL 2016-11-03 15:13 - 2016-11-03 15:13 - 00576091 _____ C:\WINDOWS\Packet.KTL 2016-11-03 15:13 - 2016-11-03 15:13 - 00288104 _____ C:\WINDOWS\SentOSPackets.KTL 2016-11-03 15:13 - 2016-11-03 15:13 - 00288088 _____ C:\WINDOWS\Control.KTL 2016-11-03 15:13 - 2016-11-03 15:13 - 00004123 _____ C:\WINDOWS\NGIControl.KTL 2016-10-23 13:47 - 2016-11-08 14:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ElsterFormular |
22.11.2016, 02:38 | #8 |
| Malwarefund Win32/Herz.B FRST.txt Fortsetzung Code:
ATTFilter ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-11-22 01:59 - 2013-04-25 21:16 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-11-22 01:57 - 2015-06-23 19:08 - 00001222 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002UA.job 2016-11-22 01:33 - 2015-07-29 01:24 - 00000000 ____D C:\ProgramData\MFAData 2016-11-22 01:31 - 2015-11-05 00:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2016-11-22 01:26 - 2016-09-21 03:28 - 00003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task 2016-11-22 01:16 - 2016-04-17 13:05 - 00000000 ____D C:\ProgramData\IObit 2016-11-22 01:12 - 2016-07-23 13:21 - 00000000 ____D C:\ProgramData\NVIDIA 2016-11-22 01:12 - 2016-04-27 06:48 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-11-22 01:11 - 2015-10-30 07:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI 2016-11-22 01:10 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF 2016-11-22 01:09 - 2015-05-19 02:04 - 00000008 __RSH C:\ProgramData\ntuser.pol 2016-11-21 23:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-11-21 21:12 - 2013-05-01 00:06 - 00000000 ____D C:\Users\u\AppData\Roaming\Free Download Manager 2016-11-21 12:25 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-11-21 12:23 - 2016-04-26 23:22 - 00000000 ____D C:\Users\u\AppData\Roaming\Wise Uninstaller 2016-11-20 15:59 - 2016-07-23 02:33 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-11-20 15:59 - 2016-04-27 06:13 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat 2016-11-20 15:59 - 2016-04-27 06:13 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat 2016-11-18 12:05 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache 2016-11-18 11:00 - 2016-04-17 13:05 - 00002460 _____ C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_UK 2016-11-18 11:00 - 2016-04-17 13:05 - 00000286 _____ C:\WINDOWS\Tasks\Uninstaller_SkipUac_UK.job 2016-11-18 11:00 - 2016-04-17 13:05 - 00000000 ____D C:\ProgramData\ProductData 2016-11-18 11:00 - 2016-04-17 13:05 - 00000000 ____D C:\Program Files (x86)\IObit 2016-11-18 10:57 - 2015-06-23 19:08 - 00001170 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002Core.job 2016-11-17 12:25 - 2016-04-17 13:05 - 00000000 ____D C:\Users\u\AppData\Roaming\IObit 2016-11-17 03:49 - 2016-04-17 13:05 - 00000000 ____D C:\Users\u\AppData\LocalLow\IObit 2016-11-17 03:42 - 2013-05-14 13:34 - 00000000 __RDO C:\Users\u\SkyDrive 2016-11-17 03:41 - 2016-07-23 03:08 - 00000000 ___DC C:\WINDOWS\Panther 2016-11-17 03:34 - 2016-07-24 11:19 - 00000000 ____D C:\Users\Administrator 2016-11-17 03:24 - 2016-04-17 14:55 - 00003008 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (UK) 2016-11-17 02:54 - 2016-05-12 11:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 2016-11-17 02:44 - 2016-07-23 02:15 - 00000000 ____D C:\Users\u 2016-11-17 02:44 - 2016-04-27 06:55 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-11-17 02:39 - 2016-04-26 21:44 - 00410448 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-11-17 02:39 - 2015-04-13 02:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-11-17 02:35 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\F12 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PrintDialog 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\migwiz 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Provisioning 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Defender 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2016-11-17 02:34 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2016-11-16 01:45 - 2015-10-30 07:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2016-11-14 21:48 - 2015-09-15 23:05 - 00002268 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-11-14 20:16 - 2013-05-14 15:06 - 00000000 ____D C:\Users\u\AppData\LocalLow\Temp 2016-11-14 20:12 - 2013-07-30 17:59 - 00000000 ____D C:\Users\u\AppData\Roaming\Spotify 2016-11-14 20:05 - 2013-07-30 17:59 - 00000000 ____D C:\Users\u\AppData\Local\Spotify 2016-11-14 15:55 - 2013-04-26 00:09 - 00000000 ____D C:\Users\u\AppData\Roaming\Skype 2016-11-12 01:00 - 2013-06-17 11:51 - 00000000 ____D C:\Users\u\AppData\Roaming\Dropbox 2016-11-10 14:29 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-11-10 14:29 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-11-10 10:52 - 2015-06-23 19:08 - 00004334 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002UA 2016-11-10 10:52 - 2015-06-23 19:08 - 00003958 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002Core 2016-11-09 18:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-11-09 18:04 - 2013-07-24 19:22 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-11-09 17:58 - 2013-02-01 06:09 - 141011376 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-11-09 15:48 - 2016-04-27 06:17 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-11-09 11:11 - 2016-07-17 00:55 - 00000000 ___HD C:\$WINDOWS.~BT 2016-11-09 03:33 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Registration 2016-11-09 03:32 - 2013-10-17 18:12 - 00022863 _____ C:\WINDOWS\diagwrn.xml 2016-11-09 03:32 - 2013-10-17 18:12 - 00022863 _____ C:\WINDOWS\diagerr.xml 2016-11-08 19:13 - 2016-07-23 03:48 - 00000000 ____D C:\WINDOWS\Minidump 2016-11-08 19:12 - 2013-12-08 18:52 - 00000000 ____D C:\Users\u\AppData\Local\Foxit Reader 2016-11-08 14:20 - 2016-07-23 13:19 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-11-08 14:20 - 2016-04-27 06:13 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2016-11-08 14:20 - 2016-04-26 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Program Uninstaller 2016-11-08 14:20 - 2016-04-15 13:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 2016-11-08 14:20 - 2016-04-12 10:54 - 00000000 ____D C:\WINDOWS\de 2016-11-08 14:20 - 2016-03-22 14:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\winahnen 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\spool 