ChriSlater | 15.08.2015 23:44 | Zur Info:
Der Adwcleaner hat bei mir beim Neustart nicht die Log-Datei angezeigt.
Deshalb habe ich ihn nochmal laufen lassen(er hat auch was anderes gefunden) und vor "Cleaning" auf "Log-File" geklickt um mir das File anzeigen zu lassen. Er legt es bei mir unter C:\ ab...
Vielleicht hat sich in der Version 5.000 da was geändert? Evtl. könnt Ihr ja die Anleitung anpassen.
Hier das erste log vom AdwCleaner: Code:
# AdwCleaner v5.000 - Logfile created 16/08/2015 at 00:11:14
# Updated 14/08/2015 by Xplode
# Database : 2015-08-15.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : FS1 - FS1-PC
# Running from : C:\Users\Florian und Herminia\Downloads\AdwCleaner_5.000.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files (x86)\eSupport.com
[-] Folder Deleted : C:\Users\FS1\AppData\Local\eSupport.com
***** [ Files ] *****
[-] File Deleted : C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\foxydeal.sqlite
[-] File Deleted : C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\foxydeal.sqlite
[-] File Deleted : C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\user.js
[-] File Deleted : C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\user.js
[-] File Deleted : C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\foxydeal.sqlite
[-] File Deleted : C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\foxydeal.sqlite
[-] File Deleted : C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\user.js
[-] File Deleted : C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\user.js
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKCU\Software\eSupport.com
[!] Key Not Deleted : [x64] HKCU\Software\eSupport.com
***** [ Web browsers ] *****
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("avira.safe_search.installed", "[\"safesearch\"]");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...]
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.irmysearch.aflt", "irmsd0103");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.irmysearch.cr", "593320036");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.irmysearch.instlRef", "");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.m.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/BtAyE0A0F0C0E0EyE0EyEyDyCtN0DtAtDtC1N1R&cr=593320036&ir=");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.AL", 2);
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.aflt", "irmsd0103");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.cr", "593320036");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.dfltLng", "");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.dfltSrch", true);
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.dnsErr", true);
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.excTlbr", false);
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.hmpg", true);
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0103&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutB[...]
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.id", "902B34AFCEE4E456");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.instlDay", "16100");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.instlRef", "");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=irmsd0103&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1Czu[...]
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.tlbrId", "base");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=irmsd0103&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1C[...]
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial_i.hmpg", true);
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial_i.newTab", false);
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.023:51:35");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"147d5e562a4eb-0f93a80dda1d1b-42504136-0-147d5e562a51c3\"");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.safesearch.SAUTH_expires_at", "1432386957");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.safesearch.SAUTH_rndsnr", "\"2d1d99836bf6c10469db30b759511aa277e39540\"");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.safesearch.SAUTH_userid", "4293041816");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.safesearch.SAUTH_utoken", "\"3c65cfa91f8acc91ac6304a40cbecb105d1f9be0\"");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.safesearch.install", "1408042885800");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.safesearch.search_offer_disabled", "true");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.xpiState", "{\"app-profile\":{\"abs@avira.com\":{\"d\":\"C:\\\\Users\\\\Florian und Herminia\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ij2eysyr.default\\\\extens[...]
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("browser.search.order.1", "Mysearchdial");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.irmysearch.aflt", "irmsd0103");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.irmysearch.cr", "593320036");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.irmysearch.instlRef", "");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.aflt", "irmsd0103");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.cntry", "DE");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.cr", "593320036");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.dfltLng", "");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.dfltSrch", true);
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.dnsErr", true);
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...]
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.excTlbr", false);
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.hdrMd5", "CE8CD6F9E65E7A1F6490CC62FE642368");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.hmpg", true);
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0103&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutB[...]
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.id", "902B34AFCEE4E456");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.instlDay", "16100");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.instlRef", "");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0103&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtA[...]
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.21.023:51:35");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=irmsd0103&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1Czu[...]
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.sg", "none");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.tlbrId", "base");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=irmsd0103&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0A0F0C0E0EyE0EyEyDyCtN0D0Tzu0SyByCtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1C[...]
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial_i.hmpg", true);
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial_i.newTab", false);
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none");
[-] [C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\prefs.js] [Preference] Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.023:51:35");
*************************
:: Proxy settings cleared
:: Winsock settings cleared
!! Unable to delete Internet Explorer policies
!! Unable to delete Chrome policies
########## EOF - \AdwCleaner[C2].txt - [17795 octets] ########## Und nach dem zweiten Durchlauf: Code:
# AdwCleaner v5.000 - Logfile created 16/08/2015 at 00:24:31
# Updated 14/08/2015 by Xplode
# Database : 2015-08-15.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : FS1 - FS1-PC
# Running from : C:\Users\Florian und Herminia\Downloads\AdwCleaner_5.000.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
***** [ Web browsers ] *****
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("avira.safe_search.installed", "[\"safesearch\"]");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...]
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.ich@maltegoetz.de.tr_web_session", "{\"id\":\"RPXQ19EDYWPLnDUjfnrEIYM1wWQUETqq\",\"ts\":\"1439676931970\",\"prev\":\"hxxp%3A%2F%2Fwww.trojaner-board.de%2F169747-windows-7-malware[...]
