Leon-Yannick | 22.03.2015 21:04 | Hier der MMab Log : Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.03.2015
Suchlauf-Zeit: 08:22:51
Logdatei: MMab.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.03.22.03
Rootkit Datenbank: v2015.02.25.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Leon-Yannick
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 349535
Verstrichene Zeit: 9 Min, 51 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 3
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, 2028, Löschen bei Neustart, [9af12226ccbe3ff72b8a739c10f226da]
PUP.Optional.ELEX, C:\Program Files (x86)\XTab\HPNotify.exe, 3464, Löschen bei Neustart, [7c0fd57311794de904acf93705fd7a86]
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, 1252, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66]
Module: 10
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchFF.dll, Löschen bei Neustart, [55362a1e7d0d290dc243d19dce32c33d],
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchCH.dll, Löschen bei Neustart, [0d7ec286e9a17abcfe07df8f887813ed],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowserAction.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\IeWatchDog.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
Registrierungsschlüssel: 28
PUP.Optional.XTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, In Quarantäne, [9af12226ccbe3ff72b8a739c10f226da],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [414a1e2a8a004cea2df5ce58af5433cd],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, In Quarantäne, [4249d57365250d296f45ba0445bebc44],
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, In Quarantäne, [0e7de2663e4caf8796f1794d21e21ce4],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [177483c53357a98dadf2013720e517e9],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, In Quarantäne, [256650f839515ed81e2e617ba85bbc44],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [b3d8b5933555bd79beadf034d82d2ed2],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [d6b5cf79ef9bc571f96561da64a1fc04],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [afdcd1770a80ad89c49b2f0cea1b7e82],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [becd2f198bff69cdb4bea92ba75c4ab6],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [a7e40c3c5634b0863479e5e4af540ef2],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\1ClickDownload, In Quarantäne, [93f8d96f583274c261cf4eccfb0a619f],
PUP.Optional.BoBrowser.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\BoBrowser, In Quarantäne, [741790b88bff8fa7cd9becd1e81bd22e],
PUP.Optional.1ClickMovieDownload.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\ClickMovie1-Downloaderv10-nv-ie, In Quarantäne, [3358ef59008a340250d1617a6b98cb35],
PUP.Optional.ICinema.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\I - Cinema-nv-ie, In Quarantäne, [c2c961e7c6c47db9d9d1587e9a695ca4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [ddaeef59c5c535011ce87bb29570a35d],
PUP.Optional.Qone8, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [06855bed503a04327ded79abe71ed030],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
Registrierungswerte: 3
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [256650f839515ed81e2e617ba85bbc44]
PUP.Optional.FFToolbar.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|fftoolbar2014@etech.com, C:\Users\Leon-Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\x1z3k6f6.default-1422993842713\extensions\fftoolbar2014@etech.com, In Quarantäne, [bad179cffb8ffb3b66ea7c4235ce29d7]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, smt, In Quarantäne, [becd2f198bff69cdb4bea92ba75c4ab6]
Registrierungsdaten: 15
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1423522530&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1423522530&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513),Ersetzt,[1576e068cebce3535ce93bab0005cb35]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423522530&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423522530&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}),Ersetzt,[276480c80d7df2445d57c1249f6644bc]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513),Ersetzt,[fd8e95b3e1a925115460d411ef165fa1]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513),Ersetzt,[bccf84c41b6fd26470444d9856af4ab6]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423522530&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423522530&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}),Ersetzt,[aeddbd8bd9b16cca694bc91c13f246ba]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1423522530&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1423522530&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513),Ersetzt,[e9a263e5147688aeb98cecfacf36e41c]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513),Ersetzt,[dfac89bf78121c1a664eb33246bf2dd3]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=dspp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=dspp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}),Ersetzt,[a6e53c0cd5b58bab4f6532b3bf46e020]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513),Ersetzt,[bccfec5c3a5038fe654fe10434d119e7]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=dspp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=dspp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}),Ersetzt,[72198dbb21699a9cf8bc53928b7aaf51]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[94f740088a007abcb6878b67d62f817f]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=dspp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=dspp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}),Ersetzt,[781377d14545ff37d5e0f3f281848977]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513),Ersetzt,[aedd89bf088238fe2392ffe6bb4a8d73]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513),Ersetzt,[ed9ec8808703c76f9e17d114c144dd23]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=dspp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=dspp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}),Ersetzt,[4348d3755139ac8ae5d0776e37ce48b8]
Ordner: 35
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\image, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.OpenCandy, C:\Users\Leon-Yannick\AppData\Roaming\OpenCandy, In Quarantäne, [6e1d3414583276c04a4a2e4528db20e0],
PUP.Optional.OpenCandy, C:\Users\Leon-Yannick\AppData\Roaming\OpenCandy\E675B1F4F7804E6BBE407160939C6F4C, In Quarantäne, [6e1d3414583276c04a4a2e4528db20e0],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, In Quarantäne, [711a5eea3753b284efada0ea857ea15f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [711a5eea3753b284efada0ea857ea15f],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, In Quarantäne, [3259a2a636542d09f63ce4c3996aaf51],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, In Quarantäne, [3259a2a636542d09f63ce4c3996aaf51],
