Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 28.04.2014
Suchlauf-Zeit: 14:44:29
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.28.05
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Markus
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 252673
Verstrichene Zeit: 9 Min, 5 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 2
PUP.Optional.Conduit.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [04fcc13fc53bbf41abde8b8f5fa2d52b],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SearchProtect, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 2
PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll),Ersetzt,[0af68b75b44c5ba56425c3572ed358a8]
PUP.Optional.Conduit.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll),Ersetzt,[c838f7093ac600000d7c76a4ad548779]
Ordner: 21
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, Löschen bei Neustart, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, Löschen bei Neustart, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, Löschen bei Neustart, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\Logs, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, Löschen bei Neustart, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, Löschen bei Neustart, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.OpenCandy, C:\Users\Markus\AppData\Roaming\OpenCandy, In Quarantäne, [30d0ca36c7398c741d0788dc53af6898],
PUP.Optional.OpenCandy, C:\Users\Markus\AppData\Roaming\OpenCandy\DB9841FC3A0E4BD9BB7C3A500CC2848C, In Quarantäne, [30d0ca36c7398c741d0788dc53af6898],
Dateien: 81
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, Löschen bei Neustart, [04fcc13fc53bbf41abde8b8f5fa2d52b],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, Löschen bei Neustart, [3ac6df21cf3155ab16732bef3cc524dc],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll, Löschen bei Neustart, [0af68b75b44c5ba56425c3572ed358a8],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll, Löschen bei Neustart, [10f0f010f709e31d9bee27f3ac55c23e],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll, In Quarantäne, [c838f7093ac600000d7c76a4ad548779],
PUP.Optional.OpenCandy, C:\Users\Markus\Downloads\DTLite4491-0356.exe, In Quarantäne, [956b89771be553adbc3ed4819d67fa06],
PUP.Optional.Conduit.A, C:\Users\Markus\AppData\Local\DownloadGuide\SPIdentifier.exe, In Quarantäne, [8c74a65a4ab6788810894cbc57aafb05],
PUP.Optional.Conduit.A, C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ip6yhtgw.default\searchplugins\conduit-search.xml, In Quarantäne, [4ab66e92d42c14ec873f2f4c47bbff01],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll_1395938609611, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.jpg, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js, In Quarantäne, [46bad52bc53bee12a3a6dfc80ff40bf5],
PUP.Optional.Conduit.A, C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ip6yhtgw.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://search.conduit.com/?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=M51C7DC9D-63FC-499D-9CAC-42183CBA3099&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SP64833DFA-AB1D-4C40-95F3-F87DC335CBBB");), Ersetzt,[8d73a7598d73669ac671ce90907448b8]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner Logfile: Code:
# AdwCleaner v3.204 - Bericht erstellt am 28/04/2014 um 14:51:27
# Aktualisiert 26/04/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Markus - MARKUS-PC
# Gestartet von : C:\Users\Markus\Desktop\adwcleaner-3.204.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : bupService
[#] Dienst Gelöscht : SystemStoreService
Dienst Gelöscht : wStLibG64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\SoftwareUpdater
Ordner Gelöscht : C:\Users\Markus\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\Markus\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Markus\AppData\Roaming\BupSystem
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ip6yhtgw.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\FreeDriverScout
Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateveberGreat_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateveberGreat_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilveberGreat_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilveberGreat_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\veberGreat_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\veberGreat_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{502655BF-1153-4F2B-B690-B272A82F8F74}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{AC8CB492-A461-4661-92CA-C7E0EFAE3E4A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{502655BF-1153-4F2B-B690-B272A82F8F74}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\Software\SearchProtect
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ip6yhtgw.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Conduit Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Conduit Search");
*************************
AdwCleaner[R0].txt - [4176 octets] - [28/04/2014 14:50:12]
AdwCleaner[R1].txt - [4295 octets] - [28/04/2014 14:51:09]
AdwCleaner[S0].txt - [297 octets] - [28/04/2014 14:50:57]
AdwCleaner[S1].txt - [4082 octets] - [28/04/2014 14:51:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4142 octets] ########## --- --- ---
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Markus on 28.04.2014 at 14:55:13,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1195986596-1324513079-2585230413-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Myfree Codec
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Myfree Codec
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"
~~~ FireFox
Emptied folder: C:\Users\Markus\AppData\Roaming\mozilla\firefox\profiles\ip6yhtgw.default\minidumps [8 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.04.2014 at 14:59:05,13
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- --- Code:
can result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-04-2014
Ran by Markus (administrator) on MARKUS-PC on 28-04-2014 15:00:13
Running from C:\Users\Markus\Downloads
Windows 8.1 (Update 1) (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
(Infowatch) C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\LiveComm.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\ScanToPCActivationApp.exe
