#
FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.02.2018
Ran by SYSTEM on MININT-BESK6QG (17-02-2018 17:39:40)
Running from K:\
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Englisch (Vereinigte Staaten)
Internet Explorer Version 11
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7541976 2014-02-21] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-10-28] (Intel Corporation)
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2747168 2013-11-14] ()
HKLM-x32\...\Run: [Avira System Speedup User Starter] => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [65120 2018-01-26] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2018-01-30] (Avira Operations GmbH & Co. KG)
HKU\s.wahl\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2015-03-19] (Google Inc.)
Startup: C:\Users\s.wahl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2018-02-09]
ShortcutTarget: Dropbox.lnk -> C:\windows\system32\config\systemprofile\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\s.wahl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Synology Cloud Station Backup.lnk [2018-02-17]
ShortcutTarget: Synology Cloud Station Backup.lnk -> C:\Program Files (x86)\Synology\CloudStationBackup\bin\launcher.exe (Synology Inc.)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1128944 2017-12-18] (Avira Operations GmbH & Co. KG)
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [492560 2018-01-05] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [492560 2018-01-05] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1526832 2017-12-18] (Avira Operations GmbH & Co. KG)
S2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [445112 2018-01-30] (Avira Operations GmbH & Co. KG)
S2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [338728 2018-01-16] (Avira Operations GmbH & Co. KG)
S2 AviraUpdaterService; C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe [102304 2018-01-21] (Avira Operations GmbH & Co. KG)
S2 BFE; X:\windows\System32\bfe.dll [827904 2013-08-22] (Microsoft Corporation)
S2 BrcmMgmtAgent; C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [204288 2012-08-02] (Broadcom Corporation)
S2 Cloud Station Backup VSS Service x64; C:\Program Files (x86)\Synology\CloudStationBackup\bin\vss-service-x64.exe [287256 2016-12-28] ()
S2 CryptSvc; X:\windows\system32\cryptsvc.dll [129536 2013-08-22] (Microsoft Corporation)
S2 DcomLaunch; X:\windows\system32\rpcss.dll [761344 2013-08-22] (Microsoft Corporation)
S3 defragsvc; X:\windows\System32\defragsvc.dll [449536 2013-08-22] (Microsoft Corporation)
S3 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2486272 2013-04-30] (Dell Inc.)
S2 Dhcp; X:\windows\system32\dhcpcore.dll [353792 2013-08-22] (Microsoft Corporation)
S2 Dnscache; X:\windows\System32\dnsrslvr.dll [255488 2013-08-22] (Microsoft Corporation)
S3 EapHost; X:\windows\System32\eapsvc.dll [107008 2013-08-22] (Microsoft Corporation)
S3 EFS; X:\windows\System32\lsass.exe [45008 2013-08-22] (Microsoft Corporation)
S2 eventlog; X:\windows\System32\wevtsvc.dll [1669632 2013-08-22] (Microsoft Corporation)
S2 gpsvc; X:\windows\System32\gpsvc.dll [1311744 2013-08-22] (Microsoft Corporation)
S3 hidserv; X:\windows\system32\hidserv.dll [32256 2013-08-22] (Microsoft Corporation)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-10-28] (Intel Corporation)
S2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [103808 2008-01-22] ()
S3 IKEEXT; X:\windows\System32\ikeext.dll [1102336 2013-08-22] (Microsoft Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
S2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-11-07] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-04-03] (Intel Corporation)
S3 KeyIso; X:\windows\system32\lsass.exe [45008 2013-08-22] (Microsoft Corporation)
S2 LanmanServer; X:\windows\system32\srvsvc.dll [324608 2013-08-22] (Microsoft Corporation)
S2 LanmanWorkstation; X:\windows\System32\wkssvc.dll [284160 2013-08-22] (Microsoft Corporation)
S2 lmhosts; X:\windows\System32\lmhsvc.dll [24576 2013-08-22] (Microsoft Corporation)
S2 LMIRescue_c3689326-5d43-5451-79c7-8440471fd138; C:\Program Files (x86)\LogMeIn Rescue Applet\LMIR0002.tmp\LMI_Rescue_srv.exe [3775960 2018-02-17] (LogMeIn, Inc.)
S2 MpsSvc; X:\windows\system32\mpssvc.dll [878080 2013-08-22] (Microsoft Corporation)
S3 Netlogon; X:\windows\system32\lsass.exe [45008 2013-08-22] (Microsoft Corporation)
S3 Netman; X:\windows\System32\netman.dll [254976 2013-08-22] (Microsoft Corporation)
S2 NlaSvc; X:\windows\System32\nlasvc.dll [387584 2013-08-22] (Microsoft Corporation)
S2 nsi; X:\windows\system32\nsisvc.dll [29184 2013-08-22] (Microsoft Corporation)
S2 NVWMI; C:\Windows\System32\nvwmi64.exe [2274592 2013-11-14] (NVIDIA Corporation)
S2 PlugPlay; X:\windows\system32\umpnpmgr.dll [124928 2013-08-22] (Microsoft Corporation)
S2 poaService; C:\Program Files\Dell\PPO\poaService.exe [641232 2013-12-18] (Dell Inc.)
S2 PoaSMSrv; C:\Program Files\Dell\PPO\poaSmSrv.exe [277712 2013-12-18] (Dell Inc.)
S2 poaTaServ; C:\Program Files\Dell\PPO\poaTaServ.exe [516304 2013-12-18] (Dell Inc.)
S3 PolicyAgent; X:\windows\System32\ipsecsvc.dll [403456 2013-08-22] (Microsoft Corporation)
S2 Power; X:\windows\system32\umpo.dll [79360 2013-08-22] (Microsoft Corporation)
S2 ProfSvc; X:\windows\system32\profsvc.dll [220672 2013-08-22] (Microsoft Corporation)
S3 ProtectedStorage; X:\windows\system32\lsass.exe [45008 2013-08-22] (Microsoft Corporation)
S3 RasAuto; X:\windows\System32\rasauto.dll [101376 2013-08-22] (Microsoft Corporation)
S3 RasMan; X:\windows\System32\rasmans.dll [534016 2013-08-22] (Microsoft Corporation)
S2 RpcEptMapper; X:\windows\System32\RpcEpMap.dll [79872 2013-08-22] (Microsoft Corporation)
S2 RpcSs; X:\windows\system32\rpcss.dll [761344 2013-08-22] (Microsoft Corporation)
S2 SamSs; X:\windows\system32\lsass.exe [45008 2013-08-22] (Microsoft Corporation)
S2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1915920 2014-04-04] (SoftThinks SAS)
S2 SpeedupService; C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe [74256 2018-01-26] (Avira Operations GmbH & Co. KG)
S3 SstpSvc; X:\windows\system32\sstpsvc.dll [144384 2013-08-22] (Microsoft Corporation)
S2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-15] (DEVGURU Co., LTD.)