Dateien: 121
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, Löschen bei Neustart, [9af12226ccbe3ff72b8a739c10f226da],
PUP.Optional.ELEX, C:\Program Files (x86)\XTab\HPNotify.exe, Löschen bei Neustart, [7c0fd57311794de904acf93705fd7a86],
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchFF.dll, Löschen bei Neustart, [55362a1e7d0d290dc243d19dce32c33d],
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchCH.dll, Löschen bei Neustart, [0d7ec286e9a17abcfe07df8f887813ed],
PUP.Optional.SupTab.A, C:\Program Files (x86)\XTab\SupTab.dll, In Quarantäne, [5338ae9aa4e6a4923541ee3c60a3af51],
PUP.Optional.Conduit.A, C:\Users\Leon-Yannick\AppData\Local\Temp\dlLogic.exe, In Quarantäne, [b2d960e85c2e67cf2e024bf844bc6f91],
PUP.Optional.Conduit.A, C:\Users\Leon-Yannick\AppData\Local\Temp\dltr.exe, In Quarantäne, [0e7d1038e4a6ed495ed3ff4402fecb35],
Trojan.MSIL.Injector, C:\Users\Leon-Yannick\AppData\Local\Temp\Runner2.exe, In Quarantäne, [0e7d7cccccbec17532789e427a8b936d],
PUP.Optional.Conduit.A, C:\Users\Leon-Yannick\AppData\Local\Temp\GCVerifier.dll, In Quarantäne, [d0bbdb6d1a70b284e74852f16b95c53b],
PUP.Optional.Conduit.A, C:\Users\Leon-Yannick\AppData\Local\Temp\verifier.exe, In Quarantäne, [3f4cdf699af0f640151c3013cb35f60a],
PUP.Optional.MyStartSearch.A, C:\Users\Leon-Yannick\AppData\Local\Temp\setup.exe, In Quarantäne, [f4973810b5d52f070507d05b9a6ca858],
PUP.Optional.BrowserWatch, C:\Users\Leon-Yannick\AppData\Local\Temp\Wtmp6242692\tmp\XTab_v4.0.exe, In Quarantäne, [820984c492f83afc48bdd29cca367888],
PUP.Optional.OpenCandy, C:\Users\Leon-Yannick\Downloads\DTLite4491-0356.exe, In Quarantäne, [1f6c3513dab074c2b432d840ae586898],
PUP.Optional.Giga, C:\Users\Leon-Yannick\Downloads\Need-for-Speed_-Undercover-lnstall.exe, In Quarantäne, [2e5d15330b7fe55137b77f55a560ca36],
PUP.Optional.WebTInst.A, C:\Windows\System32\drivers\Msft_Kernel_webTinst_01009.Wdf, In Quarantäne, [ff8ca5a3a0ea49ed6f84ecc9de250cf4],
PUP.Optional.Patsearch.A, C:\Windows\patsearch.bin, In Quarantäne, [4e3d82c6f99105312cba4577b350dc24],
PUP.Optional.MyStartSearch.A, C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage, In Quarantäne, [99f2e5630783191d031dd1ed5ca7ad53],
PUP.Optional.MyStartSearch.A, C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage-journal, In Quarantäne, [fe8d3b0d74163ef8011f2995b350619f],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\uninstall.exe, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowserAction.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\conf, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ffsearch_toolbar!1.0.0.1025.xpi, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\IeWatchDog.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\install.data, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\searchProvider.xml, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about_bk.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn_apply.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\close.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf.xml, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf_back.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\input_bk.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\logo.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\main.xml, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_1.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_2.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\rigth_arrow.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\settings.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\data.html, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE.html, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE8.html, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\main.css, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\ver.txt, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\arrow.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo_hover.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_logo.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo2.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\google_trends.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon128.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon16.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon48.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\loading.gif, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\logo32.ico, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather\0.png, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\common.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ga.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ie8.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery.autocomplete.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\js.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\library.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit-ie8.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit2.0.js, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW\messages.json, In Quarantäne, [7b100d3b25656bcbd0e5348a51b29a66],
PUP.Optional.BoBrowser.A, C:\Windows\System32\Tasks\Run_Bobby_Browser, In Quarantäne, [7813c484b4d6e74f13bd0db1b1525da3],
PUP.Optional.MyStartSearch.A, C:\Users\Leon-Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\x1z3k6f6.default-1422993842713\searchplugins\mystartsearch.xml, In Quarantäne, [82099aae3555f541b5d1814504ff09f7],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, In Quarantäne, [5a31c385a8e27cba2c1acb6e8481f709],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, In Quarantäne, [5f2cc97f8ffb90a60f385ddc27de53ad],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, In Quarantäne, [bdce49ff9bef2e0888c055e4aa5baa56],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, In Quarantäne, [4249fa4eeaa069cd98b1cd6c679e837d],