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\InputMethod 2016-11-08 14:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\IME 2016-11-08 14:20 - 2015-01-30 14:36 - 00000000 ____D C:\WINDOWS\system32\appmgmt 2016-11-08 14:20 - 2014-11-11 18:19 - 00000000 ____D C:\WINDOWS\SysWOW64\vbox 2016-11-08 14:20 - 2014-11-11 18:19 - 00000000 ____D C:\WINDOWS\system32\vbox 2016-11-08 14:20 - 2014-08-19 21:42 - 00000000 ____D C:\WINDOWS\SysWOW64\Adobe 2016-11-08 14:20 - 2014-07-16 17:39 - 00000000 ____D C:\WINDOWS\SysWOW64\SafeMonk 2016-11-08 14:20 - 2013-11-06 22:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2016-11-08 14:20 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared 2016-11-08 14:20 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared 2016-11-08 14:20 - 2013-02-01 08:43 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\sl 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\nl 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\it 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\hu 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\fr 2016-11-08 14:20 - 2013-02-01 07:50 - 00000000 ____D C:\WINDOWS\da 2016-11-08 14:20 - 2012-07-26 10:43 - 00000000 ____D C:\WINDOWS\en-GB 2016-11-08 14:19 - 2016-10-18 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-11-08 14:19 - 2016-10-02 19:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow 2016-11-08 14:19 - 2016-10-02 19:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ColdCut 2016-11-08 14:19 - 2016-07-23 13:19 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-11-08 14:19 - 2016-07-23 13:19 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-11-08 14:19 - 2016-05-25 13:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-11-08 14:19 - 2016-05-11 11:19 - 00000000 ____D C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Multimedia Mouse Driver 2016-11-08 14:19 - 2016-05-10 16:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader 2016-11-08 14:19 - 2016-01-06 16:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity 2016-11-08 14:19 - 2015-12-25 14:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-11-08 14:19 - 2015-12-20 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser in the Box 2016-11-08 14:19 - 2015-12-07 20:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiCryptoWall 2016-11-08 14:19 - 2015-11-13 12:51 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2 2016-11-08 14:19 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-11-08 14:19 - 2015-09-05 16:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc 2016-11-08 14:19 - 2015-07-23 01:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2016-11-08 14:19 - 2015-05-10 12:18 - 00000000 ____D C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2016-11-08 14:19 - 2015-05-02 01:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon 2016-11-08 14:19 - 2014-12-15 15:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Audio 2016-11-08 14:19 - 2014-10-06 12:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo Backup Free 7.5 2016-11-08 14:19 - 2014-10-06 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 10.1 2016-11-08 14:19 - 2014-07-10 17:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlightGear 2.4.0 2016-11-08 14:19 - 2014-07-10 16:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex 2016-11-08 14:19 - 2013-11-02 19:03 - 00000000 ____D C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DirSync 2016-11-08 14:19 - 2013-10-27 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3Gain 2016-11-08 14:19 - 2013-10-02 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SeaMonkey 2016-11-08 14:19 - 2013-09-06 13:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 2016-11-08 14:19 - 2013-08-21 22:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MediaMonkey 2016-11-08 14:19 - 2013-07-20 13:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2016-11-08 14:19 - 2013-07-03 17:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solid Edge 2D Drafting ST5 2016-11-08 14:19 - 2013-05-14 13:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva 2016-11-08 14:19 - 2013-05-01 00:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager 2016-11-08 14:19 - 2013-04-28 18:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bing-Desktop 2016-11-08 14:19 - 2013-04-26 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup 2016-11-08 14:19 - 2013-04-26 18:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Maustreiber 2016-11-08 14:19 - 2013-04-26 18:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-11-08 14:19 - 2013-04-25 23:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler 2016-11-08 14:19 - 2013-04-25 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView 2016-11-08 14:19 - 2013-02-01 08:13 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2016-11-08 14:19 - 2013-02-01 08:10 - 00000000 ____D C:\Program Files\Intel 2016-11-08 14:19 - 2013-02-01 08:06 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PhotoDirector 3 2016-11-08 14:19 - 2013-02-01 08:00 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HomeCinema 2016-11-08 14:19 - 2013-02-01 07:57 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover 2016-11-08 14:19 - 2013-02-01 07:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medion MediaPack 3 2016-11-08 11:59 - 2013-04-25 21:16 - 00003870 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-11-06 04:09 - 2016-07-23 02:12 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2016-11-06 04:09 - 2016-07-23 02:12 - 00000000 ____D C:\WINDOWS\system32\DAX2 2016-11-06 04:07 - 2016-07-24 15:51 - 05200128 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys 2016-11-06 04:07 - 2016-07-24 15:51 - 03087472 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll 2016-11-06 04:07 - 2016-07-24 15:51 - 00447728 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll 2016-11-06 04:07 - 2016-07-24 15:51 - 00192992 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll 2016-11-06 04:07 - 2016-07-24 15:51 - 00151792 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll 2016-11-06 04:07 - 2016-07-24 15:51 - 00023696 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll 2016-11-02 11:09 - 2013-07-20 13:19 - 00000000 ____D C:\Users\u\AppData\Local\Google 2016-10-30 17:05 - 2013-06-15 19:24 - 00000000 ____D C:\Users\u\AppData\Roaming\vlc 2016-10-28 