|
Plagegeister aller Art und deren Bekämpfung: Amazon ZipWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
05.11.2017, 09:55 | #1 |
| Amazon Zip Hallo und guten Morgen, ich habe gerade im total verschlafenen Zustand meine Mails abgefragt. Hatte von Amazon ne Datei drin wegen einer Bestellung und, so blöd wie ich war, den Anhang angeklickt. Erst kurz drauf habe ich realisiert, dass das ne Zip Datei war. Hab das Fenster das aufging auch gleich geschlossen. Bin mir jetzt aber nicht sicher ob ich mir was eingefangen habe. Ich bin so blöd, hätte nicht gedacht, dass mir das mal passiert. Fazit, nie im verschlafenen Zustand die Mails kontrollieren. Ich hab auch gleich ein FRST durchlaufen lassen. Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2015 01 (ATTENTION: ====> FRST version is 991 days old and could be outdated) Ran by Fam. Ade (administrator) on FAMADE-PC on 05-11-2017 09:44:30 Running from C:\Users\Fam. Ade\Desktop Loaded Profiles: Fam. Ade & Ginua & (Available profiles: Fam. Ade & Ginua & Shari) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-Agent.exe (Nico Mak Computing) C:\Program Files\WinZip\WZUpdateNotifier.exe (WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe (Nico Mak Computing) C:\Program Files\WinZip\FAHWindow64.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\n360.exe (DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Microsoft Corporation) C:\Windows\System32\LogonUI.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_27_0_0_183_ActiveX.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [fssui] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263512 2012-11-30] () HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2015-01-14] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-11-01] (Dropbox, Inc.) HKLM-x32\...\RunOnce: [{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}] => C:\ProgramData\Package Cache\{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}\Avira.OE.Setup.Bundle.exe [1288968 2017-11-01] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759384 2013-06-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3011152 2015-11-10] (Valve Corporation) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [1690248 2016-12-01] (BlueStack Systems, Inc.) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759384 2013-06-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3011152 2015-11-10] (Valve Corporation) HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [1690248 2016-12-01] (BlueStack Systems, Inc.) HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation) HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\Policies\system: [LogonHoursAction] 2 HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-356143711-355811113-2582273239-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation) HKU\S-1-5-21-356143711-355811113-2582273239-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-356143711-355811113-2582273239-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\SCANNERMAP\...\Run: [Google Update] => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-05-08] (Google Inc.) HKU\SCANNERMAP\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation) HKU\SCANNERMAP\...\Policies\system: [LogonHoursAction] 2 HKU\SCANNERMAP\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Benachrichtigungsdienst.lnk ShortcutTarget: Update Benachrichtigungsdienst.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\buShell.dll (Symantec Corporation) GroupPolicyUsers\S-1-5-21-356143711-355811113-2582273239-1008\User: Group Policy restriction detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-356143711-355811113-2582273239-1007\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-356143711-355811113-2582273239-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-356143711-355811113-2582273239-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\SCANNERMAP\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/ SearchScopes: HKLM-x32 -> DefaultScope value is missing. SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> DefaultScope {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms} BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\coIEPlg.dll (Symantec Corporation) BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\IPS\IPSBHO.DLL No File BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll No File Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\coIEPlg.dll (Symantec Corporation) Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\coIEPlg.dll (Symantec Corporation) DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=1.6.0_35 -> C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: @soft-xpansion/npsxpdf -> C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Fam. Ade\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Fam. Ade\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin HKU\SCANNERMAP: @tools.google.com/Google Update;version=3 -> C:\Users\Shari\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\SCANNERMAP: @tools.google.com/Google Update;version=9 -> C:\Users\Shari\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Extension: Search Shield Study - C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default\Extensions\@unified-urlbar-shield-study-opt-out-new-users.xpi [2017-10-11] FF Extension: Safe Browsing Version 4 (temporary add-on) - C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-11] FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon FF Extension: Norton Security Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon [2017-10-11] FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-02-14] FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon FF HKLM-x32\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb StartMenuInternet: Firefox-308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe Chrome: ======= CHR Profile: C:\Users\Fam. Ade\AppData\Local\Google\Chrome\User Data\default CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\Exts\Chrome.crx [Not Found] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\Exts\Chrome.crx [Not Found] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-02-07] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) [File not signed] S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1128432 2017-10-14] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [490968 2017-10-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [490968 2017-10-14] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1525240 2017-10-14] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [407408 2017-10-26] (Avira Operations GmbH & Co. KG) S3 becldr3Service; C:\Program Files (x86)\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [176128 2011-04-19] () [File not signed] S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [486936 2016-12-01] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [470552 2016-12-01] (BlueStack Systems, Inc.) S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [511512 2016-12-01] (BlueStack Systems, Inc.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51016 2017-11-01] (Dropbox, Inc.) R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1386496 2016-08-22] (Microsoft Corporation) S2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [437224 2016-10-27] (Digital Wave Ltd.) R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes) R2 N360; C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\N360.exe [326144 2017-10-04] (Symantec Corporation) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [180824 2013-06-17] (Sandboxie Holdings, LLC) R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.) S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-09-18] (soft Xpansion) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2012-10-01] () R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [64504 2017-06-17] (Avira Operations GmbH & Co. KG) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [194272 2017-09-24] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [151128 2017-09-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-03-02] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [78600 2017-03-02] (Avira Operations GmbH & Co. KG) R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\BASHDefs\20171101.001\BHDrvx64.sys [1872024 2017-10-11] (Symantec Corporation) S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-12-01] (BlueStack Systems) S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-11-08] (Bluestack System Inc. ) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\160B000.029\ccSetx64.sys [187520 2017-10-04] (Symantec Corporation) S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [508056 2017-10-18] (Symantec Corporation) U3 EraserUtilDrv11721; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11721.sys [158360 2017-10-18] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [158336 2017-06-28] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\IPSDefs\20171103.001\IDSvia64.sys [1056920 2017-10-14] (Symantec Corporation) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2012-10-01] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-11-05] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [198360 2013-06-17] (Sandboxie Holdings, LLC) R1 SRTSP; C:\Windows\System32\Drivers\N360x64\160B000.029\SRTSP64.SYS [812704 2017-10-04] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\160B000.029\SRTSPX64.SYS [49304 2017-10-04] (Symantec Corporation) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.) R0 SymEFASI; C:\Windows\System32\drivers\N360x64\160B000.029\SYMEFASI64.SYS [1868416 2017-10-04] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [102568 2017-07-27] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\160B000.029\Ironx64.SYS [301288 2017-10-04] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\160B000.029\SYMNETS.SYS [566912 2017-10-04] (Symantec Corporation) S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [151184 2016-03-10] (MBB) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S3 NAVENG; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\SDSDefs\20160713.008\ENG64.SYS [X] S3 NAVEX15; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\SDSDefs\20160713.008\EX64.SYS [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2017-11-05 09:44 - 2017-11-05 09:45 - 00033073 _____ () C:\Users\Fam. Ade\Desktop\FRST.txt 2017-11-04 14:13 - 2017-11-04 14:13 - 00000000 ____D () C:\Windows\System32\Tasks\Remediation 2017-11-02 18:56 - 2017-11-02 18:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-11-01 12:58 - 2017-11-01 12:58 - 00051016 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-11-01 12:58 - 2017-11-01 12:58 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-11-01 12:58 - 2017-11-01 12:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-11-01 12:58 - 2017-11-01 12:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-10-25 11:42 - 2017-10-25 11:42 - 05250048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2017-10-12 12:17 - 2017-10-13 06:30 - 00000000 ____D () C:\Users\TEMP.FamAde-PC.001 2017-10-12 03:05 - 2017-10-12 03:05 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360 2017-10-12 02:59 - 2017-10-12 02:59 - 00003208 _____ () C:\Windows\System32\Tasks\Norton WSC Integration 2017-10-12 02:16 - 2017-10-12 02:16 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2017-10-11 11:46 - 2017-09-13 16:33 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-10-11 11:46 - 2017-09-13 16:32 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-10-11 11:46 - 2017-09-13 16:32 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-10-11 11:46 - 2017-09-13 16:32 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-10-11 11:46 - 2017-09-13 16:32 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-10-11 11:46 - 2017-09-13 16:31 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:13 - 04001512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-10-11 11:46 - 2017-09-13 16:13 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-10-11 11:46 - 2017-09-13 16:10 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:05 