PUP.Optional.OpenCandy, C:\Users\Leon-Yannick\AppData\Roaming\OpenCandy\E675B1F4F7804E6BBE407160939C6F4C\WebCompanionInstaller.exe, In Quarantäne, [6e1d3414583276c04a4a2e4528db20e0],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [711a5eea3753b284efada0ea857ea15f],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\GoogleCrashHandler.exe, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\GoogleUpdate.exe, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\GoogleUpdateBroker.exe, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\GoogleUpdateHelper.msi, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\GoogleUpdateOnDemand.exe, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\goopdate.dll, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\goopdateres_en.dll, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\npGoogleUpdate4.dll, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\psmachine.dll, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.340287\psuser.dll, In Quarantäne, [9eedf75171190c2a2561f399af542bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\GoogleCrashHandler.exe, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\GoogleUpdate.exe, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\GoogleUpdateBroker.exe, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\GoogleUpdateHelper.msi, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\GoogleUpdateOnDemand.exe, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\goopdate.dll, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\goopdateres_en.dll, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\npGoogleUpdate4.dll, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\psmachine.dll, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.GlobalUpdate.A, C:\Users\Leon-Yannick\AppData\Local\Temp\comh.346746\psuser.dll, In Quarantäne, [a4e74503ff8b7fb7a1e5ed9f659e6e92],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update\conf, In Quarantäne, [3259a2a636542d09f63ce4c3996aaf51],
PUP.Optional.MyStartSearch.A, C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://www.mystartsearch.com/?type=hppp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513",), Ersetzt,[b4d71f2925653df9ae6f0429f0164fb1]
PUP.Optional.CrossRider.A, C:\Users\Leon-Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\x1z3k6f6.default-1422993842713\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "14b74e2dfa256ad958f834e57b34e6fb");), Ersetzt,[34577fc9bdcd6bcb94a95ad6c442718f]
PUP.Optional.MyStartSearch.A, C:\Users\Leon-Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\x1z3k6f6.default-1422993842713\search.json, Gut: (), Schlecht: (mystartsearch), Ersetzt,[5a31c97f9ded16201da80b2128de1be5]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end)
Hier der AdwCleaner Log Code:
# AdwCleaner v4.112 - Bericht erstellt 22/03/2015 um 20:03:54
# Aktualisiert 09/03/2015 von Xplode
# Datenbank : 2015-03-22.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x64)
# Benutzername : Leon-Yannick - LEON-YANNICK-PC
# Gestarted von : C:\Users\Leon-Yannick\Downloads\AdwCleaner_4.112.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Leon-Yannick\AppData\Local\cool_mirage
Ordner Gelöscht : C:\Users\Leon-Yannick\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Leon-Yannick\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Datei Gelöscht : C:\Windows\DtcInstall.log
Datei Gelöscht : C:\Windows\TSSysprep.log
Datei Gelöscht : C:\Users\Leon-Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\x1z3k6f6.default-1422993842713\user.js
Datei Gelöscht : C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-devtools_devtools_0.localstorage
Datei Gelöscht : C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-devtools_devtools_0.localstorage-journal
Datei Gelöscht : C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage
Datei Gelöscht : C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage-journal
***** [ Geplante Tasks ] *****
Task Gelöscht : Run_Bobby_Browser
Task Gelöscht : PostPoneInstall
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C0C3A6C6-03BC-4195-8FCB-AEA091301353}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\powerpack
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\BetterMarkIt
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\SupDp
Schlüssel Gelöscht : HKLM\SOFTWARE\Clara
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v36.0.1 (x86 de)
[x1z3k6f6.default-1422993842713\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.alias", "mystartsearch");
[x1z3k6f6.default-1422993842713\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.iconURL", "hxxp://www.mystartsearch.com/web/favicon.ico");
[x1z3k6f6.default-1422993842713\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.name", "mystartsearch");
[x1z3k6f6.default-1422993842713\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.url", "hxxp://www.mystartsearch.com/web/?type=dspp&ts=1423522566&from=smt&uid=WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513&q={searchTerms}");
[x1z3k6f6.default-1422993842713\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.enable_search1", false);
[x1z3k6f6.default-1422993842713\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
-\\ Google Chrome v41.0.2272.101
*************************
AdwCleaner[R0].txt - [10923 Bytes] - [22/03/2015 20:01:30]
AdwCleaner[S0].txt - [10165 Bytes] - [22/03/2015 20:03:54]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10225 Bytes] ##########
Hier der JRT Log Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.5 (03.17.2015:1)
OS: Windows 7 Professional x64
Ran by Leon-Yannick on 22.03.2015 at 20:25:56,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Leon-Yannick\AppData\Roaming\mozilla\firefox\profiles\x1z3k6f6.default-1422993842713\prefs.js
user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine");
user_pref("browser.search.searchengine.ptid", "smt");
user_pref("browser.search.searchengine.uid", "WDCXWD6400AACS-00D6B1_WD-WCAU4D62251322513");
Emptied folder: C:\Users\Leon-Yannick\AppData\Roaming\mozilla\firefox\profiles\x1z3k6f6.default-1422993842713\minidumps [9 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.03.2015 at 20:31:39,17
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Hier der Frische Frst Log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Leon-Yannick (administrator) on LEON-YANNICK-PC on 22-03-2015 20:34:36
Running from C:\Users\Leon-Yannick\Downloads
Loaded Profiles: Leon-Yannick (Available profiles: Leon-Yannick)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Gainward Co. Ltd.) C:\Program Files (x86)\EXPERTool\TBPanel.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Spotify Ltd) C:\Users\Leon-Yannick\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Spotify Ltd) C:\Users\Leon-Yannick\AppData\Roaming\Spotify\Spotify.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Spotify Ltd) C:\Users\Leon-Yannick\AppData\Roaming\Spotify\SpotifyCrashService.exe
(Spotify Ltd) C:\Users\Leon-Yannick\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Leon-Yannick\AppData\Roaming\Spotify\Spotify.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-02-10] (AVAST Software)
HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2874048 2015-02-19] (Valve Corporation)
HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\...\Run: [TBPanel] => C:\Program Files (x86)\EXPERTool\TBPanel.exe [2195240 2015-01-20] (Gainward Co. Ltd.)
HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\...\Run: [Spotify Web Helper] => C:\Users\Leon-Yannick\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1964088 2015-03-18] (Spotify Ltd)
HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\...\Run: [Spotify] => C:\Users\Leon-Yannick\AppData\Roaming\Spotify\Spotify.exe [6701624 2015-03-18] (Spotify Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2095702127-3137971373-1474782704-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2095702127-3137971373-1474782704-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-04] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-02-10] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-04] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-03] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-02-10] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-03] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Leon-Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\x1z3k6f6.default-1422993842713
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-11] ()
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-03] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-03] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF SearchPlugin: C:\Users\Leon-Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\x1z3k6f6.default-1422993842713\searchplugins\google-avast.xml [2015-02-24]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-02-10]
Chrome:
=======
CHR StartupUrls: Default -> "https://www.google.com/?trackid=sp-006"
CHR DefaultSearchKeyword: Default -> google
CHR DefaultSuggestURL: Default -> https://www.google.com/complete/search?client=chrome&q={searchTerms}
CHR Profile: C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-05]
CHR Extension: (Google Drive) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-05]
CHR Extension: (YouTube) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-05]
CHR Extension: (Google Search) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-05]
CHR Extension: (Google Sheets) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-05]
CHR Extension: (LoungeDestroyer) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2015-03-13]
CHR Extension: (Avast Online Security) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-02-10]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Wallet) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-05]
CHR Extension: (Gmail) - C:\Users\Leon-Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-05]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-02-10]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-02-10] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2015-02-10] (Avast Software)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2015-02-07] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5436176 2015-02-17] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-02-10] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [87912 2015-02-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-02-10] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-02-10] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-02-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-02-10] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-02-10] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-02-10] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2015-02-04] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2015-02-10] (Avast Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-22 20:31 - 2015-03-22 20:33 - 00001169 _____ () C:\Users\Leon-Yannick\Desktop\JRT.txt
2015-03-22 20:10 - 2015-03-22 20:12 - 01388672 _____ (Thisisu) C:\Users\Leon-Yannick\Downloads\JRT.exe
2015-03-22 20:09 - 2015-03-22 20:09 - 00010342 _____ () C:\Users\Leon-Yannick\Desktop\AdwCleaner[S0].txt
2015-03-22 20:01 - 2015-03-22 20:03 - 00000000 ____D () C:\AdwCleaner
2015-03-22 20:00 - 2015-03-22 20:00 - 02171392 _____ () C:\Users\Leon-Yannick\Downloads\AdwCleaner_4.112.exe
2015-03-22 19:59 - 2015-03-22 19:59 - 00035071 _____ () C:\Users\Leon-Yannick\Desktop\MMab.txt
2015-03-22 13:25 - 2015-02-05 18:57 - 00621384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-03-22 09:38 - 2015-03-22 09:38 - 00022381 _____ () C:\ComboFix.txt
2015-03-22 09:24 - 2015-03-22 09:38 - 00000000 ____D () C:\Qoobox
2015-03-22 09:24 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-22 09:24 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-22 09:24 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-22 09:24 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-22 09:24 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-22 09:24 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-03-22 09:24 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-03-22 09:24 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-03-22 09:23 - 2015-03-22 09:37 - 00000000 ____D () C:\Windows\erdnt
2015-03-22 09:23 - 2015-03-22 09:23 - 05615380 ____R (Swearware) C:\Users\Leon-Yannick\Desktop\ComboFix.exe
2015-03-22 09:23 - 2015-03-22 09:23 - 05615380 _____ (Swearware) C:\Users\Leon-Yannick\Downloads\ComboFix.exe
2015-03-22 09:05 - 2015-03-22 09:05 - 00023643 _____ () C:\Users\Leon-Yannick\Downloads\Addition.txt
2015-03-22 09:04 - 2015-03-22 20:34 - 00015163 _____ () C:\Users\Leon-Yannick\Downloads\FRST.txt
2015-03-22 09:04 - 2015-03-22 20:34 - 00000000 ____D () C:\FRST
2015-03-22 09:03 - 2015-03-22 09:04 - 02095616 _____ (Farbar) C:\Users\Leon-Yannick\Downloads\FRST64 (1).exe
2015-03-22 09:03 - 2015-03-22 09:03 - 02095616 _____ (Farbar) C:\Users\Leon-Yannick\Downloads\FRST64.exe
2015-03-22 08:22 - 2015-03-22 19:57 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-22 08:22 - 2015-03-22 08:22 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-22 08:22 - 2015-03-22 08:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-22 08:22 - 2015-03-22 08:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-22 08:22 - 2015-03-22 08:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-22 08:22 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-22 08:22 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-03-22 08:22 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-22 08:19 - 2015-03-22 08:19 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Leon-Yannick\Downloads\mbam-setup-2.1.4.1018.exe