S3 swprv; X:\windows\System32\swprv.dll [716288 2013-08-22] (Microsoft Corporation)
S2 TeamViewer9; D:\Progr. Teamviiewer\TeamViewer_Service.exe [4799760 2014-09-12] (TeamViewer GmbH)
S3 TrustedInstaller; X:\windows\servicing\TrustedInstaller.exe [98816 2013-08-22] (Microsoft Corporation)
S3 VaultSvc; X:\windows\system32\lsass.exe [45008 2013-08-22] (Microsoft Corporation)
S3 vds; X:\windows\System32\vds.exe [1283584 2013-08-22] (Microsoft Corporation)
S3 VSS; X:\windows\system32\vssvc.exe [1436160 2013-08-22] (Microsoft Corporation)
S3 W32Time; X:\windows\system32\w32time.dll [404480 2013-08-22] (Microsoft Corporation)
S3 wbengine; X:\windows\system32\wbengine.exe [1542144 2013-08-22] (Microsoft Corporation)
S2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [25704 2018-02-04] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-10-20] (Microsoft Corporation)
S2 Winmgmt; X:\windows\system32\wbem\WMIsvc.dll [220672 2013-08-22] (Microsoft Corporation)
S3 wmiApSrv; X:\windows\system32\wbem\WmiApSrv.exe [195072 2013-08-22] (Microsoft Corporation)
S3 QWAVE; %windir%\system32\qwave.dll [X]
S3 seclogon; %windir%\system32\seclogon.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 1394ohci; X:\windows\system32\drivers\1394ohci.sys [231424 2013-08-22] (Microsoft Corporation)
S0 ACPI; X:\windows\System32\drivers\ACPI.sys [522592 2013-08-22] (Microsoft Corporation)
S1 AFD; X:\windows\system32\drivers\afd.sys [567296 2013-08-22] (Microsoft Corporation)
S3 agp440; X:\windows\system32\drivers\agp440.sys [62304 2013-08-22] (Microsoft Corporation)
S3 akshasp; C:\Windows\System32\DRIVERS\akshasp.sys [60488 2014-07-14] (SafeNet Inc.)
S3 aksusb; C:\Windows\System32\DRIVERS\aksusb.sys [303624 2014-07-14] (SafeNet Inc.)
S3 AmdK8; X:\windows\system32\drivers\amdk8.sys [95744 2013-08-22] (Microsoft Corporation)
S3 AmdPPM; X:\windows\system32\drivers\amdppm.sys [98816 2013-08-22] (Microsoft Corporation)
S3 amdsata; X:\windows\system32\drivers\amdsata.sys [79200 2013-08-22] (Advanced Micro Devices)
S3 amdsbs; X:\windows\system32\drivers\amdsbs.sys [259424 2013-08-22] (AMD Technologies Inc.)
S0 amdxata; X:\windows\System32\drivers\amdxata.sys [25952 2013-08-22] (Advanced Micro Devices)
S3 arcsas; X:\windows\system32\drivers\arcsas.sys [114016 2013-08-22] (PMC-Sierra, Inc.)
S3 AsyncMac; X:\windows\System32\DRIVERS\asyncmac.sys [26624 2013-08-22] (Microsoft Corporation)
S3 atapi; X:\windows\system32\drivers\atapi.sys [26464 2013-08-22] (Microsoft Corporation)
S0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [64504 2017-06-14] (Avira Operations GmbH & Co. KG)
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [196344 2017-12-18] (Avira Operations GmbH & Co. KG)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [153552 2018-02-09] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-03-02] (Avira Operations GmbH & Co. KG)
S2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [78600 2017-03-02] (Avira Operations GmbH & Co. KG)
S3 b06bdrv; X:\windows\system32\drivers\bxvbda.sys [531296 2013-08-22] (Broadcom Corporation)
S3 b57nd60a; X:\windows\System32\DRIVERS\b57nd60a.sys [425984 2013-08-22] (Broadcom Corporation)
S3 bowser; X:\windows\System32\DRIVERS\bowser.sys [102912 2013-08-22] (Microsoft Corporation)
S4 cdfs; X:\windows\System32\DRIVERS\cdfs.sys [88576 2013-08-22] (Microsoft Corporation)
S1 cdrom; X:\windows\System32\DRIVERS\cdrom.sys [164352 2013-08-22] (Microsoft Corporation)
S3 CmBatt; X:\windows\system32\drivers\CmBatt.sys [25472 2013-08-22] (Microsoft Corporation)
S0 CNG; X:\windows\System32\Drivers\cng.sys [564520 2013-08-22] (Microsoft Corporation)
S3 DellProf; C:\Windows\System32\drivers\DellProf.sys [23312 2013-04-29] (Dell Computer Corporation)
S1 DfsC; X:\windows\System32\Drivers\dfsc.sys [134656 2013-08-22] (Microsoft Corporation)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
S0 Disk; X:\windows\System32\drivers\disk.sys [100192 2013-08-22] (Microsoft Corporation)
S3 DXGKrnl; X:\windows\System32\drivers\dxgkrnl.sys [1537376 2013-08-22] (Microsoft Corporation)
S3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [488216 2014-03-05] (Intel Corporation)
S3 ebdrv; X:\windows\system32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 elxstor; X:\windows\system32\drivers\elxstor.sys [712032 2013-08-22] (Emulex)
S3 ErrDev; X:\windows\system32\drivers\errdev.sys [10240 2013-08-22] (Microsoft Corporation)
S3 fdc; X:\windows\system32\drivers\fdc.sys [30720 2013-08-22] (Microsoft Corporation)
S0 FileInfo; X:\windows\System32\drivers\fileinfo.sys [79200 2013-08-22] (Microsoft Corporation)
S3 Filetrace; X:\windows\System32\drivers\filetrace.sys [34816 2013-08-22] (Microsoft Corporation)
S3 flpydisk; X:\windows\system32\drivers\flpydisk.sys [25088 2013-08-22] (Microsoft Corporation)
S0 FltMgr; X:\windows\System32\drivers\fltmgr.sys [358752 2013-08-22] (Microsoft Corporation)
S3 FsDepends; X:\windows\System32\drivers\FsDepends.sys [56672 2013-08-22] (Microsoft Corporation)
S0 fvevol; X:\windows\System32\DRIVERS\fvevol.sys [579424 2013-08-22] (Microsoft Corporation)
S3 gagp30kx; X:\windows\system32\drivers\gagp30kx.sys [65888 2013-08-22] (Microsoft Corporation)
S3 HDAudBus; X:\windows\System32\DRIVERS\HDAudBus.sys [78336 2013-08-22] (Microsoft Corporation)
S3 HidBatt; X:\windows\system32\drivers\HidBatt.sys [26624 2013-08-22] (Microsoft Corporation)
S3 HidUsb; X:\windows\system32\drivers\hidusb.sys [33792 2013-08-22] (Microsoft Corporation)
S3 HpSAMD; X:\windows\system32\drivers\HpSAMD.sys [64352 2013-08-22] (Hewlett-Packard Company)
S3 i8042prt; X:\windows\System32\DRIVERS\i8042prt.sys [107520 2013-08-22] (Microsoft Corporation)
S0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28008 2013-10-18] (Intel Corporation)
S3 iaStorV; X:\windows\system32\drivers\iaStorV.sys [412000 2013-08-22] (Intel Corporation)
S3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21408 2013-08-08] ()
S3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21920 2013-08-08] ()
S3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-07] ()
S3 IntcAzAudAddService; C:\Windows\System32\drivers\RTDVHD64.sys [2319832 2014-03-14] (Realtek Semiconductor Corp.)