22:48 - 2015-10-30 08:26 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-10-28 22:48 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-10-28 21:37 - 2013-02-01 07:52 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-10-28 21:37 - 2013-02-01 07:52 - 00000000 ____D C:\ProgramData\Skype 2016-10-25 09:58 - 2016-04-27 06:48 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2016-10-23 13:49 - 2014-05-24 22:43 - 00000000 ____D C:\ProgramData\elsterformular 2016-10-23 13:47 - 2014-05-24 22:42 - 00000000 ____D C:\Program Files (x86)\ElsterFormular ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2004-01-21 18:29 - 2004-01-21 14:52 - 2863868 _____ () C:\Program Files (x86)\CADtools.aip 2016-04-26 23:22 - 2016-04-26 23:22 - 0000376 _____ () C:\Users\u\AppData\Roaming\wpulog.txt 2013-04-27 11:27 - 2016-10-20 19:00 - 0074752 _____ () C:\Users\u\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-04-26 00:22 - 2015-12-08 12:38 - 0007652 _____ () C:\Users\u\AppData\Local\resmon.resmoncfg 2016-07-23 02:12 - 2016-07-23 02:12 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Einige Dateien in TEMP: ==================== C:\Users\u\AppData\Local\Temp\libeay32.dll C:\Users\u\AppData\Local\Temp\msvcr120.dll C:\Users\u\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-11-13 17:39 ==================== Ende von FRST.txt ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 20-11-2016 01 durchgeführt von UK (22-11-2016 02:24:31) Gestartet von D:\Desktop\malware apps Windows 10 Pro Version 1511 (X64) (2016-07-23 02:06:14) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2736805842-114790362-3470889979-500 - Administrator - Enabled) => C:\Users\Administrator BitBox (S-1-5-21-2736805842-114790362-3470889979-1036 - Limited - Enabled) DefaultAccount (S-1-5-21-2736805842-114790362-3470889979-503 - Limited - Disabled) Gast (S-1-5-21-2736805842-114790362-3470889979-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2736805842-114790362-3470889979-1039 - Limited - Enabled) UK (S-1-5-21-2736805842-114790362-3470889979-1002 - Administrator - Enabled) => C:\Users\u ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated) Adobe Illustrator 10.0.3 (HKLM-x32\...\{412033BC-44CF-48D9-B813-4B835101F4D3}) (Version: 10.0.3 - Adobe Systems, Inc.) Adobe Photoshop 7.0 (HKLM-x32\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.) Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version: 3.0 - Adobe Systems, Inc.) Advanced SystemCare 10 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 10.0.3 - IObit) Amazon Kindle (HKLM-x32\...\Amazon Kindle) (Version: - Amazon) Amazon Kindle (HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Amazon Kindle) (Version: 1.14.0.43019 - Amazon) AntiCryptoWall (HKLM\...\{BE40AB1F-558F-4434-B72F-461EF97E7796}_is1) (Version: 1.0.9.1 - Bitdefender) Ashampoo AppLauncher (Medion) v.1.0.0 (HKLM-x32\...\Ashampoo AppLauncher (Medion)_is1) (Version: 1.0.0 - Ashampoo GmbH & Co. KG) Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team) Autodesk 3ds Max 2011 64-Bit (HKLM\...\{39BFB02A-9692-0407-A808-3F5C7B1F8953}) (Version: 13.0 - Autodesk) AVG (Version: 16.131.7924 - AVG Technologies) Hidden AVG 2016 (Version: 16.0.4664 - AVG Technologies) Hidden AVG Protection (HKLM\...\AVG) (Version: 2016.131.7924 - AVG Technologies) Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.2.126.0 - Microsoft Corporation) Browser in the Box (HKLM-x32\...\BitBox) (Version: 4.1.4-r150 - Sirrix AG) CCleaner (HKLM\...\CCleaner) (Version: 5.22 - Piriform) CDex - Open Source Digital Audio CD Extractor (HKLM-x32\...\CDex) (Version: 1.70.5.2014 - Georgy Berdyshev) Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.53 - Cliqz.com) ColdCut (HKLM-x32\...\{8944ED10-DBF2-4FA9-8B5D-D7E1B046C761}_is1) (Version: ColdCut - © Jan Brummelte) CyberLink PhotoNow (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.7717 - CyberLink Corp.) CyberLink PowerDirector (Version: 9.0.0.3815c - CyberLink Corp.) Hidden CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.7.0.0913 - CyberLink Corp.) CyberLink PowerRecover (Version: 5.7.0.0913 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DC Magic Audio (HKLM-x32\...\DCMaUnInstall) (Version: - ) Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform) DirSync 2.96 (HKLM-x32\...\DirSync) (Version: - Stephen Kalisch) Driver Booster 4.0 (HKLM-x32\...\Driver Booster_is1) (Version: 4.0.4 - IObit) Dropbox (HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Dropbox) (Version: 14.4.19 - Dropbox, Inc.) EaseUS Partition Master 10.1 (HKLM-x32\...\EaseUS Partition Master_is1) (Version: - EaseUS) EaseUS Todo Backup Free 7.5 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 7.5 - CHENGDU YIWO Tech Development Co., Ltd) ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 17.4.19695 - Landesfinanzdirektion Thüringen) EPSON BX535WD Series Printer Uninstall (HKLM\...\EPSON BX535WD Series) (Version: - SEIKO EPSON Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EpsonNet Config V4 (HKLM-x32\...\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.1.1 - SEIKO EPSON CORPORATION) EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) ffdshow [rev 2946] [2009-05-15] (HKLM-x32\...\ffdshow_is1) (Version: 1.0 - ) FlightGear 2.4.0 (HKLM-x32\...\FlightGear 2.4.0_is1) (Version: - The FlightGear Team) FMW 1 (Version: 1.132.1 - AVG Technologies) Hidden FormatFactory 3.6.0.0 (HKLM-x32\...\FormatFactory) (Version: 3.6.0.0 - Format Factory) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.3.6.321 - Foxit Software Inc.) Free Download Manager 3.9.3 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG) Free YouTube to MP3 Converter version 3.12.60.713 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.60.713 - DVDVideoSoft Ltd.) Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden GIMP 2.8.4 (HKLM\...\GIMP-2_is1) (Version: 2.8.4 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.99 - Google Inc.) Google Earth (HKLM-x32\...\{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}) (Version: 7.1.1.1888 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{DA2600C1-6BDF-4FD1-1212-148929CC1385}) (Version: 2.6.1212.0302 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.7.0.1013 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel(R) WiDi (HKLM\...