|
Log-Analyse und Auswertung: Chrome: standardsuchmaschine cleanserp.net nicht entfernbarWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
15.10.2017, 18:46 | #1 |
| Chrome: standardsuchmaschine cleanserp.net nicht entfernbar Guten tag die Herren. Ich schildere euch jetzt mal mein Problem, und zwar steht es schon im titel: habe ein falsches setup gedownloadet wodurch sich mein Browser eine cleanserp.net weiterleitung geholt hat, und ein plugin namens handytab. Was ich gemacht habe: Das Plugin lies sich ganz einfach löschen, jedoch war es bei dem neuinstallieren immer wieder dabei. in den einstellungen wollte ich sie löschen, doch leider öffnete sich das menü nicht. Kurz mal im code nachgeguckt, siehe da es war ein hidden parameter (?) aktiviert. Habe also kurzerhand das hidden entfernt, und schon habe ich die löschen funktion gefunden. Als ich jedoch löschen wollte ist nichts passiert. Danach habe ich versucht auf werkseinstellung zurückzusetzen. hat auch nicht geklappt. Habe auch chrome mehrfach deinstalliert, und installiert (sowohl C:\Program Files (x86)\Google\Chrome als auch C:\Users\lolli\AppData\Local\Google\Chrome) Norton Security Eraser benutzt, hat nur das falsche setup gelöscht. AdwCleaner7 benutzt, hat auch nichts gebracht. Hat leider genauso wenig geklappt. Dann war ich mit meinem Latein am Ende. Deswegen bin ich hier gelandet. Auch google hat mir leider nicht geholfen. Weitere Infos: -Abfrage-URL: https://cleanserp.net/search?q=%s& uid=qTMyGCjMg1l9Xc%2FaIotvaQLJkzP43L9fm%2Bp2Bj4fsH2kfiYpGPzxqz60rbg%2BvW8O75hN5 LCe1l5%2FEDaLpn11S%2FWODVJOQ%2FA%3D&pid=fob -Suchmaschine: Web (Standard) -Suchkürzel cleanserp.net Meine Idee wäre nun ein script zu machen welches einfach die Suchmaschine löscht. Nur leider habe ich keine Ahnung vom programmieren. Logdaten: siehe nächster Thread Falls noch Informationen fehlen, bitte schreiben, das ist mein erster thread und ich bin bei sowas noch recht unerfahren. FRST.txt FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-10-2017 durchgeführt von lolli (Administrator) auf BUEFFELSTEAK (15-10-2017 14:12:59) Gestartet von C:\Users\lolli\Desktop Geladene Profile: lolli (Verfügbare Profile: lolli & Gast) Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Symantec Corporation) C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\NSBU.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Symantec Corporation) C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\NSBU.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe (Gaijin Entertainment) C:\Users\lolli\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe (Discord Inc.) C:\Users\lolli\AppData\Local\Discord\app-0.0.298\Discord.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Discord Inc.) C:\Users\lolli\AppData\Local\Discord\app-0.0.298\Discord.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Discord Inc.) C:\Users\lolli\AppData\Local\Discord\app-0.0.298\Discord.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Windows\SysWOW64\PnkBstrA.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.) D:\Programme (x86)\VMware\vmware-authd.exe (Symantec Corporation) C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\coNatHst.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Malwarebytes) C:\Users\lolli\Desktop\adwcleaner\adwcleaner_7.0.3.1.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8844032 2016-01-27] (Realtek Semiconductor) HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\FRITZWLANMini.exe HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296216 2015-02-17] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [Logitech Vid] => C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe [5458704 2009-07-16] (Logitech Inc.) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [Gaijin.Net Agent] => C:\Users\lolli\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [2010056 2017-09-18] (Gaijin Entertainment) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3098952 2017-10-04] (Electronic Arts) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [Discord] => C:\Users\lolli\AppData\Local\Discord\app-0.0.298\Discord.exe [57477112 2017-08-08] (Discord Inc.) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [WhatsApp] => C:\Users\lolli\AppData\Local\WhatsApp\app-0.2.5863\WhatsApp.exe [88291088 2017-08-25] (WhatsApp) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [GoogleChromeAutoLaunch_EAD5220BE58481D673E8E5AC649D5A3B] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1451352 2017-09-21] (Google Inc.) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3101984 2017-10-14] (Valve Corporation) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\MountPoints2: {74d1bd53-d391-11e6-83c5-806e6f6e6963} - E:\autorun.exe HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\MountPoints2: {76ad84ad-b4a7-11e6-8c05-e87deb8b7fe1} - F:\pushinst.exe HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation) GroupPolicy: Beschränkung - Chrome <==== ACHTUNG CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <==== ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{4B0EFC37-DB22-4F17-B202-33899678EDDC}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{C211DC80-35AC-4527-9515-3E96F5877EBC}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== SearchScopes: HKU\S-1-5-21-1308867931-3025274077-1958192452-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NSBU&chn=1000&geo=DE&ver=22&locale=de_DE&guid=23AE3930-324A-4D54-9A19-0636058E9577&doi=2016-09-01&gct=sb&qsrc=2869 BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-28] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-28] (Oracle Corporation) BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security with Backup\Engine32\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll => Keine Datei BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll => Keine Datei Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security with Backup\Engine32\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation) FireFox: ======== FF DefaultProfile: vlmc4c4b.default FF ProfilePath: C:\Users\lolli\AppData\Roaming\Mozilla\Firefox\Profiles\vlmc4c4b.default [2017-10-15] FF Extension: (Cliqz) - C:\Users\lolli\AppData\Roaming\Mozilla\Firefox\Profiles\vlmc4c4b.default\Extensions\funnelcake@cliqz.com.xpi [2017-10-15] FF Extension: (Search Volume Modeling) - C:\Users\lolli\AppData\Roaming\Mozilla\Firefox\Profiles\vlmc4c4b.default\Extensions\searchvolmodel@mozilla.com.xpi [2017-10-15] FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.11.0.41\coFFAddon FF Extension: (Norton Security Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.11.0.41\coFFAddon [2017-10-15] FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.11.0.41\coFFAddon FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-28] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-28] (Oracle Corporation) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [Keine Datei] FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [Keine Datei] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) Chrome: ======= CHR Profile: C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default [2017-10-15] CHR Extension: (Präsentationen) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-15] CHR Extension: (Docs) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-15] CHR Extension: (Google Drive) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-15] CHR Extension: (YouTube) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-15] CHR Extension: (Norton Security Toolbar) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2017-10-15] CHR Extension: (Handy Tab) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\clgckgfbhciacomhlchmgdnplmdiadbj [2017-10-15] CHR Extension: (Tampermonkey) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-10-15] CHR Extension: (Tabellen) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-15] CHR Extension: (Google Docs Offline) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-15] CHR Extension: (Norton Identity Safe) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2017-10-15] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-15] CHR Extension: (Google Mail) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-15] CHR Extension: (Chrome Media Router) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-15] CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\Exts\Chrome.crx <nicht gefunden> CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\Exts\Chrome.crx <nicht gefunden> CHR HKLM-x32\...\Chrome\Extension: [clgckgfbhciacomhlchmgdnplmdiadbj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1494024 2017-02-08] () R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-05-11] (Digital Wave Ltd.) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395024 2016-12-09] (EasyAntiCheat Ltd) S3 HnGService_prototype; D:\My Games\Heroes & Generals prototype\prototype\hngservice.exe [780072 2017-06-21] (Reto-Moto ApS) S3 HnGSteamService; D:\My Games\Steam Spiele\steamapps\common\Heroes & Generals\hngservice.exe [777000 2017-10-11] (Reto-Moto ApS) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344184 2017-01-24] (Intel Corporation) R2 NSBU; C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\NSBU.exe [326144 2017-10-04] (Symantec Corporation) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-01] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-05-03] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2120032 2017-10-04] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3000168 2017-10-04] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2017-05-25] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2017-05-29] () R2 VMAuthdService; D:\Programme (x86)\VMware\vmware-authd.exe [87256 2015-06-24] (VMware, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2013-12-17] (AVM Berlin) R1 BHDrvx64; C:\Program Files\Norton Security with Backup\NortonData\22.11.0.41\Definitions\BASHDefs\20171011.003\BHDrvx64.sys [1872032 2017-10-11] (Symantec Corporation) R1 ccSet_NSBU; C:\Windows\system32\drivers\NSBUx64\160B000.029\ccSetx64.sys [187520 2017-10-04] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [508032 2017-10-14] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [158336 2017-10-14] (Symantec Corporation) S3 fwlanusb6; C:\Windows\System32\DRIVERS\fwlanusb6.sys [1327744 2014-03-27] (AVM GmbH) R1 IDSVia64; C:\Program Files\Norton Security with Backup\NortonData\22.11.0.41\Definitions\IPSDefs\20171013.001\IDSvia64.sys [1056920 2017-10-13] (Symantec Corporation) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [50088 2017-02-08] (Visicom Media Inc.) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35992 2014-12-29] (Visicom Media Inc.) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-05-03] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [48248 2017-05-03] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57976 2017-05-03] (NVIDIA Corporation) R3 SRTSP; C:\Windows\system32\drivers\NSBUx64\160B000.029\SRTSP64.SYS [812704 2017-10-04] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NSBUx64\160B000.029\SRTSPX64.SYS [49304 2017-10-04] (Symantec Corporation) R0 SymEFASI; C:\Windows\System32\drivers\NSBUx64\160B000.029\SYMEFASI64.SYS [1868416 2017-10-04] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [102568 2017-10-14] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NSBUx64\160B000.029\Ironx64.SYS [301288 2017-10-04] (Symantec Corporation) R1 SymNetS; C:\Windows\system32\drivers\NSBUx64\160B000.029\SYMNETS.SYS [566912 2017-10-04] (Symantec Corporation) R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [32472 2015-06-24] (VMware, Inc.) R0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-10-08] (VMware, Inc.) S3 GPU-Z; \??\C:\Users\lolli\AppData\Local\Temp\GPU-Z.sys [X] <==== ACHTUNG S2 iocbios2; \??\C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [X] S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X] S3 NAVENG; \??\C:\Program Files (x86)\Norton 360\NortonData\22.8.0.50\Definitions\SDSDefs\20170526.019\NAVENG.SYS [X] S3 NAVEX15; \??\C:\Program Files (x86)\Norton 360\NortonData\22.8.0.50\Definitions\SDSDefs\20170526.019\NAVEX15.SYS [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-10-15 14:12 - 2017-10-15 14:13 - 000020165 _____ C:\Users\lolli\Desktop\FRST.txt 2017-10-15 14:12 - 2017-10-15 14:12 - 002401792 _____ (Farbar) C:\Users\lolli\Desktop\FRST64.exe 2017-10-15 14:12 - 2017-10-15 14:12 - 000000000 ____D C:\FRST 2017-10-15 13:41 - 2017-10-15 13:41 - 000000000 ____D C:\Windows\System32\Tasks\Remediation 2017-10-15 13:25 - 2017-10-15 13:25 - 001130328 _____ (Google Inc.) C:\Users\lolli\Downloads\ChromeSetup(1).exe 2017-10-15 13:25 - 2017-10-15 13:25 - 000002251 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-10-15 13:14 - 2017-10-15 13:16 - 000000000 ____D C:\AdwCleaner 2017-10-15 13:14 - 2017-10-15 13:14 - 000000000 ____D C:\Users\lolli\Desktop\adwcleaner 2017-10-15 12:40 - 2017-10-15 13:32 - 000000000 ____D C:\Users\lolli\AppData\Local\Google 2017-10-15 12:39 - 2017-10-15 12:39 - 001130328 _____ (Google Inc.) C:\Users\lolli\Downloads\ChromeSetup.exe 2017-10-15 11:51 - 2017-10-15 12:39 - 000000000 ____D C:\Users\lolli\AppData\Local\NPE 2017-10-15 11:51 - 2017-10-15 11:51 - 003436224 _____ (Symantec Corporation) C:\Users\lolli\Downloads\NPE.exe 2017-10-15 11:48 - 2017-10-15 12:43 - 000000000 ____D C:\Users\lolli\AppData\LocalLow\Mozilla 2017-10-15 11:48 - 2017-10-15 11:53 - 000000000 ____D C:\Users\lolli\AppData\Local\Mozilla 2017-10-15 11:48 - 2017-10-15 11:48 - 000001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2017-10-15 11:48 - 2017-10-15 11:48 - 000000000 ____D C:\Users\lolli\AppData\Roaming\Mozilla 2017-10-15 11:48 - 2017-10-15 11:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-10-15 11:48 - 2017-10-15 11:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-10-15 11:24 - 2017-10-15 11:24 - 000170047 _____ C:\Users\lolli\Desktop\bookmarks_15.10.17.html 2017-10-15 11:16 - 2017-10-15 11:16 - 000017134 _____ C:\Users\lolli\Downloads\tabssaver_data.tsd 2017-10-15 11:16 - 2017-10-15 11:16 - 000017134 _____ C:\Users\lolli\Desktop\tabssaver_data.tsd 2017-10-15 00:32 - 2017-10-15 00:34 - 000001066 _____ C:\Users\lolli\Desktop\GTAVLauncher.exe.lnk 2017-10-15 00:30 - 2017-10-15 00:30 - 000571119 _____ ( ) C:\Users\lolli\Downloads\GTA5FileCheck_SHA1.exe.exe 2017-10-15 00:30 - 2017-10-15 00:30 - 000001760 __RSH C:\ProgramData\ntuser.pol 2017-10-15 00:17 - 2017-10-15 00:17 - 000042711 _____ C:\Users\lolli\Downloads\IVAsiLoader.rar 2017-10-15 00:05 - 2017-10-15 00:05 - 000668160 _____ () C:\Users\lolli\Desktop\modded gta v launcher 2.2.exe 2017-10-15 00:05 - 2017-10-15 00:05 - 000541089 _____ C:\Users\lolli\Downloads\ca2813-[BroXe] Modded GTA V Launcher 2.2 (1).zip 2017-10-15 00:05 - 2017-10-15 00:05 - 000541089 _____ C:\Users\lolli\Desktop\ca2813-[BroXe] Modded GTA V Launcher 2.2 (1).zip 2017-10-15 00:05 - 2017-10-15 00:05 - 000000000 ____D C:\Users\lolli\AppData\Local\LauncherV2English 2017-10-15 00:03 - 2017-10-15 00:03 - 000541089 _____ C:\Users\lolli\Downloads\ca2813-[BroXe] Modded GTA V Launcher 2.2.zip 2017-10-14 23:44 - 2017-10-14 23:42 - 007931434 _____ C:\Users\lolli\Desktop\d6faf9-Enhanced Native Trainer - update 35 QoL 1.zip 2017-10-14 23:42 - 2017-10-14 23:42 - 007931434 _____ C:\Users\lolli\Downloads\d6faf9-Enhanced Native Trainer - update 35 QoL 1.zip 2017-10-14 23:32 - 2017-10-14 23:32 - 000000616 _____ C:\Users\lolli\Desktop\dlclist.xml 2017-10-14 23:30 - 2017-10-14 23:30 - 000000000 ____D C:\Users\lolli\Documents\OpenIV 2017-10-14 23:28 - 2017-10-14 23:28 - 000000000 ____D C:\Users\lolli\AppData\Local\New Technology Studio 2017-10-14 23:21 - 2017-10-14 23:20 - 061915159 _____ C:\Users\lolli\Desktop\3ee6de-Eurofighter_Typhoon.zip 2017-10-14 23:20 - 2017-10-14 23:20 - 061915159 _____ C:\Users\lolli\Downloads\3ee6de-Eurofighter_Typhoon.zip 2017-10-14 23:15 - 2017-10-14 23:15 - 007195928 _____ (Microsoft Corporation) C:\Users\lolli\Downloads\vcredist_x64.exe 2017-10-14 23:14 - 2017-10-14 23:14 - 069999448 _____ (Microsoft Corporation) C:\Users\lolli\Downloads\NDP452-KB2901907-x86-x64-AllOS-ENU.exe 2017-10-14 23:10 - 2017-10-14 23:07 - 000036049 _____ C:\Users\lolli\Desktop\bde7c9-Metric_Speedometer_2.2.0.zip 2017-10-14 23:10 - 2017-10-14 22:49 - 000945684 _____ C:\Users\lolli\Desktop\ScriptHookV_1.0.1180.2.zip 2017-10-14 23:09 - 2017-10-14 23:07 - 000398545 _____ C:\Users\lolli\Desktop\ScriptHookVDotNet.zip 2017-10-14 23:09 - 2017-10-14 22:49 - 000003888 _____ C:\Users\lolli\Desktop\66dda6-ManualTransmission.zip 2017-10-14 23:07 - 2017-10-14 23:07 - 000398545 _____ C:\Users\lolli\Downloads\ScriptHookVDotNet.zip 2017-10-14 23:07 - 2017-10-14 23:07 - 000036049 _____ C:\Users\lolli\Downloads\bde7c9-Metric_Speedometer_2.2.0.zip 2017-10-14 22:49 - 2017-10-14 22:49 - 000945684 _____ C:\Users\lolli\Downloads\ScriptHookV_1.0.1180.2.zip 2017-10-14 22:49 - 2017-10-14 22:49 - 000003888 _____ C:\Users\lolli\Downloads\66dda6-ManualTransmission.zip 2017-10-14 21:17 - 2017-10-14 21:17 - 000004194 _____ C:\Windows\System32\Tasks\Norton Security Scan for lolli 2017-10-14 21:17 - 2017-10-14 21:17 - 000001464 _____ C:\Users\Public\Desktop\Norton Security Scan.LNK 2017-10-14 21:17 - 2017-10-14 21:17 - 000000000 ____D C:\Windows\system32\Drivers\NSSx64 2017-10-14 21:17 - 2017-10-14 21:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan 2017-10-14 21:17 - 2017-10-14 21:17 - 000000000 ____D C:\Program Files (x86)\Norton Security Scan 2017-10-14 20:32 - 2017-10-14 20:32 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2017-10-14 20:30 - 2017-04-28 00:50 - 003550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2017-10-14 20:30 - 2017-04-12 15:05 - 004296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2017-10-14 20:27 - 2017-09-13 17:33 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-10-14 20:27 - 2017-09-13 17:32 