(Samsung) E:\Kies\Kies.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPNetworkCommunicatorCom.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Isku Keyboard\IskuMonitor.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Samsung Electronics Co., Ltd.) E:\Kies\KiesTrayAgent.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPNetworkCommunicator.exe
(Thisisu) C:\Users\Markus\Desktop\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7510232 2014-01-23] (Realtek Semiconductor)
HKLM\...\Run: [Cm106Sound] => C:\Windows\Syswow64\cm106.dll [12935168 2012-10-09] (C-Media Corporation)
HKLM-x32\...\Run: [RoccatIsku] => C:\Program Files (x86)\ROCCAT\Isku Keyboard\IskuMonitor.EXE [536576 2013-10-30] (ROCCAT GmbH)
HKLM-x32\...\Run: [RoccatKone+] => C:\Program Files (x86)\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.EXE [557056 2013-10-25] (ROCCAT GmbH)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\runner_avp.exe [24256 2013-11-11] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] => E:\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-1195986596-1324513079-2585230413-1001\...\Run: [HP Officejet 6500 E710a-f (NET)] => C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-1195986596-1324513079-2585230413-1001\...\Run: [KiesPreload] => E:\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
HKU\S-1-5-21-1195986596-1324513079-2585230413-1001\...\MountPoints2: {6a16b0c6-bf47-11e3-8254-08606e59436f} - "G:\Autorun.exe"
Startup: C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
Startup: C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 6500 E710a-f (Netzwerk).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 6500 E710a-f (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM-x32 - Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ip6yhtgw.default
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ip6yhtgw.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-25]
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\url_advisor@kaspersky.com [2014-03-25]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\virtual_keyboard@kaspersky.com [2014-03-25]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\content_blocker@kaspersky.com [2014-03-25]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\anti_banner@kaspersky.com [2014-03-25]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\online_banking@kaspersky.com [2014-03-25]
==================== Services (Whitelisted) =================
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [356128 2013-11-11] (Kaspersky Lab ZAO)
R2 CSObjectsSrv; C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [818888 2013-09-25] (Infowatch)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [49464 2014-03-06] (Hewlett-Packard Company)
R2 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-07-26] (Nitro PDF Software)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S3 Alpham1; C:\Windows\System32\drivers\Alpham164.sys [52992 2007-07-23] (Ideazon Corporation)
S3 Alpham2; C:\Windows\System32\drivers\Alpham264.sys [21760 2007-03-20] (Ideazon Corporation)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R3 cmuda3; C:\Windows\system32\drivers\cmudax3.sys [3848192 2012-09-28] (C-Media Inc)
R0 CSCrySec; C:\Windows\System32\DRIVERS\CSCrySec.sys [98504 2013-09-25] (Infowatch)
R1 CSVirtualDiskDrv; C:\Windows\system32\DRIVERS\CSVirtualDiskDrv.sys [67784 2013-09-25] (Infowatch)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-12] (Disc Soft Ltd)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-04-02] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29792 2013-11-11] (Kaspersky Lab)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-11-11] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625760 2013-11-11] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [28504 2013-11-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2013-11-11] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-11-11] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-11-11] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-11-11] (Kaspersky Lab ZAO)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation)
S3 SaiH0464; C:\Windows\system32\DRIVERS\SaiH0464.sys [171144 2007-05-01] (Saitek)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 USBMULCD; C:\Windows\system32\drivers\CM10664.sys [4120576 2012-10-04] (C-Media Electronics Inc)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation)
R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation)
R1 {85280d41-aaff-423b-b5f7-c41996a73cad}w64; C:\Windows\System32\drivers\{85280d41-aaff-423b-b5f7-c41996a73cad}w64.sys [61120 2014-04-24] (StdLib)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-28 14:59 - 2014-04-28 14:59 - 00001706 _____ () C:\Users\Markus\Desktop\JRT.txt
2014-04-28 14:55 - 2014-04-28 14:55 - 00000000 ____D () C:\Windows\ERUNT
2014-04-28 14:50 - 2014-04-28 14:51 - 00000000 ____D () C:\AdwCleaner
2014-04-28 14:48 - 2014-04-28 14:48 - 00017393 _____ () C:\Users\Markus\Desktop\mbam.txt
2014-04-28 14:45 - 2014-04-28 14:52 - 00027794 _____ () C:\Windows\PFRO.log
2014-04-28 14:32 - 2014-04-28 14:47 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-28 14:32 - 2014-04-28 14:32 - 00001124 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-28 14:32 - 2014-04-28 14:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-28 14:32 - 2014-04-28 14:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-28 14:32 - 2014-04-28 14:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-28 14:32 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-28 14:32 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-28 14:32 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-28 14:29 - 2014-04-28 14:30 - 01016261 _____ (Thisisu) C:\Users\Markus\Desktop\JRT.exe
2014-04-28 14:29 - 2014-04-28 14:29 - 01329501 _____ () C:\Users\Markus\Desktop\adwcleaner-3.204.exe
2014-04-28 14:27 - 2014-04-28 14:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Markus\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-28 12:41 - 2014-04-28 12:41 - 00025477 _____ () C:\Users\Markus\Downloads\logfiles.7z
2014-04-28 12:22 - 2014-04-28 12:22 - 00021762 _____ () C:\Users\Markus\Downloads\gmer.txt
2014-04-28 12:14 - 2014-04-28 15:00 - 00015981 _____ () C:\Users\Markus\Downloads\FRST.txt
2014-04-28 12:14 - 2014-04-28 15:00 - 00000000 ____D () C:\FRST