S3 intelide; X:\windows\system32\drivers\intelide.sys [18272 2013-08-22] (Microsoft Corporation)
S3 intelppm; X:\windows\System32\DRIVERS\intelppm.sys [98816 2013-08-22] (Microsoft Corporation)
S3 IPMIDRV; X:\windows\system32\drivers\IPMIDrv.sys [79360 2013-08-22] (Microsoft Corporation)
S3 isapnp; X:\windows\system32\drivers\isapnp.sys [21856 2013-08-22] (Microsoft Corporation)
S3 iScsiPrt; X:\windows\system32\drivers\msiscsi.sys [274784 2013-08-22] (Microsoft Corporation)
S3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-08-07] ()
S3 kbdclass; X:\windows\System32\DRIVERS\kbdclass.sys [58208 2013-08-22] (Microsoft Corporation)
S3 kbdhid; X:\windows\System32\DRIVERS\kbdhid.sys [32256 2013-08-22] (Microsoft Corporation)
S0 KSecDD; X:\windows\System32\Drivers\ksecdd.sys [100704 2013-08-22] (Microsoft Corporation)
S0 KSecPkg; X:\windows\System32\Drivers\ksecpkg.sys [192864 2013-08-22] (Microsoft Corporation)
S3 ksthunk; X:\windows\system32\drivers\ksthunk.sys [21248 2013-08-22] (Microsoft Corporation)
S3 LSI_SAS; X:\windows\system32\drivers\lsi_sas.sys [109408 2013-08-22] (LSI Corporation)
S3 LSI_SAS2; X:\windows\system32\drivers\lsi_sas2.sys [93536 2013-08-22] (LSI Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-08-19] (Malwarebytes Corporation)
S3 megasas; X:\windows\system32\drivers\megasas.sys [56672 2013-08-22] (LSI Corporation)
S3 MegaSR; X:\windows\system32\drivers\MegaSR.sys [575840 2013-08-22] (LSI Corporation, Inc.)
S3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [118272 2014-04-03] (Intel Corporation)
S3 mouclass; X:\windows\System32\DRIVERS\mouclass.sys [51040 2013-08-22] (Microsoft Corporation)
S3 mouhid; X:\windows\System32\DRIVERS\mouhid.sys [30208 2013-08-22] (Microsoft Corporation)
S0 mountmgr; X:\windows\System32\drivers\mountmgr.sys [101728 2013-08-22] (Microsoft Corporation)
S3 mpsdrv; X:\windows\System32\drivers\mpsdrv.sys [74240 2013-08-22] (Microsoft Corporation)
S3 mrxsmb; X:\windows\System32\DRIVERS\mrxsmb.sys [402432 2013-08-22] (Microsoft Corporation)
S3 mrxsmb10; X:\windows\System32\DRIVERS\mrxsmb10.sys [283648 2013-08-22] (Microsoft Corporation)
S3 mrxsmb20; X:\windows\System32\DRIVERS\mrxsmb20.sys [206848 2013-08-22] (Microsoft Corporation)
S3 mshidkmdf; X:\windows\System32\drivers\mshidkmdf.sys [8192 2013-08-22] (Microsoft Corporation)
S0 msisadrv; X:\windows\System32\drivers\msisadrv.sys [17248 2013-08-22] (Microsoft Corporation)
S3 MSKSSRV; X:\windows\System32\drivers\MSKSSRV.sys [10624 2013-08-22] (Microsoft Corporation)
S3 MSPCLOCK; X:\windows\System32\drivers\MSPCLOCK.sys [7040 2013-08-22] (Microsoft Corporation)
S3 MSPQM; X:\windows\System32\drivers\MSPQM.sys [6784 2013-08-22] (Microsoft Corporation)
S1 mssmbios; X:\windows\System32\DRIVERS\mssmbios.sys [37728 2013-08-22] (Microsoft Corporation)
S3 MSTEE; X:\windows\System32\drivers\MSTEE.sys [7936 2013-08-22] (Microsoft Corporation)
S3 MTConfig; X:\windows\system32\drivers\MTConfig.sys [13312 2013-08-22] (Microsoft Corporation)
S0 Mup; X:\windows\System32\Drivers\mup.sys [78688 2013-08-22] (Microsoft Corporation)
S0 NDIS; X:\windows\System32\drivers\ndis.sys [1118552 2013-08-22] (Microsoft Corporation)
S3 NdisTapi; X:\windows\System32\DRIVERS\ndistapi.sys [24576 2013-08-22] (Microsoft Corporation)
S3 Ndisuio; X:\windows\System32\DRIVERS\ndisuio.sys [60416 2013-08-22] (Microsoft Corporation)
S3 NdisWan; X:\windows\System32\DRIVERS\ndiswan.sys [220672 2013-08-22] (Microsoft Corporation)
S1 NetBIOS; X:\windows\System32\DRIVERS\netbios.sys [48128 2013-08-22] (Microsoft Corporation)
S1 NetBT; X:\windows\System32\DRIVERS\netbt.sys [282624 2013-08-22] (Microsoft Corporation)
S1 nsiproxy; X:\windows\System32\drivers\nsiproxy.sys [39936 2013-08-22] (Microsoft Corporation)
S3 nvraid; X:\windows\system32\drivers\nvraid.sys [150368 2013-08-22] (NVIDIA Corporation)
S3 nvstor; X:\windows\system32\drivers\nvstor.sys [168288 2013-08-22] (NVIDIA Corporation)
S3 nv_agp; X:\windows\system32\drivers\nv_agp.sys [124768 2013-08-22] (Microsoft Corporation)
S3 Parport; X:\windows\system32\drivers\parport.sys [94208 2013-08-22] (Microsoft Corporation)
S0 partmgr; X:\windows\System32\drivers\partmgr.sys [88928 2013-08-22] (Microsoft Corporation)
S0 pci; X:\windows\System32\drivers\pci.sys [285536 2013-08-22] (Microsoft Corporation)
S3 pciide; X:\windows\system32\drivers\pciide.sys [14688 2013-08-22] (Microsoft Corporation)
S3 pcmcia; X:\windows\system32\drivers\pcmcia.sys [114528 2013-08-22] (Microsoft Corporation)
S0 pcw; X:\windows\System32\drivers\pcw.sys [50016 2013-08-22] (Microsoft Corporation)
S3 phantomtap; C:\Windows\System32\DRIVERS\phantomtap.sys [35664 2017-05-18] (The OpenVPN Project)
S3 POADrvr; C:\Windows\System32\drivers\POADrvr.sys [21264 2013-12-18] (Dell Computer Corporation)
S3 PptpMiniport; X:\windows\System32\DRIVERS\raspptp.sys [107520 2013-08-22] (Microsoft Corporation)
S3 Processor; X:\windows\system32\drivers\processr.sys [92160 2013-08-22] (Microsoft Corporation)
S3 RasAcd; X:\windows\System32\DRIVERS\rasacd.sys [17408 2013-08-22] (Microsoft Corporation)
S3 RasAgileVpn; X:\windows\System32\DRIVERS\AgileVpn.sys [95744 2013-08-22] (Microsoft Corporation)
S3 Rasl2tp; X:\windows\System32\DRIVERS\rasl2tp.sys [120832 2013-08-22] (Microsoft Corporation)
S3 RasPppoe; X:\windows\System32\DRIVERS\raspppoe.sys [84992 2013-08-22] (Microsoft Corporation)
S3 RasSstp; X:\windows\System32\DRIVERS\rassstp.sys [96256 2013-08-22] (Microsoft Corporation)
S1 rdbss; X:\windows\System32\DRIVERS\rdbss.sys [408576 2013-08-22] (Microsoft Corporation)
S3 sbp2port; X:\windows\system32\drivers\sbp2port.sys [107872 2013-08-22] (Microsoft Corporation)
S3 sdbus; X:\windows\system32\drivers\sdbus.sys [234848 2013-08-22] (Microsoft Corporation)
S3 Serenum; X:\windows\System32\DRIVERS\serenum.sys [23040 2013-08-22] (Microsoft Corporation)
S1 Serial; X:\windows\System32\DRIVERS\serial.sys [83456 2013-08-22] (Microsoft Corporation)
S3 sermouse; X:\windows\system32\drivers\sermouse.sys [26112 2013-08-22] (Microsoft Corporation)
S3 sfloppy; X:\windows\system32\drivers\sfloppy.sys [17408 2013-08-22] (Microsoft Corporation)
S3 SiSRaid2; X:\windows\system32\drivers\SiSRaid2.sys [44896 2013-08-22] (Silicon Integrated Systems Corp.)