\{23D486D4-FBE0-40F3-A245-E4D56D094764}) (Version: 3.5.41.0 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{2b83a547-7e0f-4dca-8990-97ff818fa3d8}) (Version: 15.6.0 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) KRISTAL Audio Engine (HKLM-x32\...\KRISTAL Audio Engine) (Version: - ) LatencyMon 6.00 (HKLM\...\LatencyMon_is1) (Version: - Resplendence Software Projects Sp.) Launch Manager (HKLM-x32\...\{D0846526-66DD-4DC9-A02C-98F9A2806812}) (Version: 1.5.1.8 - Wistron Corp.) Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) MediaMonkey 4.1 (HKLM-x32\...\MediaMonkey_is1) (Version: 4.1 - Ventis Media Inc.) Mediathek (HKLM-x32\...\{EFFED0C0-5299-422E-AFE6-8B8066D18A2A}) (Version: 1.4.0 - Medion) Medion Home Cinema 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) Medion Home Cinema 10 (x32 Version: 10.1924 - CyberLink Corp.) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{e6e75766-da0f-4ba2-9788-6ea593ce702d}) (Version: 12.0.30501.0 - Microsoft Corporation) MouseDriver (HKLM-x32\...\{643E1970-324F-474C-8610-55F3F053BC01}) (Version: 1.00.0000 - ) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek) Mozilla Firefox 50.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.0 (x86 de)) (Version: 50.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.0.0.6152 - Mozilla) Multimedia Mouse Driver (HKLM-x32\...\InstallShield_{A9495514-098A-4869-A464-C455857BC464}) (Version: 2.0 - Ihr Firmenname) Multimedia Mouse Driver (x32 Version: 2.0 - Ihr Firmenname) Hidden NVIDIA 3D Vision Treiber 353.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.62 - NVIDIA Corporation) NVIDIA Grafiktreiber 353.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.62 - NVIDIA Corporation) NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation) OpenOffice 4.1.2 (HKLM-x32\...\{E6AD67BB-1C33-4AB3-A387-E0D48137AB70}) (Version: 4.12.9782 - Apache Software Foundation) OpenOffice 4.1.2 Language Pack (German) (HKLM-x32\...\{E0E6DB8D-D2B1-4A0B-A09C-44DBC09BF499}) (Version: 4.12.9782 - Apache Software Foundation) Oracle VM VirtualBox 5.0.10_Sirrix (HKLM\...\{15DB0BEC-4D4B-4471-9E37-2FB454965C05}) (Version: 5.0.10 - Sirrix AG) paint.net (HKLM\...\{F509C1F4-0029-49F9-B145-A4C4E8DF481A}) (Version: 4.0.3 - dotPDN LLC) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.) Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Reader for PC (HKLM-x32\...\{D279DFB7-97A3-439D-8BE9-95D8AFA68562}) (Version: 2.4.01.10241 - Sony Corporation) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7794 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.46 - Piriform) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.) Hidden Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.) SeaMonkey 2.40 (x86 de) (HKLM-x32\...\SeaMonkey 2.40 (x86 de)) (Version: 2.40 - Mozilla) Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.16034.4 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.1.16034.4 - Samsung Electronics Co., Ltd.) Hidden Solid Edge 2D Drafting ST5 (HKLM-x32\...\{6AE4221E-7BB6-4D22-A157-5AA0F206EF30}) (Version: 105.00.01015 - Siemens) Spotify (HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\Spotify) (Version: 1.0.42.151.g19de0aa6 - Spotify AB) Sweet Home 3D version 4.6 (HKLM\...\Sweet Home 3D_is1) (Version: - eTeks) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.19.1 - Synaptics Incorporated) Unity (HKLM-x32\...\Unity) (Version: - Unity Technologies ApS) Unity Web Player (HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\UnityWebPlayer) (Version: 5.3.6f1 - Unity Technologies ApS) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Vulkan Run Time Libraries 1.0.5.1 (HKLM\...\VulkanRT1.0.5.1) (Version: 1.0.5.1 - LunarG, Inc.) Winahnen 6.51 (HKLM-x32\...\Winahnen) (Version: 6.51 - Cyberlab GmbH) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Wise Program Uninstaller 1.96 (HKLM-x32\...\Wise Program Uninstaller_is1) (Version: 1.96 - WiseCleaner.com, Inc.) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll () CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2736805842-114790362-3470889979-1002_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\u\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0BD5A988-59E8-49BB-9365-4E1725064C36} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {214D3269-76F4-4291-B9E5-7525B5B3FCBE} - System32\Tasks\ASC10_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-11-10] (IObit) Task: {247308E9-66CE-4324-B318-3ED1EBB0ECF8} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002Core => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {2C74D5F8-22E0-4A30-A58C-4462427CA7D0} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-11-09] (Microsoft Corporation) Task: {2FB4CFDF-3396-4702-BD4F-C1C371F43971} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-09-22] (Oracle Corporation) Task: {3802260F-4C4B-4948-8980-03EF66E049CF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {4B1BFEF3-AA86-4DD7-A4E8-A675A283752E} - System32\Tasks\Uninstaller_SkipUac_UK => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe Task: {500250FB-2304-49FF-B3D3-15DA6D2E338A} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG Task: {569AF090-9860-4BD5-A4CF-A91B7CF1FE83} - System32\Tasks\Defraggler Volume C Task => C:\Program Files\Defraggler\df64.exe [2016-03-08] (Piriform Ltd) Task: {5B3A3A2A-B5C5-4ADC-9A8C-6EA6EB1EDC90} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {606A4DE5-12F6-455C-A32C-1B203E403503} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Keine Datei <==== ACHTUNG Task: {640E7F00-9D80-4AAA-A0AA-E62828580740} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {6AD5537A-83EA-4E26-86D0-2F7FBEF13D71} - System32\Tasks\ASC10_SkipUac_UK => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-11-11] (IObit) Task: {6D3DFBB8-08BE-4544-BC25-6F8EC54BC860} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> Keine Datei <==== ACHTUNG Task: {6DAC5A9A-A3DF-46AE-9C33-416F3191CA51} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {6DC35D43-D1FB-428B-98B6-4058DA64BE3D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {77985C08-6D66-46E5-88EB-6CEE7604899B} - \Microsoft\Windows\Setup\gwx\rundetector -> Keine Datei <==== ACHTUNG Task: {87721D04-8D72-4F96-AC0C-EA284D9B9F71} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {905FB805-E39D-4CF4-835F-829B8907356F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {98A2E36E-6902-4350-BB0C-B0DBBB4F8159} - System32\Tasks\AVG-SSU_1116av_DELETE => C:\ProgramData\Avg_Update_1116av\AVG-Secure-Search-Update_1116av.exe Task: {9BC69F5F-77BC-4BAC-9651-0B346EA4A320} - System32\Tasks\Synaptics TouchPad Enhancements => Program Files\Synaptics\SynTP\SynTPEnh.exe Task: {A2104205-7A54-472D-ABFC-AE12D9BB6B90} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {ABD0E0FE-32B4-48E1-82EB-D8B34E0728F0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {AD2C4855-CAB9-420C-8B53-4E7AE96479C4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-26] (Piriform Ltd) Task: {B3473A15-8F0E-48DF-93D3-499B8BEECCD8} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG Task: {BB82A172-7AA9-4CFC-9932-DE373FE3E9D5} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002UA => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {BDDBCBA1-6C7F-4D79-BA99-E5D6AE466E1E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {C3CB5C01-A5A4-4D89-9483-1FFFAAEE19C6} - System32\Tasks\AVG-SSU_1116av => C:\ProgramData\Avg_Update_1116av\AVG-Secure-Search-Update_1116av.exe Task: {C5A8771C-782B-4082-B79A-FB8E3ADCD3F2} - System32\Tasks\{5043C671-56F2-4441-BD17-E62D27136F46} => pcalua.exe -a "C:\Program Files (x86)\pazera-software\MOV_to_AVI_Converter\unins000.exe" -d "C:\Program Files (x86)\pazera-software\MOV_to_AVI_Converter" Task: {C87E602A-82BA-4025-87C8-0BF70E0062B6} - System32\Tasks\{4E86AB65-D547-4799-BFA7-96F9D06FD3D7} => pcalua.exe -a "J:\backup\Downloads\GRAFIK\illustrator10\CADtools 3\Install Hot Door CADtools.exe" -d "J:\backup\Downloads\GRAFIK\illustrator10\CADtools 3" Task: {DC0EB0F0-2991-4968-AAD8-FCDFA9444125} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {E23EA3DC-6853-494B-9B8C-A7F113B1B65A} - System32\Tasks\Driver Booster SkipUAC (UK) => C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DriverBooster.exe [2016-10-09] (IObit) Task: {F24B0DCE-7E54-4C06-88CD-03FC83A4120D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-08] (Adobe Systems Incorporated) Task: {F3AE50C8-80D6-46F8-9793-5B3D2F2CB57E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {FD77217B-EA1D-4D9D-A217-274FFEF19337} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\4.0.4\Scheduler.exe [2016-09-20] (IObit) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\Defraggler Volume C Task.job => Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002Core.job => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2736805842-114790362-3470889979-1002UA.job => C:\Users\u\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_UK.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MEDIONhome.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.medion.com ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Welcome.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.aldi-essen.de ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 08:17 - 2015-10-30 08:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-07-23 13:20 - 2015-07-23 02:10 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-11-09 16:38 - 2016-10-25 10:42 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-11-09 16:38 - 2016-10-25 10:42 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-07-23 03:11 - 2016-07-23 03:11 - 00959168 _____ () C:\Users\u\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\ClientTelemetry.dll 2016-04-27 06:17 - 2016-04-27 06:17 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-23 13:16 - 2016-07-01 04:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-11-09 16:39 - 2016-10-25 05:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-09 16:38 - 2016-10-25 05:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-09 16:39 - 2016-10-25 05:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-09 16:39 - 2016-10-25 05:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-07-23 13:32 - 2016-07-23 13:32 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-11-17 02:56 - 2016-03-31 17:57 - 00625440 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll 2016-11-17 02:54 - 2016-08-18 18:43 - 00442144 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madExcept_.bpl 2016-11-17 02:54 - 2016-08-18 18:43 - 00210720 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madBasic_.bpl 2016-11-17 02:54 - 2016-08-18 18:43 - 00059680 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madDisAsm_.bpl 2016-11-17 02:54 - 2016-11-01 10:11 - 00078624 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\GetProcessDLL.dll 2015-11-05 00:47 - 2016-04-07 14:15 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll 2016-11-17 13:39 - 2016-11-17 13:39 - 00016384 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\7f002ef0b02a7544d20e117968d12bdd\PSIClient.ni.dll 2013-02-01 08:10 - 2012-06-25 09:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2016-07-23 13:32 - 2016-07-23 13:32 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-07-23 13:32 - 2016-07-23 13:32 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PAexec => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1001movie.com -> 1001movie.com IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\1001night.biz -> 1001night.biz IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\100gal.net -> 100gal.net IE restricted site: HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\100sexlinks.com -> 100sexlinks.com Da befinden sich 4788 mehr Seiten. ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2736805842-114790362-3470889979-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\u\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\irfanview_wallpaper.bmp DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\startupreg: BingDesktop => c:\program files (x86)\microsoft\bingdesktop\bingdesktop.exe /fromkey MSCONFIG\startupreg: EaseUS EPM tray => c:\program files (x86)\easeus\easeus partition master 10.1\bin\epmnews.exe MSCONFIG\startupreg: iWareV3 => c:\program files (x86)\hamamousedriver\officemouse.exe HKLM\...\StartupApproved\Run: => "BTMTrayAgent" HKLM\...\StartupApproved\Run: => "NvBackend" HKLM\...\StartupApproved\Run32: => "CLMLServer_For_P2G8" HKLM\...\StartupApproved\Run32: => "CLVirtualDrive" HKLM\...\StartupApproved\Run32: => "RemoteControl10" HKLM\...\StartupApproved\Run32: => "YouCam Service" HKLM\...\StartupApproved\Run32: => "BingDesktop" HKLM\...\StartupApproved\Run32: => "EaseUS EPM tray" HKLM\...\StartupApproved\Run32: => "Reader Application Helper" HKLM\...