2014-04-28 12:14 - 2014-04-28 12:15 - 00023886 _____ () C:\Users\Markus\Downloads\Addition.txt
2014-04-28 12:13 - 2014-04-28 12:13 - 00000544 _____ () C:\Users\Markus\Downloads\defogger_disable.log
2014-04-28 12:13 - 2014-04-28 12:13 - 00000168 _____ () C:\Users\Markus\defogger_reenable
2014-04-28 12:09 - 2014-04-28 12:09 - 00380416 _____ () C:\Users\Markus\Downloads\Gmer-19357.exe
2014-04-28 12:09 - 2014-04-28 12:09 - 00050477 _____ () C:\Users\Markus\Downloads\Defogger.exe
2014-04-28 12:05 - 2014-04-28 12:06 - 02061824 _____ (Farbar) C:\Users\Markus\Downloads\FRST64.exe
2014-04-26 21:29 - 2014-04-26 21:29 - 30328333 _____ () C:\Users\Markus\Downloads\UH-1_20130810.zip
2014-04-26 21:29 - 2014-04-26 21:29 - 04170135 _____ () C:\Users\Markus\Downloads\apache_20110119.zip
2014-04-26 20:58 - 2014-04-26 20:58 - 00000000 ____D () C:\Users\Markus\Downloads\A-10_20121203
2014-04-26 20:57 - 2014-04-26 20:57 - 04212023 _____ () C:\Users\Markus\Downloads\Lockheed-SR71_20120507.zip
2014-04-26 20:56 - 2014-04-26 20:56 - 00984206 _____ () C:\Users\Markus\Downloads\F-117_20130317.zip
2014-04-26 20:55 - 2014-04-26 20:55 - 09328046 _____ () C:\Users\Markus\Downloads\A-10_20121203.zip
2014-04-26 20:20 - 2014-04-26 20:20 - 00000000 ____D () C:\ProgramData\Saitek
2014-04-26 20:17 - 2014-04-26 20:18 - 129201056 _____ (Mad catz ) C:\Users\Markus\Downloads\Smart Technology 7_0_27_13 64Bit.exe
2014-04-26 20:17 - 2014-04-26 20:17 - 02841532 _____ (Saitek ) C:\Users\Markus\Downloads\Saitek_Cyborg_Evo_SD6_64.exe
2014-04-26 20:10 - 2014-04-26 20:27 - 00056832 ___SH () C:\Users\Markus\Desktop\Thumbs.db
2014-04-26 20:05 - 2014-04-26 20:05 - 00000000 ____D () C:\Users\Markus\Documents\FlightGear
2014-04-26 20:05 - 2014-04-26 20:05 - 00000000 ____D () C:\Users\Markus\AppData\Local\CrashRpt
2014-04-26 20:03 - 2014-04-26 20:03 - 00000000 ____D () C:\Users\Markus\AppData\Roaming\fltk.org
2014-04-26 20:03 - 2014-04-26 20:03 - 00000000 ____D () C:\ProgramData\fltk.org
2014-04-26 20:02 - 2014-04-26 21:38 - 00000000 ____D () C:\Users\Markus\AppData\Roaming\flightgear.org
2014-04-26 20:02 - 2014-04-26 20:02 - 00000000 ____D () C:\ProgramData\flightgear.org
2014-04-26 19:54 - 2014-04-26 19:56 - 1062570539 _____ (The FlightGear Team ) C:\Users\Markus\Downloads\Setup_FlightGear_3.0.0__1_.exe
2014-04-26 14:23 - 2014-04-26 14:23 - 00076800 _____ () C:\Users\Markus\Downloads\panini_V3.xls
2014-04-25 14:19 - 2014-04-25 14:19 - 00000000 ____D () C:\Users\Markus\AppData\Roaming\dvdcss
2014-04-25 13:44 - 2014-04-24 12:20 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\{85280d41-aaff-423b-b5f7-c41996a73cad}w64.sys
2014-04-24 10:27 - 2014-04-24 10:28 - 00001681 _____ () C:\Users\Markus\Documents\Config.wtf.txt
2014-04-23 14:28 - 2014-04-25 14:58 - 00001693 _____ () C:\Windows\setupact.log
2014-04-23 14:28 - 2014-04-23 14:28 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-23 14:15 - 2014-04-23 14:15 - 04787368 _____ (Piriform Ltd) C:\Users\Markus\Downloads\ccsetup412.exe
2014-04-23 13:06 - 2014-02-22 18:59 - 01519520 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2014-04-23 13:06 - 2014-02-22 18:59 - 01290688 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2014-04-23 13:06 - 2014-02-22 18:59 - 00526304 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-04-23 13:06 - 2014-02-22 18:59 - 00461176 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2014-04-23 13:06 - 2014-02-22 18:59 - 00407536 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2014-04-23 13:06 - 2014-02-22 18:59 - 00289752 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2014-04-23 13:06 - 2014-02-22 18:59 - 00209160 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll
2014-04-23 13:06 - 2014-02-22 18:59 - 00139464 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2014-04-23 13:06 - 2014-02-22 18:59 - 00123448 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2014-04-23 13:06 - 2014-02-22 18:58 - 00036200 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2014-04-23 13:06 - 2014-02-22 18:15 - 01929608 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2014-04-23 13:06 - 2014-02-22 18:15 - 01206000 _____ (Microsoft Corporation) C:\Windows\system32\Taskmgr.exe
2014-04-23 13:06 - 2014-02-22 18:15 - 00531128 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-04-23 13:06 - 2014-02-22 18:15 - 00275312 _____ (Microsoft Corporation) C:\Windows\system32\powrprof.dll
2014-04-23 13:06 - 2014-02-22 18:15 - 00188464 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe
2014-04-23 13:06 - 2014-02-22 18:15 - 00071888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpfve.sys
2014-04-23 13:06 - 2014-02-22 18:02 - 00170952 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2014-04-23 13:06 - 2014-02-22 18:02 - 00083120 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-04-23 13:06 - 2014-02-22 18:02 - 00080048 _____ (Microsoft Corporation) C:\Windows\system32\taskhostex.exe
2014-04-23 13:06 - 2014-02-22 18:00 - 00590168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-04-23 13:06 - 2014-02-22 18:00 - 00249688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2014-04-23 13:06 - 2014-02-22 18:00 - 00236888 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2014-04-23 13:06 - 2014-02-22 18:00 - 00151384 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2014-04-23 13:06 - 2014-02-22 18:00 - 00079192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fileinfo.sys
2014-04-23 13:06 - 2014-02-22 17:59 - 00032088 _____ (Microsoft Corporation) C:\Windows\system32\ploptin.dll
2014-04-23 13:06 - 2014-02-22 17:59 - 00027480 _____ (Microsoft Corporation) C:\Windows\system32\SysResetErr.exe
2014-04-23 13:06 - 2014-02-22 17:55 - 01435304 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2014-04-23 13:06 - 2014-02-22 17:55 - 00388408 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2014-04-23 13:06 - 2014-02-22 17:55 - 00244848 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2014-04-23 13:06 - 2014-02-22 17:55 - 00162176 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe
2014-04-23 13:06 - 2014-02-22 17:55 - 00152848 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2014-04-23 13:06 - 2014-02-22 17:55 - 00131168 _____ (Microsoft Corporation) C:\Windows\system32\easinvoker.exe