2015-03-21 22:06 - 2015-03-21 22:06 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\Python
2015-03-21 22:06 - 2015-03-21 22:06 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Local\ActiveState
2015-03-21 22:05 - 2015-03-21 22:05 - 00000000 ____D () C:\Python27
2015-03-21 22:05 - 2015-03-21 22:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveState ActivePython 2.7 (32-bit)
2015-03-21 22:04 - 2015-03-21 22:04 - 37773312 _____ () C:\Users\Leon-Yannick\Downloads\ActivePython-2.7.8.10-win32-x86.msi
2015-03-21 22:02 - 2015-03-21 22:16 - 00000000 ____D () C:\Users\Leon-Yannick\Downloads\Whatsapp_Xtract_V2.2_2012-11-17
2015-03-21 22:02 - 2015-03-21 22:02 - 01876725 _____ () C:\Users\Leon-Yannick\Downloads\Whatsapp_Xtract_V2.2_2012-11-17.zip
2015-03-21 21:30 - 2015-03-21 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-21 21:10 - 2015-03-21 21:10 - 00001111 _____ () C:\Users\Public\Desktop\Minimal ADB and Fastboot.lnk
2015-03-18 20:25 - 2015-03-18 20:25 - 00314024 _____ () C:\Windows\Minidump\031815-24632-01.dmp
2015-03-18 18:56 - 2015-03-18 18:56 - 00001788 _____ () C:\Users\Leon-Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-03-12 16:35 - 2015-03-12 16:56 - 00000000 ____D () C:\Sichern
2015-03-11 19:04 - 2015-03-11 19:04 - 03736125 _____ () C:\Users\Leon-Yannick\Downloads\testdisk-6.14.win.zip
2015-03-11 19:04 - 2015-03-11 19:04 - 00000000 ____D () C:\Users\Leon-Yannick\Downloads\testdisk-6.14.win
2015-03-11 16:16 - 2015-03-11 16:16 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2015-03-11 16:03 - 2015-03-11 16:04 - 60039168 _____ () C:\Users\Leon-Yannick\Downloads\PhysX-9.14.0702-SystemSoftware.msi
2015-03-10 22:42 - 2015-02-24 04:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-10 22:42 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-03-10 22:42 - 2015-02-21 02:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-10 22:42 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-03-10 22:42 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-03-10 22:42 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-03-10 22:42 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-03-10 22:42 - 2015-02-21 00:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-10 22:42 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-03-10 22:42 - 2015-02-20 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-10 22:42 - 2015-02-20 04:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-10 22:42 - 2015-02-20 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-10 22:42 - 2015-02-20 03:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-10 22:42 - 2015-02-20 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-10 22:42 - 2015-02-20 03:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-10 22:42 - 2015-02-20 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-10 22:42 - 2015-02-20 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-10 22:42 - 2015-02-20 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-10 22:42 - 2015-02-20 03:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-10 22:42 - 2015-02-20 03:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-10 22:42 - 2015-02-20 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-10 22:42 - 2015-02-20 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-10 22:42 - 2015-02-20 03:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-10 22:42 - 2015-02-20 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-10 22:42 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-03-10 22:42 - 2015-02-20 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-10 22:42 - 2015-02-20 03:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-10 22:42 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-03-10 22:42 - 2015-02-20 03:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-10 22:42 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-03-10 22:42 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-10 22:42 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-03-10 22:42 - 2015-02-20 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-10 22:42 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-03-10 22:42 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-03-10 22:42 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-03-10 22:42 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-03-10 22:42 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-03-10 22:42 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-03-10 22:42 - 2015-02-20 02:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-10 22:42 - 2015-02-20 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-10 22:42 - 2015-02-20 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-10 22:42 - 2015-02-20 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-10 22:42 - 2015-02-20 02:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-10 22:42 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-10 22:42 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-03-10 22:42 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-03-10 22:42 - 2015-02-20 02:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-10 22:42 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-03-10 22:42 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-03-10 22:42 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-10 22:42 - 2015-02-20 02:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-10 22:42 - 2015-02-20 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-10 22:42 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-03-10 22:42 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-03-10 22:42 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-03-10 22:29 - 2015-02-03 04:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-10 22:29 - 2015-02-03 04:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-03-10 22:29 - 2015-02-03 04:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-10 22:29 - 2015-02-03 04:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-03-10 