S3 SiSRaid4; X:\windows\system32\drivers\sisraid4.sys [81760 2013-08-22] (Silicon Integrated Systems)
S3 srv; X:\windows\System32\DRIVERS\srv.sys [454656 2013-08-22] (Microsoft Corporation)
S3 srv2; X:\windows\System32\DRIVERS\srv2.sys [674816 2013-08-22] (Microsoft Corporation)
S3 srvnet; X:\windows\System32\DRIVERS\srvnet.sys [244224 2013-08-22] (Microsoft Corporation)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 stexstor; X:\windows\system32\drivers\stexstor.sys [31072 2013-08-22] (Promise Technology, Inc.)
S3 storvsc; X:\windows\system32\drivers\storvsc.sys [45888 2013-08-22] (Microsoft Corporation)
S3 swenum; X:\windows\System32\DRIVERS\swenum.sys [14176 2013-08-22] (Microsoft Corporation)
S0 Tcpip; X:\windows\System32\drivers\tcpip.sys [2549600 2013-08-22] (Microsoft Corporation)
S3 TCPIP6; X:\windows\System32\DRIVERS\tcpip.sys [2549600 2013-08-22] (Microsoft Corporation)
S0 tdrpman251; C:\Windows\System32\DRIVERS\tdrpm251.sys [1455648 2014-10-23] (Acronis)
S1 tdx; X:\windows\System32\DRIVERS\tdx.sys [107520 2013-08-22] (Microsoft Corporation)
S3 uagp35; X:\windows\system32\drivers\uagp35.sys [64864 2013-08-22] (Microsoft Corporation)
S4 udfs; X:\windows\System32\DRIVERS\udfs.sys [316928 2013-08-22] (Microsoft Corporation)
S3 uliagpkx; X:\windows\system32\drivers\uliagpkx.sys [65888 2013-08-22] (Microsoft Corporation)
S3 umbus; X:\windows\System32\DRIVERS\umbus.sys [46080 2013-08-22] (Microsoft Corporation)
S3 UmPass; X:\windows\system32\drivers\umpass.sys [11776 2013-08-22] (Microsoft Corporation)
S3 usbccgp; X:\windows\System32\DRIVERS\usbccgp.sys [155488 2013-08-22] (Microsoft Corporation)
S3 usbehci; X:\windows\system32\drivers\usbehci.sys [89952 2013-08-22] (Microsoft Corporation)
S3 usbhub; X:\windows\system32\drivers\usbhub.sys [422240 2013-08-22] (Microsoft Corporation)
S3 usbohci; X:\windows\system32\drivers\usbohci.sys [30208 2013-08-22] (Microsoft Corporation)
S3 USBSTOR; X:\windows\System32\DRIVERS\USBSTOR.SYS [142688 2013-08-22] (Microsoft Corporation)
S3 usbuhci; X:\windows\system32\drivers\usbuhci.sys [34816 2013-08-22] (Microsoft Corporation)
S0 vdrvroot; X:\windows\System32\drivers\vdrvroot.sys [37728 2013-08-22] (Microsoft Corporation)
S3 vhdmp; X:\windows\system32\drivers\vhdmp.sys [551776 2013-08-22] (Microsoft Corporation)
S3 viaide; X:\windows\system32\drivers\viaide.sys [19808 2013-08-22] (VIA Technologies, Inc.)