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-10-14 20:27 - 2017-09-13 17:32 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-10-14 20:27 - 2017-09-13 17:32 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-10-14 20:27 - 2017-09-13 17:32 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-10-14 20:27 - 2017-09-13 17:31 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:13 - 004001512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-10-14 20:27 - 2017-09-13 17:13 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-10-14 20:27 - 2017-09-13 17:10 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:05 - 000324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2017-10-14 20:27 - 2017-09-13 17:00 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-10-14 20:27 - 2017-09-13 17:00 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-10-14 20:27 - 2017-09-13 17:00 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-10-14 20:27 - 2017-09-13 17:00 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-10-14 20:27 - 2017-09-13 16:57 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-10-14 20:27 - 2017-09-13 16:56 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-10-14 20:27 - 2017-09-13 16:53 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-10-14 20:27 - 2017-09-13 16:53 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-10-14 20:27 - 2017-09-13 16:53 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-10-14 20:27 - 2017-09-13 16:52 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-10-14 20:27 - 2017-09-13 16:52 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-10-14 20:27 - 2017-09-13 16:50 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-10-14 20:27 - 2017-09-13 16:47 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-10-14 20:27 - 2017-09-13 16:46 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-10-14 20:27 - 2017-09-13 16:46 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-10-14 20:27 - 2017-09-09 02:45 - 000395984 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-10-14 20:27 - 2017-09-09 01:47 - 000347344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-10-14 20:27 - 2017-09-08 17:34 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-10-14 20:27 - 2017-09-08 17:30 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-10-14 20:27 - 2017-09-08 17:14 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-10-14 20:27 - 2017-09-08 17:13 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-10-14 20:27 - 2017-09-08 17:13 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-10-14 20:27 - 2017-09-08 17:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-10-14 20:27 - 2017-09-08 17:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll 2017-10-14 20:27 - 2017-09-08 17:10 - 000312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-10-14 20:27 - 2017-09-08 17:10 - 000109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2017-10-14 20:27 - 2017-09-08 17:00 - 003222016 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-10-14 20:27 - 2017-09-08 17:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2017-10-14 20:27 - 2017-09-08 17:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2017-10-14 20:27 - 2017-09-08 16:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2017-10-14 20:27 - 2017-09-08 16:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2017-10-14 20:27 - 2017-09-08 16:20 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll 2017-10-14 20:27 - 2017-09-08 16:20 - 000345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll 2017-10-14 20:27 - 2017-09-08 16:20 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll 2017-10-14 20:27 - 2017-09-07 23:38 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-10-14 20:27 - 2017-09-07 23:37 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-10-14 20:27 - 2017-09-07 23:19 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-10-14 20:27 - 2017-09-07 23:18 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-10-14 20:27 - 2017-09-07 23:18 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-10-14 20:27 - 2017-09-07 23:17 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-10-14 20:27 - 2017-09-07 23:17 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-10-14 20:27 - 2017-09-07 23:15 - 002902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-10-14 20:27 - 2017-09-07 23:08 - 025729536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-10-14 20:27 - 2017-09-07 23:08 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-10-14 20:27 - 2017-09-07 23:07 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-10-14 20:27 - 2017-09-07 23:02 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-10-14 20:27 - 2017-09-07 23:01 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-10-14 20:27 - 2017-09-07 23:01 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-10-14 20:27 - 2017-09-07 23:01 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-10-14 20:27 - 2017-09-07 23:00 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-10-14 20:27 - 2017-09-07 22:52 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-10-14 20:27 - 2017-09-07 22:48 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-10-14 20:27 - 2017-09-07 22:40 - 005982208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-10-14 20:27 - 2017-09-07 22:39 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-10-14 20:27 - 2017-09-07 22:38 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-10-14 20:27 - 2017-09-07 22:37 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-10-14 20:27 - 2017-09-07 22:33 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-10-14 20:27 - 2017-09-07 22:32 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-10-14 20:27 - 2017-09-07 22:29 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-10-14 20:27 - 2017-09-07 22:27 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-10-14 20:27 - 2017-09-07 22:13 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-10-14 20:27 - 2017-09-07 22:10 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-10-14 20:27 - 2017-09-07 22:10 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-10-14 20:27 - 2017-09-07 22:08 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-10-14 20:27 - 2017-09-07 22:08 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-10-14 20:27 - 2017-09-07 21:44 - 015262720 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-10-14 20:27 - 2017-09-07 21:40 - 003240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-10-14 20:27 - 2017-09-07 21:27 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-10-14 20:27 - 2017-09-07 21:27 - 001548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-10-14 20:27 - 2017-09-07 21:17 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-10-14 20:27 - 2017-09-07 21:11 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-10-14 20:27 - 2017-09-07 21:10 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-10-14 20:27 - 2017-09-07 21:10 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-10-14 20:27 - 2017-09-07 21:10 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-10-14 20:27 - 2017-09-07 21:09 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-10-14 20:27 - 2017-09-07 21:04 - 020267008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-10-14 20:27 - 2017-09-07 21:03 - 002292736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-10-14 20:27 - 2017-09-07 21:03 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-10-14 20:27 - 2017-09-07 21:02 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-10-14 20:27 - 2017-09-07 20:59 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-10-14 20:27 - 2017-09-07 20:58 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-10-14 20:27 - 2017-09-07 20:58 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-10-14 20:27 - 2017-09-07 20:58 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-10-14 20:27 - 2017-09-07 20:49 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-10-14 20:27 - 2017-09-07 20:44 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2017-10-14 20:27 - 2017-09-07 20:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-10-14 20:27 - 2017-09-07 20:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-10-14 20:27 - 2017-09-07 20:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-10-14 20:27 - 2017-09-07 20:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-10-14 20:27 - 2017-09-07 20:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-10-14 20:27 - 2017-09-07 20:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-10-14 20:27 - 2017-09-07 20:29 - 004547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-10-14 20:27 - 2017-09-07 20:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-10-14 20:27 - 2017-09-07 20:26 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-10-14 20:27 - 2017-09-07 20:25 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-10-14 20:27 - 2017-09-07 20:25 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-10-14 20:27 - 2017-09-07 20:17 - 013677568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-10-14 20:27 - 2017-09-07 20:01 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-10-14 20:27 - 2017-09-07 19:57 - 001316864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-10-14 20:27 - 2017-09-07 19:57 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-10-14 20:27 - 2017-09-07 17:31 - 002851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2017-10-14 20:27 - 2017-09-07 17:12 - 002755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll 2017-10-14 20:27 - 2017-09-07 16:55 - 000461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-10-14 20:27 - 2017-09-07 16:55 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-10-14 20:27 - 2017-09-07 16:55 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-10-14 20:27 - 2017-08-19 17:28 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2017-10-14 20:27 - 2017-08-19 17:28 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2017-10-14 20:27 - 2017-08-19 17:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2017-10-14 20:27 - 2017-08-19 17:28 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2017-10-14 20:27 - 2017-08-19 17:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2017-10-14 20:27 - 2017-08-19 17:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2017-10-14 20:27 - 2017-08-19 17:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2017-10-14 20:27 - 2017-08-19 17:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2017-10-14 20:27 - 2017-08-19 17:08 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2017-10-14 20:27 - 2017-08-19 17:08 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2017-10-14 20:27 - 2017-08-19 16:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2017-10-14 20:27 - 2017-08-19 16:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2017-10-14 20:27 - 2017-08-16 17:29 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-10-14 20:27 - 2017-08-16 17:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-10-14 20:27 - 2017-08-15 17:29 - 014182400 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2017-10-14 20:27 - 2017-08-15 17:29 - 001867264 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2017-10-14 20:27 - 2017-08-15 17:10 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2017-10-14 20:27 - 2017-08-15 17:10 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 003203584 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 001032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2017-10-14 20:27 - 2017-08-14 19:34 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll 2017-10-14 20:27 - 2017-08-13 23:45 - 000040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2017-10-14 20:27 - 2017-08-13 23:37 - 002144256 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe 2017-10-14 20:27 - 2017-08-13 23:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe 2017-10-14 20:27 - 2017-08-11 08:35 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll 2017-10-14 20:27 - 2017-08-11 08:34 - 000971776 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2017-10-14 20:27 - 2017-08-11 08:34 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2017-10-14 20:27 - 2017-08-11 08:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll 2017-10-14 20:27 - 2017-08-11 08:34 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll 2017-10-14 20:27 - 2017-08-11 08:20 - 000071680 _____ C:\Windows\system32\PrintBrmUi.exe 2017-10-14 20:27 - 2017-08-11 08:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe 2017-10-14 20:27 - 2017-08-11 08:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe 2017-10-14 20:27 - 2017-08-11 08:19 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll 2017-10-14 20:27 - 2017-08-11 08:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe 2017-10-14 20:27 - 2017-08-11 08:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe 2017-10-14 20:27 - 2017-08-11 08:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe 2017-10-14 20:27 - 2017-08-11 08:01 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll 2017-10-14 20:27 - 2017-08-11 08:00 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2017-10-14 20:27 - 2017-08-11 07:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys 2017-10-14 20:27 - 2017-07-29 16:56 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2017-10-14 20:27 - 2017-07-21 16:26 - 000518144 _____ C:\Windows\SysWOW64\msjetoledb40.dll 2017-10-14 20:27 - 2017-07-21 16:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexch40.dll 2017-10-14 20:27 - 2017-07-21 16:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjtes40.dll 2017-10-14 20:27 - 2017-07-21 16:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll 2017-10-14 20:27 - 2017-07-14 17:29 - 000486400 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2017-10-14 20:27 - 2017-07-14 17:29 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll 2017-10-14 20:27 - 2017-07-14 17:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2017-10-14 20:27 - 2017-07-14 16:57 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe 2017-10-14 20:27 - 2017-07-14 16:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe 2017-10-14 20:27 - 2017-07-14 16:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll 2017-10-14 20:27 - 2017-07-08 17:34 - 000370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2017-10-14 20:27 - 2017-07-07 17:33 - 000363752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys 2017-10-14 20:27 - 2017-07-07 17:29 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll 2017-10-14 20:27 - 2017-07-07 17:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswdat10.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjter40.dll 2017-10-14 20:27 - 2017-06-15 22:23 - 000753664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2017-10-14 20:27 - 2017-06-13 00:49 - 001363456 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll 2017-10-14 20:27 - 2017-06-13 00:49 - 000594432 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll 2017-10-14 20:27 - 2017-06-13 00:49 - 000475136 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx 2017-10-14 20:27 - 2017-06-13 00:49 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll 2017-10-14 20:27 - 2017-06-13 00:29 - 001227264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll 2017-10-14 20:27 - 2017-06-13 00:29 - 000444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll 2017-10-14 20:27 - 2017-06-13 00:29 - 000390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx 2017-10-14 20:27 - 2017-06-13 00:28 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll 2017-10-14 20:27 - 2017-06-13 00:14 - 000379392 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe 2017-10-14 20:27 - 2017-06-13 00:14 - 000172544 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe 2017-10-14 20:27 - 2017-06-13 00:14 - 000103936 _____ (Microsoft Corporation) C:\Windows\system32\resmon.exe 2017-10-14 20:27 - 2017-06-13 00:06 - 000303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe 2017-10-14 20:27 - 2017-06-13 00:06 - 000157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfmon.exe 2017-10-14 20:27 - 2017-06-13 00:06 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resmon.exe 2017-10-14 20:27 - 2017-06-02 10:10 - 000733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-10-14 20:27 - 2017-05-30 06:56 - 001895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2017-10-14 20:27 - 2017-05-30 06:56 - 000377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2017-10-14 20:27 - 2017-05-30 06:56 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2017-10-14 20:27 - 2017-05-21 06:24 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-10-14 20:27 - 2017-05-21 06:06 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-10-14 20:27 - 2017-05-16 17:35 - 000986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2017-10-14 20:27 - 2017-05-16 17:35 - 000265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2017-10-14 20:27 - 2017-05-16 17:30 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2017-10-14 20:27 - 2017-05-12 20:26 - 000382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2017-10-14 20:27 - 2017-05-12 20:22 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2017-10-14 20:27 - 2017-05-12 20:22 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2017-10-14 20:27 - 2017-05-12 20:22 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2017-10-14 20:27 - 2017-05-12 20:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2017-10-14 20:27 - 2017-05-12 20:07 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2017-10-14 20:27 - 2017-05-12 20:03 - 000070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2017-10-14 20:27 - 2017-05-12 20:03 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2017-10-14 20:27 - 2017-05-12 20:03 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2017-10-14 20:27 - 2017-05-12 19:43 