22:29 - 2015-02-03 04:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-10 22:29 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-10 22:29 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-10 22:29 - 2015-02-03 04:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-10 22:29 - 2015-02-03 04:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-10 22:29 - 2015-02-03 04:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-10 22:29 - 2015-02-03 04:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-10 22:29 - 2015-02-03 04:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-10 22:29 - 2015-02-03 04:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-10 22:29 - 2015-02-03 04:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-10 22:29 - 2015-02-03 04:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-10 22:29 - 2015-02-03 04:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-10 22:29 - 2015-02-03 04:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-10 22:29 - 2015-02-03 04:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-10 22:29 - 2015-02-03 04:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-10 22:29 - 2015-02-03 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-10 22:29 - 2015-02-03 04:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-10 22:29 - 2015-02-03 04:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-10 22:29 - 2015-02-03 04:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-03-10 22:29 - 2015-02-03 04:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-03-10 22:29 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-03-10 22:29 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-03-10 22:29 - 2015-02-03 04:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-03-10 22:29 - 2015-02-03 04:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2015-03-10 22:29 - 2015-02-03 04:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2015-03-10 22:29 - 2015-02-03 04:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2015-03-10 22:29 - 2015-02-03 04:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-03-10 22:29 - 2015-02-03 03:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-10 22:29 - 2014-10-31 23:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-10 22:29 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-10 22:29 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-03-10 22:16 - 2015-03-06 06:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-10 22:16 - 2015-03-06 06:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-10 22:16 - 2015-03-06 06:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-10 22:16 - 2015-03-06 06:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-10 22:16 - 2015-03-06 06:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-10 22:16 - 2015-03-06 06:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-10 22:16 - 2015-03-06 06:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-10 22:16 - 2015-03-06 06:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-10 22:16 - 2015-03-06 06:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-10 22:16 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-03-10 22:16 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-03-10 22:16 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-03-10 22:16 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-03-10 22:16 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-03-10 22:16 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-03-10 22:16 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-03-10 22:16 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-03-10 22:16 - 2015-03-06 06:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-03-10 22:16 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-03-10 22:16 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-03-10 22:16 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-03-10 22:16 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-03-10 22:16 - 2015-01-31 00:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-10 22:09 - 2015-02-20 05:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-10 22:09 - 2015-02-20 05:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-10 22:09 - 2015-02-20 05:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-10 22:09 - 2015-02-20 05:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-10 22:09 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-03-10 22:09 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-03-10 22:09 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-03-10 22:09 - 2015-02-20 05:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-03-10 22:09 - 2015-02-20 04:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-10 22:09 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-03-10 22:07 - 2015-01-31 04:48 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-10 22:07 - 2015-01-31 04:48 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-10 22:07 - 2015-01-31 00:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-10 22:06 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-03-10 22:06 - 2015-02-13 06:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-10 22:06 - 2015-02-03 04:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-10 22:06 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2015-03-10 22:04 - 2015-02-26 04:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-10 22:04 - 2015-02-03 04:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-10 22:04 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-10 22:04 - 2015-01-17 03:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-10 22:04 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-03-10 21:59 - 2015-02-04 04:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-10 21:59 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2015-03-10 17:56 - 2015-03-10 17:56 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\TeamViewer
2015-03-09 22:27 - 2015-03-09 22:28 - 00287342 _____ () C:\Windows\msxml4-KB973688-enu.LOG
2015-03-08 16:44 - 2015-03-08 16:44 - 00291026 _____ () C:\Windows\msxml4-KB954430-enu.LOG