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"aff6841090c9255bec520273e18b3721c1608139\"");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.safesearch.install", "1439676913899");
[-] [C:\Users\Florian und Herminia\AppData\Roaming\Mozilla\Firefox\Profiles\ij2eysyr.default\prefs.js] [Preference] Deleted : user_pref("extensions.xpiState", "{\"app-profile\":{\"abs@avira.com\":{\"d\":\"C:\\\\Users\\\\Florian und Herminia\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ij2eysyr.default\\\\extens[...]
*************************
:: Proxy settings cleared
:: Winsock settings cleared
!! Unable to delete Internet Explorer policies
!! Unable to delete Chrome policies
########## EOF - \AdwCleaner[C3].txt - [2315 octets] ########## Hier das Logfile vom Junkware Removal Tool: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.6 (08.10.2015:1)
OS: Windows 7 Home Premium x64
Ran by FS1 on 16.08.2015 at 0:33:25,42
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update BrowseMark
~~~ Files
~~~ Folders
~~~ Chrome
[C:\Users\FS1\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\FS1\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\FS1\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\FS1\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.08.2015 at 0:36:18,51
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und FRST: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:14-08-2015
durchgeführt von FS1 (Administrator) auf FS1-PC (16-08-2015 00:37:52)
Gestartet von C:\Users\Florian und Herminia\Downloads
Geladene Profile: FS1 & Florian und Herminia (Verfügbare Profile: FS1 & Florian und Herminia)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\reader_sl.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13776088 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1391472 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [782008 2015-07-28] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [186408 2013-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2715536 2015-04-10] (Dominik Reichl)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [Diamondback] => C:\Program Files (x86)\Razer\Diamondback\Razer\Diamondback\razerhid.exe [226816 2009-10-09] ()
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1279120 2012-09-27] (CANON INC.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452272 2012-08-31] (CANON INC.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [134368 2015-07-02] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [56080 2015-07-27] (Raptr, Inc)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-07-28] (Advanced Micro Devices, Inc.)
HKLM\...\RunOnce: [*WerKernelReporting] => C:\Windows\SYSTEM32\WerFault.exe [415232 2009-07-14] (Microsoft Corporation)
HKLM-x32\...\RunOnce: [EasyTuneVI] => C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [40960 2012-07-09] ()
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-06-18] (Malwarebytes Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-482367994-563254700-3851287216-1000\...\Run: [Update Service] => C:\Program Files (x86)\Common Files\Teknum Systems\update.exe [19456 2014-01-30] (Teknum Systems AS)
HKU\S-1-5-21-482367994-563254700-3851287216-1000\...\Run: [PureSync] => C:\Program Files (x86)\PureSync\PureSyncTray.exe [997040 2015-05-19] (Jumping Bytes)
HKU\S-1-5-21-482367994-563254700-3851287216-1000\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)
HKU\S-1-5-21-482367994-563254700-3851287216-1000\...\Run: [Desura] => C:\Program Files (x86)\Desura\desura.exe [2679392 2015-07-06] (Desura Net Pty Ltd)
HKU\S-1-5-21-482367994-563254700-3851287216-1000\...\Run: [Comrade.exe] => C:\Program Files (x86)\GameSpy\Comrade\Comrade.exe
HKU\S-1-5-21-482367994-563254700-3851287216-1000\...\Run: [Turn Off Monitor] => C:\Program Files (x86)\Turn Off Monitor\TurnOffMon.exe :silent
HKU\S-1-5-21-482367994-563254700-3851287216-1000\...\Run: [Auto LogOff] => C:\Program Files (x86)\Turn Off Monitor\AutoLogOff.exe :silent
HKU\S-1-5-21-482367994-563254700-3851287216-1000\...\RunOnce: [Report] => \AdwCleaner[C3].txt [2382 2015-08-16] ()
HKU\S-1-5-21-482367994-563254700-3851287216-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-482367994-563254700-3851287216-1002\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-482367994-563254700-3851287216-1002\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-482367994-563254700-3851287216-1002\...\Run: [AppleIEDAV] => C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1080104 2014-08-04] (Apple Inc.)
HKU\S-1-5-21-482367994-563254700-3851287216-1002\...\Run: [PureSync] => C:\Program Files (x86)\PureSync\PureSyncTray.exe [997040 2015-05-19] (Jumping Bytes)
HKU\S-1-5-21-482367994-563254700-3851287216-1002\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-01-30]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Florian und Herminia\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Florian und Herminia\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Florian und Herminia\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Florian und Herminia\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll Keine Datei
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\FS1\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\FS1\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\FS1\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-482367994-563254700-3851287216-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-482367994-563254700-3851287216-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt
SearchScopes: HKU\S-1-5-21-482367994-563254700-3851287216-1000 -> DefaultScope {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll [2014-01-24] (CANON INC.)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-01-24] (CANON INC.)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-08-06] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-06] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll [2014-01-24] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-01-24] (CANON INC.)