S3 VMBusHID; X:\windows\system32\drivers\VMBusHID.sys [21760 2013-08-22] (Microsoft Corporation)
S0 volmgr; X:\windows\System32\drivers\volmgr.sys [73568 2013-08-22] (Microsoft Corporation)
S0 volmgrx; X:\windows\System32\drivers\volmgrx.sys [377696 2013-08-22] (Microsoft Corporation)
S0 volsnap; X:\windows\System32\drivers\volsnap.sys [312160 2013-08-22] (Microsoft Corporation)
S3 vsmraid; X:\windows\system32\drivers\vsmraid.sys [168800 2013-08-22] (VIA Technologies Inc.,Ltd)
S3 WacomPen; X:\windows\system32\drivers\wacompen.sys [26752 2013-08-22] (Microsoft Corporation)
S3 WANARP; X:\windows\System32\DRIVERS\wanarp.sys [79872 2013-08-22] (Microsoft Corporation)
S1 Wanarpv6; X:\windows\System32\DRIVERS\wanarp.sys [79872 2013-08-22] (Microsoft Corporation)
S0 Wdf01000; X:\windows\System32\drivers\Wdf01000.sys [839488 2013-08-22] (Microsoft Corporation)
S3 WIMMount; X:\windows\System32\drivers\wimmount.sys [33632 2013-08-22] (Microsoft Corporation)
S3 WmiAcpi; X:\windows\System32\DRIVERS\wmiacpi.sys [16384 2013-08-22] (Microsoft Corporation)
S4 ws2ifsl; X:\windows\system32\drivers\ws2ifsl.sys [21504 2013-08-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-02-17 17:38 - 2018-02-17 17:38 - 000000000 ____D C:\FRST
2018-02-17 17:00 - 2018-02-17 17:32 - 000000000 _____ C:\Recovery.txt
2018-02-17 00:57 - 2018-02-17 00:57 - 000085272 _____ C:\Users\s.wahl\Downloads\ConnectWiseControl.Client.exe
2018-02-17 00:54 - 2018-02-17 00:54 - 000000000 ____D C:\Users\s.wahl\AppData\Local\LogMeIn Rescue Applet
2018-02-17 00:54 - 2018-02-17 00:54 - 000000000 ____D C:\Program Files (x86)\LogMeIn Rescue Applet
2018-02-17 00:53 - 2018-02-17 00:53 - 002205736 _____ (LogMeIn, Inc.) C:\Users\s.wahl\Downloads\Support-LogMeInRescue.exe
2018-02-14 06:55 - 2018-02-14 06:55 - 000002132 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2018-02-14 06:44 - 2018-02-10 11:52 - 000395928 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2018-02-14 06:44 - 2018-02-10 11:03 - 000347296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-02-14 06:44 - 2018-02-10 00:44 - 025740288 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2018-02-14 06:44 - 2018-02-09 23:30 - 002724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2018-02-14 06:44 - 2018-02-09 23:29 - 000004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2018-02-14 06:44 - 2018-02-09 23:19 - 002900480 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2018-02-14 06:44 - 2018-02-09 23:17 - 000417280 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2018-02-14 06:44 - 2018-02-09 23:17 - 000066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2018-02-14 06:44 - 2018-02-09 23:17 - 000048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2018-02-14 06:44 - 2018-02-09 23:16 - 000577536 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2018-02-14 06:44 - 2018-02-09 23:16 - 000088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2018-02-14 06:44 - 2018-02-09 23:10 - 000054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2018-02-14 06:44 - 2018-02-09 23:10 - 000034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2018-02-14 06:44 - 2018-02-09 23:09 - 005782016 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2018-02-14 06:44 - 2018-02-09 23:07 - 000615936 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2018-02-14 06:44 - 2018-02-09 23:06 - 000816640 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2018-02-14 06:44 - 2018-02-09 23:06 - 000814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2018-02-14 06:44 - 2018-02-09 23:06 - 000144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2018-02-14 06:44 - 2018-02-09 23:06 - 000116224 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2018-02-14 06:44 - 2018-02-09 23:01 - 000969216 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2018-02-14 06:44 - 2018-02-09 22:58 - 000489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2018-02-14 06:44 - 2018-02-09 22:52 - 000087552 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2018-02-14 06:44 - 2018-02-09 22:52 - 000077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2018-02-14 06:44 - 2018-02-09 22:51 - 000107520 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
2018-02-14 06:44 - 2018-02-09 22:49 - 000199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2018-02-14 06:44 - 2018-02-09 22:48 - 000092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2018-02-14 06:44 - 2018-02-09 22:46 - 000315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2018-02-14 06:44 - 2018-02-09 22:45 - 000152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
2018-02-14 06:44 - 2018-02-09 22:36 - 015283712 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2018-02-14 06:44 - 2018-02-09 22:36 - 000262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2018-02-14 06:44 - 2018-02-09 22:34 - 000807936 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2018-02-14 06:44 - 2018-02-09 22:34 - 000726528 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2018-02-14 06:44 - 2018-02-09 22:33 - 001359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2018-02-14 06:44 - 2018-02-09 22:32 - 002134528 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2018-02-14 06:44 - 2018-02-09 22:27 - 003241472 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2018-02-14 06:44 - 2018-02-09 22:20 - 020274176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-02-14 06:44 - 2018-02-09 22:14 - 001546240 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2018-02-14 06:44 - 2018-02-09 22:08 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-02-14 06:44 - 2018-02-09 22:02 - 000800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2018-02-14 06:44 - 2018-02-09 21:57 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-02-14 06:44 - 2018-02-09 21:57 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-02-14 06:44 - 2018-02-09 21:57 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-02-14 06:44 - 2018-02-09 21:57 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-02-14 06:44 - 2018-02-09 21:56 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-02-14 06:44 - 2018-02-09 21:54 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-02-14 06:44 - 2018-02-09 21:52 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-02-14 06:44 - 2018-02-09 21:51 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-02-14 06:44 - 2018-02-09 21:50 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-02-14 06:44 - 2018-02-09 21:49 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-02-14 06:44 - 2018-02-09 21:49 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-02-14 06:44 - 2018-02-09 21:49 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-02-14 06:44 - 2018-02-09 21:42 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-02-14 06:44 - 2018-02-09 21:39 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-02-14 06:44 - 2018-02-09 21:38 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-02-14 06:44 - 2018-02-09 21:38 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-02-14 06:44 - 2018-02-09 21:36 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-02-14 06:44 - 2018-02-09 21:35 - 004498944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-02-14 06:44 - 2018-02-09 21:35 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-02-14 06:44 - 2018-02-09 21:35 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-02-14 06:44 - 2018-02-09 21:34 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-02-14 06:44 - 2018-02-09 21:33 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-02-14 06:44 - 2018-02-09 21:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-02-14 06:44 - 2018-02-09 21:27 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-02-14 06:44 - 2018-02-09 21:27 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-02-14 06:44 - 2018-02-09 21:26 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-02-14 06:44 - 2018-02-09 21:14 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-02-14 06:44 - 2018-02-09 21:10 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-02-14 06:44 - 2018-02-09 21:08 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-02-14 06:44 - 2018-01-12 08:46 - 000631680 _____ (Microsoft Corporation) C:\Windows\System32\winresume.efi