2015-03-08 16:44 - 2015-03-08 16:44 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2015-03-08 01:56 - 2015-03-08 01:56 - 00000216 _____ () C:\DebugTrace-RockallDLL.log
2015-03-07 20:19 - 2015-03-07 20:19 - 00002161 _____ () C:\Users\Public\Desktop\Age of Empires III.lnk
2015-03-07 20:19 - 2015-03-07 20:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-03-07 19:55 - 2015-03-07 19:55 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2015-03-02 23:08 - 2015-03-02 23:08 - 00000000 ____D () C:\Users\Leon-Yannick\Desktop\Backup-TA-9.11
2015-03-02 23:07 - 2015-03-02 23:07 - 01599713 _____ () C:\Users\Leon-Yannick\Downloads\Backup-TA-9.11.zip
2015-03-02 22:41 - 2015-03-02 22:41 - 00000000 ____D () C:\Users\Leon-Yannick\Desktop\clockworkmod
2015-03-02 13:52 - 2015-03-02 13:52 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ggsemc_01009.Wdf
2015-03-02 13:52 - 2015-03-02 13:52 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ggflt_01009.Wdf
2015-03-02 13:44 - 2015-03-02 13:44 - 00000800 _____ () C:\Users\Leon-Yannick\Desktop\Flashtool.lnk
2015-03-02 12:51 - 2015-03-02 12:53 - 00012992 _____ () C:\Windows\DPINST.LOG
2015-03-02 12:49 - 2015-03-02 13:44 - 00000000 ____D () C:\Users\Leon-Yannick\.flashTool
2015-03-02 12:49 - 2015-03-02 12:49 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool
2015-03-02 12:49 - 2015-03-02 12:49 - 00000000 ____D () C:\Users\Leon-Yannick\.swt
2015-03-02 12:47 - 2015-03-02 13:55 - 00000000 ____D () C:\Flashtool
2015-03-02 12:11 - 2015-03-02 12:32 - 184443528 _____ (Androxyde) C:\Users\Leon-Yannick\Downloads\flashtool-0.9.18.5-windows.exe
2015-02-28 21:23 - 2015-03-08 00:46 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-28 20:11 - 2015-02-28 20:11 - 00000222 _____ () C:\Users\Leon-Yannick\Desktop\Nosgoth.url
2015-02-26 14:08 - 2015-02-26 14:08 - 21340088 _____ () C:\Users\Leon-Yannick\Downloads\C6903_14.4.A.0.157_KERNEL-21-non-rootable.ftf
2015-02-26 14:04 - 2015-02-26 14:04 - 21331858 _____ () C:\Users\Leon-Yannick\Downloads\C6903_14.4.A.0.108_KERNEL-21-towel-rootable.ftf
2015-02-26 13:47 - 2015-02-26 13:52 - 25047264 _____ () C:\Users\Leon-Yannick\Downloads\Z1-lockeddualrecovery2.8.2-RELEASE.installer.zip
2015-02-26 13:22 - 2015-02-26 13:22 - 02880770 _____ () C:\Users\Leon-Yannick\Downloads\EasyRootTool v12.4.zip
2015-02-26 13:16 - 2015-02-26 13:16 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf
2015-02-26 13:12 - 2015-02-26 13:12 - 00000000 ____D () C:\Users\Leon-Yannick\.android
2015-02-26 13:11 - 2015-02-26 13:12 - 00000000 ____D () C:\newroot
2015-02-26 13:03 - 2013-05-12 23:27 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2015-02-26 13:03 - 2013-05-12 23:27 - 01002728 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll
2015-02-26 12:59 - 2015-02-26 12:59 - 32242911 _____ () C:\Users\Leon-Yannick\Downloads\newroot.rar
2015-02-26 12:15 - 2015-02-26 12:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-02-25 17:47 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-25 17:47 - 2015-01-09 00:43 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-02-20 17:09 - 2015-02-20 17:09 - 00311624 _____ () C:\Windows\Minidump\022015-27549-01.dmp
2015-02-20 01:18 - 2015-02-20 01:18 - 32106640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 25460880 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 24768144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 20466496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 17253848 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 16017040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 14119744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 13294528 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 13208200 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 10773704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 10713256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 10284872 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-02-20 01:18 - 2015-02-20 01:18 - 03610768 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 03247248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 02902784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 01895240 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434752.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434752.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 01540240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00969872 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00943760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00929936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00908104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00877816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00496272 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00399504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00390472 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00353224 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00345744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00305136 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00195728 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-02-20 01:18 - 2015-02-20 01:18 - 00177624 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00164752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-02-20 01:18 - 2015-02-20 01:18 - 00030536 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-22 20:35 - 2015-02-12 16:30 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\TS3Client
2015-03-22 20:13 - 2009-07-14 05:45 - 00022528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-22 20:13 - 2009-07-14 05:45 - 00022528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-22 20:11 - 2015-02-04 17:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-22 20:09 - 2015-02-02 22:43 - 01052548 _____ () C:\Windows\WindowsUpdate.log
2015-03-22 20:06 - 2015-02-07 00:05 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\Spotify
2015-03-22 20:06 - 2015-02-07 00:05 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Local\Spotify
2015-03-22 20:06 - 2015-02-05 19:48 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-22 20:06 - 2015-02-03 14:19 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-03-22 20:06 - 2009-07-14 05:51 - 00057752 _____ () C:\Windows\setupact.log