DPF: HKLM {AA570693-00E2-4907-B6F1-60A1199B030C} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://enter.myvtg.com/dana-cached/sc/JuniperSetupClient.cab
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{4075167C-F8E9-42EC-8410-32FC3C3D03C1}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default
FF NewTab: about:blank
FF DefaultSearchUrl: hxxp://www.google.de
FF Homepage: hxxp://www.google.de/
FF Keyword.URL:
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [2014-12-03] (EA Digital Illusions CE AB)
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2014-07-28] (CANON INC.)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [Keine Datei]
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll [Keine Datei]
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2014-12-03] (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-06] (Oracle Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-482367994-563254700-3851287216-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\FS1\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-07-07] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-482367994-563254700-3851287216-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Florian und Herminia\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-07-07] (Unity Technologies ApS)
FF Extension: FoxyProxy Standard - C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\Extensions\foxyproxy-basic@eric.h.jung [2014-01-30]
FF Extension: ProxTube - Unblock YouTube - C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\Extensions\ich@maltegoetz.de [2014-01-30]
FF Extension: KeeFox - C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\Extensions\keefox@chris.tomlinson [2014-01-30]
FF Extension: FireShot - C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2014-01-30]
FF Extension: EPUBReader - C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F} [2014-01-30]
FF Extension: WOT - C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-01-30]
FF Extension: NoScript - C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-30]
FF Extension: Adblock Plus - C:\Users\FS1\AppData\Roaming\Mozilla\Firefox\Profiles\88w9tvn9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-30]
Chrome:
=======
CHR Profile: C:\Users\FS1\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-07-28] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [887128 2015-07-28] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [461672 2015-07-28] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [461672 2015-07-28] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1213072 2015-07-28] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [218816 2015-07-02] (Avira Operations GmbH & Co. KG)
S2 backupsvc5; C:\Program Files (x86)\Digital Dynamic\Advanced Backup Manager\backupsvc5.exe [1382912 2015-03-17] () [Datei ist nicht signiert]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [814464 2015-03-06] ()
S2 gadjservice; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [16896 2015-04-14] () [Datei ist nicht signiert]
S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [Datei ist nicht signiert]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1997168 2015-06-17] (Electronic Arts)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-11-09] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162528 2015-07-28] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [141416 2015-07-28] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-07-10] (Disc Soft Ltd)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2015-04-16] ()
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2014-12-26] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
S3 Razerlow; C:\Windows\System32\drivers\Razerlow.sys [21120 2005-11-07] (Razer (Asia-Pacific) Pte Ltd)
S2 AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Personal 2014.SP3e\WNt600x64\Sandra.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-08-16 00:36 - 2015-08-16 00:36 - 00001181 _____ C:\Users\FS1\Desktop\JRT.txt
2015-08-16 00:36 - 2015-08-16 00:36 - 00001181 _____ C:\JRT.txt
2015-08-16 00:32 - 2015-08-16 00:32 - 01791580 _____ (Malwarebytes Corporation) C:\Users\Florian und Herminia\Downloads\JRT.exe
2015-08-16 00:24 - 2015-08-16 00:24 - 00002382 _____ C:\AdwCleaner[C3].txt
2015-08-16 00:23 - 2015-08-16 00:24 - 00002170 _____ C:\AdwCleaner[S6].txt
2015-08-16 00:20 - 2015-08-16 00:22 - 00002170 _____ C:\AdwCleaner[S5].txt
2015-08-16 00:19 - 2015-08-16 00:20 - 00002170 _____ C:\AdwCleaner[S4].txt
2015-08-16 00:11 - 2015-08-16 00:11 - 00017867 _____ C:\AdwCleaner[C2].txt
2015-08-16 00:09 - 2015-08-16 00:10 - 00017147 _____ C:\AdwCleaner[S3].txt
2015-08-16 00:08 - 2015-08-16 00:08 - 01563648 _____ C:\Users\Florian und Herminia\Downloads\AdwCleaner_5.000.exe
2015-08-14 22:17 - 2015-08-16 00:37 - 00021626 _____ C:\Users\Florian und Herminia\Downloads\FRST.txt
2015-08-14 22:17 - 2015-08-14 22:18 - 00067970 _____ C:\Users\Florian und Herminia\Downloads\Addition.txt
2015-08-14 22:02 - 2015-08-14 22:02 - 901412676 _____ C:\Windows\MEMORY.DMP
2015-08-14 22:02 - 2015-08-14 22:02 - 00276864 _____ C:\Windows\Minidump\081415-22495-01.dmp
2015-08-14 21:55 - 2015-08-16 00:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-14 21:16 - 2015-08-14 21:16 - 00380416 _____ C:\Users\Florian und Herminia\Downloads\Gmer-19357.exe
2015-08-14 21:15 - 2015-08-14 21:25 - 00000000 ____D C:\Users\Florian und Herminia\Downloads\Log-Files Trojan Scan
2015-08-14 21:13 - 2015-08-14 21:13 - 00050477 _____ C:\Users\Florian und Herminia\Downloads\Defogger.exe
2015-08-14 21:13 - 2015-08-14 21:13 - 00000538 _____ C:\Users\Florian und Herminia\Downloads\defogger_disable.log
2015-08-14 21:13 - 2015-08-14 21:13 - 00000168 _____ C:\Users\FS1\defogger_reenable
2015-08-14 21:06 - 2015-08-16 00:37 - 00000000 ____D C:\FRST
2015-08-14 21:05 - 2015-08-14 21:06 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-14 21:05 - 2015-08-14 21:05 - 02173952 _____ (Farbar) C:\Users\Florian und Herminia\Downloads\FRST64.exe