2014-04-23 13:06 - 2014-02-22 17:55 - 00105864 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2014-04-23 13:06 - 2014-02-22 17:53 - 03394384 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2014-04-23 13:06 - 2014-02-22 17:50 - 02588168 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2014-04-23 13:06 - 2014-02-22 17:50 - 00761792 _____ (Microsoft Corporation) C:\Windows\system32\iuilp.dll
2014-04-23 13:06 - 2014-02-22 17:50 - 00645104 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-04-23 13:06 - 2014-02-22 17:50 - 00555736 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2014-04-23 13:06 - 2014-02-22 17:50 - 00258784 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2014-04-23 13:06 - 2014-02-22 17:50 - 00101216 _____ (Microsoft Corporation) C:\Windows\system32\RestoreOptIn.exe
2014-04-23 13:06 - 2014-02-22 17:50 - 00054816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wpcfltr.sys
2014-04-23 13:06 - 2014-02-22 17:50 - 00043408 _____ (Microsoft Corporation) C:\Windows\system32\CloudNotifications.exe
2014-04-23 13:06 - 2014-02-22 17:50 - 00032544 _____ (Microsoft Corporation) C:\Windows\system32\UserAccountBroker.exe
2014-04-23 13:06 - 2014-02-22 17:49 - 00384856 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2014-04-23 13:06 - 2014-02-22 17:49 - 00372568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-23 13:06 - 2014-02-22 17:49 - 00325464 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2014-04-23 13:06 - 2014-02-22 17:49 - 00280920 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2014-04-23 13:06 - 2014-02-22 17:49 - 00189784 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS
2014-04-23 13:06 - 2014-02-22 17:49 - 00148824 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-04-23 13:06 - 2014-02-22 17:49 - 00146776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys
2014-04-23 13:06 - 2014-02-22 17:49 - 00079192 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\sdstor.sys
2014-04-23 13:06 - 2014-02-22 17:48 - 02574240 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-04-23 13:06 - 2014-02-22 17:48 - 01791752 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll
2014-04-23 13:06 - 2014-02-22 17:48 - 00210736 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe
2014-04-23 13:06 - 2014-02-22 17:46 - 01927600 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2014-04-23 13:06 - 2014-02-22 17:46 - 01445616 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2014-04-23 13:06 - 2014-02-22 17:46 - 01000424 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2014-04-23 13:06 - 2014-02-22 17:46 - 00669896 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-04-23 13:06 - 2014-02-22 17:44 - 00924504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refs.sys
2014-04-23 13:06 - 2014-02-22 17:44 - 00539992 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2014-04-23 13:06 - 2014-02-22 17:44 - 00424280 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-04-23 13:06 - 2014-02-22 17:44 - 00360792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2014-04-23 13:06 - 2014-02-22 17:44 - 00311640 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-04-23 13:06 - 2014-02-22 17:43 - 01727760 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-04-23 13:06 - 2014-02-22 17:43 - 01659056 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-04-23 13:06 - 2014-02-22 17:43 - 01519592 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-04-23 13:06 - 2014-02-22 17:43 - 01487520 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-04-23 13:06 - 2014-02-22 17:43 - 01356360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-04-23 13:06 - 2014-02-22 17:43 - 00142576 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-04-23 13:06 - 2014-02-22 17:43 - 00094560 _____ (Microsoft Corporation) C:\Windows\system32\bcd.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 02142976 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 01399176 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 01374384 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 01215832 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 00881616 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 00800552 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 00609456 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 00391008 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 00372360 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 00324896 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2014-04-23 13:06 - 2014-02-22 17:41 - 00028416 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-04-23 13:06 - 2014-02-22 17:40 - 01118552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-04-23 13:06 - 2014-02-22 16:52 - 01767440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2014-04-23 13:06 - 2014-02-22 16:52 - 00251504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powrprof.dll
2014-04-23 13:06 - 2014-02-22 16:51 - 01063976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Taskmgr.exe
2014-04-23 13:06 - 2014-02-22 16:51 - 00140456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2014-04-23 13:06 - 2014-02-22 16:42 - 01017936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2014-04-23 13:06 - 2014-02-22 16:42 - 00422968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-04-23 13:06 - 2014-02-22 16:42 - 00410568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2014-04-23 13:06 - 2014-02-22 16:42 - 00369288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2014-04-23 13:06 - 2014-02-22 16:42 - 00232896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqmapi.dll
2014-04-23 13:06 - 2014-02-22 16:42 - 00137344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2014-04-23 13:06 - 2014-02-22 16:42 - 00098072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2014-04-23 13:06 - 2014-02-22 16:41 - 00033056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2014-04-23 13:06 - 2014-02-22 16:38 - 01374384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2014-04-23 13:06 - 2014-02-22 16:38 - 01077944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2014-04-23 13:06 - 2014-02-22 16:38 - 00506120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2014-04-23 13:06 - 2014-02-22 16:38 - 00336232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2014-04-23 13:06 - 2014-02-22 16:38 - 00089848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2014-04-23 13:06 - 2014-02-22 16:25 - 02410496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-04-23 13:06 - 2014-02-22 16:25 - 00180240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SndVol.exe