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2017-10-11 11:46 - 2017-09-13 16:00 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-10-11 11:46 - 2017-09-13 16:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-10-11 11:46 - 2017-09-13 16:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-10-11 11:46 - 2017-09-13 16:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-10-11 11:46 - 2017-09-13 15:57 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-10-11 11:46 - 2017-09-13 15:56 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-10-11 11:46 - 2017-09-13 15:53 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-10-11 11:46 - 2017-09-13 15:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-10-11 11:46 - 2017-09-13 15:53 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-10-11 11:46 - 2017-09-13 15:52 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-10-11 11:46 - 2017-09-13 15:52 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-10-11 11:46 - 2017-09-13 15:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-10-11 11:46 - 2017-09-13 15:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-10-11 11:46 - 2017-09-13 15:46 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-10-11 11:46 - 2017-09-13 15:46 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-10-11 11:46 - 2017-09-09 01:45 - 00395984 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-10-11 11:46 - 2017-09-09 00:47 - 00347344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-10-11 11:46 - 2017-09-08 16:34 - 01680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-10-11 11:46 - 2017-09-08 16:30 - 02319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 02058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-10-11 11:46 - 2017-09-08 16:14 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-10-11 11:46 - 2017-09-08 16:13 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-10-11 11:46 - 2017-09-08 16:13 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-10-11 11:46 - 2017-09-08 16:10 - 01549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-10-11 11:46 - 2017-09-08 16:10 - 01363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll 2017-10-11 11:46 - 2017-09-08 16:10 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-10-11 11:46 - 2017-09-08 16:10 - 00109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2017-10-11 11:46 - 2017-09-08 16:00 - 03222016 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-10-11 11:46 - 2017-09-08 16:00 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2017-10-11 11:46 - 2017-09-08 16:00 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2017-10-11 11:46 - 2017-09-08 15:59 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2017-10-11 11:46 - 2017-09-08 15:59 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2017-10-11 11:46 - 2017-09-08 15:20 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll 2017-10-11 11:46 - 2017-09-08 15:20 - 00345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll 2017-10-11 11:46 - 2017-09-08 15:20 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll 2017-10-11 11:46 - 2017-09-07 22:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-10-11 11:46 - 2017-09-07 22:37 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-10-11 11:46 - 2017-09-07 22:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-10-11 11:46 - 2017-09-07 22:18 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-10-11 11:46 - 2017-09-07 22:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-10-11 11:46 - 2017-09-07 22:17 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-10-11 11:46 - 2017-09-07 22:17 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-10-11 11:46 - 2017-09-07 22:15 - 02902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-10-11 11:46 - 2017-09-07 22:08 - 25729536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-10-11 11:46 - 2017-09-07 22:08 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-10-11 11:46 - 2017-09-07 22:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-10-11 11:46 - 2017-09-07 22:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-10-11 11:46 - 2017-09-07 22:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-10-11 11:46 - 2017-09-07 22:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-10-11 11:46 - 2017-09-07 22:01 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-10-11 11:46 - 2017-09-07 22:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-10-11 11:46 - 2017-09-07 21:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-10-11 11:46 - 2017-09-07 21:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-10-11 11:46 - 2017-09-07 21:40 - 05982208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-10-11 11:46 - 2017-09-07 21:39 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-10-11 11:46 - 2017-09-07 21:38 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-10-11 11:46 - 2017-09-07 21:37 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-10-11 11:46 - 2017-09-07 21:33 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-10-11 11:46 - 2017-09-07 21:32 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-10-11 11:46 - 2017-09-07 21:29 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-10-11 11:46 - 2017-09-07 21:27 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-10-11 11:46 - 2017-09-07 21:13 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-10-11 11:46 - 2017-09-07 21:10 - 00807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-10-11 11:46 - 2017-09-07 21:10 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-10-11 11:46 - 2017-09-07 21:08 - 02134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-10-11 11:46 - 2017-09-07 21:08 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-10-11 11:46 - 2017-09-07 20:44 - 15262720 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-10-11 11:46 - 2017-09-07 20:40 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-10-11 11:46 - 2017-09-07 20:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-10-11 11:46 - 2017-09-07 20:27 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-10-11 11:46 - 2017-09-07 20:17 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-10-11 11:46 - 2017-09-07 20:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-10-11 11:46 - 2017-09-07 20:10 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-10-11 11:46 - 2017-09-07 20:10 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-10-11 11:46 - 2017-09-07 20:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-10-11 11:46 - 2017-09-07 20:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-10-11 11:46 - 2017-09-07 20:04 - 20267008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-10-11 11:46 - 2017-09-07 20:03 - 02292736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-10-11 11:46 - 2017-09-07 20:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-10-11 11:46 - 2017-09-07 20:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-10-11 11:46 - 2017-09-07 19:59 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-10-11 11:46 - 2017-09-07 19:58 - 00663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-10-11 11:46 - 2017-09-07 19:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-10-11 11:46 - 2017-09-07 19:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-10-11 11:46 - 2017-09-07 19:49 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-10-11 11:46 - 2017-09-07 19:44 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2017-10-11 11:46 - 2017-09-07 19:44 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-10-11 11:46 - 2017-09-07 19:43 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-10-11 11:46 - 2017-09-07 19:40 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-10-11 11:46 - 2017-09-07 19:39 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-10-11 11:46 - 2017-09-07 19:37 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-10-11 11:46 - 2017-09-07 19:36 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-10-11 11:46 - 2017-09-07 19:29 - 04547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-10-11 11:46 - 2017-09-07 19:29 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-10-11 11:46 - 2017-09-07 19:26 - 00694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-10-11 11:46 - 2017-09-07 19:25 - 02058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-10-11 11:46 - 2017-09-07 19:25 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-10-11 11:46 - 2017-09-07 19:17 - 13677568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-10-11 11:46 - 2017-09-07 19:01 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-10-11 11:46 - 2017-09-07 18:57 - 01316864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-10-11 11:46 - 2017-09-07 18:57 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-10-11 11:46 - 2017-09-07 16:31 - 02851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2017-10-11 11:46 - 2017-09-07 16:12 - 02755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll 2017-10-11 11:46 - 2017-09-07 15:55 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-10-11 11:46 - 2017-09-07 15:55 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-10-11 11:46 - 2017-09-07 15:55 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-10-11 11:46 - 2017-08-19 16:28 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2017-10-11 11:46 - 2017-08-19 16:28 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2017-10-11 11:46 - 2017-08-19 16:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2017-10-11 11:46 - 2017-08-19 16:10 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2017-10-11 11:46 - 2017-08-19 16:10 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2017-10-11 11:46 - 2017-08-19 16:10 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2017-10-11 11:46 - 2017-08-19 16:08 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2017-10-11 11:46 - 2017-08-19 16:08 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2017-10-11 11:46 - 2017-08-19 15:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2017-10-11 11:46 - 2017-08-19 15:57 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2017-10-11 11:46 - 2017-08-14 18:35 - 01032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2017-10-11 11:46 - 2017-08-14 18:35 - 00827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2017-10-11 11:46 - 2017-08-14 18:35 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2017-10-11 11:46 - 2017-08-13 22:45 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2017-10-11 07:41 - 2017-10-11 07:46 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Local\Mozilla 2017-10-11 07:40 - 2017-11-02 08:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2017-10-11 07:40 - 2017-11-02 08:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2017-10-11 07:40 - 2017-10-11 07:40 - 00000936 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-10-11 07:40 - 2017-10-11 07:40 - 00000924 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2017-10-11 07:37 - 2017-10-11 07:37 - 00245912 _____ (Mozilla) C:\Users\Fam. Ade\Downloads\Firefox Installer.