2015-08-14 21:05 - 2015-08-14 21:05 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-08-14 21:05 - 2015-08-14 21:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-14 21:04 - 2015-08-14 21:04 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-14 21:04 - 2015-08-14 21:04 - 00000000 ____D C:\Program Files\Common Files\AV
2015-08-14 21:04 - 2015-08-14 21:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-14 21:04 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-14 21:04 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-14 21:04 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-14 21:03 - 2015-08-14 21:04 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Florian und Herminia\Downloads\mbam-setup-2.1.8.1057.exe
2015-08-14 19:42 - 2015-08-14 19:42 - 00000000 ____D C:\ProgramData\Jumping Bytes
2015-08-14 19:38 - 2015-08-14 19:38 - 06609608 _____ (Piriform Ltd) C:\Users\FS1\Downloads\ccsetup508.exe
2015-08-12 22:36 - 2015-07-30 15:13 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 22:36 - 2015-07-30 15:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 21:43 - 2015-08-12 21:43 - 00038912 _____ C:\Users\Florian und Herminia\Downloads\Rücklage 2012-2015(1) - Backup 08-2015.xls
2015-08-12 20:44 - 2015-07-21 02:39 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-12 20:44 - 2015-07-21 02:12 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-08-12 20:44 - 2015-07-16 23:14 - 25192448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-12 20:44 - 2015-07-16 22:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-12 20:44 - 2015-07-16 22:54 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-12 20:44 - 2015-07-16 22:37 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-12 20:44 - 2015-07-16 22:36 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-12 20:44 - 2015-07-16 22:36 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-12 20:44 - 2015-07-16 22:36 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-12 20:44 - 2015-07-16 22:35 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-12 20:44 - 2015-07-16 22:35 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-12 20:44 - 2015-07-16 22:27 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-12 20:44 - 2015-07-16 22:26 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-12 20:44 - 2015-07-16 22:26 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-12 20:44 - 2015-07-16 22:23 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-12 20:44 - 2015-07-16 22:21 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-12 20:44 - 2015-07-16 22:21 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-12 20:44 - 2015-07-16 22:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-12 20:44 - 2015-07-16 22:21 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-12 20:44 - 2015-07-16 22:20 - 19870208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-12 20:44 - 2015-07-16 22:12 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-12 20:44 - 2015-07-16 22:08 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-12 20:44 - 2015-07-16 22:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-08-12 20:44 - 2015-07-16 22:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-12 20:44 - 2015-07-16 21:55 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-12 20:44 - 2015-07-16 21:54 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-12 20:44 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-08-12 20:44 - 2015-07-16 21:51 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-12 20:44 - 2015-07-16 21:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-08-12 20:44 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-08-12 20:44 - 2015-07-16 21:50 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-08-12 20:44 - 2015-07-16 21:49 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-08-12 20:44 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-12 20:44 - 2015-07-16 21:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-08-12 20:44 - 2015-07-16 21:43 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-08-12 20:44 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-08-12 20:44 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-08-12 20:44 - 2015-07-16 21:39 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-08-12 20:44 - 2015-07-16 21:38 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-08-12 20:44 - 2015-07-16 21:36 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-12 20:44 - 2015-07-16 21:35 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-12 20:44 - 2015-07-16 21:34 - 14451200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-12 20:44 - 2015-07-16 21:33 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-12 20:44 - 2015-07-16 21:32 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-12 20:44 - 2015-07-16 21:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-08-12 20:44 - 2015-07-16 21:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-12 20:44 - 2015-07-16 21:20 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-08-12 20:44 - 2015-07-16 21:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-08-12 20:44 - 2015-07-16 21:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-08-12 20:44 - 2015-07-16 21:12 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-08-12 20:44 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-12 20:44 - 2015-07-16 21:12 - 02427904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-12 20:44 - 2015-07-16 21:12 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-08-12 20:44 - 2015-07-16 21:12 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-08-12 20:44 - 2015-07-16 21:11 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-12 20:44 - 2015-07-16 21:11 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-08-12 20:44 - 2015-07-16 21:11 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-08-12 20:44 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-12 20:44 - 2015-07-16 21:06 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-08-12 20:44 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-08-12 20:44 - 2015-07-16 21:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-08-12 