2014-04-23 13:06 - 2014-02-22 16:18 - 00477744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-04-23 13:06 - 2014-02-22 16:18 - 00419928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2014-04-23 13:06 - 2014-02-22 16:18 - 00089848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RestoreOptIn.exe
2014-04-23 13:06 - 2014-02-22 16:18 - 00041320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudNotifications.exe
2014-04-23 13:06 - 2014-02-22 16:18 - 00029912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserAccountBroker.exe
2014-04-23 13:06 - 2014-02-22 16:11 - 00490136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-04-23 13:06 - 2014-02-22 16:08 - 01474104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-04-23 13:06 - 2014-02-22 16:08 - 00079496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcd.dll
2014-04-23 13:06 - 2014-02-22 16:04 - 02144984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2014-04-23 13:06 - 2014-02-22 16:04 - 01206000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2014-04-23 13:06 - 2014-02-22 16:04 - 01011280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2014-04-23 13:06 - 2014-02-22 16:04 - 00707048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-04-23 13:06 - 2014-02-22 16:04 - 00650736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2014-04-23 13:06 - 2014-02-22 16:04 - 00518552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-04-23 13:06 - 2014-02-22 16:04 - 00317584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2014-04-23 13:06 - 2014-02-22 16:04 - 00296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll
2014-04-23 13:06 - 2014-02-22 16:04 - 00285144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2014-04-23 13:06 - 2014-02-22 14:24 - 02825216 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2014-04-23 13:06 - 2014-02-22 14:22 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-04-23 13:06 - 2014-02-22 14:20 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-system-events.dll
2014-04-23 13:06 - 2014-02-22 14:20 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-kernel-power-events.dll
2014-04-23 13:06 - 2014-02-22 14:17 - 00902144 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2014-04-23 13:06 - 2014-02-22 14:17 - 00890880 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2014-04-23 13:06 - 2014-02-22 14:17 - 00874496 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2014-04-23 13:06 - 2014-02-22 14:17 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\f3ahvoas.dll
2014-04-23 13:06 - 2014-02-22 14:17 - 00008192 ____H (Microsoft Corporation) C:\Windows\system32\ext-ms-win-ntuser-private-l1-1-1.dll
2014-04-23 13:06 - 2014-02-22 14:17 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\ext-ms-win-session-winsta-l1-1-0.dll
2014-04-23 13:06 - 2014-02-22 14:17 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\ext-ms-win-ntuser-private-l1-1-0.dll
2014-04-23 13:06 - 2014-02-22 14:17 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\ext-ms-win-kernel32-package-l1-1-1.dll
2014-04-23 13:06 - 2014-02-22 14:15 - 04192768 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-04-23 13:06 - 2014-02-22 14:14 - 00298496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-04-23 13:06 - 2014-02-22 14:14 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys
2014-04-23 13:06 - 2014-02-22 14:14 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\watchdog.sys
2014-04-23 13:06 - 2014-02-22 14:14 - 00033280 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\BasicRender.sys
2014-04-23 13:06 - 2014-02-22 14:11 - 00272896 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-04-23 13:06 - 2014-02-22 14:09 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-04-23 13:06 - 2014-02-22 14:08 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\OobeFldr.dll
2014-04-23 13:06 - 2014-02-22 14:08 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\syncui.dll
2014-04-23 13:06 - 2014-02-22 14:08 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2014-04-23 13:06 - 2014-02-22 14:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2014-04-23 13:06 - 2014-02-22 14:08 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-04-23 13:06 - 2014-02-22 14:08 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-04-23 13:06 - 2014-02-22 14:07 - 00545792 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2014-04-23 13:06 - 2014-02-22 14:07 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-04-23 13:06 - 2014-02-22 14:07 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\WofUtil.dll
2014-04-23 13:06 - 2014-02-22 14:07 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\clrhost.dll
2014-04-23 13:06 - 2014-02-22 14:06 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-04-23 13:06 - 2014-02-22 14:04 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\offreg.dll
2014-04-23 13:06 - 2014-02-22 14:03 - 00349696 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2014-04-23 13:06 - 2014-02-22 14:03 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2014-04-23 13:06 - 2014-02-22 14:02 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2014-04-23 13:06 - 2014-02-22 14:01 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\spcompat.dll
2014-04-23 13:06 - 2014-02-22 14:00 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-04-23 13:06 - 2014-02-22 14:00 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe
2014-04-23 13:06 - 2014-02-22 14:00 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\lpksetupproxyserv.dll
2014-04-23 13:06 - 2014-02-22 13:59 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgrade.exe
2014-04-23 13:06 - 2014-02-22 13:57 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\slc.dll
2014-04-23 13:06 - 2014-02-22 13:57 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-04-23 13:06 - 2014-02-22 13:54 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2014-04-23 13:06 - 2014-02-22 13:50 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\ActionQueue.dll
2014-04-23 13:06 - 2014-02-22 13:50 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2014-04-23 13:06 - 2014-02-22 13:48 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\ocsetapi.dll