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2017-10-14 20:27 - 2017-05-12 18:25 - 001251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-10-14 20:27 - 2017-05-12 17:58 - 001648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-10-14 20:27 - 2017-05-12 17:58 - 001180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-10-14 20:27 - 2017-05-10 17:33 - 000091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe 2017-10-14 20:27 - 2017-05-10 17:29 - 003165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2017-10-14 20:27 - 2017-05-10 17:29 - 000192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2017-10-14 20:27 - 2017-05-10 17:29 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-10-14 20:27 - 2017-05-10 17:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2017-10-14 20:27 - 2017-05-10 17:16 - 000091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe 2017-10-14 20:27 - 2017-05-10 17:14 - 002651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-10-14 20:27 - 2017-05-10 17:13 - 000709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-10-14 20:27 - 2017-05-10 17:13 - 000140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2017-10-14 20:27 - 2017-05-10 17:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2017-10-14 20:27 - 2017-05-10 17:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2017-10-14 20:27 - 2017-05-10 17:13 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-10-14 20:27 - 2017-05-10 17:13 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2017-10-14 20:27 - 2017-05-10 17:12 - 000174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2017-10-14 20:27 - 2017-05-10 17:00 - 000573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-10-14 20:27 - 2017-05-10 17:00 - 000093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-10-14 20:27 - 2017-05-10 17:00 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2017-10-14 20:27 - 2017-05-10 17:00 - 000030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2017-10-14 20:27 - 2017-05-07 17:33 - 000094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2017-10-14 20:27 - 2017-05-07 17:29 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2017-10-14 20:27 - 2017-04-21 17:34 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2017-10-14 20:27 - 2017-04-21 17:15 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2017-10-14 20:27 - 2017-04-17 17:37 - 000876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2017-10-14 20:27 - 2017-04-17 17:12 - 000581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2017-10-14 20:27 - 2017-04-12 17:32 - 001483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2017-10-14 20:27 - 2017-04-12 17:32 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2017-10-14 20:27 - 2017-04-12 17:32 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2017-10-14 20:27 - 2017-04-12 17:32 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2017-10-14 20:27 - 2017-04-12 17:26 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2017-10-14 20:27 - 2017-04-12 17:25 - 001176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2017-10-14 20:27 - 2017-04-12 17:25 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2017-10-14 20:27 - 2017-04-12 17:25 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2017-10-14 20:27 - 2017-04-04 16:53 - 000496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2017-10-14 20:27 - 2017-03-30 17:03 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe 2017-10-14 20:27 - 2017-03-30 16:58 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe 2017-10-14 20:27 - 2017-03-10 18:32 - 001389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll 2017-10-14 20:27 - 2017-03-10 18:32 - 000300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll 2017-10-14 20:27 - 2017-03-10 18:20 - 001508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll 2017-10-14 20:27 - 2017-03-10 18:20 - 000237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll 2017-10-14 20:27 - 2017-03-10 17:57 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe 2017-10-14 20:27 - 2017-03-10 17:55 - 000205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2017-10-14 20:27 - 2017-03-10 17:55 - 000195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys 2017-10-14 20:27 - 2017-03-07 18:30 - 000085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll 2017-10-14 20:27 - 2017-03-07 18:17 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll 2017-10-14 20:27 - 2017-03-07 16:05 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2017-10-14 20:27 - 2017-03-04 03:27 - 001574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-10-14 20:27 - 2017-03-04 03:27 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll 2017-10-14 20:27 - 2017-03-04 03:14 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-10-14 20:27 - 2017-03-04 03:14 - 000077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll 2017-10-14 20:27 - 2017-02-09 18:32 - 000769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-10-14 20:27 - 2017-02-09 18:32 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2017-10-14 20:27 - 2017-02-09 18:32 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll 2017-10-14 20:27 - 2017-02-09 18:31 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2017-10-14 20:27 - 2017-02-09 18:31 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll 2017-10-14 20:27 - 2017-02-09 18:14 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2017-10-14 20:27 - 2017-02-09 18:14 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll 2017-10-14 20:27 - 2017-02-09 18:14 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2017-10-14 20:27 - 2017-02-09 17:51 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-10-14 20:27 - 2017-01-13 20:00 - 000976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-10-14 20:27 - 2017-01-13 20:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2017-10-14 20:27 - 2017-01-13 19:45 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-10-14 20:27 - 2017-01-13 19:45 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2017-10-14 20:27 - 2017-01-11 20:01 - 001887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2017-10-14 20:27 - 2017-01-11 20:01 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2017-10-14 20:27 - 2017-01-11 19:43 - 001241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2017-10-14 20:27 - 2017-01-11 19:43 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2017-10-14 20:27 - 2016-03-24 00:40 - 003181568 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2017-10-14 20:27 - 2016-03-24 00:40 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2017-10-14 20:25 - 2017-10-14 20:25 - 000000000 ____D C:\Windows\System32\Tasks\Norton Security with Backup 2017-10-14 20:25 - 2017-05-03 17:34 - 000094952 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-10-14 20:25 - 2017-05-03 17:29 - 001206272 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 001555968 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000620544 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000535552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000311296 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000217088 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000127488 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-10-14 20:25 - 2017-03-23 04:06 - 001691136 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2017-10-14 20:24 - 2017-10-14 20:24 - 000102568 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2017-10-14 20:24 - 2017-10-14 20:24 - 000008309 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2017-10-14 20:24 - 2017-10-14 20:24 - 000003230 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2017-10-14 20:24 - 2017-10-14 20:24 - 000002312 _____ C:\Users\Public\Desktop\Norton Security with Backup.lnk 2017-10-14 20:24 - 2017-10-14 20:24 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security with Backup 2017-10-14 20:24 - 2017-10-14 20:24 - 000000000 ____D C:\Windows\system32\Drivers\NSBUx64 2017-10-14 20:24 - 2017-10-14 20:24 - 000000000 ____D C:\Program Files\Norton Security with Backup 2017-10-14 20:24 - 2017-10-14 20:24 - 000000000 ____D C:\Program Files\Common Files\Symantec Shared 2017-10-14 20:23 - 2017-10-14 21:17 - 000000000 ____D C:\Program Files (x86)\NortonInstaller 2017-10-14 20:22 - 2017-10-14 20:23 - 001112832 _____ (Symantec Corporation) C:\Users\lolli\Downloads\NortonNSBUDownloader.exe 2017-10-11 19:21 - 2017-10-11 19:21 - 000540126 _____ C:\Users\lolli\Downloads\Loader.zip 2017-10-07 14:18 - 2017-10-07 14:18 - 000417336 _____ C:\Windows\Minidump\100717-7456-01.dmp 2017-10-05 21:01 - 2017-10-05 21:02 - 000000807 _____ C:\Users\lolli\Desktop\Conquest Reforged.lnk 2017-10-05 20:55 - 2017-10-05 20:55 - 007195735 _____ C:\Users\lolli\Downloads\Conquest_Reforged_Launcher.exe 2017-10-04 20:27 - 2017-10-15 00:00 - 000000566 _____ C:\Users\lolli\Desktop\gradient.lnk 2017-09-30 20:52 - 2017-09-30 20:52 - 000000222 _____ C:\Users\lolli\Desktop\Insurgency.url 2017-09-28 19:00 - 2017-10-12 21:24 - 000001212 _____ C:\Users\lolli\Desktop\nativelog.txt 2017-09-26 17:02 - 2017-09-26 17:02 - 000000000 ____D C:\Users\lolli\AppData\Roaming\CrispyCheats 2017-09-26 16:58 - 2017-10-15 10:34 - 000000000 ____D C:\Users\lolli\Desktop\wf 2017-09-26 16:58 - 2017-09-26 16:58 - 000530970 _____ C:\Users\lolli\Downloads\Update (1).zip 2017-09-26 16:26 - 2017-10-14 21:23 - 000000000 ____D C:\Users\lolli\Desktop\sortieren 2017-09-26 16:26 - 2017-09-26 16:26 - 000530970 _____ C:\Users\lolli\Downloads\Update.zip 2017-09-26 16:02 - 2017-09-26 16:02 - 000978053 _____ C:\Users\lolli\Downloads\7r14ngl3_SafeMenu_GTAO1.41_v1.4.1_unknowncheats.me_.zip 2017-09-25 16:01 - 2017-09-25 16:02 - 000544418 _____ C:\Users\lolli\Downloads\Modmenu.zip 2017-09-23 14:02 - 2017-09-23 14:03 - 351282768 _____ (GIANTS Software ) C:\Users\lolli\Downloads\FarmingSimulator2015Patch1.4.2DE.exe 2017-09-22 09:52 - 2017-09-22 09:52 - 000000867 _____ C:\Users\lolli\Desktop\Landwirtschafts Simulator 15 .lnk 2017-09-22 09:52 - 2017-09-22 09:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Landwirtschafts Simulator 2015 2017-09-17 10:13 - 2017-09-17 10:13 - 007169765 _____ C:\Users\lolli\Downloads\POLITIKER VONG HEUTE.mp4 2017-09-17 10:13 - 2017-09-17 10:13 - 007169765 _____ C:\Users\lolli\Downloads\POLITIKER VONG HEUTE (1).mp4 ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-10-15 13:25 - 2016-11-27 16:01 - 000002263 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-10-15 13:25 - 2016-11-27 16:00 - 000000000 ____D C:\Program Files (x86)\Google 2017-10-15 13:24 - 2009-07-14 06:45 - 000021696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-10-15 13:24 - 2009-07-14 06:45 - 000021696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-10-15 13:22 - 2011-04-12 09:43 - 000701584 _____ C:\Windows\system32\perfh007.dat 2017-10-15 13:22 - 2011-04-12 09:43 - 000150250 _____ C:\Windows\system32\perfc007.dat 2017-10-15 13:22 - 2009-07-14 07:13 - 001626622 _____ C:\Windows\system32\PerfStringBackup.INI 2017-10-15 13:22 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf 2017-10-15 13:16 - 2017-06-09 23:03 - 000000000 ____D C:\Users\lolli\AppData\Roaming\WhatsApp 2017-10-15 13:16 - 2017-05-01 16:12 - 000000000 ____D C:\ProgramData\Origin 2017-10-15 13:16 - 2017-02-02 18:45 - 000000000 __SHD C:\Users\lolli\IntelGraphicsProfiles 2017-10-15 13:16 - 2016-12-05 17:17 - 000000000 ____D C:\ProgramData\VMware 2017-10-15 13:16 - 2016-11-27 17:58 - 000000000 ____D C:\Program Files (x86)\Steam 2017-10-15 13:16 - 2016-11-27 16:10 - 000000000 ____D C:\ProgramData\NVIDIA 2017-10-15 13:15 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-10-15 12:40 - 2016-11-27 16:00 - 000003542 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-10-15 12:40 - 2016-11-27 16:00 - 000003414 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-10-15 12:35 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\rescache 2017-10-15 11:51 - 2016-11-27 16:48 - 000000000 ____D C:\ProgramData\Norton 2017-10-15 00:30 - 2009-07-14 05:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy 2017-10-15 00:30 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy 2017-10-15 00:07 - 2016-12-03 15:47 - 000000000 ____D C:\Users\lolli\AppData\Local\CrashDumps 2017-10-14 23:29 - 2016-12-17 11:41 - 000000000 ____D C:\Users\lolli\AppData\Roaming\Skype 2017-10-14 23:15 - 2016-11-27 16:09 - 000000000 ____D C:\ProgramData\Package Cache 2017-10-14 21:38 - 2016-12-09 23:20 - 000000000 ____D C:\Users\lolli\AppData\LocalLow\Heroes and Generals 2017-10-14 21:38 - 2016-11-27 15:47 - 000000000 ____D C:\Users\lolli 2017-10-14 21:18 - 2016-11-29 17:00 - 000000000 ____D C:\Program Files\Common Files\AV 2017-10-14 20:50 - 2016-12-13 00:06 - 000000000 ___SD C:\Windows\system32\CompatTel 2017-10-14 20:50 - 2016-12-13 00:06 - 000000000 ____D C:\Windows\system32\appraiser 2017-10-14 20:50 - 2009-07-14 07:32 - 000000000 ____D C:\Program Files\DVD Maker 2017-10-14 20:50 - 2009-07-14 06:45 - 000347608 _____ C:\Windows\system32\FNTCACHE.DAT 2017-10-14 20:50 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\SysWOW64\migwiz 2017-10-14 20:50 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\migwiz 2017-10-14 20:50 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\PolicyDefinitions 2017-10-14 20:34 - 2016-12-12 23:10 - 000000000 ____D C:\Windows\system32\MRT 2017-10-14 20:32 - 2016-12-12 23:10 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-10-14 20:31 - 2016-12-01 21:56 - 001600014 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2017-10-14 20:25 - 2016-11-27 16:48 - 000000000 ____D C:\Users\lolli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton 2017-10-14 20:23 - 2016-11-27 16:48 - 000000000 ____D C:\Users\Public\Downloads\Norton 2017-10-14 20:17 - 2016-11-27 16:49 - 000000000 ____D C:\ProgramData\NortonInstaller 2017-10-14 10:02 - 2017-05-01 16:13 - 000000000 ____D C:\Program Files (x86)\Origin 2017-10-13 20:11 - 2016-12-09 20:53 - 000000000 ____D C:\Users\lolli\AppData\Roaming\TS3Client 2017-10-13 14:03 - 2017-06-09 23:03 - 000002173 _____ C:\Users\lolli\Desktop\WhatsApp.lnk 2017-10-13 14:03 - 2017-06-09 23:03 - 000000000 ____D C:\Users\lolli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2017-10-13 14:03 - 2017-06-09 23:02 - 000000000 ____D C:\Users\lolli\AppData\Local\WhatsApp 2017-10-13 14:03 - 2017-06-04 14:29 - 000000000 ____D C:\Users\lolli\AppData\Local\SquirrelTemp 2017-10-13 14:03 - 2016-12-11 12:41 - 000000000 ____D C:\Users\lolli\AppData\Local\ElevatedDiagnostics 2017-10-12 19:05 - 2017-06-04 16:53 - 000000000 ____D C:\Users\lolli\AppData\Roaming\.minecraft 2017-10-11 21:11 - 2016-11-27 18:06 - 000000000 ____D C:\Users\lolli\AppData\Local\Battle.net 2017-10-11 21:11 - 2016-11-27 18:05 - 000000000 ____D C:\Program Files (x86)\Battle.net 2017-10-10 17:00 - 2017-04-04 17:28 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-10-10 17:00 - 2017-04-04 17:28 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-10-10 17:00 - 2017-04-04 17:28 - 000004536 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-10-10 17:00 - 2017-04-04 17:28 - 000004378 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-10-10 17:00 - 2017-04-04 17:28 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2017-10-10 17:00 - 2017-04-04 17:28 - 000000000 ____D C:\Windows\system32\Macromed 2017-10-10 16:58 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF 2017-10-07 14:18 - 2016-11-27 17:24 - 000000000 ____D C:\Windows\Minidump 2017-10-05 18:36 - 2017-09-06 00:32 - 000000000 ____D C:\Users\lolli\AppData\Local\Arma 3 Launcher 2017-10-05 14:20 - 2017-04-08 19:48 - 000000000 ____D C:\Users\lolli\AppData\Local\Arma 3 2017-09-30 00:36 - 2017-06-04 14:29 - 000000000 ____D C:\Users\lolli\AppData\Local\Discord 2017-09-26 16:04 - 2017-08-30 14:21 - 000000000 ____D C:\Users\lolli\Desktop\7r14ngl3_SafeMenu_GTAO1.41_v1.4.1 2017-09-26 15:53 - 2016-12-05 17:24 - 000000000 ____D C:\Users\lolli\AppData\Local\VMware 2017-09-26 15:41 - 2009-07-14 07:32 - 000000000 ____D C:\Windows\system32\FxsTmp 2017-09-26 15:40 - 2016-12-05 17:23 - 000000000 ____D C:\Users\lolli\AppData\Roaming\VMware 2017-09-23 21:38 - 2016-11-27 18:06 - 000000000 ____D C:\Users\lolli\AppData\Local\Blizzard Entertainment 2017-09-22 10:09 - 2016-11-27 20:23 - 000000000 ____D C:\Users\lolli\Documents\My Games 2017-09-16 11:36 - 2009-07-14 07:08 - 000032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-01-06 23:35 - 2017-01-06 23:35 - 000000000 _____ () C:\Users\lolli\AppData\Roaming\dc.ogt 2016-12-05 20:44 - 2017-02-19 12:05 - 000007593 _____ () C:\Users\lolli\AppData\Local\Resmon.ResmonCfg 2016-11-30 15:31 - 2016-11-30 15:31 - 000000000 _____ () C:\Users\lolli\AppData\Local\{53610194-4399-4785-BE0D-499C08F45399} 2016-12-03 23:58 - 2016-12-03 23:58 - 000000000 _____ () C:\Users\lolli\AppData\Local\{6D4BEAEE-319E-4DEA-B08C-2372AD9F872D} 2016-12-12 22:20 - 2016-12-12 22:20 - 000000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-10-11 18:06 ==================== Ende von FRST.txt ============================ |
15.10.2017, 20:15 | #2 |
/// TB-Ausbilder | Chrome: standardsuchmaschine cleanserp.net nicht entfernbarMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Um die Bereinigung möchlichst effektiv und schnell gestalten zu können, bitte ich um Beachtung der folgenden Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Wir starten so:
|
16.10.2017, 15:47 | #3 |
| Logs So, danke dass du dich meinem problem annimmst