20:44 - 2015-07-16 21:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-12 20:44 - 2015-07-16 20:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-12 20:44 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-12 20:44 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-12 20:44 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-08-12 20:44 - 2015-07-15 20:15 - 05568960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-12 20:44 - 2015-07-15 20:15 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-12 20:44 - 2015-07-15 20:15 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-08-12 20:44 - 2015-07-15 20:15 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-12 20:44 - 2015-07-15 20:12 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-12 20:44 - 2015-07-15 20:11 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-08-12 20:44 - 2015-07-15 20:11 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-08-12 20:44 - 2015-07-15 20:11 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-08-12 20:44 - 2015-07-15 20:11 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-08-12 20:44 - 2015-07-15 20:11 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 01743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-08-12 20:44 - 2015-07-15 20:10 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-08-12 20:44 - 2015-07-15 20:10 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-08-12 20:44 - 2015-07-15 20:10 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-08-12 20:44 - 2015-07-15 20:10 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-12 20:44 - 2015-07-15 20:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-08-12 20:44 - 2015-07-15 20:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-08-12 20:44 - 2015-07-15 20:05 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-08-12 20:44 - 2015-07-15 20:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:59 - 03989952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-08-12 20:44 - 2015-07-15 19:59 - 03934656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-08-12 20:44 - 2015-07-15 19:56 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-12 20:44 - 2015-07-15 19:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-08-12 20:44 - 2015-07-15 19:55 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-08-12 20:44 - 2015-07-15 19:55 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-08-12 20:44 - 2015-07-15 19:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-08-12 20:44 - 2015-07-15 19:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-08-12 20:44 - 2015-07-15 19:54 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-08-12 20:44 - 2015-07-15 19:54 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-08-12 20:44 - 2015-07-15 19:54 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-08-12 20:44 - 2015-07-15 19:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-08-12 20:44 - 2015-07-15 19:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-08-12 20:44 - 2015-07-15 19:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-08-12 20:44 - 2015-07-15 19:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-08-12 20:44 - 2015-07-15 19:53 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-08-12 20:44 - 2015-07-15 19:53 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-12 20:44 - 2015-07-15 19:53 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-08-12 20:44 - 2015-07-15 19:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-08-12 20:44 - 2015-07-15 19:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-08-12 20:44 - 2015-07-15 19:53 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-08-12 20:44 - 2015-07-15 19:49 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-08-12 20:44 - 2015-07-15 19:48 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 18:46 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-12 20:44 - 2015-07-15 18:46 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-12 20:44 - 2015-07-15 18:46 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-12 20:44 - 2015-07-15 18:37 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-08-12 20:44 - 2015-07-15 18:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-08-12 20:44 - 2015-07-15 18:34 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 18:34 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 18:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 18:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-12 20:44 - 2015-07-15 05:19 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-12 20:44 - 2015-07-15 05:19 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-12 20:44 - 2015-07-15 05:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-12 20:44 - 2015-07-15 05:14 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-08-12 20:44 - 2015-07-15 05:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-08-12 20:44 - 2015-07-15 04:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-08-12 20:44 - 2015-07-15 04:55 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-08-12 20:44 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-08-12 20:44 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-08-12 20:44 - 2015-07-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-08-12 20:44 - 2015-07-01 22:49 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-12 20:44 - 2015-07-01 22:48 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-12 20:44 - 2015-07-01 22:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-08-12 20:44 - 2015-07-01 22:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-08-12 20:43 - 2015-07-30 20:06 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-12 20:43 - 2015-07-30 20:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-12 20:43 - 2015-07-30 20:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-12 20:43 - 2015-07-30 20:06 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-08-12 20:43 - 2015-07-30 20:06 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-12 20:43 - 2015-07-30 20:06 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-08-12 