2018-02-14 06:44 - 2018-01-12 08:44 - 005581544 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2018-02-14 06:44 - 2018-01-12 08:44 - 001894120 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2018-02-14 06:44 - 2018-01-12 08:44 - 000708328 _____ (Microsoft Corporation) C:\Windows\System32\winload.efi
2018-02-14 06:44 - 2018-01-12 08:44 - 000377064 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2018-02-14 06:44 - 2018-01-12 08:44 - 000371432 _____ (Microsoft Corporation) C:\Windows\System32\clfs.sys
2018-02-14 06:44 - 2018-01-12 08:44 - 000287976 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2018-02-14 06:44 - 2018-01-12 08:44 - 000262376 _____ (Microsoft Corporation) C:\Windows\System32\hal.dll
2018-02-14 06:44 - 2018-01-12 08:44 - 000154856 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2018-02-14 06:44 - 2018-01-12 08:44 - 000095464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2018-02-14 06:44 - 2018-01-12 08:40 - 001460736 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 001212928 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 001163264 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000880640 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000731648 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000484864 _____ (Microsoft Corporation) C:\Windows\System32\StructuredQuery.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000463872 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000419840 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000361984 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000345600 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000316928 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000215552 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000210432 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000190464 _____ (Microsoft Corporation) C:\Windows\System32\rpchttp.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000123904 _____ (Microsoft Corporation) C:\Windows\System32\bcrypt.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000063488 _____ (Microsoft Corporation) C:\Windows\System32\setbcdlocale.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000059904 _____ (Microsoft Corporation) C:\Windows\System32\appidapi.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000044032 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000043520 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000034816 _____ (Microsoft Corporation) C:\Windows\System32\appidsvc.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:33 - 001665384 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2018-02-14 06:44 - 2018-01-12 08:29 - 004014312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-02-14 06:44 - 2018-01-12 08:29 - 003959016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-02-14 06:44 - 2018-01-12 08:27 - 004834816 _____ (Microsoft Corporation) C:\Windows\System32\xpsrchvw.exe
2018-02-14 06:44 - 2018-01-12 08:27 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 08:16 - 003405824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2018-02-14 06:44 - 2018-01-12 08:16 - 000076288 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2018-02-14 06:44 - 2018-01-12 08:16 - 000030208 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2018-02-14 06:44 - 2018-01-12 08:15 - 000032896 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidparse.sys
2018-02-14 06:44 - 2018-01-12 08:11 - 000148480 _____ (Microsoft Corporation) C:\Windows\System32\appidpolicyconverter.exe
2018-02-14 06:44 - 2018-01-12 08:11 - 000062464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\appid.sys
2018-02-14 06:44 - 2018-01-12 08:11 - 000017920 _____ (Microsoft Corporation) C:\Windows\System32\appidcertstorecheck.exe
2018-02-14 06:44 - 2018-01-12 08:10 - 000064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
2018-02-14 06:44 - 2018-01-12 08:07 - 000338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe
2018-02-14 06:44 - 2018-01-12 08:06 - 000296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2018-02-14 06:44 - 2018-01-12 08:03 - 000159744 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
2018-02-14 06:44 - 2018-01-12 08:02 - 000291328 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
2018-02-14 06:44 - 2018-01-12 08:02 - 000129536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2018-02-14 06:44 - 2018-01-12 08:02 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-02-14 06:44 - 2018-01-12 08:01 - 000112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe
2018-02-14 06:44 - 2018-01-12 08:01 - 000030720 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2018-02-14 06:44 - 2018-01-12 07:57 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-02-14 06:44 - 2018-01-12 07:57 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-02-14 06:44 - 2018-01-12 07:57 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-02-14 06:44 - 2018-01-12 07:57 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-02-14 06:44 - 2018-01-12 07:57 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-02-14 06:44 - 2018-01-12 07:56 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 07:56 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 07:56 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-02-14 06:44 - 2018-01-12 07:56 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-02-14 06:44 - 2018-01-11 08:41 - 001133568 _____ (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2018-02-14 06:44 - 2018-01-11 08:22 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2018-02-14 06:44 - 2018-01-11 08:09 - 003224064 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2018-02-14 06:44 - 2018-01-05 08:31 - 000151552 _____ (Microsoft Corporation) C:\Windows\System32\t2embed.dll
2018-02-14 06:44 - 2018-01-05 08:31 - 000041472 _____ (Microsoft Corporation) C:\Windows\System32\lpk.dll
2018-02-14 06:44 - 2018-01-05 08:30 - 000100864 _____ (Microsoft Corporation) C:\Windows\System32\fontsub.dll
2018-02-14 06:44 - 2018-01-05 08:30 - 000046080 _____ (Adobe Systems) C:\Windows\System32\atmlib.dll
2018-02-14 06:44 - 2018-01-05 08:30 - 000014336 _____ (Microsoft Corporation) C:\Windows\System32\dciman32.dll