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2017-11-05 09:44 - 2014-04-30 11:01 - 00000000 ____D () C:\FRST 2017-11-05 09:28 - 2017-09-24 11:26 - 00003316 _____ () C:\Windows\System32\Tasks\Avira_Antivirus_Systray 2017-11-05 09:25 - 2014-05-04 19:58 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-11-05 09:22 - 2015-06-02 12:53 - 00001218 _____ () C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-11-05 09:13 - 2012-09-24 16:26 - 01489376 _____ () C:\Windows\WindowsUpdate.log 2017-11-05 09:08 - 2014-05-21 19:03 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA.job 2017-11-05 04:22 - 2015-06-02 12:53 - 00001214 _____ () C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-11-05 04:18 - 2009-07-14 05:45 - 00023344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-11-05 04:18 - 2009-07-14 05:45 - 00023344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-11-04 23:18 - 2016-12-13 08:43 - 00000000 ____D () C:\Program Files (x86)\Bluestacks 2017-11-04 20:08 - 2014-05-21 19:03 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core.job 2017-11-04 12:23 - 2014-10-12 20:18 - 00000000 ____D () C:\Users\Fam. Ade\Documents\Tennis Damen 2017-11-02 18:56 - 2015-06-02 12:53 - 00000000 ____D () C:\Program Files (x86)\Dropbox 2017-11-01 11:34 - 2017-09-24 11:26 - 00003122 _____ () C:\Windows\System32\Tasks\Avira SystrayStartTrigger 2017-11-01 11:34 - 2013-03-06 13:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2017-11-01 11:33 - 2015-01-21 19:58 - 00000000 ____D () C:\ProgramData\Package Cache 2017-10-30 11:38 - 2015-04-26 14:09 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Local\CrashDumps 2017-10-25 11:43 - 2013-03-06 13:08 - 00004366 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-10-25 11:43 - 2012-09-24 16:42 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-10-25 11:43 - 2012-09-24 16:42 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-10-25 11:43 - 2012-09-24 16:42 - 00000000 ____D () C:\Windows\system32\Macromed 2017-10-25 11:42 - 2012-09-24 16:42 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2017-10-13 06:35 - 2014-05-23 19:19 - 00000000 ____D () C:\Program Files (x86)\Steam 2017-10-13 06:32 - 2013-04-13 14:13 - 00001618 _____ () C:\Windows\Sandboxie.ini 2017-10-13 06:32 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2017-10-13 06:32 - 2009-07-14 05:51 - 00081321 _____ () C:\Windows\setupact.log 2017-10-13 06:31 - 2012-09-24 17:15 - 01196614 _____ () C:\Windows\PFRO.log 2017-10-12 05:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2017-10-12 04:17 - 2015-06-11 02:52 - 00000000 ____D () C:\Program Files\Common Files\AV 2017-10-12 03:05 - 2009-07-14 18:58 - 00703308 _____ () C:\Windows\system32\perfh007.dat 2017-10-12 03:05 - 2009-07-14 18:58 - 00151134 _____ () C:\Windows\system32\perfc007.dat 2017-10-12 03:05 - 2009-07-14 06:13 - 01629508 _____ () C:\Windows\system32\PerfStringBackup.INI 2017-10-12 02:59 - 2015-03-03 14:28 - 00000000 ____D () C:\Windows\system32\Drivers\N360x64 2017-10-12 02:58 - 2016-07-14 02:49 - 00002224 _____ () C:\Users\Public\Desktop\Norton 360.lnk 2017-10-12 02:58 - 2015-08-13 03:06 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 2017-10-12 02:57 - 2009-07-14 05:45 - 00530920 _____ () C:\Windows\system32\FNTCACHE.DAT 2017-10-12 02:32 - 2013-07-25 02:04 - 00000000 ____D () C:\Windows\system32\MRT 2017-10-12 02:16 - 2013-04-06 13:50 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-10-12 02:12 - 2013-09-18 11:19 - 01604370 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2017-10-12 02:04 - 2012-09-25 13:28 - 00000000 ____D () C:\ProgramData\Microsoft Help 2017-10-11 07:41 - 2014-01-08 12:21 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Roaming\Mozilla 2017-10-11 07:08 - 2013-01-21 10:05 - 00000000 ____D () C:\Users\Fam. Ade\Documents\Fußpflege 2017-10-06 19:11 - 2017-09-11 12:28 - 00015194 _____ () C:\Users\Fam. Ade\Documents\Wintertraining17-18.xlsx ==================== Files in the root of some directories ======= 2013-01-03 14:56 - 2013-01-03 17:16 - 0000029 _____ () C:\Users\Fam. Ade\AppData\Roaming\default.rss 2013-01-03 17:15 - 2013-01-03 17:15 - 0000000 _____ () C:\Users\Fam. Ade\AppData\Roaming\downloads.m3u 2013-09-23 19:56 - 2013-09-23 19:56 - 0000059 _____ () C:\Users\Fam. Ade\AppData\Roaming\WB.CFG 2013-09-23 19:56 - 2013-09-23 19:56 - 0000005 _____ () C:\Users\Fam. Ade\AppData\Roaming\WBPU-TTL.DAT 2016-12-13 08:51 - 2017-03-22 12:36 - 0000552 _____ () C:\Users\Fam. Ade\AppData\Local\TroubleshooterConfig.json 2014-07-03 14:24 - 2014-07-03 14:24 - 0000057 _____ () C:\ProgramData\Ament.ini ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-10-30 00:14 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2015 01 Ran by Fam. Ade at 2017-11-05 09:46:18 Running from C:\Users\Fam. Ade\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F} AV: Norton 360 Online (Enabled - Up to date) {30744133-1E94-7B35-F4A3-82A5AEF1CBAA} AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton 360 Online (Enabled - Up to date) {8B15A0D7-38AE-74BB-CE13-B9D7D5768117} FW: Norton 360 Online (Enabled) {084FC016-54FB-7A6D-DFFC-2B9050228CD1} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated) Adobe Digital Editions 2.0 (HKLM-x32\...\Adobe Digital Editions 2.0) (Version: 2.0 - Adobe Systems Incorporated) Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.183 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{53A19094-2C04-A9B9-7309-3E92152D4845}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.) Any Video Converter 3.5.8 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com) Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG) Avira (HKLM-x32\...\{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}) (Version: 1.2.98.37213 - Avira Operations GmbH & Co. KG) Avira (HKLM-x32\...\{f5da837f-e932-4f55-995c-7e97c5cbebdd}) (Version: 1.2.98.29730 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.2.98.37213 - Avira Operations GmbH & Co. KG) Hidden Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.32.12 - Avira Operations GmbH & Co. KG) BCL easyConverter 3.0 Licensing Module (BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 Loader SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 Module (Loader, BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 Module (RTF, BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 RTF SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden Benutzerhandbuch ESDX5000_CX4900 (HKLM-x32\...\Benutzerhandbuch ESDX5000_CX4900) (Version: - ) BlueStacks App Player (HKLM-x32\...\BlueStacks) (Version: 2.5.78.7302 - BlueStack Systems, Inc.) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6521 - CDBurnerXP) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DC Universe Online (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\SOE-DC Universe Online) (Version: 1.0.3.183 - Sony Online Entertainment) DC Universe Online (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SOE-DC Universe Online) (Version: 1.0.3.183 - Sony Online Entertainment) DC Universe Online Live (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\SOE-DC Universe Online Live PSG) (Version: - Sony Online Entertainment) DC Universe Online Live (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SOE-DC Universe Online Live PSG) (Version: - Sony Online Entertainment) DC Universe Online PSG (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\soe-DC Universe Online PSG) (Version: 1.0.3.183 - Sony Online Entertainment) DC Universe Online PSG (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\soe-DC Universe Online PSG) (Version: 1.0.3.183 - Sony Online Entertainment) DEUTSCHLAND SPIELT GAME CENTER (HKLM-x32\...\DSGPlayer) (Version: 1.0.0.46 - INTENIUM GmbH) Die Siedler 7 (HKLM-x32\...\{63860309-DA8A-4BAE-9EAE-CE1D6D79340C}) (Version: 1.12.1396 - Ubisoft) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.22 - DivX, LLC) DMG Extractor (HKLM-x32\...\DMGExtractor) (Version: 1.1.1.1 - Reincubate Ltd) doPDF 7.3 printer (HKLM\...\doPDF 7 printer_is1) (Version: - Softland) Dropbox (HKLM-x32\...\Dropbox) (Version: 38.4.27 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - ) EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - ) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{6C5F8503-55D2-4398-858C-362B7A7AF51C}) (Version: 2.1.31.0 - MAGIX AG) Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Free Easy Burner V 5.1 (HKLM-x32\...\Free Easy Burner_is1) (Version: 5.1.0.0 - Koyote soft) Free MP4 Video Converter (HKLM-x32\...\Free MP4 Video Converter_is1) (Version: 5.0.102.1027 - Digital Wave Ltd) Freemium Free PDF Perfect (HKLM-x32\...\{88265079-D6F4-4292-86BE-D2053E80BFE4}) (Version: 1.0 - Freemium) GameMaker-Studio 1.2 (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\GameMaker-Studio12) (Version: - YoYo Games Ltd.) GameMaker-Studio 1.2 (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\GameMaker-Studio12) (Version: - YoYo Games Ltd.) Goat Simulator (HKLM-x32\...\Steam App 265930) (Version: - Coffee Stain Studios) Google Chrome (HKU\SCANNERMAP\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden Green City: Die Stadt deiner Träume (HKLM-x32\...\Green City: Die Stadt deiner Träume) (Version: 1.0.0.0 - INTENIUM GmbH) HP Officejet 6700 Basic Device Software (HKLM\...\{A1CFA587-90D4-4DE6-B200-68CC0F92252F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HPDiagnosticCoreDll (HKLM-x32\...\{9262B08F-E183-4FED-A2BD-23FF1A84EB79}) (Version: 1.0.15.0 - Hewlett Packard) Image Converter (HKLM-x32\...\Image Converter Image Converter) (Version: 1.0.0 - Image Converter) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden James Cameron's AVATAR(tm): DAS SPIEL (HKLM-x32\...\{7E19B002-4CA3-4C9F-BA92-91D101B97219}) (Version: 1.02.00 - Ubisoft) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Lawn & Order: Die Gartenprofis (HKLM-x32\...\Lawn & Order: Die Gartenprofis) (Version: 1.0.0.0 - INTENIUM GmbH) Magic Life (HKLM-x32\...\Magic Life) (Version: 1.0.0.0 - INTENIUM GmbH) MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{5900B465-32E8-48DA-AC09-21B8363F7A41}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video deluxe 2013 (HKLM-x32\...\MAGIX_{8C73E551-5AFA-42EE-B76E-64821590BCD3}) (Version: 12.0.0.32 - MAGIX AG) MAGIX Video deluxe 2013 (Version: 12.0.0.32 - MAGIX AG) Hidden Malkreuz (x32 Version: 1.00.0000 - Medienwerkstatt Mühlacker Verlagsgesellschaft mbH) Hidden Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Mein CEWE FOTOBUCH (HKLM-x32\...\Mein CEWE FOTOBUCH) (Version: 5.1.6 - CEWE Stiftung u Co. KGaA) Microsoft .NET Framework 4.7 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.7.02053 - Microsoft Corporation) Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Moai: Erschaffe deinen Traum (HKLM-x32\...\Moai: Erschaffe deinen Traum) (Version: 1.0.0.0 - INTENIUM GmbH) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Firefox 56.0.2 (x64 de) (HKLM\...\Mozilla Firefox 56.0.2 (x64 de)) (Version: 56.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Nero 12 (HKLM-x32\...\{95E152CF-0EB5-4BFA-B6EE-8FC7F9601BA5}) (Version: 12.0.02900 - Nero AG) Norton 360 Online (HKLM-x32\...\N360) (Version: 22.11.0.41 - Symantec Corporation) PDF2Word Converter Version 1.0.8 (Build 164, 7-PDF) (HKLM-x32\...\PDF2Word Converter (7-PDF)_is1) (Version: PDF2Word Converter - Version 1.0.8 (Build 164) - 7-PDF, Germany - Thorsten Hodes) PIF DESIGNER (HKLM-x32\...\{B90450DF-E781-46FD-B1F1-0C86DA40E443}) (Version: - ) Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - ) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15013.18 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.3.15013.18 - Samsung Electronics Co., Ltd.) Hidden Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.) Sandboxie 4.02 (64-bit) (HKLM\...\Sandboxie) (Version: 4.02 - Sandboxie Holdings, LLC) Search-Results Toolbar (HKLM-x32\...\koyotesofttoolbarnew) (Version: 1.0.0.12 - APN LLC) <==== ATTENTION Stadt der Narren (HKLM-x32\...\Stadt der Narren) (Version: 1.0.0.0 - INTENIUM GmbH) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Taxpool-Buchhalter Mini 6.24 (HKLM-x32\...\Taxpool-Buchhalter Mini) (Version: 6.24 - psynetic® Software) TomTom MyDrive Connect 4.1.4.3089 (HKLM-x32\...\MyDriveConnect) (Version: 4.1.4.3089 - TomTom) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) VLC media player 2.0.5 (HKLM-x32\...\VLC media player) (Version: 2.0.5 - VideoLAN) Vokabeltrainer für Windows Version 1.51 (HKLM-x32\...\Vokabeltrainer für Windows_is1) (Version: - diginvent) Welcome App (Start-up experience) (x32 Version: 12.0.15000 - Nero AG) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) WinZip 20.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EF}) (Version: 20.0.11659 - WinZip Computing, S.L. ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 19-10-2017 08:15:47 Geplanter Prüfpunkt 26-10-2017 23:00:01 Geplanter Prüfpunkt 03-11-2017 00:00:03 Geplanter Prüfpunkt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2014-05-02 10:11 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0A4539CC-5316-4A61-A8D8-4293850F15AB} - \ProtectedSearch\Protected Search No Task File <==== ATTENTION Task: {38B020D1-357C-46F5-BE86-B4F07C855C6A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-25] (Adobe Systems Incorporated) Task: {3DD9AF00-814A-442E-BFB1-DC652AFA045E} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton 360 Online\Upgrade.exe [2017-10-04] (Symantec Corporation) Task: {4F387278-2353-45BD-9D8A-4FF1C5E179E9} - System32\Tasks\HP AR Program Upload - 2def856e98fd42c0af2ab35d45102a3a0e33f155164447319ccbababe29426c0 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: {5549F126-D485-4FEC-9719-9A267731B31F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-08] (Google Inc.) Task: {707B181D-A35C-47F7-A039-9AE8C7AE9045} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-08] (Google Inc.) Task: {718F6CAB-BBCC-4B69-83C6-7C640482C103} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => C:\Windows\system32\compattelrunner.exe [2017-05-03] (Microsoft Corporation) Task: {76C4BED5-8938-498E-8B9C-DF91AC9CC146} - System32\Tasks\Norton 360\Norton 360 Online Error Processor => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\SymErr.exe [2017-10-04] (Symantec Corporation) Task: {78298D72-8D94-4D21-8547-B8E7F33AE507} - \Browser Updater\Browser Updater No Task File <==== ATTENTION Task: {81F538A1-8928-4F07-AADA-B1F413A22C5B} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {829625F8-5F95-4644-AF85-07F67B1BA23B} - System32\Tasks\{616C99AF-BEAA-4FB4-B382-A2B20D86BF98} => pcalua.exe -a "C:\Users\Fam. Ade\Downloads\epson30027eu.exe" -d "C:\Users\Fam. Ade\Desktop" Task: {86915168-38FE-4D52-8A11-943B62A978C1} - System32\Tasks\HP AR Program Upload - 6b89bd66a6e048649e04dc31f8a1706355a107ddc5e946ea96303cd76419b11a => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: {A8F4716A-C403-4172-8143-1C37E871A9A1} - System32\Tasks\HP AR Program Upload - b5c01ba5ad9742f4a0f74f1e55da5e26a18df2df1c71450ba082ef8703b8a046 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: {AC41F180-9E7F-4FF9-A73E-8679FD382213} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\WSCStub.exe [2017-10-04] (Symantec Corporation) Task: {ACB42A5E-DD1D-4A78-A33D-B8D97BF29E44} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated) Task: {B04ADAFE-C2D3-4B5E-92E6-282F4E5D2466} - System32\Tasks\Avira SystrayStartTrigger => Avira.SystrayStartTrigger.exe Task: {CD4E143F-DF5F-425A-AD44-2B5FB4A8B8F7} - System32\Tasks\HP AR Program Upload - e330d555d2874ebabc0a30c862a2da613d4700ba94ea4d58b3ea0a32d8279410 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: {DA6FBD2A-306D-4AFB-B613-EC241A16AAC3} - System32\Tasks\HP AR Program Upload - 1d8f182b717540109e3b0ba996d8e3a5ddca8dc77dbe40168d810be1d221880c => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: {DB4BFC02-368F-42E8-A891-583B1A4B7666} - System32\Tasks\Norton 360\Norton 360 Online Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\SymErr.exe [2017-10-04] (Symantec Corporation) Task: {E74A986E-6F94-49FE-A756-29239914FF0B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {E788F862-969C-49EA-8C62-4A862DF892BF} - System32\Tasks\{96513A81-C24F-4D2B-B615-9465B77B3F3E} => pcalua.exe -a "C:\Program Files (x86)\Common Files\Freemium\Uninstall\{88265079-D6F4-4292-86BE-D2053E80BFE4}.exe" -c /X{88265079-D6F4-4292-86BE-D2053E80BFE4} Task: {EC16D64F-AB1A-4596-9D67-D3175F7EF657} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-11-16] (Microsoft Corporation) Task: {ED78580D-DCE2-4EE7-8B0C-05F674DE4621} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {F08F917F-B88F-40C8-B27B-0AA46D8F0B91} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {FA8C6F5A-DDF6-4572-9A22-F2B113B8607A} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2017-10-14] (Avira Operations GmbH & Co. KG) Task: {FB495BFB-94A9-45B1-B537-46D21553FE01} - System32\Tasks\{F05BE82B-0D12-4C43-9B39-6F8C0F9D86D0} => pcalua.exe -a "C:\Users\Fam. Ade\Desktop\Setup.exe" -d "C:\Users\Fam. Ade\Desktop" Task: {FB98B0F5-C9FE-4ACA-8476-9DFC13597F8C} - System32\Tasks\{1409713F-E48C-431F-96D2-68F676C4E085} => pcalua.exe -a "C:\Users\Fam. Ade\Downloads\mmskasse.exe" -d "C:\Users\Fam. Ade\Downloads" Task: {FFE725A4-F749-49E7-AFF3-25B7A3B47FC2} - System32\Tasks\HP AR Program Upload - 7dca521ae57b484ea823d2e9c7cbe31f29d3c42b6c9e458097c61fd4bf5ad836 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core.job => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA.job => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2013-09-18 11:23 - 2010-06-17 19:56 - 00087040 _____ () C:\Windows\System32\redmonnt.dll 2012-11-30 03:06 - 2012-11-30 03:06 - 01263512 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2012-12-19 15:32 - 2012-12-19 15:32 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2012-11-30 03:07 - 2012-11-30 03:07 - 00100248 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2009-02-26 12:46 - 2009-02-26 12:46 - 00064344 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll 2011-06-22 10:46 - 2011-06-22 10:46 - 00434016 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll 2015-11-11 03:41 - 2015-11-11 03:41 - 00756376 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SecureAssist => ""="service" ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-356143711-355811113-2582273239-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Fam. Ade\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Fam. Ade\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\s-1-5-21-356143711-355811113-2582273239-1007\Control Panel\Desktop\\Wallpaper -> C:\Users\Ginua\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-356143711-355811113-2582273239-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Ginua\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\SCANNERMAP\Control Panel\Desktop\\Wallpaper -> C:\Users\Shari\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-356143711-355811113-2582273239-500 - Administrator - Disabled) Fam. Ade (S-1-5-21-356143711-355811113-2582273239-1001 - Administrator - Enabled) => C:\Users\Fam. Ade Gast (S-1-5-21-356143711-355811113-2582273239-501 - Limited - Disabled) Ginua (S-1-5-21-356143711-355811113-2582273239-1007 - Limited - Enabled) => C:\Users\Ginua HomeGroupUser$ (S-1-5-21-356143711-355811113-2582273239-1002 - Limited - Enabled) Shari (S-1-5-21-356143711-355811113-2582273239-1008 - Limited - Enabled) => C:\Users\Shari ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/05/2017 09:42:35 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (11/05/2017 04:10:06 AM) (Source: SideBySide) (EventID: 9) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Das Stammelement der Manifestdatei muss assembliert sein. Error: (11/05/2017 04:09:57 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (11/05/2017 04:09:47 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1". Die abhängige Assemblierung "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (11/04/2017 04:28:58 AM) (Source: SideBySide) (EventID: 9) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Das Stammelement der Manifestdatei muss assembliert sein. Error: (11/04/2017 04:28:49 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (11/04/2017 04:28:38 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1". Die abhängige Assemblierung "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (11/03/2017 04:32:21 AM) (Source: SideBySide) (EventID: 9) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Das Stammelement der Manifestdatei muss assembliert sein. Error: (11/03/2017 04:32:12 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (11/03/2017 04:32:02 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1". Die abhängige Assemblierung "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". System errors: ============= Error: (10/29/2017 09:44:21 AM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung empfangen: 20. Error: (10/13/2017 06:34:30 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (10/13/2017 06:33:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Live Family Safety Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/13/2017 06:33:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Live Family Safety Service erreicht. Error: (10/13/2017 06:33:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Digital Wave Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/13/2017 06:33:02 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Digital Wave Update Service erreicht. Error: (10/12/2017 00:17:05 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1096) (User: FamAde-PC) Description: Fehler bei der Verarbeitung der Gruppenrichtlinie. Es wurde versucht, registrierungsbasierte Richtlinieneinstellungen für das Gruppenrichtlinienobjekt "LocalGPO" zu lesen. Die Gruppenrichtlinieneinstellungen dürfen nicht erzwungen werden, bis dieses Ereignis behoben ist. Weitere Informationen über den Dateinamen und -pfad, der den Fehler verursacht hat, können den Ereignisdetails entnommen werden. Error: (10/12/2017 02:59:17 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (10/12/2017 02:50:25 AM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (10/06/2017 07:27:20 AM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung empfangen: 20. Microsoft Office Sessions: ========================= Error: (10/30/2017 11:40:40 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6776.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 91167 seconds with 60 seconds of active time. This session ended with a crash. Error: (09/21/2017 07:28:21 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6776.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 65740 seconds with 480 seconds of active time. This session ended with a crash. Error: (08/14/2017 02:35:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6774.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 113 seconds with 60 seconds of active time. This session ended with a crash. Error: (02/25/2017 01:38:24 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6762.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 350330 seconds with 600 seconds of active time. This session ended with a crash. Error: (01/05/2017 00:14:09 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6762.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 173666 seconds with 1740 seconds of active time. This session ended with a crash. Error: (12/13/2016 00:16:07 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6759.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2708 seconds with 540 seconds of active time. This session ended with a crash. Error: (11/04/2016 01:28:16 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6755.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1512 seconds with 0 seconds of active time. This session ended with a crash. Error: (10/04/2016 05:51:15 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6755.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 41009 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/30/2016 10:38:24 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6755.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 73493 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/10/2016 02:42:57 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6750.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 273 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-05-02 11:10:37.809 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-05-02 11:10:37.310 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: AMD Athlon(tm) II X4 620 Processor Percentage of memory in use: 63% Total physical RAM: 4094.16 MB Available physical RAM: 1487.49 MB Total Pagefile: 8186.51 MB Available Pagefile: 4522.39 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:288.71 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: EF017F90) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ==================== End Of Log ============================ LG Ani |
05.11.2017, 11:51 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Amazon Zip Bitte Avira deinstallieren. Wir deinstallieren dann am besten auch gleich weiteren unnötigen oder veralteten Krempel.