20:43 - 2015-07-30 20:06 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-08-12 20:43 - 2015-07-30 19:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-08-12 20:43 - 2015-07-30 19:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-08-12 20:43 - 2015-07-30 19:57 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-08-12 20:43 - 2015-07-30 19:57 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-12 20:43 - 2015-07-30 19:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-08-12 20:43 - 2015-07-30 19:55 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-08-12 20:43 - 2015-07-30 18:56 - 03208192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-12 20:43 - 2015-07-30 18:52 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-12 20:43 - 2015-07-30 18:49 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-12 20:43 - 2015-07-10 19:51 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-12 20:43 - 2015-07-10 19:34 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-08-12 20:43 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-12 20:43 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-12 20:43 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-09 19:50 - 2015-08-09 19:50 - 00058877 _____ C:\Windows\SysWOW64\CCCInstall_201508091950019805.log
2015-08-09 19:50 - 2015-08-09 19:50 - 00000000 ____D C:\ProgramData\ATI
2015-08-09 19:49 - 2015-08-09 19:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-08-08 19:44 - 2015-08-08 19:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX920 series
2015-08-08 19:44 - 2012-09-20 05:00 - 00393728 _____ (CANON INC.) C:\Windows\system32\CNMXLMBL.DLL
2015-08-08 19:35 - 2015-08-08 19:35 - 40279184 _____ C:\Users\Florian und Herminia\Downloads\mp68-win-mx920-1_00-ea32_2.exe
2015-08-08 19:35 - 2015-08-08 19:35 - 27851928 _____ C:\Users\Florian und Herminia\Downloads\xp68-win-mx920-5_65-ea32_2.exe
2015-08-06 20:38 - 2015-08-06 20:38 - 00000000 ____D C:\ProgramData\Sun
2015-08-06 20:21 - 2015-07-28 22:09 - 00017344 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-06 20:21 - 2015-07-28 22:05 - 01116672 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-06 20:21 - 2015-07-28 22:05 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-06 20:21 - 2015-07-28 22:05 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-06 20:21 - 2015-07-28 22:05 - 00437760 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-06 20:21 - 2015-07-28 22:05 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-06 20:21 - 2015-07-28 22:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-06 20:21 - 2015-07-28 21:55 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-06 20:21 - 2015-07-20 20:12 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-08-06 20:21 - 2015-07-20 20:12 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-06 20:21 - 2015-07-20 20:12 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-06 20:21 - 2015-07-20 20:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-08-06 20:21 - 2015-07-20 20:12 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-08-06 20:21 - 2015-07-20 20:12 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-08-06 20:21 - 2015-07-20 20:12 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-08-06 20:21 - 2015-07-20 20:12 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-08-06 20:21 - 2015-07-20 20:12 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-08-06 20:21 - 2015-07-20 20:12 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-08-06 20:21 - 2015-07-20 20:12 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-08-06 20:21 - 2015-07-20 19:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-08-06 20:21 - 2015-07-20 19:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-08-06 20:21 - 2015-07-20 19:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-08-06 20:21 - 2015-07-20 19:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-08-06 20:21 - 2015-07-20 19:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-08-06 20:21 - 2015-05-09 20:26 - 00493504 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-06 20:21 - 2015-03-14 05:21 - 01632768 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-08-06 20:21 - 2015-03-14 05:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-08-06 20:21 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-08-06 20:21 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-08-04 21:40 - 2015-08-04 21:41 - 00003487 _____ C:\Users\Florian und Herminia\Downloads\Umsatzanzeige_5539514443_20150804.csv
2015-07-29 05:44 - 2015-07-29 05:44 - 00107784 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll
2015-07-29 05:44 - 2015-07-29 05:44 - 00100568 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll
2015-07-29 05:43 - 2015-07-29 05:43 - 00141792 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll
2015-07-29 05:43 - 2015-07-29 05:43 - 00128384 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll
2015-07-29 05:43 - 2015-07-29 05:43 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll
2015-07-29 05:43 - 2015-07-29 05:43 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll
2015-07-29 05:42 - 2015-07-29 05:42 - 00133016 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2015-07-29 05:42 - 2015-07-29 05:42 - 00120144 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll
2015-07-29 05:42 - 2015-07-29 05:42 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2015-07-29 05:42 - 2015-07-29 05:42 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2015-07-29 05:40 - 2015-07-29 05:40 - 10094152 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2015-07-29 05:39 - 2015-07-29 05:39 - 08893160 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll
2015-07-29 05:39 - 2015-07-29 05:39 - 08779872 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll
2015-07-29 05:26 - 2015-07-29 05:26 - 00297672 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys
2015-07-29 05:15 - 2015-07-29 05:15 - 21622784 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2015-07-29 05:09 - 2015-07-29 05:09 - 47785472 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2015-07-29 05:09 - 2015-07-29 05:09 - 00235008 _____ C:\Windows\system32\clinfo.exe