2018-02-14 06:44 - 2018-01-05 08:25 - 000383720 _____ (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2018-02-14 06:44 - 2018-01-05 08:14 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-02-14 06:44 - 2018-01-05 08:11 - 000111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-02-14 06:44 - 2018-01-05 08:11 - 000071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-02-14 06:44 - 2018-01-05 08:11 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-02-14 06:44 - 2018-01-05 08:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-02-14 06:44 - 2018-01-05 07:50 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-02-14 06:44 - 2017-12-05 09:36 - 001484288 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2018-02-14 06:44 - 2017-12-05 09:36 - 000229376 _____ (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2018-02-14 06:44 - 2017-12-05 09:36 - 000218112 _____ (Microsoft Corporation) C:\Windows\System32\WinSCard.dll
2018-02-14 06:44 - 2017-12-05 09:36 - 000190976 _____ (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2018-02-14 06:44 - 2017-12-05 09:36 - 000141824 _____ (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2018-02-14 06:44 - 2017-12-05 09:36 - 000092160 _____ (Microsoft Corporation) C:\Windows\System32\TabSvc.dll
2018-02-14 06:44 - 2017-12-05 09:08 - 001176576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2018-02-14 06:44 - 2017-12-05 09:08 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2018-02-14 06:44 - 2017-12-05 09:08 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2018-02-14 06:44 - 2017-12-05 09:08 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-02-14 06:44 - 2017-12-05 09:08 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2018-02-14 06:44 - 2017-12-05 08:04 - 000404992 _____ (Microsoft Corporation) C:\Windows\System32\wisptis.exe
2018-02-14 06:43 - 2018-01-21 15:50 - 000136424 _____ (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
2018-02-14 06:43 - 2018-01-21 15:40 - 000654336 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
2018-02-14 06:43 - 2018-01-19 06:05 - 001994752 _____ (Microsoft Corporation) C:\Windows\System32\aitstatic.exe
2018-02-14 06:43 - 2018-01-19 06:05 - 001569280 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll
2018-02-14 06:43 - 2018-01-19 06:05 - 000749568 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll
2018-02-14 06:43 - 2018-01-19 06:05 - 000604672 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll
2018-02-14 06:43 - 2018-01-19 06:05 - 000450048 _____ (Microsoft Corporation) C:\Windows\System32\centel.dll
2018-02-14 06:43 - 2018-01-19 06:05 - 000378880 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll
2018-02-14 06:43 - 2018-01-19 06:05 - 000262144 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll
2018-02-14 06:43 - 2018-01-19 06:05 - 000236544 _____ (Microsoft Corporation) C:\Windows\System32\aepic.dll
2018-02-06 04:02 - 2018-02-06 04:02 - 000250700 _____ C:\Users\s.wahl\Downloads\5A79995F.pdf
2018-02-06 03:50 - 2018-02-06 03:50 - 000631931 _____ C:\Users\s.wahl\Downloads\5A7996A2.pdf
2018-02-03 02:11 - 2018-02-03 02:11 - 000001240 _____ C:\Users\s.wahl\Desktop\Ibrahimovic - Verknüpfung.lnk
2018-02-02 07:45 - 2018-02-02 07:45 - 000269755 _____ C:\Users\s.wahl\Downloads\Girokonto_5404686345_Kontoauszug_20180201.pdf
2018-01-30 00:40 - 2018-01-30 00:40 - 000001262 _____ C:\Users\s.wahl\Desktop\umsatzliste 2018 - Verknüpfung.lnk
2018-01-29 23:37 - 2018-02-17 00:13 - 000000000 ____D C:\Users\Public\Speedup Sessions
2018-01-22 22:48 - 2018-01-22 22:48 - 000000000 ____D C:\Windows\pss
2018-01-22 07:53 - 2018-02-07 23:21 - 000000000 ___RD C:\Users\s.wahl\Desktop\Scanner
2018-01-22 07:48 - 2018-01-22 07:48 - 000000000 ____D C:\Users\s.wahl\AppData\Roaming\ControlCenter4
2018-01-22 07:45 - 2018-01-22 22:04 - 000000086 _____ C:\Windows\Brpfx04a.ini
2018-01-22 07:45 - 2018-01-22 07:45 - 000000092 _____ C:\Windows\brpcfx.ini
2018-01-22 07:39 - 2018-01-22 22:04 - 000000000 ____D C:\ProgramData\PCFaxTx
2018-01-22 07:39 - 2018-01-22 07:39 - 000000066 _____ C:\Windows\Brfaxrx.ini
2018-01-22 07:39 - 2018-01-22 07:39 - 000000000 ____D C:\Users\Public\Documents\BrFaxRx
2018-01-22 07:39 - 2018-01-22 07:39 - 000000000 ____D C:\ProgramData\ControlCenter4
2018-01-22 07:39 - 2018-01-22 07:39 - 000000000 ____D C:\Program Files (x86)\ControlCenter4
2018-01-22 07:39 - 2018-01-22 07:39 - 000000000 ____D C:\Program Files (x86)\Browny02
2018-01-22 07:39 - 2018-01-22 07:39 - 000000000 ____D C:\Brother
2018-01-22 07:39 - 2012-12-12 02:37 - 000318464 _____ (Brother Industries, Ltd.) C:\Windows\System32\BrFaxTxAppRun64.dll
2018-01-22 07:39 - 2012-11-02 01:15 - 000319488 ____R (brother) C:\Windows\System32\NSSRH64.dll
2018-01-22 07:39 - 2012-10-28 21:14 - 000058880 ____R (Brother Industries,Ltd) C:\Windows\System32\Brnsplg.dll
2018-01-22 07:39 - 2012-07-14 00:53 - 000087040 ____R (Brother Industries, Ltd.) C:\Windows\System32\BrNetSti.dll
2018-01-22 07:39 - 2012-06-14 04:55 - 000058880 ____R (Brother Industries,Ltd.) C:\Windows\System32\BrWiaNCp.dll
2018-01-22 07:39 - 2005-04-21 20:36 - 000143360 ____R C:\Windows\System32\BrSNMP64.dll
2018-01-22 07:38 - 2018-01-22 07:39 - 000000000 ____D C:\Program Files (x86)\Brother
2018-01-22 07:38 - 2013-07-12 05:03 - 000214016 _____ (brother) C:\Windows\SysWOW64\NSSearch.dll
2018-01-22 07:38 - 2012-12-03 04:39 - 000002560 _____ (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2S.dll
2018-01-22 07:38 - 2010-03-15 10:45 - 000073728 _____ (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2.dll
2018-01-22 07:38 - 2007-12-13 13:16 - 000005632 _____ (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2L.dll
2018-01-22 07:10 - 2018-01-22 07:10 - 000000000 ____D C:\Users\s.wahl\AppData\Local\ElevatedDiagnostics
2018-01-22 05:41 - 2018-02-09 01:42 - 000000350 _____ C:\Windows\BRRBCOM.INI
2018-01-22 05:32 - 2018-01-22 05:32 - 000944664 _____ C:\Users\s.wahl\Downloads\LC-IGUIDE-Telekom_DE.pdf
2018-01-22 02:46 - 2018-01-22 02:46 - 000000000 ____D C:\Program Files\Nuance
2018-01-22 02:45 - 2018-01-22 02:45 - 000000000 ____D C:\ProgramData\zeon
2018-01-22 02:44 - 2018-01-22 07:33 - 000000000 ____D C:\ProgramData\ScanSoft
2018-01-22 02:44 - 2018-01-22 07:33 - 000000000 ____D C:\ProgramData\Nuance
2018-01-22 02:44 - 2018-01-22 07:33 - 000000000 ____D C:\Program Files (x86)\Nuance
2018-01-22 02:44 - 2018-01-22 02:44 - 000000000 ____D C:\Users\s.wahl\AppData\Roaming\Nuance
2018-01-22 02:44 - 2018-01-22 02:44 - 000000000 ____D C:\ProgramData\FLEXnet
2018-01-18 07:02 - 2018-01-18 07:02 - 001290962 _____ C:\Users\s.wahl\Downloads\Fabrikverkaufsflyer_2017.pdf
2018-01-18 06:08 - 2018-01-18 06:08 - 000001061 _____ C:\Users\s.wahl\Desktop\Entwürfe 2018 - Verknüpfung.lnk
2018-01-18 05:22 - 2018-01-03 04:44 - 000001313 _____ C:\Users\s.wahl\Desktop\Umsätze 2018 - Verknüpfung.lnk
2018-01-18 02:11 - 2018-01-18 02:10 - 000001376 _____ C:\Users\s.wahl\Desktop\2018. 31.12 - Verknüpfung.lnk
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-02-17 08:44 - 2015-01-30 05:06 - 000001063 _____ C:\malwarelog.txt
2018-02-17 01:55 - 2015-06-12 22:42 - 000001228 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2536871828-1541946132-2492561043-1000UA.job
2018-02-17 01:52 - 2009-07-13 20:45 - 000031088 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-02-17 01:52 - 2009-07-13 20:45 - 000031088 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-02-17 01:48 - 2009-07-13 21:32 - 000000000 ____D C:\Windows\System32\FxsTmp