__________________Avira empfehlen wir schon seit Jahren aus mehreren Gründen nicht mehr. Ein Grund ist ne rel. hohe Fehlalarmquote, der zweite Hauptgrund ist, dass die immer noch mit ASK zusammenarbeiten (Avira Suchfunktion geht über ASK). Auch andere Freewareanbieter wie AVG, Avast oder Panda sprangen auf diesen Zug auf; so was ist bei Sicherheitssoftware einfach inakzeptabel. Vgl. Antivirensoftware: Schutz Für Ihre Dateien, Aber Auf Kosten Ihrer Privatsphäre? | Emsisoft Blog Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Gib Bescheid wenn Avira weg ist; wenn wir hier durch sind, kannst du auf einen anderen Virenscanner umsteigen, Infos folgen dann im Abschlussposting. Bitte JETZT nix mehr ohne Absprache installieren!
__________________ |
05.11.2017, 13:42 | #3 |
| Amazon Zip so hab jetzt alle Programme mit Revo gelöscht. Hoffe auch alles richtig gemacht zu haben.
__________________Avira ist auch weg. Den Norton den ich drauf hatte, ist von der Telekom. Grüße Ani |
05.11.2017, 13:58 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Amazon Zip Ich brauche neue FRST-Logs . Haken setzen bei addition.txt dann auf Untersuchen klicken.
__________________ Logfiles bitte immer in CODE-Tags posten |
05.11.2017, 18:30 | #5 |
| Amazon Zip Hier die neuen FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2015 01 (ATTENTION: ====> FRST version is 991 days old and could be outdated) Ran by Fam. Ade (administrator) on FAMADE-PC on 05-11-2017 17:15:19 Running from C:\Users\Fam. Ade\Desktop Loaded Profiles: Fam. Ade & Ginua (Available profiles: Fam. Ade & Ginua & Shari) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-Agent.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Microsoft Corporation) C:\Windows\System32\LogonUI.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_27_0_0_183_ActiveX.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [fssui] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263512 2012-11-30] () HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2015-01-14] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-11-01] (Dropbox, Inc.) HKLM-x32\...\RunOnce: [{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}] => C:\ProgramData\Package Cache\{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}\Avira.OE.Setup.Bundle.exe [1288968 2017-11-01] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759384 2013-06-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3011152 2015-11-10] (Valve Corporation) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [1690248 2016-12-01] (BlueStack Systems, Inc.) HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\RunOnce: [JavaInstallRetry] => RUNONCE=1 SPONSORS=0 HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759384 2013-06-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3011152 2015-11-10] (Valve Corporation) HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [1690248 2016-12-01] (BlueStack Systems, Inc.) HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation) HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\Policies\system: [LogonHoursAction] 2 HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\SCANNERMAP\...\Run: [Google Update] => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-05-08] (Google Inc.) HKU\SCANNERMAP\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation) HKU\SCANNERMAP\...\Policies\system: [LogonHoursAction] 2 HKU\SCANNERMAP\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.) GroupPolicyUsers\S-1-5-21-356143711-355811113-2582273239-1008\User: Group Policy restriction detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-356143711-355811113-2582273239-1007\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-356143711-355811113-2582273239-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-356143711-355811113-2582273239-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\SCANNERMAP\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/ SearchScopes: HKLM-x32 -> DefaultScope value is missing. SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> DefaultScope {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms} BHO: No Name -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> No File BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: No Name -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> No File BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll No File Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=1.6.0_35 -> C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll No File FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @soft-xpansion/npsxpdf -> C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Fam. Ade\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Fam. Ade\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin HKU\SCANNERMAP: @tools.google.com/Google Update;version=3 -> C:\Users\Shari\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\SCANNERMAP: @tools.google.com/Google Update;version=9 -> C:\Users\Shari\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Extension: Search Shield Study - C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default\Extensions\@unified-urlbar-shield-study-opt-out-new-users.xpi [2017-10-11] FF Extension: Safe Browsing Version 4 (temporary add-on) - C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-11] FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-02-14] FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF HKLM-x32\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb StartMenuInternet: Firefox-308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe Chrome: ======= CHR Profile: C:\Users\Fam. Ade\AppData\Local\Google\Chrome\User Data\default CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-02-07] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) [File not signed] S3 becldr3Service; C:\Program Files (x86)\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [176128 2011-04-19] () [File not signed] S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [486936 2016-12-01] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [470552 2016-12-01] (BlueStack Systems, Inc.) S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [511512 2016-12-01] (BlueStack Systems, Inc.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51016 2017-11-01] (Dropbox, Inc.) R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1386496 2016-08-22] (Microsoft Corporation) S2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [437224 2016-10-27] (Digital Wave Ltd.) R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [180824 2013-06-17] (Sandboxie Holdings, LLC) R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.) S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-09-18] (soft Xpansion) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 Avira.ServiceHost; "C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2012-10-01] () R4 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-03-02] (Avira Operations GmbH & Co. KG) S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-12-01] (BlueStack Systems) S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-11-08] (Bluestack System Inc. ) S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2012-10-01] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-11-05] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [198360 2013-06-17] (Sandboxie Holdings, LLC) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.) S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [151184 2016-03-10] (MBB) S3 catchme; \??\C:\ComboFix\catchme.sys [X] R4 ccSet_N360; \SystemRoot\system32\drivers\N360x64\160B000.029\ccSetx64.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] R4 IDSVia64; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\IPSDefs\20171103.001\IDSvia64.sys [X] S3 NAVENG; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\SDSDefs\20160713.008\ENG64.SYS [X] S3 NAVEX15; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\SDSDefs\20160713.008\EX64.SYS [X] R4 SRTSPX; \SystemRoot\system32\drivers\N360x64\160B000.029\SRTSPX64.SYS [X] R4 SymEFASI; system32\drivers\N360x64\160B000.029\SYMEFASI64.SYS [X] R4 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2017-11-05 12:50 - 2017-11-05 12:50 - 00001034 _____ () C:\Users\Public\Desktop\Revo Uninstaller.lnk 2017-11-05 12:50 - 2017-11-05 12:50 - 00000000 ____D () C:\Program Files\VS Revo Group 2017-11-05 09:46 - 2017-11-05 09:48 - 00041679 _____ () C:\Users\Fam. Ade\Desktop\Addition.txt 2017-11-05 09:44 - 2017-11-05 17:15 - 00025572 _____ () C:\Users\Fam. Ade\Desktop\FRST.txt 2017-11-04 14:13 - 2017-11-05 13:30 - 00000000 ____D () C:\Windows\System32\Tasks\Remediation 2017-11-02 18:56 - 2017-11-02 18:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-11-01 12:58 - 2017-11-01 12:58 - 00051016 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-11-01 12:58 - 2017-11-01 12:58 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-11-01 12:58 - 2017-11-01 12:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-11-01 12:58 - 2017-11-01 12:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-10-25 11:42 - 2017-10-25 11:42 - 05250048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2017-10-12 12:17 - 2017-10-13 06:30 - 00000000 ____D () C:\Users\TEMP.FamAde-PC.001 2017-10-12 02:16 - 2017-10-12 02:16 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2017-10-11 11:46 - 2017-09-13 16:33 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-10-11 11:46 - 2017-09-13 16:32 