__________________FRST.txt FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-10-2017 durchgeführt von lolli (Administrator) auf BUEFFELSTEAK (16-10-2017 16:46:19) Gestartet von C:\Users\lolli\Desktop Geladene Profile: lolli (Verfügbare Profile: lolli & Gast) Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Symantec Corporation) C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\NSBU.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe () C:\Windows\SysWOW64\PnkBstrA.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.) D:\Programme (x86)\VMware\vmware-authd.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (Symantec Corporation) C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\NSBU.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe (Gaijin Entertainment) C:\Users\lolli\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe (Discord Inc.) C:\Users\lolli\AppData\Local\Discord\app-0.0.298\Discord.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (Discord Inc.) C:\Users\lolli\AppData\Local\Discord\app-0.0.298\Discord.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Discord Inc.) C:\Users\lolli\AppData\Local\Discord\app-0.0.298\Discord.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Symantec Corporation) C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\coNatHst.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8844032 2016-01-27] (Realtek Semiconductor) HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\FRITZWLANMini.exe HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296216 2015-02-17] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [Logitech Vid] => C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe [5458704 2009-07-16] (Logitech Inc.) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [Gaijin.Net Agent] => C:\Users\lolli\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [2010056 2017-09-18] (Gaijin Entertainment) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3098952 2017-10-04] (Electronic Arts) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [Discord] => C:\Users\lolli\AppData\Local\Discord\app-0.0.298\Discord.exe [57477112 2017-08-08] (Discord Inc.) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [WhatsApp] => C:\Users\lolli\AppData\Local\WhatsApp\app-0.2.5863\WhatsApp.exe [88291088 2017-08-25] (WhatsApp) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [GoogleChromeAutoLaunch_EAD5220BE58481D673E8E5AC649D5A3B] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1451352 2017-09-21] (Google Inc.) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3101984 2017-10-14] (Valve Corporation) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\MountPoints2: {74d1bd53-d391-11e6-83c5-806e6f6e6963} - E:\autorun.exe HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\MountPoints2: {76ad84ad-b4a7-11e6-8c05-e87deb8b7fe1} - F:\pushinst.exe HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation) GroupPolicy: Beschränkung - Chrome <==== ACHTUNG CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <==== ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{4B0EFC37-DB22-4F17-B202-33899678EDDC}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{C211DC80-35AC-4527-9515-3E96F5877EBC}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== SearchScopes: HKU\S-1-5-21-1308867931-3025274077-1958192452-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NSBU&chn=1000&geo=DE&ver=22&locale=de_DE&guid=23AE3930-324A-4D54-9A19-0636058E9577&doi=2016-09-01&gct=sb&qsrc=2869 BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-28] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-28] (Oracle Corporation) BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security with Backup\Engine32\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll => Keine Datei BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll => Keine Datei Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security with Backup\Engine32\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation) FireFox: ======== FF DefaultProfile: vlmc4c4b.default FF ProfilePath: C:\Users\lolli\AppData\Roaming\Mozilla\Firefox\Profiles\vlmc4c4b.default [2017-10-16] FF Extension: (Cliqz) - C:\Users\lolli\AppData\Roaming\Mozilla\Firefox\Profiles\vlmc4c4b.default\Extensions\funnelcake@cliqz.com.xpi [2017-10-15] FF Extension: (Search Volume Modeling) - C:\Users\lolli\AppData\Roaming\Mozilla\Firefox\Profiles\vlmc4c4b.default\Extensions\searchvolmodel@mozilla.com.xpi [2017-10-15] FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.11.0.41\coFFAddon FF Extension: (Norton Security Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.11.0.41\coFFAddon [2017-10-15] FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.11.0.41\coFFAddon FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-28] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-28] (Oracle Corporation) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [Keine Datei] FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [Keine Datei] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) Chrome: ======= CHR Profile: C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default [2017-10-16] CHR Extension: (Präsentationen) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-15] CHR Extension: (Docs) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-15] CHR Extension: (Google Drive) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-15] CHR Extension: (YouTube) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-15] CHR Extension: (Norton Security Toolbar) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2017-10-15] CHR Extension: (Handy Tab) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\clgckgfbhciacomhlchmgdnplmdiadbj [2017-10-15] CHR Extension: (Tampermonkey) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-10-15] CHR Extension: (Tabellen) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-15] CHR Extension: (Google Docs Offline) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-15] CHR Extension: (Norton Identity Safe) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2017-10-15] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-15] CHR Extension: (Google Mail) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-15] CHR Extension: (Chrome Media Router) - C:\Users\lolli\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-15] CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\Exts\Chrome.crx <nicht gefunden> CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\Exts\Chrome.crx <nicht gefunden> CHR HKLM-x32\...\Chrome\Extension: [clgckgfbhciacomhlchmgdnplmdiadbj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1494024 2017-02-08] () R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-05-11] (Digital Wave Ltd.) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395024 2016-12-09] (EasyAntiCheat Ltd) S3 HnGService_prototype; D:\My Games\Heroes & Generals prototype\prototype\hngservice.exe [780072 2017-06-21] (Reto-Moto ApS) S3 HnGSteamService; D:\My Games\Steam Spiele\steamapps\common\Heroes & Generals\hngservice.exe [777000 2017-10-11] (Reto-Moto ApS) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344184 2017-01-24] (Intel Corporation) R2 NSBU; C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\NSBU.exe [326144 2017-10-04] (Symantec Corporation) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-01] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-05-03] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2120032 2017-10-04] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3000168 2017-10-04] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2017-05-25] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2017-05-29] () R2 VMAuthdService; D:\Programme (x86)\VMware\vmware-authd.exe [87256 2015-06-24] (VMware, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2013-12-17] (AVM Berlin) R1 BHDrvx64; C:\Program Files\Norton Security with Backup\NortonData\22.11.0.41\Definitions\BASHDefs\20171011.003\BHDrvx64.sys [1872032 2017-10-11] (Symantec Corporation) R1 ccSet_NSBU; C:\Windows\system32\drivers\NSBUx64\160B000.029\ccSetx64.sys [187520 2017-10-04] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [508032 2017-10-14] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [158336 2017-10-14] (Symantec Corporation) S3 fwlanusb6; C:\Windows\System32\DRIVERS\fwlanusb6.sys [1327744 2014-03-27] (AVM GmbH) R1 IDSVia64; C:\Program Files\Norton Security with Backup\NortonData\22.11.0.41\Definitions\IPSDefs\20171013.001\IDSvia64.sys [1056920 2017-10-13] (Symantec Corporation) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [50088 2017-02-08] (Visicom Media Inc.) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35992 2014-12-29] (Visicom Media Inc.) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-05-03] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [48248 2017-05-03] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57976 2017-05-03] (NVIDIA Corporation) R3 SRTSP; C:\Windows\system32\drivers\NSBUx64\160B000.029\SRTSP64.SYS [812704 2017-10-04] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NSBUx64\160B000.029\SRTSPX64.SYS [49304 2017-10-04] (Symantec Corporation) R0 SymEFASI; C:\Windows\System32\drivers\NSBUx64\160B000.029\SYMEFASI64.SYS [1868416 2017-10-04] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [102568 2017-10-14] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NSBUx64\160B000.029\Ironx64.SYS [301288 2017-10-04] (Symantec Corporation) R1 SymNetS; C:\Windows\system32\drivers\NSBUx64\160B000.029\SYMNETS.SYS [566912 2017-10-04] (Symantec Corporation) R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [32472 2015-06-24] (VMware, Inc.) R0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-10-08] (VMware, Inc.) S3 GPU-Z; \??\C:\Users\lolli\AppData\Local\Temp\GPU-Z.sys [X] <==== ACHTUNG S2 iocbios2; \??\C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [X] S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X] S3 NAVENG; \??\C:\Program Files (x86)\Norton 360\NortonData\22.8.0.50\Definitions\SDSDefs\20170526.019\NAVENG.SYS [X] S3 NAVEX15; \??\C:\Program Files (x86)\Norton 360\NortonData\22.8.0.50\Definitions\SDSDefs\20170526.019\NAVEX15.SYS [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-10-15 14:13 - 2017-10-15 14:13 - 000053993 _____ C:\Users\lolli\Desktop\Addition.txt 2017-10-15 14:12 - 2017-10-16 16:46 - 000019567 _____ C:\Users\lolli\Desktop\FRST.txt 2017-10-15 14:12 - 2017-10-16 16:46 - 000000000 ____D C:\FRST 2017-10-15 14:12 - 2017-10-15 14:12 - 002401792 _____ (Farbar) C:\Users\lolli\Desktop\FRST64.exe 2017-10-15 13:41 - 2017-10-15 13:41 - 000000000 ____D C:\Windows\System32\Tasks\Remediation 2017-10-15 13:25 - 2017-10-15 13:25 - 001130328 _____ (Google Inc.) C:\Users\lolli\Downloads\ChromeSetup(1).exe 2017-10-15 13:25 - 2017-10-15 13:25 - 000002251 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-10-15 13:14 - 2017-10-15 13:16 - 000000000 ____D C:\AdwCleaner 2017-10-15 13:14 - 2017-10-15 13:14 - 000000000 ____D C:\Users\lolli\Desktop\adwcleaner 2017-10-15 12:40 - 2017-10-15 13:32 - 000000000 ____D C:\Users\lolli\AppData\Local\Google 2017-10-15 12:39 - 2017-10-15 12:39 - 001130328 _____ (Google Inc.) C:\Users\lolli\Downloads\ChromeSetup.exe 2017-10-15 11:51 - 2017-10-15 12:39 - 000000000 ____D C:\Users\lolli\AppData\Local\NPE 2017-10-15 11:51 - 2017-10-15 11:51 - 003436224 _____ (Symantec Corporation) C:\Users\lolli\Downloads\NPE.exe 2017-10-15 11:48 - 2017-10-15 12:43 - 000000000 ____D C:\Users\lolli\AppData\LocalLow\Mozilla 2017-10-15 11:48 - 2017-10-15 11:53 - 000000000 ____D C:\Users\lolli\AppData\Local\Mozilla 2017-10-15 11:48 - 2017-10-15 11:48 - 000001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2017-10-15 11:48 - 2017-10-15 11:48 - 000000000 ____D C:\Users\lolli\AppData\Roaming\Mozilla 2017-10-15 11:48 - 2017-10-15 11:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-10-15 11:48 - 2017-10-15 11:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-10-15 11:24 - 2017-10-15 11:24 - 000170047 _____ C:\Users\lolli\Desktop\bookmarks_15.10.17.html 2017-10-15 11:16 - 2017-10-15 11:16 - 000017134 _____ C:\Users\lolli\Downloads\tabssaver_data.tsd 2017-10-15 11:16 - 2017-10-15 11:16 - 000017134 _____ C:\Users\lolli\Desktop\tabssaver_data.tsd 2017-10-15 00:32 - 2017-10-15 00:34 - 000001066 _____ C:\Users\lolli\Desktop\GTAVLauncher.exe.lnk 2017-10-15 00:30 - 2017-10-15 00:30 - 000571119 _____ ( ) C:\Users\lolli\Downloads\GTA5FileCheck_SHA1.exe.exe 2017-10-15 00:30 - 2017-10-15 00:30 - 000001760 __RSH C:\ProgramData\ntuser.pol 2017-10-15 00:17 - 2017-10-15 00:17 - 000042711 _____ C:\Users\lolli\Downloads\IVAsiLoader.rar 2017-10-15 00:05 - 2017-10-15 00:05 - 000668160 _____ () C:\Users\lolli\Desktop\modded gta v launcher 2.2.exe 2017-10-15 00:05 - 2017-10-15 00:05 - 000541089 _____ C:\Users\lolli\Downloads\ca2813-[BroXe] Modded GTA V Launcher 2.2 (1).zip 2017-10-15 00:05 - 2017-10-15 00:05 - 000541089 _____ C:\Users\lolli\Desktop\ca2813-[BroXe] Modded GTA V Launcher 2.2 (1).zip 2017-10-15 00:05 - 2017-10-15 00:05 - 000000000 ____D C:\Users\lolli\AppData\Local\LauncherV2English 2017-10-15 00:03 - 2017-10-15 00:03 - 000541089 _____ C:\Users\lolli\Downloads\ca2813-[BroXe] Modded GTA V Launcher 2.2.zip 2017-10-14 23:44 - 2017-10-14 23:42 - 007931434 _____ C:\Users\lolli\Desktop\d6faf9-Enhanced Native Trainer - update 35 QoL 1.zip 2017-10-14 23:42 - 2017-10-14 23:42 - 007931434 _____ C:\Users\lolli\Downloads\d6faf9-Enhanced Native Trainer - update 35 QoL 1.zip 2017-10-14 23:32 - 2017-10-14 23:32 - 000000616 _____ C:\Users\lolli\Desktop\dlclist.xml 2017-10-14 23:30 - 2017-10-14 23:30 - 000000000 ____D C:\Users\lolli\Documents\OpenIV 2017-10-14 23:28 - 2017-10-14 23:28 - 000000000 ____D C:\Users\lolli\AppData\Local\New Technology Studio 2017-10-14 23:21 - 2017-10-14 23:20 - 061915159 _____ C:\Users\lolli\Desktop\3ee6de-Eurofighter_Typhoon.zip 2017-10-14 23:20 - 2017-10-14 23:20 - 061915159 _____ C:\Users\lolli\Downloads\3ee6de-Eurofighter_Typhoon.zip 2017-10-14 23:15 - 2017-10-14 23:15 - 007195928 _____ (Microsoft Corporation) C:\Users\lolli\Downloads\vcredist_x64.exe 2017-10-14 23:14 - 2017-10-14 23:14 - 069999448 _____ (Microsoft Corporation) C:\Users\lolli\Downloads\NDP452-KB2901907-x86-x64-AllOS-ENU.exe 2017-10-14 23:10 - 2017-10-14 23:07 - 000036049 _____ C:\Users\lolli\Desktop\bde7c9-Metric_Speedometer_2.2.0.zip 2017-10-14 23:10 - 2017-10-14 22:49 - 000945684 _____ C:\Users\lolli\Desktop\ScriptHookV_1.0.1180.2.zip 2017-10-14 23:09 - 2017-10-14 23:07 - 000398545 _____ C:\Users\lolli\Desktop\ScriptHookVDotNet.zip 2017-10-14 23:09 - 2017-10-14 22:49 - 000003888 _____ C:\Users\lolli\Desktop\66dda6-ManualTransmission.zip 2017-10-14 23:07 - 2017-10-14 23:07 - 000398545 _____ C:\Users\lolli\Downloads\ScriptHookVDotNet.zip 2017-10-14 23:07 - 2017-10-14 23:07 - 000036049 _____ C:\Users\lolli\Downloads\bde7c9-Metric_Speedometer_2.2.0.zip 2017-10-14 22:49 - 2017-10-14 22:49 - 000945684 _____ C:\Users\lolli\Downloads\ScriptHookV_1.0.1180.2.zip 2017-10-14 22:49 - 2017-10-14 22:49 - 000003888 _____ C:\Users\lolli\Downloads\66dda6-ManualTransmission.zip 2017-10-14 21:17 - 2017-10-14 21:17 - 000004194 _____ C:\Windows\System32\Tasks\Norton Security Scan for lolli 2017-10-14 21:17 - 2017-10-14 21:17 - 000001464 _____ C:\Users\Public\Desktop\Norton Security Scan.LNK 2017-10-14 21:17 - 2017-10-14 21:17 - 000000000 ____D C:\Windows\system32\Drivers\NSSx64 2017-10-14 21:17 - 2017-10-14 21:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan 2017-10-14 21:17 - 2017-10-14 21:17 - 000000000 ____D C:\Program Files (x86)\Norton Security Scan 2017-10-14 20:32 - 2017-10-14 20:32 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2017-10-14 20:30 - 2017-04-28 00:50 - 003550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2017-10-14 20:30 - 2017-04-12 15:05 - 004296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2017-10-14 20:27 - 2017-09-13 17:33 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-10-14 20:27 - 2017-09-13 17:32 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-10-14 20:27 - 2017-09-13 17:32 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-10-14 20:27 - 2017-09-13 17:32 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-10-14 20:27 - 2017-09-13 17:32 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-10-14 20:27 - 2017-09-13 17:31 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-10-14 20:27 - 2017-09-13 17:28 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:13 - 004001512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-10-14 20:27 - 2017-09-13 17:13 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-10-14 20:27 - 2017-09-13 17:10 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-10-14 20:27 - 2017-09-13 17:09 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 17:05 - 000324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2017-10-14 20:27 - 2017-09-13 17:00 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-10-14 20:27 - 2017-09-13 17:00 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-10-14 20:27 - 2017-09-13 17:00 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-10-14 20:27 - 2017-09-13 17:00 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-10-14 20:27 - 2017-09-13 16:57 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-10-14 20:27 - 2017-09-13 16:56 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-10-14 20:27 - 2017-09-13 16:53 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-10-14 20:27 - 2017-09-13 16:53 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-10-14 20:27 - 2017-09-13 16:53 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-10-14 20:27 - 2017-09-13 16:52 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-10-14 20:27 - 2017-09-13 16:52 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-10-14 20:27 - 2017-09-13 16:50 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-10-14 20:27 - 2017-09-13 16:47 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-10-14 20:27 - 2017-09-13 16:46 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-10-14 20:27 - 2017-09-13 16:46 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-10-14 20:27 - 2017-09-13 16:46 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-10-14 20:27 - 2017-09-09 02:45 - 000395984 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-10-14 20:27 - 2017-09-09 01:47 - 000347344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-10-14 20:27 - 2017-09-08 17:34 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-10-14 20:27 - 2017-09-08 17:30 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-10-14 20:27 - 2017-09-08 17:30 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-10-14 20:27 - 2017-09-08 17:14 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-10-14 20:27 - 2017-09-08 17:13 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-10-14 20:27 - 2017-09-08 17:13 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-10-14 20:27 - 2017-09-08 17:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-10-14 20:27 - 2017-09-08 17:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll 2017-10-14 20:27 - 2017-09-08 17:10 - 000312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-10-14 20:27 - 2017-09-08 17:10 - 000109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2017-10-14 20:27 - 2017-09-08 17:09 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2017-10-14 20:27 - 2017-09-08 17:00 - 003222016 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-10-14 20:27 - 2017-09-08 17:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2017-10-14 20:27 - 2017-09-08 17:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2017-10-14 20:27 - 2017-09-08 16:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2017-10-14 20:27 - 2017-09-08 16:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2017-10-14 20:27 - 2017-09-08 16:20 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll 2017-10-14 20:27 - 2017-09-08 16:20 - 000345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll 2017-10-14 20:27 - 2017-09-08 16:20 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll 2017-10-14 20:27 - 2017-09-07 23:38 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-10-14 20:27 - 2017-09-07 23:37 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-10-14 20:27 - 2017-09-07 23:19 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-10-14 20:27 - 2017-09-07 23:18 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-10-14 20:27 - 2017-09-07 23:18 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-10-14 20:27 - 2017-09-07 23:17 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-10-14 20:27 - 2017-09-07 23:17 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-10-14 20:27 - 2017-09-07 23:15 - 002902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-10-14 20:27 - 2017-09-07 23:08 - 025729536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-10-14 20:27 - 2017-09-07 23:08 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-10-14 20:27 - 2017-09-07 23:07 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-10-14 20:27 - 2017-09-07 23:02 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-10-14 20:27 - 2017-09-07 23:01 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-10-14 20:27 - 2017-09-07 23:01 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-10-14 20:27 - 2017-09-07 23:01 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-10-14 20:27 - 2017-09-07 23:00 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-10-14 20:27 - 2017-09-07 22:52 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-10-14 20:27 - 2017-09-07 22:48 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-10-14 20:27 - 2017-09-07 22:40 - 005982208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-10-14 20:27 - 2017-09-07 22:39 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-10-14 20:27 - 2017-09-07 22:38 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-10-14 20:27 - 2017-09-07 22:37 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-10-14 20:27 - 2017-09-07 22:33 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-10-14 20:27 - 2017-09-07 22:32 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-10-14 20:27 - 2017-09-07 22:29 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-10-14 20:27 - 2017-09-07 22:27 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-10-14 20:27 - 2017-09-07 22:13 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-10-14 20:27 - 2017-09-07 22:10 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-10-14 20:27 - 2017-09-07 22:10 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-10-14 20:27 - 2017-09-07 22:08 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-10-14 20:27 - 2017-09-07 22:08 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-10-14 20:27 - 2017-09-07 21:44 - 015262720 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-10-14 20:27 - 2017-09-07 21:40 - 003240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-10-14 20:27 - 2017-09-07 21:27 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-10-14 20:27 - 2017-09-07 21:27 - 001548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-10-14 20:27 - 2017-09-07 21:17 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-10-14 20:27 - 2017-09-07 21:11 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-10-14 20:27 - 2017-09-07 21:10 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-10-14 20:27 - 2017-09-07 21:10 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-10-14 20:27 - 2017-09-07 21:10 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-10-14 20:27 - 2017-09-07 21:09 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-10-14 20:27 - 2017-09-07 21:04 - 020267008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-10-14 20:27 - 2017-09-07 21:03 - 002292736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-10-14 20:27 - 2017-09-07 21:03 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-10-14 20:27 - 2017-09-07 21:02 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-10-14 20:27 - 2017-09-07 20:59 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-10-14 20:27 - 2017-09-07 20:58 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-10-14 20:27 - 2017-09-07 20:58 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-10-14 20:27 - 2017-09-07 20:58 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-10-14 20:27 - 2017-09-07 20:49 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-10-14 20:27 - 2017-09-07 20:44 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2017-10-14 20:27 - 2017-09-07 20:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-10-14 20:27 - 2017-09-07 20:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-10-14 20:27 - 2017-09-07 20:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-10-14 20:27 - 2017-09-07 20:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-10-14 20:27 - 2017-09-07 20:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-10-14 20:27 - 2017-09-07 20:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-10-14 20:27 - 2017-09-07 20:29 - 004547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-10-14 20:27 - 2017-09-07 20:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-10-14 20:27 - 2017-09-07 20:26 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-10-14 20:27 - 2017-09-07 20:25 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-10-14 20:27 - 2017-09-07 20:25 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-10-14 20:27 - 2017-09-07 20:17 - 013677568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-10-14 20:27 - 2017-09-07 20:01 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-10-14 20:27 - 2017-09-07 19:57 - 001316864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-10-14 20:27 - 2017-09-07 19:57 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-10-14 20:27 - 2017-09-07 17:31 - 002851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2017-10-14 20:27 - 2017-09-07 17:12 - 002755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll 2017-10-14 20:27 - 2017-09-07 16:55 - 000461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-10-14 20:27 - 2017-09-07 16:55 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-10-14 20:27 - 2017-09-07 16:55 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-10-14 20:27 - 2017-08-19 17:28 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2017-10-14 20:27 - 2017-08-19 17:28 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2017-10-14 20:27 - 2017-08-19 17:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2017-10-14 20:27 - 2017-08-19 17:28 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2017-10-14 20:27 - 2017-08-19 17:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2017-10-14 20:27 - 2017-08-19 17:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2017-10-14 20:27 - 2017-08-19 17:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2017-10-14 20:27 - 2017-08-19 17:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2017-10-14 20:27 - 2017-08-19 17:08 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2017-10-14 20:27 - 2017-08-19 17:08 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2017-10-14 20:27 - 2017-08-19 16:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2017-10-14 20:27 - 2017-08-19 16:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2017-10-14 20:27 - 2017-08-16 17:29 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-10-14 20:27 - 2017-08-16 17:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-10-14 20:27 - 2017-08-15 17:29 - 014182400 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2017-10-14 20:27 - 2017-08-15 17:29 - 001867264 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2017-10-14 20:27 - 2017-08-15 17:10 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2017-10-14 20:27 - 2017-08-15 17:10 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 003203584 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 001032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll 2017-10-14 20:27 - 2017-08-14 19:35 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2017-10-14 20:27 - 2017-08-14 19:34 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll 2017-10-14 20:27 - 2017-08-13 23:45 - 000040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2017-10-14 20:27 - 2017-08-13 23:37 - 002144256 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe 2017-10-14 20:27 - 2017-08-13 23:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe 2017-10-14 20:27 - 2017-08-11 08:35 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll 2017-10-14 20:27 - 2017-08-11 08:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll 2017-10-14 20:27 - 2017-08-11 08:34 - 000971776 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2017-10-14 20:27 - 2017-08-11 08:34 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2017-10-14 20:27 - 2017-08-11 08:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll 2017-10-14 20:27 - 2017-08-11 08:34 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll 2017-10-14 20:27 - 2017-08-11 08:20 - 000071680 _____ C:\Windows\system32\PrintBrmUi.exe 2017-10-14 20:27 - 2017-08-11 08:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe 2017-10-14 20:27 - 2017-08-11 08:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe 2017-10-14 20:27 - 2017-08-11 08:19 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll 2017-10-14 20:27 - 2017-08-11 08:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll 2017-10-14 20:27 - 2017-08-11 08:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe 2017-10-14 20:27 - 2017-08-11 08:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe 2017-10-14 20:27 - 2017-08-11 08:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe 2017-10-14 20:27 - 2017-08-11 08:01 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll 2017-10-14 20:27 - 2017-08-11 08:00 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2017-10-14 20:27 - 2017-08-11 07:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys 2017-10-14 20:27 - 2017-07-29 16:56 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2017-10-14 20:27 - 2017-07-21 16:26 - 000518144 _____ C:\Windows\SysWOW64\msjetoledb40.dll 2017-10-14 20:27 - 2017-07-21 16:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexch40.dll 2017-10-14 20:27 - 2017-07-21 16:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjtes40.dll 2017-10-14 20:27 - 2017-07-21 16:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll 2017-10-14 20:27 - 2017-07-14 17:29 - 000486400 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2017-10-14 20:27 - 2017-07-14 17:29 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll 2017-10-14 20:27 - 2017-07-14 17:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2017-10-14 20:27 - 2017-07-14 16:57 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe 2017-10-14 20:27 - 2017-07-14 16:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe 2017-10-14 20:27 - 2017-07-14 16:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll 2017-10-14 20:27 - 2017-07-08 17:34 - 000370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2017-10-14 20:27 - 2017-07-07 17:33 - 000363752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys 2017-10-14 20:27 - 2017-07-07 17:29 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll 2017-10-14 20:27 - 2017-07-07 17:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswdat10.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll 2017-10-14 20:27 - 2017-07-01 15:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjter40.dll 2017-10-14 20:27 - 2017-06-15 22:23 - 000753664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2017-10-14 20:27 - 2017-06-13 00:49 - 001363456 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll 2017-10-14 20:27 - 2017-06-13 00:49 - 000594432 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll 2017-10-14 20:27 - 2017-06-13 00:49 - 000475136 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx 2017-10-14 20:27 - 2017-06-13 00:49 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll 2017-10-14 20:27 - 2017-06-13 00:29 - 001227264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll 2017-10-14 20:27 - 2017-06-13 00:29 - 000444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll 2017-10-14 20:27 - 2017-06-13 00:29 - 000390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx 2017-10-14 20:27 - 2017-06-13 00:28 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll 2017-10-14 20:27 - 2017-06-13 00:14 - 000379392 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe 2017-10-14 20:27 - 2017-06-13 00:14 - 000172544 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe 2017-10-14 20:27 - 2017-06-13 00:14 - 000103936 _____ (Microsoft Corporation) C:\Windows\system32\resmon.exe 2017-10-14 20:27 - 2017-06-13 00:06 - 000303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe 2017-10-14 20:27 - 2017-06-13 00:06 - 000157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfmon.exe 2017-10-14 20:27 - 2017-06-13 00:06 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resmon.exe 2017-10-14 20:27 - 2017-06-02 10:10 - 000733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-10-14 20:27 - 2017-05-30 06:56 - 001895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2017-10-14 20:27 - 2017-05-30 06:56 - 000377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2017-10-14 20:27 - 2017-05-30 06:56 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2017-10-14 20:27 - 2017-05-21 06:24 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-10-14 20:27 - 2017-05-21 06:06 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-10-14 20:27 - 2017-05-16 17:35 - 000986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2017-10-14 20:27 - 2017-05-16 17:35 - 000265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2017-10-14 20:27 - 2017-05-16 17:30 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2017-10-14 20:27 - 2017-05-12 20:26 - 000382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2017-10-14 20:27 - 2017-05-12 20:22 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2017-10-14 20:27 - 2017-05-12 20:22 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2017-10-14 20:27 - 2017-05-12 20:22 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2017-10-14 20:27 - 2017-05-12 20:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2017-10-14 20:27 - 2017-05-12 20:07 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2017-10-14 20:27 - 2017-05-12 20:03 - 000070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2017-10-14 20:27 - 2017-05-12 20:03 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2017-10-14 20:27 - 2017-05-12 20:03 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2017-10-14 20:27 - 2017-05-12 19:43 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2017-10-14 20:27 - 2017-05-12 18:25 - 001251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-10-14 20:27 - 2017-05-12 17:58 - 001648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-10-14 20:27 - 2017-05-12 17:58 - 001180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-10-14 20:27 - 2017-05-10 17:33 - 000091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe 2017-10-14 20:27 - 2017-05-10 17:29 - 003165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2017-10-14 20:27 - 2017-05-10 17:29 - 000192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2017-10-14 20:27 - 2017-05-10 17:29 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-10-14 20:27 - 2017-05-10 17:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2017-10-14 20:27 - 2017-05-10 17:16 - 000091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe 2017-10-14 20:27 - 2017-05-10 17:14 - 002651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-10-14 20:27 - 2017-05-10 17:13 - 000709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-10-14 20:27 - 2017-05-10 17:13 - 000140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2017-10-14 20:27 - 2017-05-10 17:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2017-10-14 20:27 - 2017-05-10 17:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2017-10-14 20:27 - 2017-05-10 17:13 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-10-14 20:27 - 2017-05-10 17:13 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2017-10-14 20:27 - 2017-05-10 17:12 - 000174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2017-10-14 20:27 - 2017-05-10 17:00 - 000573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-10-14 20:27 - 2017-05-10 17:00 - 000093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-10-14 20:27 - 2017-05-10 17:00 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2017-10-14 20:27 - 2017-05-10 17:00 - 000030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2017-10-14 20:27 - 2017-05-07 17:33 - 000094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2017-10-14 20:27 - 2017-05-07 17:29 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2017-10-14 20:27 - 2017-04-21 17:34 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2017-10-14 20:27 - 2017-04-21 17:15 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2017-10-14 20:27 - 2017-04-17 17:37 - 000876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2017-10-14 20:27 - 2017-04-17 17:12 - 000581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2017-10-14 20:27 - 2017-04-12 17:32 - 001483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2017-10-14 20:27 - 2017-04-12 17:32 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2017-10-14 20:27 - 2017-04-12 17:32 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2017-10-14 20:27 - 2017-04-12 17:32 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2017-10-14 20:27 - 2017-04-12 17:26 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2017-10-14 20:27 - 2017-04-12 17:25 - 001176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2017-10-14 20:27 - 2017-04-12 17:25 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2017-10-14 20:27 - 2017-04-12 17:25 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2017-10-14 20:27 - 2017-04-04 16:53 - 000496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2017-10-14 20:27 - 2017-03-30 17:03 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe 2017-10-14 20:27 - 2017-03-30 16:58 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe 2017-10-14 20:27 - 2017-03-10 18:32 - 001389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll 2017-10-14 20:27 - 2017-03-10 18:32 - 000300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll 2017-10-14 20:27 - 2017-03-10 18:20 - 001508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll 2017-10-14 20:27 - 2017-03-10 18:20 - 000237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll 2017-10-14 20:27 - 2017-03-10 17:57 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe 2017-10-14 20:27 - 2017-03-10 17:55 - 000205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2017-10-14 20:27 - 2017-03-10 17:55 - 000195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys 2017-10-14 20:27 - 2017-03-07 18:30 - 000085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll 2017-10-14 20:27 - 2017-03-07 18:17 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll 2017-10-14 20:27 - 2017-03-07 16:05 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2017-10-14 20:27 - 2017-03-04 03:27 - 001574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-10-14 20:27 - 2017-03-04 03:27 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll 2017-10-14 20:27 - 2017-03-04 03:14 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-10-14 20:27 - 2017-03-04 03:14 - 000077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll 2017-10-14 20:27 - 2017-02-09 18:32 - 000769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-10-14 20:27 - 2017-02-09 18:32 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2017-10-14 20:27 - 2017-02-09 18:32 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll 2017-10-14 20:27 - 2017-02-09 18:31 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2017-10-14 20:27 - 2017-02-09 18:31 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll 2017-10-14 20:27 - 2017-02-09 18:14 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2017-10-14 20:27 - 2017-02-09 18:14 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll 2017-10-14 20:27 - 2017-02-09 18:14 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2017-10-14 20:27 - 2017-02-09 17:51 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:36 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-10-14 20:27 - 2017-01-18 17:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-10-14 20:27 - 2017-01-13 20:00 - 000976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-10-14 20:27 - 2017-01-13 20:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2017-10-14 20:27 - 2017-01-13 19:45 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-10-14 20:27 - 2017-01-13 19:45 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2017-10-14 20:27 - 2017-01-11 20:01 - 001887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2017-10-14 20:27 - 2017-01-11 20:01 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2017-10-14 20:27 - 2017-01-11 19:43 - 001241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2017-10-14 20:27 - 2017-01-11 19:43 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2017-10-14 20:27 - 2016-03-24 00:40 - 003181568 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2017-10-14 20:27 - 2016-03-24 00:40 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2017-10-14 20:25 - 2017-10-14 20:25 - 000000000 ____D C:\Windows\System32\Tasks\Norton Security with Backup 2017-10-14 20:25 - 2017-05-03 17:34 - 000094952 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-10-14 20:25 - 2017-05-03 17:29 - 001206272 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 001555968 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000620544 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000535552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000311296 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000217088 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-10-14 20:25 - 2017-05-03 15:05 - 000127488 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-10-14 20:25 - 2017-03-23 04:06 - 001691136 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2017-10-14 20:24 - 2017-10-14 20:24 - 000102568 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2017-10-14 20:24 - 2017-10-14 20:24 - 000008309 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2017-10-14 20:24 - 2017-10-14 20:24 - 000003230 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2017-10-14 20:24 - 2017-10-14 20:24 - 000002312 _____ C:\Users\Public\Desktop\Norton Security with Backup.lnk 2017-10-14 20:24 - 2017-10-14 20:24 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security with Backup 2017-10-14 20:24 - 2017-10-14 20:24 - 000000000 ____D C:\Windows\system32\Drivers\NSBUx64 2017-10-14 20:24 - 2017-10-14 20:24 - 000000000 ____D C:\Program Files\Norton Security with Backup 2017-10-14 20:24 - 2017-10-14 20:24 - 000000000 ____D C:\Program Files\Common Files\Symantec Shared 2017-10-14 20:23 - 2017-10-14 21:17 - 000000000 ____D C:\Program Files (x86)\NortonInstaller 2017-10-14 20:22 - 2017-10-14 20:23 - 001112832 _____ (Symantec Corporation) C:\Users\lolli\Downloads\NortonNSBUDownloader.exe 2017-10-11 19:21 - 2017-10-11 19:21 - 000540126 _____ C:\Users\lolli\Downloads\Loader.zip 2017-10-07 14:18 - 2017-10-07 14:18 - 000417336 _____ C:\Windows\Minidump\100717-7456-01.dmp 2017-10-05 21:01 - 2017-10-05 21:02 - 000000807 _____ C:\Users\lolli\Desktop\Conquest Reforged.lnk 2017-10-05 20:55 - 2017-10-05 20:55 - 007195735 _____ C:\Users\lolli\Downloads\Conquest_Reforged_Launcher.exe 2017-10-04 20:27 - 2017-10-15 00:00 - 000000566 _____ C:\Users\lolli\Desktop\gradient.lnk 2017-09-30 20:52 - 2017-09-30 20:52 - 000000222 _____ C:\Users\lolli\Desktop\Insurgency.url 2017-09-28 19:00 - 2017-10-12 21:24 - 000001212 _____ C:\Users\lolli\Desktop\nativelog.txt 2017-09-26 17:02 - 2017-09-26 17:02 - 000000000 ____D C:\Users\lolli\AppData\Roaming\CrispyCheats 2017-09-26 16:58 - 2017-10-15 18:03 - 000000000 ____D C:\Users\lolli\Desktop\wf 2017-09-26 16:58 - 2017-09-26 16:58 - 000530970 _____ C:\Users\lolli\Downloads\Update (1).zip 2017-09-26 16:26 - 2017-10-14 21:23 - 000000000 ____D C:\Users\lolli\Desktop\sortieren 2017-09-26 16:26 - 2017-09-26 16:26 - 000530970 _____ C:\Users\lolli\Downloads\Update.zip 2017-09-26 16:02 - 2017-09-26 16:02 - 000978053 _____ C:\Users\lolli\Downloads\7r14ngl3_SafeMenu_GTAO1.41_v1.4.1_unknowncheats.me_.zip 2017-09-25 16:01 - 2017-09-25 16:02 - 000544418 _____ C:\Users\lolli\Downloads\Modmenu.zip 2017-09-23 14:02 - 2017-09-23 14:03 - 351282768 _____ (GIANTS Software ) C:\Users\lolli\Downloads\FarmingSimulator2015Patch1.4.2DE.exe 2017-09-22 09:52 - 2017-09-22 09:52 - 000000867 _____ C:\Users\lolli\Desktop\Landwirtschafts Simulator 15 .lnk 2017-09-22 09:52 - 2017-09-22 09:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Landwirtschafts Simulator 2015 2017-09-17 10:13 - 2017-09-17 10:13 - 007169765 _____ C:\Users\lolli\Downloads\POLITIKER VONG HEUTE.mp4 2017-09-17 10:13 - 2017-09-17 10:13 - 007169765 _____ C:\Users\lolli\Downloads\POLITIKER VONG HEUTE (1).mp4 ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-10-16 16:44 - 2017-05-01 16:12 - 000000000 ____D C:\ProgramData\Origin 2017-10-16 15:06 - 2009-07-14 06:45 - 000021696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-10-16 15:06 - 2009-07-14 06:45 - 000021696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-10-16 15:00 - 2017-04-04 17:28 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-10-16 15:00 - 2017-04-04 17:28 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-10-16 15:00 - 2017-04-04 17:28 - 000004536 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-10-16 15:00 - 2017-04-04 17:28 - 000004378 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-10-16 15:00 - 2017-04-04 17:28 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2017-10-16 15:00 - 2017-04-04 17:28 - 000000000 ____D C:\Windows\system32\Macromed 2017-10-16 14:58 - 2011-04-12 09:43 - 000701584 _____ C:\Windows\system32\perfh007.dat 2017-10-16 14:58 - 2011-04-12 09:43 - 000150250 _____ C:\Windows\system32\perfc007.dat 2017-10-16 14:58 - 2009-07-14 07:13 - 001626622 _____ C:\Windows\system32\PerfStringBackup.INI 2017-10-16 14:58 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf 2017-10-16 14:56 - 2016-11-27 17:58 - 000000000 ____D C:\Program Files (x86)\Steam 2017-10-16 14:54 - 2016-12-09 23:20 - 000000000 ____D C:\Users\lolli\AppData\LocalLow\Heroes and Generals 2017-10-16 14:54 - 2016-11-27 15:47 - 000000000 ____D C:\Users\lolli 2017-10-16 14:53 - 2017-06-09 23:03 - 000000000 ____D C:\Users\lolli\AppData\Roaming\WhatsApp 2017-10-16 14:53 - 2017-02-02 18:45 - 000000000 __SHD C:\Users\lolli\IntelGraphicsProfiles 2017-10-16 14:53 - 2016-11-27 16:10 - 000000000 ____D C:\ProgramData\NVIDIA 2017-10-16 14:52 - 2016-12-05 17:17 - 000000000 ____D C:\ProgramData\VMware 2017-10-16 14:52 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-10-15 18:02 - 2016-12-03 15:47 - 000000000 ____D C:\Users\lolli\AppData\Local\CrashDumps 2017-10-15 13:25 - 2016-11-27 16:01 - 000002263 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-10-15 13:25 - 2016-11-27 16:00 - 000000000 ____D C:\Program Files (x86)\Google 2017-10-15 12:40 - 2016-11-27 16:00 - 000003542 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-10-15 12:40 - 2016-11-27 16:00 - 000003414 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-10-15 12:35 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\rescache 2017-10-15 11:51 - 2016-11-27 16:48 - 000000000 ____D C:\ProgramData\Norton 2017-10-15 00:30 - 2009-07-14 05:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy 2017-10-15 00:30 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy 2017-10-14 23:29 - 2016-12-17 11:41 - 000000000 ____D C:\Users\lolli\AppData\Roaming\Skype 2017-10-14 23:15 - 2016-11-27 16:09 - 000000000 ____D C:\ProgramData\Package Cache 2017-10-14 21:18 - 2016-11-29 17:00 - 000000000 ____D C:\Program Files\Common Files\AV 2017-10-14 20:50 - 2016-12-13 00:06 - 000000000 ___SD C:\Windows\system32\CompatTel 2017-10-14 20:50 - 2016-12-13 00:06 - 000000000 ____D C:\Windows\system32\appraiser 2017-10-14 20:50 - 2009-07-14 07:32 - 000000000 ____D C:\Program Files\DVD Maker 2017-10-14 20:50 - 2009-07-14 06:45 - 000347608 _____ C:\Windows\system32\FNTCACHE.DAT 2017-10-14 20:50 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\SysWOW64\migwiz 2017-10-14 20:50 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\migwiz 2017-10-14 20:50 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\PolicyDefinitions 2017-10-14 20:34 - 2016-12-12 23:10 - 000000000 ____D C:\Windows\system32\MRT 2017-10-14 20:32 - 2016-12-12 23:10 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-10-14 20:31 - 2016-12-01 21:56 - 001600014 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2017-10-14 20:25 - 2016-11-27 16:48 - 000000000 ____D C:\Users\lolli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton 2017-10-14 20:23 - 2016-11-27 16:48 - 000000000 ____D C:\Users\Public\Downloads\Norton 2017-10-14 20:17 - 2016-11-27 16:49 - 000000000 ____D C:\ProgramData\NortonInstaller 2017-10-14 10:02 - 2017-05-01 16:13 - 000000000 ____D C:\Program Files (x86)\Origin 2017-10-13 20:11 - 2016-12-09 20:53 - 000000000 ____D C:\Users\lolli\AppData\Roaming\TS3Client 2017-10-13 14:03 - 2017-06-09 23:03 - 000002173 _____ C:\Users\lolli\Desktop\WhatsApp.lnk 2017-10-13 14:03 - 2017-06-09 23:03 - 000000000 ____D C:\Users\lolli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2017-10-13 14:03 - 2017-06-09 23:02 - 000000000 ____D C:\Users\lolli\AppData\Local\WhatsApp 2017-10-13 14:03 - 2017-06-04 14:29 - 000000000 ____D C:\Users\lolli\AppData\Local\SquirrelTemp 2017-10-13 14:03 - 2016-12-11 12:41 - 000000000 ____D C:\Users\lolli\AppData\Local\ElevatedDiagnostics 2017-10-12 19:05 - 2017-06-04 16:53 - 000000000 ____D C:\Users\lolli\AppData\Roaming\.minecraft 2017-10-11 21:11 - 2016-11-27 18:06 - 000000000 ____D C:\Users\lolli\AppData\Local\Battle.net 2017-10-11 21:11 - 2016-11-27 18:05 - 000000000 ____D C:\Program Files (x86)\Battle.net 2017-10-10 16:58 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF 2017-10-07 14:18 - 2016-11-27 17:24 - 000000000 ____D C:\Windows\Minidump 2017-10-05 18:36 - 2017-09-06 00:32 - 000000000 ____D C:\Users\lolli\AppData\Local\Arma 3 Launcher 2017-10-05 14:20 - 2017-04-08 19:48 - 000000000 ____D C:\Users\lolli\AppData\Local\Arma 3 2017-09-30 00:36 - 2017-06-04 14:29 - 000000000 ____D C:\Users\lolli\AppData\Local\Discord 2017-09-26 16:04 - 2017-08-30 14:21 - 000000000 ____D C:\Users\lolli\Desktop\7r14ngl3_SafeMenu_GTAO1.41_v1.4.1 2017-09-26 15:53 - 2016-12-05 17:24 - 000000000 ____D C:\Users\lolli\AppData\Local\VMware 2017-09-26 15:41 - 2009-07-14 07:32 - 000000000 ____D C:\Windows\system32\FxsTmp 2017-09-26 15:40 - 2016-12-05 17:23 - 000000000 ____D C:\Users\lolli\AppData\Roaming\VMware 2017-09-23 21:38 - 2016-11-27 18:06 - 000000000 ____D C:\Users\lolli\AppData\Local\Blizzard Entertainment 2017-09-22 10:09 - 2016-11-27 20:23 - 000000000 ____D C:\Users\lolli\Documents\My Games 2017-09-16 11:36 - 2009-07-14 07:08 - 000032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-01-06 23:35 - 2017-01-06 23:35 - 000000000 _____ () C:\Users\lolli\AppData\Roaming\dc.ogt 2016-12-05 20:44 - 2017-02-19 12:05 - 000007593 _____ () C:\Users\lolli\AppData\Local\Resmon.ResmonCfg 2016-11-30 15:31 - 2016-11-30 15:31 - 000000000 _____ () C:\Users\lolli\AppData\Local\{53610194-4399-4785-BE0D-499C08F45399} 2016-12-03 23:58 - 2016-12-03 23:58 - 000000000 _____ () C:\Users\lolli\AppData\Local\{6D4BEAEE-319E-4DEA-B08C-2372AD9F872D} 2016-12-12 22:20 - 2016-12-12 22:20 - 000000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-10-11 18:06 ==================== Ende von FRST.txt ============================ Nächster Log kommt gleich, sonst wird es zu lang. |
16.10.2017, 15:48 | #4 |