2015-07-29 05:08 - 2015-07-29 05:08 - 39714816 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2015-07-29 05:07 - 2015-07-29 05:07 - 00065024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-07-29 05:07 - 2015-07-29 05:07 - 00059392 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-07-29 05:06 - 2015-07-29 05:06 - 27535872 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl12cl64.dll
2015-07-29 05:05 - 2015-07-29 05:05 - 22318592 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl12cl.dll
2015-07-29 04:41 - 2015-07-29 04:41 - 06477312 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll
2015-07-29 04:41 - 2015-07-29 04:41 - 00127488 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll
2015-07-29 04:41 - 2015-07-29 04:41 - 00113664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll
2015-07-29 04:36 - 2015-07-29 04:36 - 05068288 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll
2015-07-29 04:34 - 2015-07-29 04:34 - 30752256 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll
2015-07-29 04:34 - 2015-07-29 04:34 - 00050688 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2015-07-29 04:34 - 2015-07-29 04:34 - 00039424 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll
2015-07-29 04:33 - 2015-07-29 04:33 - 00093696 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll
2015-07-29 04:33 - 2015-07-29 04:33 - 00086528 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll
2015-07-29 04:32 - 2015-07-29 04:32 - 03437632 _____ C:\Windows\system32\atiumd6a.cap
2015-07-29 04:30 - 2015-07-29 04:30 - 15716864 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll
2015-07-29 04:30 - 2015-07-29 04:30 - 00660928 _____ C:\Windows\SysWOW64\atiapfxx.blb
2015-07-29 04:30 - 2015-07-29 04:30 - 00660928 _____ C:\Windows\system32\atiapfxx.blb
2015-07-29 04:30 - 2015-07-29 04:30 - 00367104 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2015-07-29 04:30 - 2015-07-29 04:30 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll
2015-07-29 04:30 - 2015-07-29 04:30 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll
2015-07-29 04:30 - 2015-07-29 04:30 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2015-07-29 04:30 - 2015-07-29 04:30 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2015-07-29 04:29 - 2015-07-29 04:29 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2015-07-29 04:28 - 2015-07-29 04:28 - 25299968 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2015-07-29 04:28 - 2015-07-29 04:28 - 03471376 _____ C:\Windows\SysWOW64\atiumdva.cap
2015-07-29 04:26 - 2015-07-29 04:26 - 00672768 _____ (AMD) C:\Windows\system32\atieclxx.exe
2015-07-29 04:26 - 2015-07-29 04:26 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2015-07-29 04:26 - 2015-07-29 04:26 - 00204800 _____ C:\Windows\system32\amdgfxinfo64.dll
2015-07-29 04:26 - 2015-07-29 04:26 - 00189952 _____ C:\Windows\SysWOW64\amdgfxinfo32.dll
2015-07-29 04:26 - 2015-07-29 04:26 - 00160256 _____ C:\Windows\system32\atieah64.exe
2015-07-29 04:26 - 2015-07-29 04:26 - 00143872 _____ C:\Windows\SysWOW64\atieah32.exe
2015-07-29 04:26 - 2015-07-29 04:26 - 00029696 _____ (AMD) C:\Windows\system32\atimuixx.dll
2015-07-29 04:25 - 2015-07-29 04:25 - 00246784 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2015-07-29 04:25 - 2015-07-29 04:25 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll
2015-07-29 04:24 - 2015-07-29 04:24 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll
2015-07-29 04:24 - 2015-07-29 04:24 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll
2015-07-29 04:23 - 2015-07-29 04:23 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2015-07-29 04:22 - 2015-07-29 04:22 - 01247744 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2015-07-29 04:22 - 2015-07-29 04:22 - 00926720 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2015-07-29 04:22 - 2015-07-29 04:22 - 00926720 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxx.dll
2015-07-29 04:22 - 2015-07-29 04:22 - 00665088 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2015-07-29 04:22 - 2015-07-29 04:22 - 00156672 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll
2015-07-29 04:22 - 2015-07-29 04:22 - 00141824 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2015-07-29 04:22 - 2015-07-29 04:22 - 00075264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll
2015-07-29 04:22 - 2015-07-29 04:22 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2015-07-29 04:22 - 2015-07-29 04:22 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2015-07-29 04:19 - 2015-07-29 04:19 - 00102912 _____ C:\Windows\system32\hsa-thunk64.dll
2015-07-29 04:19 - 2015-07-29 04:19 - 00102400 _____ C:\Windows\SysWOW64\hsa-thunk.dll
2015-07-24 18:44 - 2015-07-24 18:44 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2015-07-24 18:43 - 2015-07-24 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Xbox 360 Accessories
2015-07-24 18:43 - 2015-07-24 18:43 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories
2015-07-22 21:35 - 2015-07-22 21:44 - 107458122 _____ C:\Users\Florian und Herminia\Downloads\HMS - 00102.rar
2015-07-22 20:58 - 2015-07-22 20:58 - 00000000 ____D C:\Users\Florian und Herminia\AppData\Local\CEF
2015-07-21 22:24 - 2015-07-21 22:24 - 00000000 ____D C:\Users\Florian und Herminia\AppData\Roaming\RenPy
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-08-16 00:33 - 2009-07-14 06:45 - 00022368 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-16 00:33 - 2009-07-14 06:45 - 00022368 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-16 00:32 - 2009-07-14 19:58 - 00710168 _____ C:\Windows\system32\perfh007.dat
2015-08-16 00:32 - 2009-07-14 19:58 - 00154498 _____ C:\Windows\system32\perfc007.dat
2015-08-16 00:32 - 2009-07-14 07:13 - 01650382 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-16 00:28 - 2014-01-29 23:58 - 01250160 _____ C:\Windows\WindowsUpdate.log
2015-08-16 00:25 - 2015-01-16 21:24 - 00020860 _____ C:\Windows\setupact.log