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-10-11 11:46 - 2017-09-13 16:32 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-10-11 11:46 - 2017-09-13 16:32 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-10-11 11:46 - 2017-09-13 16:32 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-10-11 11:46 - 2017-09-13 16:31 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-10-11 11:46 - 2017-09-13 16:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:13 - 04001512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-10-11 11:46 - 2017-09-13 16:13 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-10-11 11:46 - 2017-09-13 16:10 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-10-11 11:46 - 2017-09-13 16:09 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 16:05 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2017-10-11 11:46 - 2017-09-13 16:00 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-10-11 11:46 - 2017-09-13 16:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-10-11 11:46 - 2017-09-13 16:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-10-11 11:46 - 2017-09-13 16:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-10-11 11:46 - 2017-09-13 15:57 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-10-11 11:46 - 2017-09-13 15:56 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-10-11 11:46 - 2017-09-13 15:53 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-10-11 11:46 - 2017-09-13 15:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-10-11 11:46 - 2017-09-13 15:53 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-10-11 11:46 - 2017-09-13 15:52 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-10-11 11:46 - 2017-09-13 15:52 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-10-11 11:46 - 2017-09-13 15:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-10-11 11:46 - 2017-09-13 15:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-10-11 11:46 - 2017-09-13 15:46 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-10-11 11:46 - 2017-09-13 15:46 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-10-11 11:46 - 2017-09-13 15:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-10-11 11:46 - 2017-09-09 01:45 - 00395984 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-10-11 11:46 - 2017-09-09 00:47 - 00347344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-10-11 11:46 - 2017-09-08 16:34 - 01680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-10-11 11:46 - 2017-09-08 16:30 - 02319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 02058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-10-11 11:46 - 2017-09-08 16:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-10-11 11:46 - 2017-09-08 16:14 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-10-11 11:46 - 2017-09-08 16:13 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-10-11 11:46 - 2017-09-08 16:13 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-10-11 11:46 - 2017-09-08 16:10 - 01549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-10-11 11:46 - 2017-09-08 16:10 - 01363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll 2017-10-11 11:46 - 2017-09-08 16:10 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-10-11 11:46 - 2017-09-08 16:10 - 00109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2017-10-11 11:46 - 2017-09-08 16:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2017-10-11 11:46 - 2017-09-08 16:00 - 03222016 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-10-11 11:46 - 2017-09-08 16:00 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2017-10-11 11:46 - 2017-09-08 16:00 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2017-10-11 11:46 - 2017-09-08 15:59 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2017-10-11 11:46 - 2017-09-08 15:59 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2017-10-11 11:46 - 2017-09-08 15:20 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll 2017-10-11 11:46 - 2017-09-08 15:20 - 00345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll 2017-10-11 11:46 - 2017-09-08 15:20 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll 2017-10-11 11:46 - 2017-09-07 22:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-10-11 11:46 - 2017-09-07 22:37 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-10-11 11:46 - 2017-09-07 22:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-10-11 11:46 - 2017-09-07 22:18 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-10-11 11:46 - 2017-09-07 22:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-10-11 11:46 - 2017-09-07 22:17 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-10-11 11:46 - 2017-09-07 22:17 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-10-11 11:46 - 2017-09-07 22:15 - 02902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-10-11 11:46 - 2017-09-07 22:08 - 25729536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-10-11 11:46 - 2017-09-07 22:08 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-10-11 11:46 - 2017-09-07 22:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-10-11 11:46 - 2017-09-07 22:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-10-11 11:46 - 2017-09-07 22:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-10-11 11:46 - 2017-09-07 22:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-10-11 11:46 - 2017-09-07 22:01 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-10-11 11:46 - 2017-09-07 22:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-10-11 11:46 - 2017-09-07 21:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-10-11 11:46 - 2017-09-07 21:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-10-11 11:46 - 2017-09-07 21:40 - 05982208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-10-11 11:46 - 2017-09-07 21:39 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-10-11 11:46 - 2017-09-07 21:38 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-10-11 11:46 - 2017-09-07 21:37 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-10-11 11:46 - 2017-09-07 21:33 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-10-11 11:46 - 2017-09-07 21:32 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-10-11 11:46 - 2017-09-07 21:29 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-10-11 11:46 - 2017-09-07 21:27 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-10-11 11:46 - 2017-09-07 21:13 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-10-11 11:46 - 2017-09-07 21:10 - 00807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-10-11 11:46 - 2017-09-07 21:10 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-10-11 11:46 - 2017-09-07 21:08 - 02134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-10-11 11:46 - 2017-09-07 21:08 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-10-11 11:46 - 2017-09-07 20:44 - 15262720 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-10-11 11:46 - 2017-09-07 20:40 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-10-11 11:46 - 2017-09-07 20:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-10-11 11:46 - 2017-09-07 20:27 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-10-11 11:46 - 2017-09-07 20:17 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-10-11 11:46 - 2017-09-07 20:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-10-11 11:46 - 2017-09-07 20:10 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-10-11 11:46 - 2017-09-07 20:10 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-10-11 11:46 - 2017-09-07 20:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-10-11 11:46 - 2017-09-07 20:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-10-11 11:46 - 2017-09-07 20:04 - 20267008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-10-11 11:46 - 2017-09-07 20:03 - 02292736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-10-11 11:46 - 2017-09-07 20:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-10-11 11:46 - 2017-09-07 20:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-10-11 11:46 - 2017-09-07 19:59 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-10-11 11:46 - 2017-09-07 19:58 - 00663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-10-11 11:46 - 2017-09-07 19:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-10-11 11:46 - 2017-09-07 19:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-10-11 11:46 - 2017-09-07 19:49 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-10-11 11:46 - 2017-09-07 19:44 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2017-10-11 11:46 - 2017-09-07 19:44 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-10-11 11:46 - 2017-09-07 19:43 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-10-11 11:46 - 2017-09-07 19:40 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-10-11 11:46 - 2017-09-07 19:39 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-10-11 11:46 - 2017-09-07 19:37 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-10-11 11:46 - 2017-09-07 19:36 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-10-11 11:46 - 2017-09-07 19:29 - 04547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-10-11 11:46 - 2017-09-07 19:29 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-10-11 11:46 - 2017-09-07 19:26 - 00694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-10-11 11:46 - 2017-09-07 19:25 - 02058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-10-11 11:46 - 2017-09-07 19:25 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-10-11 11:46 - 