| Logs 2 Addition.txt Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-10-2017 durchgeführt von lolli (16-10-2017 16:46:37) Gestartet von C:\Users\lolli\Desktop Windows 7 Professional Service Pack 1 (X64) (2016-11-27 13:47:55) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1308867931-3025274077-1958192452-500 - Administrator - Disabled) Gast (S-1-5-21-1308867931-3025274077-1958192452-501 - Limited - Enabled) => C:\Users\Gast HomeGroupUser$ (S-1-5-21-1308867931-3025274077-1958192452-1004 - Limited - Enabled) lolli (S-1-5-21-1308867931-3025274077-1958192452-1000 - Administrator - Enabled) => C:\Users\lolli ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Norton Security (Enabled - Up to date) {30744133-1E94-7B35-F4A3-82A5AEF1CBAA} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Security (Enabled - Up to date) {8B15A0D7-38AE-74BB-CE13-B9D7D5768117} FW: Norton Security (Enabled) {084FC016-54FB-7A6D-DFFC-2B9050228CD1} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 27 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 27.0.0.170 - Adobe Systems Incorporated) Adobe Photoshop CS6 Version 13.0.1 (HKLM-x32\...\{A724DC44-6241-42D3-BA57-778B178ABC17}_is1) (Version: 13.0.1 - Adobe Systems, Inc.) Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 376.19 - NVIDIA Corporation) Hidden Arma 3 Apex (HKLM-x32\...\Arma 3 Apex_is1) (Version: - ) Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team) AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: 1.2.0.0 - AVM Berlin) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Blender (HKLM\...\Blender) (Version: 2.74 - Blender Foundation) Cheat Engine 6.7 (HKLM-x32\...\Cheat Engine 6.7_is1) (Version: - Cheat Engine) CPUID CPU-Z 1.78 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) Discord (HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\Discord) (Version: 0.0.298 - Discord Inc.) Empire Earth II SP Demo (HKLM-x32\...\{15B4652F-38E8-4252-8374-EFE88AA2FDA7}) (Version: 1.0 - Sierra) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) Euro Truck Simulator 2 (HKLM-x32\...\{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1) (Version: 1.1.1 - SCS Software) FolderIco 5.1 (HKLM\...\{22C37D82-6137-40BF-8625-7A846ED65F3A}_is1) (Version: - teorex) Free YouTube Download (HKLM-x32\...\Free YouTube Download_is1) (Version: 4.1.45.509 - Digital Wave Ltd) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games) GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games) Heroes & Generals prototype (HKLM-x32\...\Heroes & Generals prototype) (Version: 1.1.0.0 - Reto-Moto) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4578 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.4.65 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (HKLM-x32\...\{5a6a5d15-d5af-417c-b08f-f7e5eb1f98af}) (Version: 10.0.26 - Intel(R) Corporation) Hidden Java 8 Update 144 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180144F0}) (Version: 8.0.1440.1 - Oracle Corporation) Java SE Development Kit 8 Update 131 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180131}) (Version: 8.0.1310.11 - Oracle Corporation) Landwirtschafts Simulator 15 (HKLM-x32\...\FarmingSimulator2015DE_is1) (Version: 1.4.2.0 - GIANTS Software) LibreOffice 5.2.5.1 (HKLM-x32\...\{79CD8EA1-DEB1-4582-9E41-8634223BDCD4}) (Version: 5.2.5.1 - The Document Foundation) Lightworks (HKLM-x32\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 12.6.0.0 - Lightworks) Logitech Vid (HKLM-x32\...\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}) (Version: 1.10.1009 - Logitech Inc.) MegaDownloader 1.7 (HKLM\...\{C12C2297-65A4-4E64-9AE1-29F0D947FDA0}}_is1) (Version: 1.7 - AppsForMega.info) Microsoft .NET Framework 4.6.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01590 - Microsoft Corporation) Microsoft .NET Framework 4.6.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01590 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{3c3aafc8-d898-43ec-998f-965ffdae065a}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Mozilla Firefox 56.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 56.0.1 (x86 de)) (Version: 56.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.1 - Mozilla) Norton Security (HKLM-x32\...\NSBU) (Version: 22.11.0.41 - Symantec Corporation) Norton Security Scan (HKLM-x32\...\NSS) (Version: 4.6.1.103 - Symantec Corporation) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.4.2 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA GeForce Experience 3.6.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.6.0.74 - NVIDIA Corporation) NVIDIA Grafiktreiber 376.19 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.19 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs) (Version: 3.6.0.74 - NVIDIA Corporation) Hidden NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: 2.4.10.0 - NVIDIA Corporation) Hidden NvvHci (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci) (Version: 2.02.0.5 - NVIDIA Corporation) Hidden OpenIV (HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\OpenIV) (Version: 2.9.1.926 - .black/OpenIV Team) Origin (HKLM-x32\...\Origin) (Version: 10.5.3.59240 - Electronic Arts, Inc.) paint.net (HKLM\...\{02D89175-E08F-401B-BA30-8B7512B57724}) (Version: 4.0.17 - dotPDN LLC) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.88.617.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7727 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.2.0 - Rockstar Games) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0370 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 3.6.0.74 - NVIDIA Corporation) Hidden Shotcut (HKLM-x32\...\Shotcut) (Version: - ) Skype™ 7.37 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.37.103 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) Test Drive Unlimited 2 (HKLM-x32\...\Test Drive Unlimited 2_is1) (Version: - Atari) Uplay (HKLM-x32\...\Uplay) (Version: 25.0.1 - Ubisoft) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) VMware Player (HKLM\...\{E452E727-86B8-4233-8CC3-41FD817AFAFF}) (Version: 6.0.7 - VMware, Inc.) Hidden VMware Player (HKLM-x32\...\VMware_Player) (Version: 6.0.7 - VMware, Inc) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) WhatsApp (HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\...\WhatsApp) (Version: 0.2.6426 - WhatsApp) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) WorldPainter 2.3.1 (HKLM\...\4144-4862-0472-7103-1) (Version: 2.3.1 - pepsoft.org) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1308867931-3025274077-1958192452-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-1308867931-3025274077-1958192452-1000_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> D:\Programme\Blender\BlendThumb64.dll () ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\buShell.dll [2017-10-04] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\buShell.dll [2017-10-04] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\buShell.dll [2017-10-04] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\buShell.dll [2017-10-04] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\buShell.dll [2017-10-04] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\buShell.dll [2017-10-04] (Symantec Corporation) ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => D:\Programme\Notepad++\NppShell_06.dll [2017-02-13] () ContextMenuHandlers1: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\buShell.dll [2017-10-04] (Symantec Corporation) ContextMenuHandlers1: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\NavShExt.dll [2017-10-04] (Symantec Corporation) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers2: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\NavShExt.dll [2017-10-04] (Symantec Corporation) ContextMenuHandlers2-x32: [VMDiskMenuHandler] -> {271DC252-6FE1-4D59-9053-E4CF50AB99DE} => D:\Programme (x86)\VMware\vmdkShellExt.dll [2015-06-24] (VMware, Inc.) ContextMenuHandlers2-x32: [VMDiskMenuHandler64] -> {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} => D:\Programme (x86)\VMware\x64\vmdkShellExt64.dll [2015-06-24] (VMware, Inc.) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Keine Datei ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2017-01-24] (Intel Corporation) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2016-12-01] (NVIDIA Corporation) ContextMenuHandlers6: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\buShell.dll [2017-10-04] (Symantec Corporation) ContextMenuHandlers6: [Folderico] -> {CC0C45C5-EFDE-4B8A-A8B0-9ED733D9E6AC} => C:\Program Files\FolderIco\FolderIco.dll [2017-01-02] (TeoreX) ContextMenuHandlers6: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\NavShExt.dll [2017-10-04] (Symantec Corporation) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (Alexander Roshal) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0F67A5FA-A238-4553-88B1-FAC100B1C272} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-15] (Google Inc.) Task: {164CB5B8-F36A-4A65-9005-0B0CC64C0B6C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-05-03] (NVIDIA Corporation) Task: {1D758735-D8B3-4677-834A-EA8071D911EB} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {1FA0C8D8-CB0D-474F-A8E6-42C6F1DD33B4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-15] (Google Inc.) Task: {49551576-3C98-409B-A55D-F9ADAF93BF9C} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe [2017-10-04] (Symantec Corporation) Task: {4D7DC808-90EC-462C-8EB1-E775C02B2C74} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe Task: {8261D6A1-F12F-475E-BD61-EEC252C974B3} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {85F44B49-2AEF-4F26-A59F-5372D298B47F} - System32\Tasks\Norton Security Scan for lolli => C:\Program Files (x86)\Norton Security Scan\Engine\4.6.1.103\Nss.exe [2017-06-10] (Symantec Corporation) Task: {8FE485B3-7F48-4BB8-AC16-95690C1D432C} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\WSCStub.exe [2017-10-04] (Symantec Corporation) Task: {9068A51C-B36D-42F4-9EBC-DB5892D9D5B4} - System32\Tasks\{012E5D53-5E3E-417F-A191-05FE074E17FF} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Hi-Rez Studios\HiRezGamesDiagAndSupport.exe" -c uninstall=all Task: {94E4651F-DCE3-4E70-A090-F243115832B9} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03] (NVIDIA Corporation) Task: {98DDA104-8CCD-4065-95BC-017238D0D092} - System32\Tasks\Norton Security with Backup\Norton Security with Backup Error Analyzer => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\SymErr.exe [2017-10-04] (Symantec Corporation) Task: {9B3B87F3-5269-4030-A4BC-37FD6F5962CC} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-05-03] (NVIDIA Corporation) Task: {A4B4A32D-E8F0-446D-82F5-731857E8526A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-16] (Adobe Systems Incorporated) Task: {A836F77B-9588-4D0B-9978-81021A94483C} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-05-03] (NVIDIA Corporation) Task: {ACE1226B-ABF1-4382-9DAB-EA5B032F4FFB} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) Task: {BB1D1B0D-84B5-40F2-8CF8-94D59C22DA88} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_170_pepper.exe [2017-10-16] (Adobe Systems Incorporated) Task: {D49DAC06-C9AC-45A6-A4D6-AFD8631D8ABE} - System32\Tasks\Norton Security with Backup\Norton Security with Backup Error Processor => C:\Program Files\Norton Security with Backup\Engine\22.11.0.41\SymErr.exe [2017-10-04] (Symantec Corporation) Task: {E21D96B5-4E46-46E9-95CC-00D7E2A29AE3} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-09-04 14:04 - 2015-09-04 14:04 - 000032776 _____ () C:\Windows\System32\ssj1mlm.dll 2016-11-27 16:10 - 2017-05-03 22:21 - 001267320 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-11-27 16:10 - 2016-12-01 19:32 - 000134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-05-25 00:14 - 2017-05-29 18:22 - 000075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2017-05-15 16:33 - 2017-05-04 17:42 - 000114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll 2017-05-15 16:34 - 2017-05-04 17:42 - 000108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll 2017-05-15 16:34 - 2017-05-04 17:42 - 000024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll 2017-05-15 16:34 - 2017-05-04 17:42 - 000048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll 2015-06-24 14:28 - 2015-06-24 14:28 - 001301720 _____ () D:\Programme (x86)\VMware\libxml2.dll 2016-11-27 16:10 - 2017-05-03 22:21 - 001040504 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2009-07-16 16:34 - 2009-07-16 16:34 - 002140944 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtCore4.dll 2009-07-16 16:34 - 2009-07-16 16:34 - 007704336 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtGui4.dll 2009-07-16 16:34 - 2009-07-16 16:34 - 000968976 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtNetwork4.dll 2009-07-16 16:34 - 2009-07-16 16:34 - 000475408 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtOpenGL4.dll 2009-07-16 16:35 - 2009-07-16 16:35 - 000363792 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtXml4.dll 2009-07-16 16:34 - 2009-07-16 16:34 - 000199952 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtSql4.dll 2009-07-16 16:35 - 2009-07-16 16:35 - 000027408 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\SDL.dll 2009-07-16 16:35 - 2009-07-16 16:35 - 011311888 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtWebKit4.dll 2009-07-16 16:34 - 2009-07-16 16:34 - 000291600 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\phonon4.dll 2009-07-16 16:36 - 2009-07-16 16:36 - 000028944 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qgif4.dll 2009-07-16 16:36 - 2009-07-16 16:36 - 000035088 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qico4.dll 2009-07-16 16:36 - 2009-07-16 16:36 - 000138000 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qjpeg4.dll 2017-08-10 11:45 - 2017-08-08 15:13 - 001893880 _____ () C:\Users\lolli\AppData\Local\Discord\app-0.0.298\ffmpeg.dll 2017-04-15 23:39 - 2017-09-09 21:25 - 000688416 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2017-04-15 23:39 - 2016-09-01 03:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll 2017-04-15 23:39 - 2016-09-01 03:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2017-04-15 23:39 - 2016-09-01 03:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2017-04-15 23:39 - 2017-10-14 02:36 - 002546976 _____ () C:\Program Files (x86)\Steam\video.dll 2017-04-15 23:39 - 2016-01-27 09:49 - 002549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2017-04-15 23:39 - 2016-01-27 09:49 - 000442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2017-04-15 23:39 - 2016-01-27 09:49 - 000491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2017-04-15 23:39 - 2016-01-27 09:49 - 000332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2017-04-15 23:39 - 2016-01-27 09:49 - 000485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2017-04-15 23:39 - 2017-10-14 02:36 - 000901408 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2017-04-15 23:39 - 2016-07-05 00:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2017-04-15 23:39 - 2017-08-17 00:28 - 073130272 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll 2017-06-08 09:34 - 2017-09-07 04:04 - 000678400 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll 2017-04-15 23:39 - 2015-09-25 01:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll 2017-08-10 11:45 - 2017-08-08 15:13 - 001938424 _____ () C:\Users\lolli\AppData\Local\Discord\app-0.0.298\libglesv2.dll 2017-08-10 11:45 - 2017-08-08 15:13 - 000095736 _____ () C:\Users\lolli\AppData\Local\Discord\app-0.0.298\libegl.dll 2016-11-27 16:10 - 2017-05-03 22:20 - 065709176 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2017-08-10 11:45 - 2017-10-06 13:22 - 009722360 _____ () \\?\C:\Users\lolli\AppData\Roaming\discord\0.0.298\modules\discord_voice\discord_voice.node 2017-08-10 11:45 - 2017-08-10 11:45 - 001440248 _____ () \\?\C:\Users\lolli\AppData\Roaming\discord\0.0.298\modules\discord_utils\discord_utils.node 2017-10-16 14:53 - 2017-10-16 14:53 - 000148992 _____ () \\?\C:\Users\lolli\AppData\Local\Temp\7389.tmp.node 2017-08-10 11:45 - 2017-08-10 11:45 - 002658296 _____ () \\?\C:\Users\lolli\AppData\Roaming\discord\0.0.298\modules\discord_rpc\discord_rpc.node 2017-08-10 11:45 - 2017-08-10 11:45 - 002673656 _____ () \\?\C:\Users\lolli\AppData\Roaming\discord\0.0.298\modules\discord_contact_import\discord_contact_import.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Users\lolli:Heroes & Generals [38] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2017-09-25 16:03 - 2017-08-15 19:57 - 000000967 _____ C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 prod.telemetry.ros.rockstargames.com 127.0.0.1 localhost ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1308867931-3025274077-1958192452-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\lolli\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{6441E18D-20F8-4992-8FDC-D0802B5F72CE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{85C63A4D-F436-4951-A10A-DB492F1E61DE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{9567EB1C-0C45-4A34-B880-14187D2B108E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{52047054-0D7E-48CA-8D47-F952063A56CC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{B8E1624B-5A5D-45B8-AD67-6E88778EC3A8}] => (Allow) C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe FirewallRules: [{C88DF3D4-2039-4109-AE4B-F6DE70DB8D9F}] => (Allow) C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe FirewallRules: [TCP Query User{48FA66FC-F960-4691-B67D-72584487C723}C:\program files (x86)\logitech\logitech vid\vid.exe] => (Block) C:\program files (x86)\logitech\logitech vid\vid.exe FirewallRules: [UDP Query User{567E69DC-6796-4FEC-A18A-6810E2441A77}C:\program files (x86)\logitech\logitech vid\vid.exe] => (Block) C:\program files (x86)\logitech\logitech vid\vid.exe FirewallRules: [{8E0FC3D8-1FD3-468C-B4F0-E312582E7C5B}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{7ED92F5E-7808-4F99-B8EA-252943A4D4A7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{2A9FEAA9-294A-4CF6-B4E8-C3A26D99D3E0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{D0EAE553-71AA-4679-98E3-9C9CBD977405}] => (Allow) C:\Program Files (x86)\UPLAY\games\Assassin's Creed III\AC3SP.exe FirewallRules: [{68516927-7047-4E20-BD55-1DF48A9507B8}] => (Allow) C:\Program Files (x86)\UPLAY\games\Assassin's Creed III\AC3SP.exe FirewallRules: [{A5ACD6B0-2291-457F-B05C-8EC38351C62A}] => (Allow) C:\Program Files (x86)\UPLAY\games\Assassin's Creed III\AC3MP.exe FirewallRules: [{0D690094-7F19-4057-ACC2-24C27334E756}] => (Allow) C:\Program Files (x86)\UPLAY\games\Assassin's Creed III\AC3MP.exe FirewallRules: [{BA2182F5-7ECD-4FFA-B910-E0D328825FB5}] => (Allow) C:\Program Files (x86)\UPLAY\games\Anno 2070\Anno5.exe FirewallRules: [{F0070716-CEB5-49ED-8D71-11F4E1254243}] => (Allow) C:\Program Files (x86)\UPLAY\games\Anno 2070\Anno5.exe FirewallRules: [TCP Query User{E295EE23-69B5-4DD8-898B-0C0675FFC02D}C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{C649B563-7206-4275-BBF3-195398445171}C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [{758A7F89-9E57-4F33-8AD8-32F03733FA41}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{4F3425C9-AC6C-422F-A1C8-52F1CAC744EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{98C54B0F-E52C-4FA1-AC3C-294C0B85E3F6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{86DA5EF9-746F-4E3D-A4C5-ACEE97618E3F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{E483A77B-1B5A-4B34-B0C4-2AB02FF30E71}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{2EC1486F-F3F0-495A-B4A3-B4A5F2E4EEBA}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{887AC524-1547-44BA-A943-F933816F9988}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{38C318DD-6B31-444A-B8FD-5CDAC3EDD7F3}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{3A53A3CF-3FF9-4019-82A5-78C75E734391}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{C502CF77-FF89-4CDC-89DE-2E11B5EC7F04}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\theHunter\launcher\launcher.exe FirewallRules: [{394D1207-0B7C-4DAF-9F31-BE73C7A654B8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\theHunter\launcher\launcher.exe FirewallRules: [TCP Query User{2DF3E70B-89C3-4952-A9D2-6082E3534E12}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [UDP Query User{2F922D0B-755B-4E2C-A649-137D296F3175}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [{28920FC6-E9A1-4319-9476-D70CC477DBF9}] => (Allow) C:\Program Files (x86)\Nero\Nero TuneItUp\TuneItUp.exe FirewallRules: [{58B93724-0E2F-4304-9187-E3205B2FFC3C}] => (Allow) C:\Program Files (x86)\Nero\Nero TuneItUp\TuneItUp.exe FirewallRules: [TCP Query User{52F13498-0915-403D-8832-8ED540DE4BC8}C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\java.exe] => (Allow) C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\java.exe FirewallRules: [UDP Query User{E6C3FA2D-E062-4A19-962D-B5151C994A72}C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\java.exe] => (Allow) C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\java.exe FirewallRules: [{F80E090E-39DD-40DA-9DE8-1CA28FBAF4F9}] => (Allow) D:\Programme (x86)\VMware\vmware-authd.exe FirewallRules: [{52626C7A-28B8-4887-8ACB-81FF42C45756}] => (Allow) D:\Programme (x86)\VMware\vmware-authd.exe FirewallRules: [{33880D84-753F-4FFD-8EF3-7D2FC34D28C8}] => (Allow) C:\My Games\Heroes & Generals prototype\prototype\hng.exe FirewallRules: [{19BB5E5D-2993-468D-A762-987BBD795E70}] => (Allow) C:\My Games\Heroes & Generals prototype\prototype\hng.exe FirewallRules: [{AFB074BB-D2BC-4A27-8A60-C34D2BA6847F}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{88165AB9-31EC-49D7-BE9C-5F0307D64AAE}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{FD25D314-F61A-447C-9E27-5E5E841233E3}] => (Allow) C:\My Games\Assassin's Creed III\AC3SP.exe FirewallRules: [{BD23EEC5-3205-4EC4-95B3-30EE306F9C6C}] => (Allow) C:\My Games\Assassin's Creed III\AC3SP.exe FirewallRules: [{577CE623-886A-4D32-86D7-F2C46338F44B}] => (Allow) C:\My Games\Assassin's Creed III\AC3MP.exe FirewallRules: [{4EC04405-1540-4564-B145-43E00999C419}] => (Allow) C:\My Games\Assassin's Creed III\AC3MP.exe FirewallRules: [{BDB7BEA5-6300-4BBD-9975-808F9250634B}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{53A1A8DF-3C71-4167-BFDF-0E9E8CB2B05C}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{32074C2A-AF2C-4A18-8910-E7E4CA6BDA06}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{FCE53F8E-001B-477C-9793-496E65F5A169}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{07943FD8-C6EE-403D-BD76-BAA89DABFD93}C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{37081484-F50C-4D8D-A7AD-9E3618C7BDA7}C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\my games\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [{E4E25B7D-50E0-43FE-BADA-C21165275300}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\Heroes & Generals\hngsteamlauncher.exe FirewallRules: [{B0F3B087-2235-4842-BF90-3C29645A291D}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\Heroes & Generals\hngsteamlauncher.exe FirewallRules: [TCP Query User{1A870202-BA5E-4949-B400-88A466799B86}D:\my games\steam spiele\steamapps\common\newz\thenewz.exe] => (Allow) D:\my games\steam spiele\steamapps\common\newz\thenewz.exe FirewallRules: [UDP Query User{90A7FEF8-4F67-4063-9248-621A429D0501}D:\my games\steam spiele\steamapps\common\newz\thenewz.exe] => (Allow) D:\my games\steam spiele\steamapps\common\newz\thenewz.exe FirewallRules: [{564E6985-FDA7-4CD9-99AE-2AD51C15FF92}] => (Block) D:\my games\steam spiele\steamapps\common\newz\thenewz.exe FirewallRules: [{868A837D-071A-499B-BEB0-EB03C9438610}] => (Block) D:\my games\steam spiele\steamapps\common\newz\thenewz.exe FirewallRules: [{21D063DB-9577-4D02-AB84-A6445023B37A}] => (Allow) D:\My Games\Heroes & Generals prototype\prototype\hng.exe FirewallRules: [{E95993C3-15B3-4766-A63D-2EE2A0230607}] => (Allow) D:\My Games\Heroes & Generals prototype\prototype\hng.exe FirewallRules: [{34F87870-697B-4087-BB47-2F85B31C4DAA}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{CC8A0296-72C0-446B-8529-41BF3616AE2B}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{74E99F3A-5857-4EEF-9717-EBDF677006D6}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\Black Squad\binaries\win32\BlackSquadGame.exe FirewallRules: [{D4D0E25C-0EC6-44FC-8F9F-60E7D50C9728}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\Black Squad\binaries\win32\BlackSquadGame.exe FirewallRules: [TCP Query User{FF726A80-B4B1-4284-BB55-B41A8C70CF58}C:\my games\tdu2\uplauncher.exe] => (Allow) C:\my games\tdu2\uplauncher.exe FirewallRules: [UDP Query User{1967635D-6E93-40E4-BF6C-31068D000259}C:\my games\tdu2\uplauncher.exe] => (Allow) C:\my games\tdu2\uplauncher.exe FirewallRules: [{AB59305F-D384-403D-B3F6-85474524EF5C}] => (Block) C:\my games\tdu2\uplauncher.exe FirewallRules: [{D3DE6EE0-774D-4EFD-B34B-406644D64CB8}] => (Block) C:\my games\tdu2\uplauncher.exe FirewallRules: [{706EF813-1967-4B6C-A59B-4660B5405B13}] => (Allow) C:\My Games\GTA 5\GTA5.exe FirewallRules: [{9C32F89D-25DC-4D7D-99DF-9FA0C5FC89A9}] => (Allow) C:\My Games\GTA 5\GTA5.exe FirewallRules: [{ACFBB995-B36B-4798-8879-1AA459C358B4}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\Arma 3\arma3launcher.exe FirewallRules: [{922145DD-D46D-4B8F-9355-4061DC676EA5}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\Arma 3\arma3launcher.exe FirewallRules: [TCP Query User{A7868B77-71AA-49DE-A458-77BB8DDF18F9}D:\my games\steam spiele\steamapps\common\arma 3\arma3_x64.exe] => (Allow) D:\my games\steam spiele\steamapps\common\arma 3\arma3_x64.exe FirewallRules: [UDP Query User{43890B3D-819B-47A2-9597-43ECE93A17B5}D:\my games\steam spiele\steamapps\common\arma 3\arma3_x64.exe] => (Allow) D:\my games\steam spiele\steamapps\common\arma 3\arma3_x64.exe FirewallRules: [{64C87315-9EA7-4DCB-9804-C958FD84F25F}] => (Block) D:\my games\steam spiele\steamapps\common\arma 3\arma3_x64.exe FirewallRules: [{3F05A6DD-C62C-483E-8210-1A5C1A782CA2}] => (Block) D:\my games\steam spiele\steamapps\common\arma 3\arma3_x64.exe FirewallRules: [TCP Query User{73876A58-82C0-4445-B418-E8DFACB2C35E}C:\my games\gta 5\gta5.exe] => (Allow) C:\my games\gta 5\gta5.exe FirewallRules: [UDP Query User{D32C996E-8B9B-44C8-8D8A-F27BE5A426D6}C:\my games\gta 5\gta5.exe] => (Allow) C:\my games\gta 5\gta5.exe FirewallRules: [{3F7CEA44-A3DB-4988-9CCF-A94E47CEDFB8}] => (Allow) D:\My Games\Landwirtschafts Simulator 2015\FarmingSimulator2015.exe FirewallRules: [{3F81303C-ADB3-4789-B41A-2C5A7A46DF06}] => (Allow) D:\My Games\Landwirtschafts Simulator 2015\FarmingSimulator2015.exe FirewallRules: [{58C8629B-3444-4C10-A494-4E9A3D4D7309}] => (Allow) D:\My Games\Landwirtschafts Simulator 2015\x86\FarmingSimulator2015Game.exe FirewallRules: [{0611390B-844C-4335-BEE2-A3111D6970BB}] => (Allow) D:\My Games\Landwirtschafts Simulator 2015\x86\FarmingSimulator2015Game.exe FirewallRules: [{88CEC3C9-6696-477F-A028-78E8950ABC40}] => (Allow) D:\My Games\Landwirtschafts Simulator 2015\x64\FarmingSimulator2015Game.exe FirewallRules: [{526EF077-37C7-4ECE-9F18-6EE7598FD391}] => (Allow) D:\My Games\Landwirtschafts Simulator 2015\x64\FarmingSimulator2015Game.exe FirewallRules: [{6F9957D7-9FA6-4B0D-8809-8D768A9B6165}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\insurgency2\insurgency_BE.exe FirewallRules: [{0F9FB68A-C48B-4DC4-B60C-93C6D8577FC6}] => (Allow) D:\My Games\Steam Spiele\steamapps\common\insurgency2\insurgency_BE.exe FirewallRules: [TCP Query User{BE2F9C59-CE4A-4791-BB0F-8AD183756694}D:\my games\steam spiele\steamapps\common\insurgency2\insurgency.exe] => (Block) D:\my games\steam spiele\steamapps\common\insurgency2\insurgency.exe FirewallRules: [UDP Query User{B0BC51EB-7D7B-4E7D-B753-9193EC51E353}D:\my games\steam spiele\steamapps\common\insurgency2\insurgency.exe] => (Block) D:\my games\steam spiele\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{7BDA9F72-856F-4375-840B-3F1A393561FE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{79F68DFB-3ED0-4527-913C-2FB061445CD9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{4F95B1DC-7F1C-439E-BDD2-22B924890D11}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Wiederherstellungspunkte ========================= 13-10-2017 15:36:24 Geplanter Prüfpunkt 14-10-2017 20:28:08 Windows Update 14-10-2017 23:15:39 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 14-10-2017 23:15:43 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-10-2017 12:09:40 Norton_Power_Eraser_20171015120939964 ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: VMware Virtual Ethernet Adapter for VMnet1 Description: VMware Virtual Ethernet Adapter for VMnet1 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: VMware, Inc. Service: VMnetAdapter Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: VMware Virtual Ethernet Adapter for VMnet8 Description: VMware Virtual Ethernet Adapter for VMnet8 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: VMware, Inc. Service: VMnetAdapter Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: FRITZ!WLAN USB Stick AC 430 Description: FRITZ!WLAN USB Stick AC 430 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: AVM Berlin Service: fwlanusb6 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (10/16/2017 02:52:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (10/15/2017 06:02:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: MaverickClient.exe, Version: 1.0.0.0, Zeitstempel: 0x59df6194 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.23915, Zeitstempel: 0x59b94f2a Ausnahmecode: 0xe0434352 Fehleroffset: 0x000000000001a06d ID des fehlerhaften Prozesses: 0x1034 Startzeit der fehlerhaften Anwendung: 0x01d345cf0e0a955a Pfad der fehlerhaften Anwendung: C:\Users\lolli\Desktop\wf\MaverickClient.exe Pfad des fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll Berichtskennung: 4cd3044b-b1c2-11e7-9256-783682174516 Error: (10/15/2017 06:02:52 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: MaverickClient.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.Net.Sockets.SocketException bei System.Net.Sockets.Socket.Send(Byte[], Int32, Int32, System.Net.Sockets.SocketFlags) bei System.Net.Sockets.NetworkStream.Write(Byte[], Int32, Int32) Ausnahmeinformationen: System.IO.IOException bei System.Net.Sockets.NetworkStream.Write(Byte[], Int32, Int32) bei AuthLib.Functions.Client.API.SendAPIRequest(System.Net.Sockets.TcpClient, System.String) bei AuthLib.Functions.Client.Client.Version() bei BpJX4:56iF0kcb$jQ\]\,v5X\[O\*..ctor() bei ***************.*******() Ausnahmeinformationen: System.Reflection.TargetInvocationException bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean) bei System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[]) bei System.Reflection.RuntimeMethodInfo.Invoke(System.Object, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo) bei <Module>.****************(System.String[]) Error: (10/15/2017 03:47:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: MaverickClient.exe, Version: 1.0.0.0, Zeitstempel: 0x59df6194 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.23915, Zeitstempel: 0x59b94f2a Ausnahmecode: 0xe0434352 Fehleroffset: 0x000000000001a06d ID des fehlerhaften Prozesses: 0x206c Startzeit der fehlerhaften Anwendung: 0x01d345bc2e8b1570 Pfad der fehlerhaften Anwendung: C:\Users\lolli\Desktop\wf\MaverickClient.exe Pfad des fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll Berichtskennung: 6d433073-b1af-11e7-9256-783682174516 Error: (10/15/2017 03:47:46 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: MaverickClient.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.Net.Sockets.SocketException bei System.Net.Sockets.Socket.Send(Byte[], Int32, Int32, System.Net.Sockets.SocketFlags) bei System.Net.Sockets.NetworkStream.Write(Byte[], Int32, Int32) Ausnahmeinformationen: System.IO.IOException bei System.Net.Sockets.NetworkStream.Write(Byte[], Int32, Int32) bei AuthLib.Functions.Client.API.SendAPIRequest(System.Net.Sockets.TcpClient, System.String) bei AuthLib.Functions.Client.Client.Version() bei BpJX4:56iF0kcb$jQ\]\,v5X\[O\*..ctor() bei ***************.*******() Ausnahmeinformationen: System.Reflection.TargetInvocationException bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean) bei System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[]) bei System.Reflection.RuntimeMethodInfo.Invoke(System.Object, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo) bei <Module>.****************(System.String[]) Error: (10/15/2017 01:16:28 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (10/15/2017 12:11:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (10/15/2017 09:59:17 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (10/15/2017 12:14:03 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm GTA5.exe, Version 1.0.1180.2 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2b30 Startzeit: 01d345397f95ce4e Endzeit: 543 Anwendungspfad: C:\My Games\GTA 5\GTA5.exe Berichts-ID: Error: (10/15/2017 12:07:46 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: WinRAR.exe, Version: 5.40.0.0, Zeitstempel: 0x57b0c341 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.23915, Zeitstempel: 0x59b94ee4 Ausnahmecode: 0xc000000d Fehleroffset: 0x00000000000ca4e5 ID des fehlerhaften Prozesses: 0x13f4 Startzeit der fehlerhaften Anwendung: 0x01d34538cd8ab8cb Pfad der fehlerhaften Anwendung: C:\Program Files\WinRAR\WinRAR.exe Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\ntdll.dll Berichtskennung: 1b658f8b-b12c-11e7-8300-783682174516 Systemfehler: ============= Error: (10/16/2017 03:00:46 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. Error: (10/16/2017 02:59:54 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. Error: (10/16/2017 02:57:34 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. Error: (10/16/2017 02:57:34 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. Error: (10/16/2017 02:57:34 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. Error: (10/16/2017 02:54:25 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (10/16/2017 02:52:39 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (10/16/2017 02:52:39 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht. Error: (10/16/2017 02:52:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "iocbios2" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann den angegebenen Pfad nicht finden. Error: (10/16/2017 02:52:02 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. CodeIntegrity: =================================== Date: 2016-11-27 17:33:05.935 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-11-27 17:33:05.933 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz Prozentuale Nutzung des RAM: 19% Installierter physikalischer RAM: 16245.36 MB Verfügbarer physikalischer RAM: 13127.22 MB Summe virtueller Speicher: 32488.91 MB Verfügbarer virtueller Speicher: 29178.15 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:232.79 GB) (Free:10.32 GB) NTFS Drive d: (Volume) (Fixed) (Total:232.88 GB) (Free:39.68 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 165E5252) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 232.9 GB) (Disk ID: 30CB186F) Partition 1: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
16.10.2017, 20:01 | #5 |
/// TB-Ausbilder | Chrome: standardsuchmaschine cleanserp.net nicht entfernbar Servus, Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop (Bebilderte Anleitung).
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware 3 (Bebilderte Anleitung)
Schritt 3
Bitte poste mit deiner nächsten Antwort
|
18.10.2017, 16:51 | #6 |
| Logs ADwCleaner //hätte gerne schon gestern gemacht aber hatte keine zeit// Soo, hab das Programm ausgeführt wie empfohlen, nachm reboot hat windows nachgefragt wegen firewall zu chrome. habe erstmal chrome gestartet, auf neuer tab, wurde nicht weitergeleitet. Dann in die einstellung geguckt, und konnte die Änderung ganz einfach löschen. Nochmal geguckt und es war alles weg. Log: Code:
ATTFilter # AdwCleaner 7.0.3.1 - Logfile created on Wed Oct 18 15:44:12 2017 # Updated on 2017/29/09 by Malwarebytes # Running on Windows 7 Professional (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** No malicious folders deleted. ***** [ Files ] ***** No malicious files deleted. ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** No malicious registry entries deleted. ***** [ Firefox (and derivatives) ] ***** SearchProvider deleted: nortonsafe.search.ask.com - Norton Safe Search ***** [ Chromium (and derivatives) ] ***** Plugin deleted: Handy Tab - ************************* ::Tracing keys deleted ::Winsock settings cleared ::Image File Execution Options%s keys deleted ::Prefetch files deleted ::Proxy settings cleared ::Firewall rules cleared ::IE policies deleted ::Chrome policies deleted ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[C0].txt - [2561 B] - [2017/10/15 11:15:29] C:/AdwCleaner/AdwCleaner[C1].txt - [1445 B] - [2017/10/18 15:40:14] C:/AdwCleaner/AdwCleaner[S0].txt - [2641 B] - [2017/10/15 11:15:11] C:/AdwCleaner/AdwCleaner[S1].txt - [1479 B] - [2017/10/18 15:39:42] C:/AdwCleaner/AdwCleaner[S2].txt - [1451 B] - [2017/10/18 15:43:52] ########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt ########## Immerhin ist das ja jetzt weg. Gib bescheid dann mach ich auch noch die anderen schritte. |
18.10.2017, 20:27 | #7 | |
/// TB-Ausbilder | Chrome: standardsuchmaschine cleanserp.net nicht entfernbarZitat:
Danke! |
21.10.2017, 13:22 | #8 |
/// TB-Ausbilder | Chrome: standardsuchmaschine cleanserp.net nicht entfernbar Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM inklusive Link zum Thema an mich falls du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Themen zu Chrome: standardsuchmaschine cleanserp.net nicht entfernbar |
adware, ahnung, appdata, browser, cleanserp.net, code, einfach, einstellungen, entfernt, files, gen, google, guten, handy, infos, löschen, namens, nichts, node.js, nvcontainer, plugin, problem, recht, script, security, setup, standard, web, weiterleitung |