2015-03-22 20:05 - 2015-02-03 12:08 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-22 20:05 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-22 19:59 - 2015-02-05 19:48 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-22 13:28 - 2010-11-21 04:47 - 00197240 _____ () C:\Windows\PFRO.log
2015-03-22 13:25 - 2015-02-03 12:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-03-22 13:12 - 2015-02-05 21:07 - 00000000 ____D () C:\Users\Leon-Yannick\Documents\Euro Truck Simulator 2
2015-03-22 12:49 - 2015-02-11 21:25 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-22 12:48 - 2015-02-02 23:33 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-22 11:16 - 2015-02-02 23:33 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-22 10:10 - 2015-02-07 00:23 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2015-03-22 09:38 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-03-22 09:35 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-03-22 08:44 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-03-22 08:05 - 2015-02-03 00:12 - 00000000 ____D () C:\Program Files (x86)\SpeedFan
2015-03-21 14:14 - 2015-02-10 20:35 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-03-18 21:54 - 2015-02-09 17:13 - 00000000 ____D () C:\Users\Leon-Yannick\Desktop\MemTest41
2015-03-18 20:25 - 2015-02-02 22:38 - 551943321 _____ () C:\Windows\MEMORY.DMP
2015-03-18 20:25 - 2015-02-02 22:38 - 00000000 ____D () C:\Windows\Minidump
2015-03-18 18:56 - 2015-02-07 00:05 - 00001802 _____ () C:\Users\Leon-Yannick\Desktop\Spotify.lnk
2015-03-18 07:29 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-15 20:48 - 2015-02-12 16:29 - 00001011 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2015-03-15 20:48 - 2015-02-10 20:36 - 00001786 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2015-03-15 20:48 - 2015-02-10 20:35 - 00002008 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-03-15 20:48 - 2015-02-04 18:57 - 00000904 _____ () C:\Users\Public\Desktop\Catzilla.lnk
2015-03-14 22:48 - 2015-02-08 12:58 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Local\ftblauncher
2015-03-12 16:36 - 2015-02-03 14:25 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\.technic
2015-03-12 15:26 - 2011-04-12 08:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2015-03-12 15:26 - 2011-04-12 08:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2015-03-12 15:26 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-12 15:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-03-11 16:16 - 2015-02-03 12:08 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2015-03-11 14:29 - 2009-07-14 05:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-03-11 14:26 - 2009-07-14 05:45 - 00295752 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-11 14:24 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-03-11 14:24 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-03-10 17:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-03-08 05:40 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-03-08 01:58 - 2015-02-17 09:39 - 00000000 ____D () C:\Users\Leon-Yannick\Documents\My Games
2015-03-08 01:57 - 2015-02-03 15:01 - 00283647 _____ () C:\Windows\DirectX.log
2015-03-08 01:53 - 2015-02-17 16:33 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-03-08 00:54 - 2015-02-03 12:07 - 01593956 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-03-07 20:19 - 2015-02-02 22:45 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-03-03 22:12 - 2015-02-12 16:30 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2015-03-02 12:49 - 2015-02-02 22:43 - 00000000 ____D () C:\Users\Leon-Yannick
2015-03-01 13:16 - 2015-02-18 15:49 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\TIPP10
2015-02-28 20:11 - 2015-02-11 22:03 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-02-26 17:42 - 2015-02-08 13:00 - 00000000 ____D () C:\Users\Leon-Yannick\Downloads\Monster
2015-02-24 22:04 - 2015-02-04 17:41 - 00001139 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-24 22:04 - 2015-02-04 17:41 - 00001139 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-24 21:38 - 2015-01-25 17:12 - 00000365 _____ () C:\Users\Leon-Yannick\AppData\Roaming\OLHS
2015-02-24 21:10 - 2015-02-09 23:54 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\DAEMON Tools Lite
2015-02-24 21:10 - 2015-02-08 12:58 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\ftblauncher
2015-02-24 21:10 - 2015-02-04 16:14 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\NVIDIA
2015-02-24 03:17 - 2010-11-21 04:27 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-02-22 19:43 - 2015-02-18 17:59 - 00000000 ___HD () C:\Program Files (x86)\DrFoneAndroid_Temp
2015-02-22 19:41 - 2015-02-18 17:59 - 00000000 ____D () C:\Users\Leon-Yannick\AppData\Roaming\Wondershare
2015-02-22 19:41 - 2015-02-18 17:59 - 00000000 ____D () C:\Program Files (x86)\Wondershare
2015-02-20 01:18 - 2015-02-03 12:08 - 00074056 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-02-20 01:18 - 2015-02-03 12:08 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-02-20 01:18 - 2015-02-03 11:59 - 18575880 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-02-20 01:18 - 2015-02-03 11:59 - 03299512 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-02-20 01:18 - 2015-02-03 11:59 - 00995248 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-02-20 01:18 - 2015-02-03 11:59 - 00027441 _____ () C:\Windows\system32\nvinfo.pb
==================== Files in the root of some directories =======
2015-01-25 17:12 - 2015-01-25 17:12 - 0002086 _____ () C:\Users\Leon-Yannick\AppData\Roaming\CIUZJIT
2015-01-25 17:12 - 2015-02-24 21:38 - 0000365 _____ () C:\Users\Leon-Yannick\AppData\Roaming\OLHS
2015-02-04 17:25 - 2015-02-04 17:25 - 0007602 _____ () C:\Users\Leon-Yannick\AppData\Local\resmon.resmoncfg
Some content of TEMP:
====================
C:\Users\Leon-Yannick\AppData\Local\Temp\Quarantine.exe
C:\Users\Leon-Yannick\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-15 13:38
==================== End Of Log ============================ --- --- --- |