2017-09-07 19:17 - 13677568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-10-11 11:46 - 2017-09-07 19:01 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-10-11 11:46 - 2017-09-07 18:57 - 01316864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-10-11 11:46 - 2017-09-07 18:57 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-10-11 11:46 - 2017-09-07 16:31 - 02851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2017-10-11 11:46 - 2017-09-07 16:12 - 02755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll 2017-10-11 11:46 - 2017-09-07 15:55 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-10-11 11:46 - 2017-09-07 15:55 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-10-11 11:46 - 2017-09-07 15:55 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-10-11 11:46 - 2017-08-19 16:28 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2017-10-11 11:46 - 2017-08-19 16:28 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2017-10-11 11:46 - 2017-08-19 16:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2017-10-11 11:46 - 2017-08-19 16:10 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2017-10-11 11:46 - 2017-08-19 16:10 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2017-10-11 11:46 - 2017-08-19 16:10 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2017-10-11 11:46 - 2017-08-19 16:08 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2017-10-11 11:46 - 2017-08-19 16:08 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2017-10-11 11:46 - 2017-08-19 15:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2017-10-11 11:46 - 2017-08-19 15:57 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2017-10-11 11:46 - 2017-08-14 18:35 - 01032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2017-10-11 11:46 - 2017-08-14 18:35 - 00827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2017-10-11 11:46 - 2017-08-14 18:35 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2017-10-11 11:46 - 2017-08-13 22:45 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2017-10-11 07:41 - 2017-10-11 07:46 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Local\Mozilla 2017-10-11 07:40 - 2017-11-02 08:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2017-10-11 07:40 - 2017-11-02 08:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2017-10-11 07:40 - 2017-10-11 07:40 - 00000936 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-10-11 07:40 - 2017-10-11 07:40 - 00000924 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2017-10-11 07:37 - 2017-10-11 07:37 - 00245912 _____ (Mozilla) C:\Users\Fam. Ade\Downloads\Firefox Installer.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2017-11-05 17:15 - 2014-04-30 11:01 - 00000000 ____D () C:\FRST 2017-11-05 17:08 - 2014-05-21 19:03 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA.job 2017-11-05 16:22 - 2015-06-02 12:53 - 00001218 _____ () C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-11-05 13:38 - 2014-05-23 19:19 - 00000000 ____D () C:\Program Files (x86)\Steam 2017-11-05 13:31 - 2015-03-03 14:28 - 00000000 ____D () C:\ProgramData\Norton 2017-11-05 13:30 - 2015-03-03 14:28 - 00000000 ____D () C:\Program Files (x86)\Norton 360 2017-11-05 13:13 - 2014-03-22 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-11-05 13:08 - 2013-02-14 21:13 - 00000000 ____D () C:\ProgramData\DivX 2017-11-05 13:07 - 2013-03-06 13:07 - 00000000 ____D () C:\Program Files (x86)\Avira 2017-11-05 12:58 - 2013-06-06 13:06 - 00000000 ____D () C:\Users\Fam. Ade\Documents\My Digital Editions 2017-11-05 09:25 - 2014-05-04 19:58 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-11-05 09:13 - 2012-09-24 16:26 - 01489376 _____ () C:\Windows\WindowsUpdate.log 2017-11-05 04:22 - 2015-06-02 12:53 - 00001214 _____ () C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-11-05 04:18 - 2009-07-14 05:45 - 00023344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-11-05 04:18 - 2009-07-14 05:45 - 00023344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-11-04 23:18 - 2016-12-13 08:43 - 00000000 ____D () C:\Program Files (x86)\Bluestacks 2017-11-04 20:08 - 2014-05-21 19:03 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core.job 2017-11-04 12:23 - 2014-10-12 20:18 - 00000000 ____D () C:\Users\Fam. Ade\Documents\Tennis Damen 2017-11-02 18:56 - 2015-06-02 12:53 - 00000000 ____D () C:\Program Files (x86)\Dropbox 2017-11-01 11:34 - 2017-09-24 11:26 - 00003122 _____ () C:\Windows\System32\Tasks\Avira SystrayStartTrigger 2017-11-01 11:33 - 2015-01-21 19:58 - 00000000 ____D () C:\ProgramData\Package Cache 2017-10-30 11:38 - 2015-04-26 14:09 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Local\CrashDumps 2017-10-25 11:43 - 2013-03-06 13:08 - 00004366 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-10-25 11:43 - 2012-09-24 16:42 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-10-25 11:43 - 2012-09-24 16:42 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-10-25 11:43 - 2012-09-24 16:42 - 00000000 ____D () C:\Windows\system32\Macromed 2017-10-25 11:42 - 2012-09-24 16:42 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2017-10-13 06:32 - 2013-04-13 14:13 - 00001618 _____ () C:\Windows\Sandboxie.ini 2017-10-13 06:32 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2017-10-13 06:32 - 2009-07-14 05:51 - 00081321 _____ () C:\Windows\setupact.log 2017-10-13 06:31 - 2012-09-24 17:15 - 01196614 _____ () C:\Windows\PFRO.log 2017-10-12 05:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2017-10-12 04:17 - 2015-06-11 02:52 - 00000000 ____D () C:\Program Files\Common Files\AV 2017-10-12 03:05 - 2009-07-14 18:58 - 00703308 _____ () C:\Windows\system32\perfh007.dat 2017-10-12 03:05 - 2009-07-14 18:58 - 00151134 _____ () C:\Windows\system32\perfc007.dat 2017-10-12 03:05 - 2009-07-14 06:13 - 01629508 _____ () C:\Windows\system32\PerfStringBackup.INI 2017-10-12 02:59 - 2015-03-03 14:28 - 00000000 ____D () C:\Windows\system32\Drivers\N360x64 2017-10-12 02:57 - 2009-07-14 05:45 - 00530920 _____ () C:\Windows\system32\FNTCACHE.DAT 2017-10-12 02:32 - 2013-07-25 02:04 - 00000000 ____D () C:\Windows\system32\MRT 2017-10-12 02:16 - 2013-04-06 13:50 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-10-12 02:12 - 2013-09-18 11:19 - 01604370 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2017-10-12 02:04 - 2012-09-25 13:28 - 00000000 ____D () C:\ProgramData\Microsoft Help 2017-10-11 07:41 - 2014-01-08 12:21 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Roaming\Mozilla 2017-10-11 07:08 - 2013-01-21 10:05 - 00000000 ____D () C:\Users\Fam. Ade\Documents\Fußpflege 2017-10-06 19:11 - 2017-09-11 12:28 - 00015194 _____ () C:\Users\Fam. Ade\Documents\Wintertraining17-18.xlsx ==================== Files in the root of some directories ======= 2013-01-03 14:56 - 2013-01-03 17:16 - 0000029 _____ () C:\Users\Fam. Ade\AppData\Roaming\default.rss 2013-01-03 17:15 - 2013-01-03 17:15 - 0000000 _____ () C:\Users\Fam. Ade\AppData\Roaming\downloads.m3u 2013-09-23 19:56 - 2013-09-23 19:56 - 0000059 _____ () C:\Users\Fam. Ade\AppData\Roaming\WB.CFG 2013-09-23 19:56 - 2013-09-23 19:56 - 0000005 _____ () C:\Users\Fam. Ade\AppData\Roaming\WBPU-TTL.DAT 2016-12-13 08:51 - 2017-03-22 12:36 - 0000552 _____ () C:\Users\Fam. Ade\AppData\Local\TroubleshooterConfig.json 2014-07-03 14:24 - 2014-07-03 14:24 - 0000057 _____ () C:\ProgramData\Ament.ini Some content of TEMP: ==================== C:\Users\Fam. Ade\AppData\Local\Temp\SEVINST64x86.EXE C:\Users\Fam. Ade\AppData\Local\Temp\VSUSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-10-30 00:14 ==================== End Of Log ============================ Code:
ATTFilter Additional FRST Logfile: Grüße Ani |
05.11.2017, 18:45 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Amazon Zip gut gut Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ --> Amazon Zip |
06.11.2017, 17:49 | #7 |
| Amazon Zip Hallo Cosinus, also es gab keine Funde. Ich finde auch keine Datei als Logfile. Ich weiß nicht mehr wo ich noch suchen soll. Grüße Ani lies mir jetzt doch keine Ruhe, diese Log Datei zu finden. Und siehe da über Malware habe ich dann noch den Pfad gefunden wo ich die Datei finden kann. Code:
ATTFilter <?xml version="1.0" encoding="UTF-16"?> -<mbam-log> -<header> <date>2017/11/06 14:07:13 +0100</date> <logfile>mbam-log-2017-11-06 (14-07-03).xml</logfile> <isadmin>yes</isadmin> </header> -<engine> <version>2.2.0.1024</version> <malware-database>v2017.11.06.06</malware-database> <rootkit-database>v2017.10.14.01</rootkit-database> <license>free</license> <file-protection>disabled</file-protection> <web-protection>disabled</web-protection> <self-protection>disabled</self-protection> </engine> -<system> <hostname>FAMADE-PC</hostname> <ip>192.168.2.111</ip> <osversion>Windows 7 Service Pack 1</osversion> <arch>x64</arch> <username>Fam. Ade</username> <filesys>NTFS</filesys> </system> -<summary> <type>threat</type> <result>completed</result> <objects>409550</objects> <time>2652</time> <processes>0</processes> <modules>0</modules> <keys>0</keys> <values>0</values> <datas>0</datas> <folders>0</folders> <files>0</files> <sectors>0</sectors> </summary> -<options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>enabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> </items> </mbam-log> Ani |
07.11.2017, 09:24 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Amazon Zip Ist das denn so schwierig die paar Zeilen Anleitung mal richtig zu lesen?? Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.