\StartupApproved\Run32: => "KMConfig" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\StartupFolder: => "Dropbox.lnk" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\StartupFolder: => "An OneNote senden.lnk" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "SkyDrive" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "Power2GoExpress8" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "Spotify Web Helper" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "OKAYFREEDOM_Agent" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2736805842-114790362-3470889979-1002\...\StartupApproved\Run: => "Dropbox Update" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{4D4C9AD9-356F-4BFA-97FA-16244E817834}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{146E9894-E3CE-47DC-A95B-8FC9E0ECA636}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{047977D7-43F7-41D0-A3EC-BB1CF97D5B61}] => (Allow) LPort=1900 FirewallRules: [{F5FF2534-1B73-4E39-AC75-2E59DCE4FEBB}] => (Allow) LPort=2869 FirewallRules: [{343B8EF5-AD71-40DC-BAB7-AFD84845CC2E}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [UDP Query User{3821B853-4841-4163-A0D3-6FB2B599D721}C:\program files (x86)\freetime\formatfactory\formatfactory.exe] => (Allow) C:\program files (x86)\freetime\formatfactory\formatfactory.exe FirewallRules: [TCP Query User{D365C419-7280-4005-9EAC-659970EAF00A}C:\program files (x86)\freetime\formatfactory\formatfactory.exe] => (Allow) C:\program files (x86)\freetime\formatfactory\formatfactory.exe FirewallRules: [{245055FD-A157-44DB-B4FC-A996A22E088C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{C294BFF7-DCAB-4B69-A38B-02D3C528607A}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{DFBF42E0-4C71-430B-B1CE-8062419FED92}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{D2066F37-5662-48B8-A689-FB1EE3F82333}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{AC814D30-FA2E-44E0-8DB7-A5AB7EF33C54}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe FirewallRules: [{AF45708B-A877-49FD-9560-E963E09EEC5D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{04C2C747-A2F8-4774-9348-F8691706677A}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [UDP Query User{C1A9CAD9-5997-4419-A652-5B7F453CD2BA}C:\users\u\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\u\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{6CFCC5B2-469F-4E8D-A8A4-BD6D3B04D2FF}C:\users\u\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\u\appdata\roaming\spotify\spotify.exe FirewallRules: [{1CC73DFC-D009-450A-9092-AA8020FB8074}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{989D5291-5062-4C9D-A812-8641CC7AD9AD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5E3F33AC-D82E-4500-B331-F89B63496553}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{B9033C8B-5CD6-431F-A3BF-82429B1DE042}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{7CCAC3FE-9832-4310-889D-70EF859CD487}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe FirewallRules: [{4C03A924-1E11-4002-8202-1D0D4B495167}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{5D8C0ED3-DEB5-40E9-9F36-C777624753A8}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{8BCA876E-C56A-4407-9A8D-856517AA77C1}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{1E78C583-9717-4244-84DB-76BCFC22C833}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{EF944702-B94D-45F2-9B0E-5811E40E5989}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{CE0966CA-B266-46CC-984C-CBF587451532}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{09887BFF-029C-403B-8B53-08E54CFFA49E}] => (Allow) C:\Program Files (x86)\ElsterFormular\bin\pica.exe FirewallRules: [{3224EFAA-5BAA-42F6-AB8D-D467E8C9CB6D}] => (Allow) C:\Program Files (x86)\ElsterFormular\bin\pica.exe FirewallRules: [{932E0581-99ED-4E1C-B0BA-DCA7C35FB7E8}] => (Allow) C:\Program Files (x86)\ElsterFormular\bin\pica.exe FirewallRules: [{3CA21043-CBBF-46DC-BCC0-28050F77FBCC}] => (Allow) C:\Program Files (x86)\ElsterFormular\bin\pica.exe FirewallRules: [UDP Query User{A8229A15-0C45-42BD-8FC2-5C1D458E213D}C:\program files (x86)\mediamonkey\mediamonkey.exe] => (Allow) C:\program files (x86)\mediamonkey\mediamonkey.exe FirewallRules: [TCP Query User{517092E8-B102-48CE-A4D1-5B4009E2DDEB}C:\program files (x86)\mediamonkey\mediamonkey.exe] => (Allow) C:\program files (x86)\mediamonkey\mediamonkey.exe FirewallRules: [UDP Query User{C6C09EC6-0D7B-451B-9661-2A0E694BACCA}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [TCP Query User{AA849031-F27A-4B9F-A99D-F0144DC08DF3}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [{5257C427-CFFC-49FD-972D-AF35E0A1C61C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{13D13049-ACB6-44B8-96BB-FCF92AEBAB24}] => (Allow) C:\Program Files\CyberLink\PowerDirector\PDR9.EXE FirewallRules: [{07914CAC-C34D-4187-BBAE-D1CAA6D2ABDC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{1CD9D222-A437-4DAE-A8CB-DFB885ED5E95}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{FD060A25-41C1-4BE2-B90C-92DA496DD612}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe FirewallRules: [{783FF671-AE0D-4A75-AA01-2BB9E3FC8FE3}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe FirewallRules: [{E3E045E5-F501-4BE2-AA27-5C0170451BFE}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Config V4\ENConfig.exe FirewallRules: [{65A8A1C7-4F46-4F9B-8B4E-C08958F7B12E}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Config V4\ENConfig.exe FirewallRules: [{B7B03170-9F92-43BD-9485-D9BC379E4AA4}] => (Allow) C:\Users\u\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{E7D90FBE-CD4E-46D3-8E3F-DDA8F84EB824}] => (Allow) C:\Users\u\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{C3503FD4-1AD0-4650-A170-28953E966FF5}C:\users\u\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\u\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{BC410B7C-5F94-423A-A0E9-C3A9FFCCE769}C:\users\u\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\u\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{0C5ACE68-BB7C-43F3-A1EF-E0AEE4193A36}C:\users\u\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\u\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{F16CD45C-B296-4C92-AEDD-30EA494D1E35}C:\users\u\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\u\appdata\roaming\spotify\spotify.exe FirewallRules: [{A67E3198-4406-451C-BA3E-3F9BB9BC6BFA}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DriverBooster.exe FirewallRules: [{CA9D6CD5-736D-4896-9161-52532E6796C9}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DriverBooster.exe FirewallRules: [{C9C2CFE4-A6FD-4DDE-BFD4-7AE8A00756CA}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DBDownloader.exe FirewallRules: [{4DA1B66E-98F2-4BD5-8A45-16DF159B13D8}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\DBDownloader.exe FirewallRules: [{7ABD4256-E2CA-4B27-85BC-1577429DC96A}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\AutoUpdate.exe FirewallRules: [{B28718EC-D135-4C0D-8698-2485438D9072}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.0.4\AutoUpdate.exe FirewallRules: [{8B10A2D3-224F-43CD-8990-E2531D2C2182}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{C4CF1696-8AF6-431F-9671-1E385FAE5A94}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe FirewallRules: [{925B148B-3F9E-4FE0-BAA1-64E31AA2C506}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe ==================== Wiederherstellungspunkte ========================= 09-11-2016 17:53:19 Windows Update 19-11-2016 15:42:16 Geplanter Prüfpunkt ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (11/20/2016 04:04:11 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: Die Open-Prozedur für den Dienst "BITS" in der DLL "C:\Windows\System32\bitsperf.dll" war nicht erfolgreich. Die Leistungsdaten für diesen Dienst sind nicht verfügbar. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Fehlercode. Error: (11/19/2016 03:42:37 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (11/18/2016 10:50:35 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: Die Open-Prozedur für den Dienst "BITS" in der DLL "C:\Windows\System32\bitsperf.dll" war nicht erfolgreich. Die Leistungsdaten für diesen Dienst sind nicht verfügbar. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Fehlercode. Error: (11/17/2016 07:26:18 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Laptop) Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (11/12/2016 07:33:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Laptop) Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (11/09/2016 05:53:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (11/09/2016 05:52:40 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (11/08/2016 07:29:09 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (11/08/2016 07:12:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FoxitReader.exe, Version: 7.3.6.321, Zeitstempel: 0x56f0c322 Name des fehlerhaften Moduls: FoxitReader.exe, Version: 7.3.6.321, Zeitstempel: 0x56f0c322 Ausnahmecode: 0xc000041d Fehleroffset: 0x002b8f92 ID des fehlerhaften Prozesses: 0x1df4 Startzeit der fehlerhaften Anwendung: 0x01d239c6ce600a6f Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe Berichtskennung: cfd7912c-5387-4405-a309-1a866260512a Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (11/08/2016 07:12:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FoxitReader.exe, Version: 7.3.6.321, Zeitstempel: 0x56f0c322 Name des fehlerhaften Moduls: FoxitReader.exe, Version: 7.3.6.321, Zeitstempel: 0x56f0c322 Ausnahmecode: 0xc0000005 Fehleroffset: 0x002b8f92 ID des fehlerhaften Prozesses: 0x1df4 Startzeit der fehlerhaften Anwendung: 0x01d239c6ce600a6f Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe Berichtskennung: a624d073-4bf8-4778-9d7d-5cb5719ee551 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Systemfehler: ============= Error: (11/22/2016 02:01:42 AM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (11/22/2016 01:14:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (11/22/2016 01:14:37 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht. Error: (11/22/2016 01:10:48 AM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: Zugriff verweigert Error: (11/22/2016 01:10:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_130926" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (11/22/2016 01:10:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _130926" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (11/22/2016 01:10:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kontaktdaten_130926" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (11/22/2016 01:10:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Synchronisierungshost_130926" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (11/22/2016 01:09:10 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Intel(R) Management and Security Application User Notification Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/22/2016 01:09:10 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2016-11-17 23:23:34.164 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-17 02:42:59.309 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-11 10:22:26.997 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-10 10:35:56.723 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-29 20:30:56.210 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-18 17:34:33.045 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-18 12:02:10.098 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-13 19:06:30.756 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-09-22 09:57:25.275 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-09-21 04:18:21.889 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz Prozentuale Nutzung des RAM: 36% Installierter physikalischer RAM: 8054.82 MB Verfügbarer physikalischer RAM: 5141.53 MB Summe virtueller Speicher: 12627.82 MB Verfügbarer virtueller Speicher: 9873.05 MB ==================== Laufwerke ================================ Drive c: (Boot) (Fixed) (Total:134.05 GB) (Free:56.02 GB) NTFS Drive d: (Daten) (Fixed) (Total:719.95 GB) (Free:488.86 GB) NTFS Drive g: (Mediendaten 292 GB) (Fixed) (Total:272.69 GB) (Free:100.63 GB) NTFS Drive i: (leer) (Fixed) (Total:20.28 GB) (Free:20.2 GB) NTFS Drive j: (Sicherung 172 GB) (Fixed) (Total:172.79 GB) (Free:74.89 GB) NTFS Drive x: (Recover) (Fixed) (Total:60 GB) (Free:38.54 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: CEAAD2D8) Partition: GPT. ======================================================== Disk: 1 (Size: 465.8 GB) (Disk ID: 6040535F) Partition 1: (Not Active) - (Size=272.7 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=193.1 GB) - (Type=OF Extended) ==================== Ende von Addition.txt ============================ |