2014-04-23 13:06 - 2014-02-22 13:47 - 00589312 _____ (Microsoft Corporation) C:\Windows\system32\vdsdyn.dll
2014-04-23 13:06 - 2014-02-22 13:47 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
2014-04-23 13:06 - 2014-02-22 13:47 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2014-04-23 13:06 - 2014-02-22 13:46 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-23 13:06 - 2014-02-22 13:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-04-23 13:06 - 2014-02-22 13:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll
2014-04-23 13:06 - 2014-02-22 13:45 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\fhevents.dll
2014-04-23 13:06 - 2014-02-22 13:44 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-23 13:06 - 2014-02-22 13:42 - 00038680 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentServer.exe
2014-04-23 13:06 - 2014-02-22 13:41 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe
2014-04-23 13:06 - 2014-02-22 13:39 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\fhsvcctl.dll
2014-04-23 13:06 - 2014-02-22 13:37 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe
2014-04-23 13:06 - 2014-02-22 13:34 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\dmdskmgr.dll
2014-04-23 13:06 - 2014-02-22 13:32 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2014-04-23 13:06 - 2014-02-22 13:30 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-23 13:06 - 2014-02-22 13:29 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\RelPost.exe
2014-04-23 13:06 - 2014-02-22 13:28 - 02428928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2014-04-23 13:06 - 2014-02-22 13:27 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\dot3mm.dll
2014-04-23 13:06 - 2014-02-22 13:25 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\recimg.exe
2014-04-23 13:06 - 2014-02-22 13:25 - 00307712 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-04-23 13:06 - 2014-02-22 13:25 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
2014-04-23 13:06 - 2014-02-22 13:25 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\sppnp.dll
2014-04-23 13:06 - 2014-02-22 13:25 - 00008192 ____H (Microsoft Corporation) C:\Windows\SysWOW64\ext-ms-win-ntuser-private-l1-1-1.dll
2014-04-23 13:06 - 2014-02-22 13:24 - 00800256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2014-04-23 13:06 - 2014-02-22 13:24 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2014-04-23 13:06 - 2014-02-22 13:24 - 00780288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2014-04-23 13:06 - 2014-02-22 13:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SSShim.dll
2014-04-23 13:06 - 2014-02-22 13:24 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\ext-ms-win-session-winsta-l1-1-0.dll
2014-04-23 13:06 - 2014-02-22 13:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\ext-ms-win-kernel32-package-l1-1-1.dll
2014-04-23 13:06 - 2014-02-22 13:22 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
2014-04-23 13:06 - 2014-02-22 13:22 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-04-23 13:06 - 2014-02-22 13:17 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-23 13:06 - 2014-02-22 13:17 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OobeFldr.dll
2014-04-23 13:06 - 2014-02-22 13:17 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\DAMM.dll
2014-04-23 13:06 - 2014-02-22 13:17 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\BulkOperationHost.exe
2014-04-23 13:06 - 2014-02-22 13:16 - 00617472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2014-04-23 13:06 - 2014-02-22 13:16 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-23 13:06 - 2014-02-22 13:16 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2014-04-23 13:06 - 2014-02-22 13:16 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-04-23 13:06 - 2014-02-22 13:16 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-04-23 13:06 - 2014-02-22 13:16 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clrhost.dll
2014-04-23 13:06 - 2014-02-22 13:15 - 00137728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imm32.dll
2014-04-23 13:06 - 2014-02-22 13:14 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\cleanmgr.exe
2014-04-23 13:06 - 2014-02-22 13:13 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offreg.dll
2014-04-23 13:06 - 2014-02-22 13:11 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spbcd.dll
2014-04-23 13:06 - 2014-02-22 13:09 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-04-23 13:06 - 2014-02-22 13:09 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgentc.exe
2014-04-23 13:06 - 2014-02-22 13:08 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll
2014-04-23 13:06 - 2014-02-22 13:08 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
2014-04-23 13:06 - 2014-02-22 13:07 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-04-23 13:06 - 2014-02-22 13:07 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\StorageContextHandler.dll
2014-04-23 13:06 - 2014-02-22 13:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-04-23 13:06 - 2014-02-22 13:06 - 00148992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slc.dll
2014-04-23 13:06 - 2014-02-22 13:05 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\RASMM.dll
2014-04-23 13:06 - 2014-02-22 13:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\pnpclean.dll
2014-04-23 13:06 - 2014-02-22 13:05 - 00095232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2014-04-23 13:06 - 2014-02-22 13:05 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentHost.dll
2014-04-23 13:06 - 2014-02-22 13:04 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\dfrgui.exe
2014-04-23 13:06 - 2014-02-22 13:03 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-04-23 13:06 - 2014-02-22 13:02 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContent.dll
2014-04-23 13:06 - 2014-02-22 13:02 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\acppage.dll
2014-04-23 13:06 - 2014-02-22 13:01 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-04-23 13:06 - 2014-02-22 13:01 - 00112640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe
2014-04-23 13:06 - 2014-02-22 13:00 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-23 13:06 - 2014-02-22 13:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-23 13:06 - 2014-02-22 12:59 - 01283584 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2014-04-23 13:06 - 2014-02-22 12:59 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2014-04-23 13:06 - 2014-02-22 12:59 - 00163328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ocsetapi.dll