2015-08-16 00:25 - 2014-11-20 21:23 - 00000000 ____D C:\Users\Florian und Herminia\AppData\Roaming\Raptr
2015-08-16 00:25 - 2014-01-30 21:11 - 00000280 _____ C:\Windows\Tasks\RtlLanOptimizerVistaStart.job
2015-08-16 00:25 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-16 00:11 - 2014-01-30 20:58 - 00000000 ____D C:\AdwCleaner
2015-08-16 00:07 - 2015-03-07 10:52 - 00207852 _____ C:\Windows\PFRO.log
2015-08-15 00:02 - 2014-01-30 22:55 - 00000000 ____D C:\Users\Florian und Herminia\AppData\Roaming\KeePass
2015-08-15 00:00 - 2015-02-24 22:35 - 00000000 ____D C:\Download
2015-08-14 23:56 - 2014-01-30 12:01 - 00000000 ____D C:\Users\Florian und Herminia\AppData\Roaming\vlc
2015-08-14 23:06 - 2014-10-22 16:19 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-14 22:55 - 2014-02-16 16:11 - 00000000 ____D C:\Program Files (x86)\Steam
2015-08-14 22:03 - 2014-01-30 00:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-14 22:02 - 2014-05-21 20:11 - 00000000 ____D C:\Windows\Minidump
2015-08-14 21:18 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Cursors
2015-08-14 21:13 - 2014-01-29 23:58 - 00000000 ____D C:\Users\FS1
2015-08-14 21:04 - 2014-02-03 20:25 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-08-14 20:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-08-14 19:40 - 2014-01-30 21:05 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-08-14 19:40 - 2014-01-30 21:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-08-14 19:40 - 2014-01-30 21:05 - 00000000 ____D C:\Program Files\CCleaner
2015-08-14 19:39 - 2015-07-09 22:01 - 00000000 ____D C:\Program Files (x86)\PureSync
2015-08-14 19:39 - 2014-10-31 22:35 - 00000000 ____D C:\Users\Florian und Herminia\AppData\Roaming\Jumping Bytes
2015-08-14 19:35 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-13 22:31 - 2009-07-14 06:45 - 00298232 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-12 22:34 - 2014-02-12 20:41 - 00000000 ____D C:\Windows\system32\MRT
2015-08-12 22:30 - 2014-01-30 00:01 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-12 21:43 - 2015-02-02 22:13 - 00038912 _____ C:\Users\Florian und Herminia\Downloads\Rücklage 2012-2015.xls
2015-08-12 21:06 - 2014-10-22 16:19 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-12 21:06 - 2014-10-22 16:19 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-12 21:06 - 2014-10-22 16:19 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-08-09 19:50 - 2015-07-11 12:01 - 00000000 ____D C:\Users\FS1\AppData\Roaming\Raptr
2015-08-09 19:50 - 2014-07-12 23:53 - 00000000 ____D C:\Program Files (x86)\Raptr
2015-08-09 19:49 - 2014-01-30 00:20 - 00000000 ____D C:\ProgramData\AMD
2015-08-09 19:49 - 2014-01-30 00:20 - 00000000 ____D C:\Program Files\AMD
2015-08-09 19:48 - 2014-01-30 00:16 - 00000000 ____D C:\ProgramData\Package Cache
2015-08-09 19:47 - 2014-01-30 00:15 - 00000000 ____D C:\AMD
2015-08-08 23:51 - 2014-11-23 15:33 - 00000000 ____D C:\Users\Florian und Herminia\AppData\Local\Canon Easy-PhotoPrint EX
2015-08-08 23:47 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-08-06 21:55 - 2014-12-12 19:52 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-06 21:55 - 2014-05-06 22:37 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-06 20:38 - 2014-10-22 16:18 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-08-06 20:38 - 2014-10-22 16:18 - 00000000 ____D C:\Program Files (x86)\Java
2015-08-06 20:38 - 2014-01-30 21:51 - 00000000 ____D C:\ProgramData\Oracle
2015-08-04 20:43 - 2014-02-27 21:52 - 00000000 ____D C:\Users\Florian und Herminia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-07-30 18:43 - 2014-01-30 00:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-07-29 05:42 - 2015-06-23 04:08 - 00152056 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll
2015-07-29 05:42 - 2012-12-19 21:30 - 00102616 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2015-07-29 05:41 - 2015-06-23 04:08 - 11948704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll
2015-07-29 05:41 - 2015-06-23 04:08 - 01445224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll
2015-07-29 05:41 - 2012-12-19 22:09 - 01193904 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2015-07-29 05:40 - 2014-07-09 17:51 - 07929616 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2015-07-29 05:40 - 2014-07-09 17:51 - 07408936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2015-07-29 04:17 - 2015-06-23 03:21 - 00865792 _____ (AMD) C:\Windows\system32\coinst_15.20.dll
2015-07-28 19:23 - 2014-01-30 00:25 - 00162528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-07-28 19:23 - 2014-01-30 00:25 - 00141416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-07-26 18:56 - 2015-04-01 21:04 - 00000000 ___SD C:\Windows\system32\GWX
2015-07-24 18:42 - 2015-03-17 23:45 - 00065258 _____ C:\Windows\DirectX.log
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2014-01-31 00:51 - 2014-01-31 00:51 - 0000061 _____ () C:\Users\FS1\AppData\Roaming\WB.CFG
2014-07-29 22:48 - 2014-07-29 22:48 - 0000600 _____ () C:\Users\FS1\AppData\Roaming\winscp.rnd
2014-12-26 23:57 - 2014-12-26 23:57 - 0007667 _____ () C:\Users\FS1\AppData\Local\Resmon.ResmonCfg
2014-07-10 22:17 - 2014-07-10 22:17 - 0000041 ___SH () C:\ProgramData\.zreglib
2015-04-01 21:04 - 2015-04-01 21:04 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-02-23 23:44 - 2015-02-23 23:44 - 0000949 _____ () C:\ProgramData\Turn Off Monitor.ini
Einige Dateien in TEMP:
====================
C:\Users\Florian und Herminia\AppData\Local\Temp\avgnt.exe
C:\Users\Florian und Herminia\AppData\Local\Temp\PureSyncInst.exe
C:\Users\FS1\AppData\Local\Temp\avgnt.exe
C:\Users\FS1\AppData\Local\Temp\Quarantine.exe
C:\Users\FS1\AppData\Local\Temp\raptrpatch.exe
C:\Users\FS1\AppData\Local\Temp\raptr_stub.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-08-12 22:15
==================== Ende von Ergebnis ============================ Jetzt noch ein paar Fragen:
Was hat er mit FRST gefunden?
Und ist es korrekt das bei FRST nur untersucht wird? Man kann ja auch auf "Entfernen" klicken...
Vielen Dank schonmal bis hierhin schrauber! |