22.11.2016, 19:39 | #9 |
/// TB-Ausbilder /// Anleitungs-Guru | Malwarefund Win32/Herz.B Jetzt bitte Suchscan durchführen: Schritt 1 ESET Online Scanner
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
23.11.2016, 00:55 | #10 |
| Malwarefund Win32/Herz.BCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=b17a6cdd44a8b248b4aa1ba2fffc6619 # end=init # utc_time=2016-11-22 07:39:59 # local_time=2016-11-22 08:39:59 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT Update Init Update Download Update Finalize Updated modules version: 31495 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=b17a6cdd44a8b248b4aa1ba2fffc6619 # end=updated # utc_time=2016-11-22 07:43:32 # local_time=2016-11-22 08:43:32 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=b17a6cdd44a8b248b4aa1ba2fffc6619 # engine=31495 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2016-11-22 11:40:34 # local_time=2016-11-23 12:40:34 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 511557 42967688 0 0 # scanned=440445 # found=15 # cleaned=0 # scan_time=14222 sh=E5A3C100D2D0FD94482783AF2B2FF94CDFC9923F ft=1 fh=a0ddd0619a504a2e vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst.exe" sh=B44563F350D13A61F4BAB2F9789F5DB242FBE6CA ft=1 fh=0f31995336839b28 vn="JS/Adware.OkayFreedom.B Anwendung" ac=I fn="C:\Users\u\AppData\Roaming\Steganos Updates\okayfreedom.exe" sh=77DB346946411FB2FC738E41FB5CBA8C3977BA3C ft=1 fh=09817c38a1110951 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\Downloads\Vollversion OkayFreedom Premium Flat - CHIP-Installer.exe" sh=D0357617961BF3D526BEFAAB0048CBB983EA4DF9 ft=1 fh=c604c933e8b9509f vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="D:\sicherung goflex146gb\backup\Downloads\Büro\PDFCreator-1_7_0_setup.exe" sh=0C7E1F8EB63F9F1C75EB08A156E54A7349853EFF ft=1 fh=d24020069345d3b6 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="D:\sicherung goflex146gb\backup\Downloads\GRAFIK\PDFCreator-1_6_0_setup.exe" sh=AAEB7DF581622DF024AEBC8334A2FD1A41B0F961 ft=1 fh=7156b3e211cf553a vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\sicherung goflex146gb\backup\Downloads\MEDIA\ASIO4ALL - CHIP-Installer.exe" sh=EC3FA9335CF9402DD2B5BDEAACDAFED8F53E8ED1 ft=1 fh=b634ee102f30f686 vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="D:\sicherung goflex146gb\backup\Downloads\MEDIA\FreeVideoToMP3Converter.exe" sh=E8CD33623287C08C7CC3662A042E45522654BB30 ft=1 fh=7cd3b160b0dbd4bd vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="D:\sicherung goflex146gb\backup\Downloads\MEDIA\FreeYouTubeToMP3Converter.exe" sh=5DC34A7B59175F98F475EFDEA6877AA4AF79C989 ft=1 fh=88cf7b708d93a913 vn="Win32/Toolbar.Widgi.Y evtl. unerwünschte Anwendung" ac=I fn="D:\sicherung goflex146gb\backup\Downloads\TOOLS\PDFCreator-1_2_0_setup.exe" sh=D0357617961BF3D526BEFAAB0048CBB983EA4DF9 ft=1 fh=c604c933e8b9509f vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="J:\backup\Downloads\Büro\PDFCreator-1_7_0_setup.exe" sh=0C7E1F8EB63F9F1C75EB08A156E54A7349853EFF ft=1 fh=d24020069345d3b6 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="J:\backup\Downloads\GRAFIK\PDFCreator-1_6_0_setup.exe" sh=AAEB7DF581622DF024AEBC8334A2FD1A41B0F961 ft=1 fh=7156b3e211cf553a vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="J:\backup\Downloads\MEDIA\ASIO4ALL - CHIP-Installer.exe" sh=EC3FA9335CF9402DD2B5BDEAACDAFED8F53E8ED1 ft=1 fh=b634ee102f30f686 vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="J:\backup\Downloads\MEDIA\FreeVideoToMP3Converter.exe" sh=E8CD33623287C08C7CC3662A042E45522654BB30 ft=1 fh=7cd3b160b0dbd4bd vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="J:\backup\Downloads\MEDIA\FreeYouTubeToMP3Converter.exe" sh=5DC34A7B59175F98F475EFDEA6877AA4AF79C989 ft=1 fh=88cf7b708d93a913 vn="Win32/Toolbar.Widgi.Y evtl. unerwünschte Anwendung" ac=I fn="J:\backup\Downloads\TOOLS\PDFCreator-1_2_0_setup.exe" gruß Rolf |
23.11.2016, 18:14 | #11 |
/// TB-Ausbilder /// Anleitungs-Guru | Malwarefund Win32/Herz.B Gibt es jetzt noch Probleme mit dem PC? Wenn ja, welche?
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
23.11.2016, 19:48 | #12 |
| Malwarefund Win32/Herz.B Hallo Jürgen, Erkennbare Probleme bestehen insoweit erstmal nicht, ich war nur unsicher, wie mit der Malwaremeldung umzugehen ist. Wie ist es denn mit den Funden von ESET? Sie sind noch nicht entfernt worden. Soweit sie sich auf Software im Downloadordner beziehen, werde ich die Programme entfernen. Was mache ich mit FormatFactory und OkayFreedom? Gruß Rolf |
24.11.2016, 22:07 | #13 |
/// TB-Ausbilder /// Anleitungs-Guru | Malwarefund Win32/Herz.B Die Funde sind ja keine Malware. Wenn Du willst können wir sie entfernen. Poste bitte noch ein frisches FRST-Log. Schritt 1 Bitte starte FRST erneut, und drücke auf Untersuchen. Bitte poste mir den Inhalt des Logs.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
25.11.2016, 14:03 | #14 |
| Malwarefund Win32/Herz.B Hallo Jürgen, sorry, wenn ich nicht so bewandert bin mit den Einstufungen der AnalyseTools. Was ist denn damit gemeint, wenn Software als 'unerwünscht' bezeichnet wird. In diesem Fall PDFCreator ASIO4ALL FormatFactory OkayFreedom FreeVideoToMP3Converter Was wäre Deine Empfehlung? Und.. die anfangs angeführte Malware Win32/Herz.B ist noch in der Quarantäne von AVG. Soll ich die einfach löschen jetzt ? Gruß Rolf |
25.11.2016, 18:48 | #15 |
/// TB-Ausbilder /// Anleitungs-Guru | Malwarefund Win32/Herz.B Deinstalliere Programme welche Du nicht brauchst. Behalte Programme die Du brauchst und welche Dich nicht stören. Ich glaube da eher an einen Fehlalarm bei AVG. In der Quarantäne sind sie in jedem Fall sicher.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
Themen zu Malwarefund Win32/Herz.B |
.dll, administrator, adobe, adobe flash player, antivirus, appdata, avast, avg, browser, cid, converter, cpu, dateien, defender, detected, digital, download, driver booster, explorer, explorer.exe, firefox, firewall, flash player, free, free download, google, helper, homepage, iexplore.exe, internet, internet explorer, launch, malware, maus, microsoft, mozilla, mp3, neustart, nvidia, office, ordner, photoshop, programme, prozesse, realtek, registry, roaming, router, scan, server, services.exe, software, start, svchost.exe, system, system32, tcp, temp, treiber, udp, usb, virus, windows, windowsapps, winlogon.exe |