2014-04-23 13:06 - 2014-02-22 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-23 13:06 - 2014-02-22 12:58 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll
2014-04-23 13:06 - 2014-02-22 12:58 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-23 13:06 - 2014-02-22 12:58 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\DAConn.dll
2014-04-23 13:06 - 2014-02-22 12:57 - 00165376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrobj.dll
2014-04-23 13:06 - 2014-02-22 12:57 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-04-23 13:06 - 2014-02-22 12:56 - 02862592 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2014-04-23 13:06 - 2014-02-22 12:56 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-04-23 13:06 - 2014-02-22 12:56 - 00350720 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll
2014-04-23 13:06 - 2014-02-22 12:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\dmvdsitf.dll
2014-04-23 13:06 - 2014-02-22 12:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\srrstr.dll
2014-04-23 13:06 - 2014-02-22 12:55 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\SrTasks.exe
2014-04-23 13:06 - 2014-02-22 12:54 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-23 13:06 - 2014-02-22 12:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PkgMgr.exe
2014-04-23 13:06 - 2014-02-22 12:52 - 02288640 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2014-04-23 13:06 - 2014-02-22 12:52 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\newdev.dll
2014-04-23 13:06 - 2014-02-22 12:51 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\spwizeng.dll
2014-04-23 13:06 - 2014-02-22 12:50 - 00136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskpart.exe
2014-04-23 13:06 - 2014-02-22 12:47 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmdskmgr.dll
2014-04-23 13:06 - 2014-02-22 12:47 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\migisol.dll
2014-04-23 13:06 - 2014-02-22 12:47 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupugc.exe
2014-04-23 13:06 - 2014-02-22 12:47 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-23 13:06 - 2014-02-22 12:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\dfp.exe
2014-04-23 13:06 - 2014-02-22 12:46 - 00283136 _____ (Microsoft Corporation) C:\Windows\system32\wbadmin.exe
2014-04-23 13:06 - 2014-02-22 12:44 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-23 13:06 - 2014-02-22 12:41 - 02566656 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll
2014-04-23 13:06 - 2014-02-22 12:41 - 00878592 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll
2014-04-23 13:06 - 2014-02-22 12:41 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-04-23 13:06 - 2014-02-22 12:41 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\netid.dll
2014-04-23 13:06 - 2014-02-22 12:40 - 00304640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-04-23 13:06 - 2014-02-22 12:40 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
2014-04-23 13:06 - 2014-02-22 12:39 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-04-23 13:06 - 2014-02-22 12:38 - 00390656 _____ (Microsoft Corporation) C:\Windows\system32\DfpCommon.dll
2014-04-23 13:06 - 2014-02-22 12:38 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll
2014-04-23 13:06 - 2014-02-22 12:37 - 00912384 _____ (Microsoft Corporation) C:\Windows\system32\nettrace.dll
2014-04-23 13:06 - 2014-02-22 12:36 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-23 13:06 - 2014-02-22 12:36 - 00441344 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-04-23 13:06 - 2014-02-22 12:36 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-04-23 13:06 - 2014-02-22 12:36 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-23 13:06 - 2014-02-22 12:35 - 00504832 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
2014-04-23 13:06 - 2014-02-22 12:35 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\aitagent.exe
2014-04-23 13:06 - 2014-02-22 12:34 - 11742720 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll
2014-04-23 13:06 - 2014-02-22 12:34 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2014-04-23 13:06 - 2014-02-22 12:33 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-23 13:06 - 2014-02-22 12:33 - 00402944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2014-04-23 13:06 - 2014-02-22 12:32 - 00118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-04-23 13:06 - 2014-02-22 12:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-23 13:06 - 2014-02-22 12:30 - 00213504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cleanmgr.exe
2014-04-23 13:06 - 2014-02-22 12:29 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-04-23 13:06 - 2014-02-22 12:28 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-04-23 13:06 - 2014-02-22 12:27 - 00397824 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2014-04-23 13:06 - 2014-02-22 12:25 - 01428480 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2014-04-23 13:06 - 2014-02-22 12:25 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StorageContextHandler.dll
2014-04-23 13:06 - 2014-02-22 12:22 - 00606208 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2014-04-23 13:06 - 2014-02-22 12:21 - 00561664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfrgui.exe
2014-04-23 13:06 - 2014-02-22 12:21 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-04-23 13:06 - 2014-02-22 12:21 - 00045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\acppage.dll
2014-04-23 13:06 - 2014-02-22 12:20 - 01152512 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
2014-04-23 13:06 - 2014-02-22 12:18 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-04-23 13:06 - 2014-02-22 12:18 - 00722432 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeui.exe
2014-04-23 13:06 - 2014-02-22 12:18 - 00488448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-04-23 13:06 - 2014-02-22 12:17 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\fhcfg.dll
2014-04-23 13:06 - 2014-02-22 12:17 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-23 13:06 - 2014-02-22 12:17 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2014-04-23 13:06 - 2014-02-22 12:16 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sud.dll