2018-02-17 00:58 - 2014-10-29 01:23 - 000000000 ____D C:\Users\s.wahl\AppData\Local\Deployment
2018-02-17 00:23 - 2017-10-10 06:58 - 000003316 _____ C:\Windows\System32\Tasks\Avira_Antivirus_Systray
2018-02-17 00:18 - 2011-02-28 20:56 - 000700194 _____ C:\Windows\System32\perfh007.dat
2018-02-17 00:18 - 2011-02-28 20:56 - 000149832 _____ C:\Windows\System32\perfc007.dat
2018-02-17 00:18 - 2009-07-13 21:13 - 001622966 _____ C:\Windows\System32\PerfStringBackup.INI
2018-02-17 00:18 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\inf
2018-02-17 00:13 - 2014-10-23 10:30 - 000000000 ____D C:\users\s.wahl
2018-02-17 00:12 - 2014-10-20 13:27 - 000000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
2018-02-17 00:12 - 2009-07-13 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-02-16 08:06 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\rescache
2018-02-15 23:14 - 2014-10-29 01:15 - 000000349 _____ C:\Windows\BRCALIB.INI
2018-02-15 23:12 - 2014-10-29 06:06 - 000000000 ____D C:\Users\s.wahl\AppData\Local\CrashDumps
2018-02-15 06:30 - 2014-10-23 11:15 - 000000000 ____D C:\ProgramData\Package Cache
2018-02-15 06:27 - 2009-07-13 20:45 - 000473232 _____ C:\Windows\System32\FNTCACHE.DAT
2018-02-15 06:26 - 2014-12-10 22:32 - 000000000 ____D C:\Windows\System32\appraiser
2018-02-14 08:29 - 2014-10-23 12:01 - 000000000 ____D C:\Windows\System32\MRT
2018-02-14 08:28 - 2017-10-11 07:27 - 130067560 ____C (Microsoft Corporation) C:\Windows\System32\MRT-KB890830.exe
2018-02-14 08:28 - 2014-10-23 12:01 - 130067560 ____C (Microsoft Corporation) C:\Windows\System32\MRT.exe
2018-02-14 08:27 - 2011-02-10 06:33 - 001596310 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-02-14 08:26 - 2009-07-13 18:34 - 000000478 _____ C:\Windows\win.ini
2018-02-14 07:00 - 2016-08-16 00:51 - 000002177 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-02-14 06:57 - 2014-12-26 22:13 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-02-14 06:55 - 2015-03-19 01:44 - 000000000 ____D C:\Program Files\Google
2018-02-14 06:55 - 2014-10-29 01:23 - 000000000 ____D C:\Program Files (x86)\Google
2018-02-09 01:35 - 2014-10-23 11:10 - 000153552 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avipbb.sys
2018-02-09 01:26 - 2015-01-20 23:23 - 000000000 ___RD C:\Users\s.wahl\Dropbox
2018-02-09 01:26 - 2014-11-11 06:23 - 000000000 ____D C:\Users\s.wahl\AppData\Roaming\Dropbox
2018-02-09 01:25 - 2017-01-17 10:25 - 000000000 ____D C:\Users\s.wahl\AppData\Local\CloudStationBackup
2018-02-07 05:57 - 2017-01-25 06:56 - 000000000 ____D C:\Users\s.wahl\Documents\Telekom
2018-02-06 03:55 - 2015-06-12 22:42 - 000001176 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2536871828-1541946132-2492561043-1000Core.job
2018-02-06 03:33 - 2014-10-20 14:15 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-02-06 03:33 - 2014-10-20 14:15 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-02-06 03:33 - 2014-10-20 14:15 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-02-06 03:33 - 2014-10-20 14:15 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-02-06 03:33 - 2014-10-20 14:15 - 000000000 ____D C:\Windows\System32\Macromed
2018-02-05 01:39 - 2014-11-06 06:54 - 000000000 ____D C:\Users\s.wahl\AppData\Roaming\Canon
2018-02-04 23:11 - 2018-01-08 00:29 - 000001674 _____ C:\Program Files (x86)\dsengine.cfg
2018-02-01 07:18 - 2014-10-29 00:45 - 000000000 ____D C:\ProgramData\CanonIJPLM
2018-01-29 23:37 - 2018-01-03 04:16 - 000003660 _____ C:\Windows\System32\Tasks\AviraSystemSpeedupUpdate
2018-01-29 23:37 - 2014-10-23 11:10 - 000000000 ____D C:\Program Files (x86)\Avira
2018-01-22 07:37 - 2014-10-20 14:19 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-01-22 06:19 - 2014-10-23 10:31 - 000120872 _____ C:\Users\s.wahl\AppData\Local\GDIPFONTCACHEV1.DAT
2018-01-22 02:41 - 2015-01-27 07:36 - 000000000 ____D C:\Program Files (x86)\MSXML 4.0
2018-01-22 02:40 - 2014-10-29 01:15 - 000000000 ____D C:\ProgramData\Brother
2018-01-18 03:53 - 2016-11-18 23:49 - 000010728 _____ C:\Users\s.wahl\Desktop\Sammelüberweisung mit Skonto.xlsx
Some files in TEMP:
====================
2014-10-23 11:11 - 2014-10-23 11:15 - 000000000 ____D () C:\Users\s.wahl\AppData\Local\Temp\avgnt.exe
2006-05-24 09:10 - 2006-05-24 09:10 - 000455600 ____R (Macrovision Corporation) C:\Users\s.wahl\AppData\Local\Temp\_isA2CD.exe
2006-05-24 09:10 - 2006-05-24 09:10 - 000455600 ____R (Macrovision Corporation) C:\Users\s.wahl\AppData\Local\Temp\_isA364.exe
==================== Known DLLs (Whitelisted) =========================
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe
[2018-01-08 23:15] - [2017-12-31 17:50] - 000455680 _____ (Microsoft Corporation) 11D6A262B617130F7C16E308C12E0D41
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2018-01-08 23:15] - [2017-12-31 18:18] - 000512000 _____ (Microsoft Corporation) BA6C9EE518A11DA4AD061B223EBED3D3
C:\Windows\System32\dnsapi.dll => MD5 is legit
C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Association (Whitelisted) =============
==================== Restore Points =========================
Restore point date: 2018-01-23 06:57
Restore point date: 2018-01-23 07:03
Restore point date: 2018-01-24 04:23
Restore point date: 2018-01-24 04:23
Restore point date: 2018-01-24 23:14
Restore point date: 2018-01-25 03:20
Restore point date: 2018-01-28 23:53
Restore point date: 2018-01-29 01:32
Restore point date: 2018-01-31 03:25
Restore point date: 2018-02-03 00:19
Restore point date: 2018-02-03 00:28
Restore point date: 2018-02-03 01:43
Restore point date: 2018-02-05 01:14
Restore point date: 2018-02-06 03:48
Restore point date: 2018-02-07 01:16
Restore point date: 2018-02-09 01:28
Restore point date: 2018-02-14 06:41
Restore point date: 2018-02-15 06:30
Restore point date: 2018-02-15 06:30
Restore point date: 2018-02-15 06:38
Restore point date: 2018-02-15 06:42
Restore point date: 2018-02-17 00:15
Restore point date: 2018-02-17 01:57
Restore point date: 2018-02-17 01:58
Restore point date: 2018-02-17 17:00
==================== Memory info ===========================
Percentage of memory in use: 13%
Total physical RAM: 8134.07 MB
Available physical RAM: 7025.43 MB
Total Virtual: 8134.07 MB
Available Virtual: 7049.67 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:226.7 GB) (Free:97.01 GB) NTFS
Drive d: (DATAPART1) (Fixed) (Total:931.51 GB) (Free:830.37 GB) NTFS
Drive j: (W8_1_MUI) (CDROM) (Total:6.91 GB) (Free:0 GB) UDF
Drive k: () (Removable) (Total:14.91 GB) (Free:5.89 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.49 GB) (Free:0.49 GB) NTFS
Drive y: (RECOVERY) (Fixed) (Total:11.73 GB) (Free:1.6 GB) NTFS ==>[system with boot components (obtained from drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 238.5 GB) (Disk ID: 82475ADB)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=11.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=226.7 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 39C80783)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
========================================================
Disk: 6 (Protective MBR) (Size: 14.9 GB) (Disk ID: 00000000)
Partition: GPT.
LastRegBack: 2018-02-16 00:11
==================== End of FRST.txt ============================
--- --- ---
__________________