__________________ Logfiles bitte immer in CODE-Tags posten |
07.11.2017, 16:26 | #9 |
| Amazon Zip Hallo Cosinus, nein es ist nicht schwierig zu lesen, aber etwas zu finden, was nicht da ist..... Ich habe das schon gepostete Logfile unter: ProgramData/Malwarebytes..../logs/protection gefunden. Nur da finde ich Dateien. Diese heißen allerdings: mbam-log-2017-11-06 (14-07-03) Code:
ATTFilter <?xml version="1.0" encoding="UTF-16"?> -<mbam-log> -<header> <date>2017/11/06 14:07:13 +0100</date> <logfile>mbam-log-2017-11-06 (14-07-03).xml</logfile> <isadmin>yes</isadmin> </header> -<engine> <version>2.2.0.1024</version> <malware-database>v2017.11.06.06</malware-database> <rootkit-database>v2017.10.14.01</rootkit-database> <license>free</license> <file-protection>disabled</file-protection> <web-protection>disabled</web-protection> <self-protection>disabled</self-protection> </engine> -<system> <hostname>FAMADE-PC</hostname> <ip>192.168.2.111</ip> <osversion>Windows 7 Service Pack 1</osversion> <arch>x64</arch> <username>Fam. Ade</username> <filesys>NTFS</filesys> </system> -<summary> <type>threat</type> <result>completed</result> <objects>409550</objects> <time>2652</time> <processes>0</processes> <modules>0</modules> <keys>0</keys> <values>0</values> <datas>0</datas> <folders>0</folders> <files>0</files> <sectors>0</sectors> </summary> -<options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>enabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> </items> </mbam-log> und protection-log-2017-11-06 Code:
ATTFilter <?xml version="1.0" encoding="UTF-8"?> -<logs> <record toVersion="2017.11.6.1" name="IP Database" last_modified_tag="58860638-df58-41a5-823a-241b21a1b1f3" fromVersion="2017.11.3.2" systemname="FAMADE-PC" username="SYSTEM" type="Update" source="Manual" datetime="2017-11-06T12:26:10.934810+01:00" LoggingEventType="1" severity="debug"/> <record toVersion="2017.11.6.5" name="Malware Database" last_modified_tag="982e017f-7413-47b5-aff0-efe7c16b2215" fromVersion="2017.11.5.2" systemname="FAMADE-PC" username="SYSTEM" type="Update" source="Manual" datetime="2017-11-06T12:26:15.068817+01:00" LoggingEventType="1" severity="debug"/> <record toVersion="2017.11.6.1" name="Domain Database" last_modified_tag="a3f190e3-2c93-4dab-827a-e33682cd0f5d" fromVersion="2017.11.3.8" systemname="FAMADE-PC" username="SYSTEM" type="Update" source="Manual" datetime="2017-11-06T12:26:15.427618+01:00" LoggingEventType="1" severity="debug"/> <record last_modified_tag="bcb56403-d990-48f2-9dac-66fc9939ee5a" systemname="FAMADE-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2017-11-06T12:26:52.689428+01:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="1" malwaredetections="0" duration="3721" starttime="2017-11-05T09:25:01+01:00" scantype="threat"/> <record last_modified_tag="bcd93e0a-c445-42f3-a8b8-8a1dfb79ab21" systemname="FAMADE-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2017-11-06T13:12:42.397022+01:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="0" malwaredetections="0" duration="2745" starttime="2017-11-06T12:26:57+01:00" scantype="threat"/> <record last_modified_tag="355175b1-4d1f-425a-9714-e53375c7bd5c" systemname="FAMADE-PC" username="SYSTEM" type="Error" source="Protection" datetime="2017-11-06T13:58:37.404704+01:00" LoggingEventType="4" severity="debug" message="IsLicensed" code="13"/> <record last_modified_tag="614a8b04-4426-4776-a205-1fe10cd07eb1" systemname="FAMADE-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-11-06T13:58:37.435905+01:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopping"/> <record last_modified_tag="e2ce1be1-c4f3-42bd-beee-a483df8051a1" systemname="FAMADE-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-11-06T13:58:37.435905+01:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopped"/> <record toVersion="2017.11.6.6" name="Malware Database" last_modified_tag="ce087538-d41e-47e2-8117-df935e2d04b3" fromVersion="2017.11.6.5" systemname="FAMADE-PC" username="SYSTEM" type="Update" source="Manual" datetime="2017-11-06T14:07:12.510043+01:00" LoggingEventType="1" severity="debug"/> <record last_modified_tag="7e042852-9354-4e35-81ab-4cb94631bc43" systemname="FAMADE-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2017-11-06T14:51:26.480271+01:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="0" malwaredetections="0" duration="2652" starttime="2017-11-06T14:07:13+01:00" scantype="threat"/> </logs> Grüße Ani |
07.11.2017, 16:32 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Amazon Zip
__________________ Logfiles bitte immer in CODE-Tags posten |
07.11.2017, 17:24 | #11 |
| Amazon Zip Hallo Cosinus, ich habe nun das Malware B. das ich drauf hatte runtergeschmissen mit Revo und nochmal neu installiert. Dann, tatsächlich, erstellte es mir das Logfile das du benötigst. Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.10.3.1001 www.malwarebytes.org Database version: main: v2017.11.07.06 rootkit: v2017.10.14.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.18816 Fam. Ade :: FAMADE-PC [administrator] 07.11.2017 16:33:05 mbar-log-2017-11-07 (16-33-05).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 409887 Time elapsed: 37 minute(s), 28 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Grüße Ani |
07.11.2017, 22:07 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Amazon Zip Schön, aber was vorher gefunden wurde weiß nun niemand mehr
__________________ Logfiles bitte immer in CODE-Tags posten |
07.11.2017, 22:16 | #13 |
| Amazon Zip oh jeh, da hab ich jetzt aber echt Scheisse gebaut allerdings hat er bei dem Durchlauf gestern auch nichts gefunden |
07.11.2017, 22:33 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Amazon Zip schwein gehabt Adware/Junkware/Toolbars entfernen Alte Versionen von adwCleaner vorher löschen, danach neu runterladen auf den Desktop! Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren! adwCleaner v7.x Downloade Dir bitte AdwCleaner auf Deinen Desktop (Bebilderte Anleitung).
__________________ Logfiles bitte immer in CODE-Tags posten |
08.11.2017, 08:05 | #15 |
| Amazon Zip anbei das Logfile vom Adware Cleaner Code:
ATTFilter # AdwCleaner 7.0.4.0 - Logfile created on Wed Nov 08 06:51:01 2017 # Updated on 2017/27/10 by Malwarebytes # Running on Windows 7 Home Premium (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\Windows\System32\config\systemprofile\AppData\LocalLow\AVG Secure Search Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AVG Secure Search ***** [ Files ] ***** No malicious files deleted. ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted: Browser Updater\Browser Updater Deleted: Browser Updater ***** [ Registry ] ***** Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d10lpsik1i8c69.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d16fk4ms6rqz1v.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d1733r3id7jrw5.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d22j4fzzszoii2.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ism.de Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\wtb-tennis.de Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.ism.de Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.wtb-tennis.de Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{97AE1DAA-7852-42DD-BA5E-1B553C951158} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{F362D347-1A0E-47C6-9636-763D41D00053} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{AB34B361-22F6-44F2-863D-DF296443DFD8} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{62460538-69BC-44FB-B14A-6AE9B1B5B5F6} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{17F8F466-53C4-42D2-B894-68B3EE270E23} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{3F3AA3CF-3A04-4447-AF4D-A2BDCDA48E20} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{79F04CF4-4BDB-47CE-AC81-A984C113C365} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{6E8C525B-5752-4A4C-9A22-7F5D692B6F01} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{5230E5A4-CE74-4FAB-A3F4-01170669CEFC} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{21931936-6C91-43DA-9181-07F863DF15A1} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3038A20B9089EC34D8F74220191FAB30 Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION|BackgroundHost64.exe Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD|BackgroundHost64.exe Deleted: [Key] - HKLM\SOFTWARE\Classes\MIME\Database\Content Type\application\x-vnd.bdliveupdate.oneclickctrl.9 Deleted: [Key] - HKLM\SOFTWARE\Classes\MIME\Database\Content Type\application\x-vnd.bdliveupdate.update3webcontrol.3 Deleted: [Value] - HKLM\SOFTWARE\Classes\.torrent|iLivid.torrent_backup Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\game-maker.de.softonic.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\kabu-kassenbuch.de.softonic.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{078FA2D5-DE68-416E-BA7F-894A4A4EAB6C} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{0AD8FD27-9029-43A1-B9D5-C54FF18C3DD7} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{1D7BEA54-B699-4A4D-83D7-D10875B8D7FD} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{45C2D25B-0816-419A-B74B-CD4D7024FB71} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{3C8BE759-0A8F-4C0D-8CAD-0E5898EAE6AF} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{4E695B8D-101C-4F95-B5C7-A7D9D2E975EF} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{2203FA35-9590-4CBA-8AFF-CC53930B7F5C} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{9566B021-2079-4C32-8F1F-A26911954C8B} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{FFC65EC8-C373-4E11-9882-905817219E16} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{6BD95127-7C32-4C10-ACF0-1C4687629C85} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{75CF0360-C187-4E6E-AB01-6FA65F3DA6CB} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{C8B204C2-D508-4B71-9CC5-AED5E1302A86} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{C3FD9F92-09FA-493C-8C1F-2A3D7DD55DDD} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{F340A9AB-C377-4855-A106-0DAC2893A1A8} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{558F32DF-FA22-4656-B0D2-64DD9EB41F8F} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{54AFDC23-353C-4789-84F5-9C955AD44AC5} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{BBA36C2E-EC79-494A-988D-19398D9222A2} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{39FB51B1-8784-4BD5-A411-F1B7A5DB4D67} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{EC5A8488-566B-442C-9E5E-259031985B7A} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{41AC4A66-D0C5-4646-BFAE-1041584C43DE} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{74009D24-8B75-4783-9E69-4566B239FB30} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{349385B4-83FC-4BE1-9DBF-DC0195C65DB4} Deleted: [Key] - HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\UniblueDriverScanner Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{E9EFC215-5D07-4CC7-80FB-BC1EF2BF58D0} Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{41435ED1-CD00-4950-905D-61BDDA585000} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{9D076A92-97E7-4946-8FE3-AE0DA86075C8} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{0C11527F-0008-4F12-9C1A-20B89DBCD8B1} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{E9386C9C-C4C5-4DE0-9836-0539D72EF6A7} Deleted: [Value] - HKCU\Software\Classes\.torrent|iLivid.torrent_backup Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{E05B5B97-4986-4DA4-B9F4-AAE4E7E9D57F} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{FCDC5AB0-703B-4565-9AD4-3CF7C9FE54B9} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{5230E5A4-CE74-4FAB-A3F4-01170669CEFC} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{21931936-6C91-43DA-9181-07F863DF15A1} Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing|bProtectShowTabsWelcome Deleted: [Key] - HKLM\SOFTWARE\Classes\Applications\iLividSetup-r343-n-bi.exe ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Prefetch files deleted ::Proxy settings cleared ::IE policies deleted ::Chrome policies deleted ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[C4].txt - [36378 B] - [2016/1/14 8:1:11] C:/AdwCleaner/AdwCleaner[S0].txt - [1577 B] - [2014/1/8 11:34:35] C:/AdwCleaner/AdwCleaner[S1].txt - [15576 B] - [2014/4/27 9:28:41] C:/AdwCleaner/AdwCleaner[S2].txt - [1435 B] - [2014/5/4 20:10:11] C:/AdwCleaner/AdwCleaner[S4].txt - [10075 B] - [2017/11/8 5:16:30] C:/AdwCleaner/AdwCleaner[S5].txt - [10143 B] - [2017/11/8 6:46:14] C:/AdwCleaner/AdwCleaner[S6].txt - [34815 B] - [2016/1/14 7:55:47] ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt ########## |
Themen zu Amazon Zip |
adware, antivir, antivirus, avdevprot, avdevprot.sys, avira, browser, combofix, einstellungen, excel, fehler, flash player, google, helper, home, mozilla, registry, scan, security, services.exe, software, svchost.exe, symantec, system, usb, warnung, windows |