2014-04-23 13:06 - 2014-02-22 12:16 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srchadmin.dll
2014-04-23 13:06 - 2014-02-22 12:16 - 00151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2014-04-23 13:06 - 2014-02-22 12:15 - 01543680 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2014-04-23 13:06 - 2014-02-22 12:14 - 02811392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2014-04-23 13:06 - 2014-02-22 12:14 - 02165760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncCenter.dll
2014-04-23 13:06 - 2014-02-22 12:14 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2014-04-23 13:06 - 2014-02-22 12:13 - 00897024 _____ (Microsoft Corporation) C:\Windows\system32\sdclt.exe
2014-04-23 13:06 - 2014-02-22 12:13 - 00557056 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs.dll
2014-04-23 13:06 - 2014-02-22 12:13 - 00307200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\newdev.dll
2014-04-23 13:06 - 2014-02-22 12:12 - 00797696 _____ (Microsoft Corporation) C:\Windows\system32\PurchaseWindowsLicense.dll
2014-04-23 13:06 - 2014-02-22 12:12 - 00352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwizeng.dll
2014-04-23 13:06 - 2014-02-22 12:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-04-23 13:06 - 2014-02-22 12:09 - 01224192 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2014-04-23 13:06 - 2014-02-22 12:09 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-23 13:06 - 2014-02-22 12:09 - 00097280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\migisol.dll
2014-04-23 13:06 - 2014-02-22 12:09 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-23 13:06 - 2014-02-22 12:08 - 00997888 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2014-04-23 13:06 - 2014-02-22 12:06 - 02943488 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-04-23 13:06 - 2014-02-22 12:05 - 01757184 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
2014-04-23 13:06 - 2014-02-22 12:04 - 00935424 _____ (Microsoft Corporation) C:\Windows\system32\rasgcw.dll
2014-04-23 13:06 - 2014-02-22 12:04 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\WLanConn.dll
2014-04-23 13:06 - 2014-02-22 12:04 - 00098304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netid.dll
2014-04-23 13:06 - 2014-02-22 12:03 - 02544128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themecpl.dll
2014-04-23 13:06 - 2014-02-22 12:03 - 00779264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-04-23 13:06 - 2014-02-22 12:02 - 08946688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
2014-04-23 13:06 - 2014-02-22 12:02 - 00258560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2014-04-23 13:06 - 2014-02-22 12:01 - 02648064 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2014-04-23 13:06 - 2014-02-22 12:01 - 01227776 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-04-23 13:06 - 2014-02-22 12:01 - 00832512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActionCenter.dll
2014-04-23 13:06 - 2014-02-22 12:01 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2014-04-23 13:06 - 2014-02-22 12:00 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-23 13:06 - 2014-02-22 12:00 - 00217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2014-04-23 13:06 - 2014-02-22 11:59 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\mdmregistration.dll
2014-04-23 13:06 - 2014-02-22 11:59 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\wmpdxm.dll
2014-04-23 13:06 - 2014-02-22 11:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-04-23 13:06 - 2014-02-22 11:57 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2014-04-23 13:06 - 2014-02-22 11:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2014-04-23 13:06 - 2014-02-22 11:55 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-23 13:06 - 2014-02-22 11:54 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\GlobCollationHost.dll
2014-04-23 13:06 - 2014-02-22 11:54 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll
2014-04-23 13:06 - 2014-02-22 11:54 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-04-23 13:06 - 2014-02-22 11:54 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\deviceassociation.dll
2014-04-23 13:06 - 2014-02-22 11:53 - 00825344 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2014-04-23 13:06 - 2014-02-22 11:53 - 00545280 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2014-04-23 13:06 - 2014-02-22 11:52 - 01132032 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2014-04-23 13:06 - 2014-02-22 11:52 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.exe
2014-04-23 13:06 - 2014-02-22 11:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\winbrand.dll
2014-04-23 13:06 - 2014-02-22 11:49 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftAccountTokenProvider.dll
2014-04-23 13:06 - 2014-02-22 11:48 - 01136128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl
2014-04-23 13:06 - 2014-02-22 11:48 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-04-23 13:06 - 2014-02-22 11:48 - 00355328 _____ (Microsoft Corporation) C:\Windows\system32\wincorlib.dll
2014-04-23 13:06 - 2014-02-22 11:48 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2014-04-23 13:06 - 2014-02-22 11:47 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2014-04-23 13:06 - 2014-02-22 11:46 - 00528896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2014-04-23 13:06 - 2014-02-22 11:46 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\winsku.dll
2014-04-23 13:06 - 2014-02-22 11:45 - 00562176 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-04-23 13:06 - 2014-02-22 11:45 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2014-04-23 13:06 - 2014-02-22 11:45 - 00453632 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2014-04-23 13:06 - 2014-02-22 11:45 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-04-23 13:06 - 2014-02-22 11:45 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\WiFiDisplay.dll
2014-04-23 13:06 - 2014-02-22 11:44 - 00675328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2014-04-23 13:06 - 2014-02-22 11:44 - 00356864 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-04-23 13:06 - 2014-02-22 11:44 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\korwbrkr.dll
2014-04-23 13:06 - 2014-02-22 11:43 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll |