GeEichberger | 20.05.2015 22:53 | Gerhard Eichberger
So, jetzt ist einmal das alles fertig.
Zuerst der Scan mit Malwarebptes Anti-Malware 2.1.6. Hier die Datei mbam.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 20.05.2015
Suchlauf-Zeit: 14:16:32
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.03.09.05
Rootkit Datenbank: v2015.02.25.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: HelmGerhard-Eichberg
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 389163
Verstrichene Zeit: 32 Min, 13 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 3
PUP.Optional.MusicToolBar.A, HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\SOFTWARE\jzipmusictoolbar181, In Quarantäne, [5a1fc77c0e7c96a025dc5e983dc6b34d],
PUP.Optional.Linkey.A, HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Linkey, In Quarantäne, [c1b8c47ffd8def4712613a6ba65dba46],
PUP.Optional.DealPly.A, HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\gaiilaahiahdejapggenmdmafpmbipje, In Quarantäne, [017810332862d660b55c617a1be8827e],
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 7
PUP.Optional.Datamngr.A, C:\ProgramData\Datamngr, In Quarantäne, [304964df0e7cca6c5bc848c8d72e56aa],
PUP.Optional.OpenCandy, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\OpenCandy, In Quarantäne, [067365dec5c5fd39453a0e5bd72c5da3],
PUP.Optional.OpenCandy, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\OpenCandy\D034EAD010CA4621A98E118F3D3676DE, In Quarantäne, [067365dec5c5fd39453a0e5bd72c5da3],
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro, In Quarantäne, [db9ec1829cee6ec8e998d6937e8537c9],
PUP.Optional.Datamngr.A, C:\Users\HelmGerhard-Eichberg\AppData\LocalLow\DataMngr, In Quarantäne, [4c2d61e2fa909a9c56562e4114ef40c0],
PUP.Optional.MusicToolBar.A, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Mozilla\Firefox\Profiles\5mtpiq13.default\jzipmusictoolbar181, In Quarantäne, [c1b84ff4fa90f640d0bd97da1de6639d],
PUP.Optional.AdsRemover.A, C:\ProgramData\Ads Remover, In Quarantäne, [50292320dbafb581b7facbc6966d7c84],
Dateien: 27
PUP.Optional.SilentInstall.A, C:\ProgramData\Browese2ssaaviee\uninstall.exe, In Quarantäne, [5029ef545535fc3a7d4a141ffb06ea16],
PUP.Optional.SilentInstall.A, C:\ProgramData\conatiinuaeotaoassaVe\uninstall.exe, In Quarantäne, [ef8ad56ecac0092dd4f356dde12052ae],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\We Love Deals\We Love Deals.exe, In Quarantäne, [f584ef54fb8fc67080f8b7767e843bc5],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\Sprucemarks\Sprucemarks.exe, In Quarantäne, [5326f54e4743df5772061419f30f52ae],
PUP.Optional.OpenCandy, C:\Users\HelmGerhard-Eichberg\Downloads\DTLite4491-0356.exe, In Quarantäne, [394055ee355513234fda02063dc93bc5],
PUP.Optional.Driverboss, C:\Users\HelmGerhard-Eichberg\AppData\Local\Lexmark Drivers Update Utility\liveupdate.7z.exe, In Quarantäne, [1f5a10333159be78466837179b6744bc],
PUP.Optional.Spigot.A, C:\Windows\Installer\394f13b.msi, In Quarantäne, [fc7d1c27147616204d434c8a42bfff01],
PUP.Optional.Datamngr.A, C:\ProgramData\Datamngr\coordinator.cfg, In Quarantäne, [304964df0e7cca6c5bc848c8d72e56aa],
PUP.Optional.Datamngr.A, C:\ProgramData\Datamngr\general.cfg, In Quarantäne, [304964df0e7cca6c5bc848c8d72e56aa],
PUP.Optional.Datamngr.A, C:\ProgramData\Datamngr\S-1-5-21-3939595492-2884219484-1246490395-1001.cfg, In Quarantäne, [304964df0e7cca6c5bc848c8d72e56aa],
PUP.Optional.Datamngr.A, C:\ProgramData\Datamngr\S-1-5-32.cfg, In Quarantäne, [304964df0e7cca6c5bc848c8d72e56aa],
PUP.Optional.OpenCandy, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\OpenCandy\D034EAD010CA4621A98E118F3D3676DE\WebCompanionInstaller.exe, In Quarantäne, [067365dec5c5fd39453a0e5bd72c5da3],
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Custom.dll, In Quarantäne, [db9ec1829cee6ec8e998d6937e8537c9],
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Readme.txt, In Quarantäne, [db9ec1829cee6ec8e998d6937e8537c9],
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Setup.dat, In Quarantäne, [db9ec1829cee6ec8e998d6937e8537c9],
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Setup.exe, In Quarantäne, [db9ec1829cee6ec8e998d6937e8537c9],
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Setup.ico, In Quarantäne, [db9ec1829cee6ec8e998d6937e8537c9],
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\TsuDll.dll, In Quarantäne, [db9ec1829cee6ec8e998d6937e8537c9],
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\_Setup.dll, In Quarantäne, [db9ec1829cee6ec8e998d6937e8537c9],
PUP.Optional.Datamngr.A, C:\Users\HelmGerhard-Eichberg\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}, In Quarantäne, [4c2d61e2fa909a9c56562e4114ef40c0],
PUP.Optional.Datamngr.A, C:\Users\HelmGerhard-Eichberg\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}64, In Quarantäne, [4c2d61e2fa909a9c56562e4114ef40c0],
PUP.Optional.MusicToolBar.A, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Mozilla\Firefox\Profiles\5mtpiq13.default\jzipmusictoolbar181\apnuserid.dat, In Quarantäne, [c1b84ff4fa90f640d0bd97da1de6639d],
PUP.Optional.MusicToolBar.A, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Mozilla\Firefox\Profiles\5mtpiq13.default\jzipmusictoolbar181\appid.dat, In Quarantäne, [c1b84ff4fa90f640d0bd97da1de6639d],
PUP.Optional.MusicToolBar.A, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Mozilla\Firefox\Profiles\5mtpiq13.default\jzipmusictoolbar181\geodata.xml, In Quarantäne, [c1b84ff4fa90f640d0bd97da1de6639d],
PUP.Optional.MusicToolBar.A, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Mozilla\Firefox\Profiles\5mtpiq13.default\jzipmusictoolbar181\setupCfg.xml, In Quarantäne, [c1b84ff4fa90f640d0bd97da1de6639d],
PUP.Optional.MusicToolBar.A, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Mozilla\Firefox\Profiles\5mtpiq13.default\jzipmusictoolbar181\sysid.dat, In Quarantäne, [c1b84ff4fa90f640d0bd97da1de6639d],
PUP.Optional.MusicToolBar.A, C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Mozilla\Firefox\Profiles\5mtpiq13.default\jzipmusictoolbar181\trackid.dat, In Quarantäne, [c1b84ff4fa90f640d0bd97da1de6639d],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Dann der Durchlauf von AdwCleaner 4.204. Hier die Datei AdwCleaner[S1].txt:
AdwCleaner Logfile: Code:
# AdwCleaner v4.204 - Bericht erstellt 20/05/2015 um 20:55:58
# Aktualisiert 12/05/2015 von Xplode
# Datenbank : 2015-05-12.2 [Lokal]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : HelmGerhard-Eichberg - HELMGERHARD-EIC
# Gestarted von : D:\Daten\Heruntergeladene Programme\AdwCleaner 4.204\von filepony.de - download-adwcleaner - get-mirror-server.html\AdwCleaner_4.204.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\{0f6172df-54c3-2c2a-0f61-172df54ccb7d}
Ordner Gelöscht : C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Ordner Gelöscht : C:\ProgramData\ldjfeejmmbnmpbonojkinjgolgfjbmjc
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Linkey
Schlüssel Gelöscht : HKLM\SOFTWARE\PIP
Schlüssel Gelöscht : HKLM\SOFTWARE\AIM Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17801
-\\ Mozilla Firefox v24.0 (de)
-\\ Google Chrome v42.0.2311.152
[C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Extension] : nmmhkkegccagdldgiimedpiccmgmieda
[C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Extension] : ldjfeejmmbnmpbonojkinjgolgfjbmjc
*************************
AdwCleaner[R0].txt - [50785 Bytes] - [16/04/2015 17:46:36]
AdwCleaner[R1].txt - [2011 Bytes] - [20/05/2015 20:50:23]
AdwCleaner[S0].txt - [43250 Bytes] - [16/04/2015 17:54:44]
AdwCleaner[S1].txt - [1832 Bytes] - [20/05/2015 20:55:58]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1891 Bytes] ########## --- --- ---
Und dann folgte der Durchlauf von Junkware Removal Tool 6.7.5. Hier die Datei JRT.txt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.7.5 (05.20.2015:1)
OS: Windows 7 Home Premium x64
Ran by HelmGerhard-Eichberg on 20.05.2015 at 23:17:46,24
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
~~~ Files
Successfully deleted: [File] C:\Users\HelmGerhard-Eichberg\appdata\local\google\chrome\user data\default\local storage\http_click.dealshark.com_0.localstorage
Successfully deleted: [File] C:\Users\HelmGerhard-Eichberg\appdata\local\google\chrome\user data\default\local storage\http_click.dealshark.com_0.localstorage-journal
Successfully deleted: [File] C:\Users\HelmGerhard-Eichberg\appdata\local\google\chrome\user data\default\local storage\http_sb.scorecardresearch.com_0.localstorage
Successfully deleted: [File] C:\Users\HelmGerhard-Eichberg\appdata\local\google\chrome\user data\default\local storage\http_sb.scorecardresearch.com_0.localstorage-journal
Successfully deleted: [File] C:\Users\HelmGerhard-Eichberg\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage
Successfully deleted: [File] C:\Users\HelmGerhard-Eichberg\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal
Successfully deleted: [File] C:\Users\HelmGerhard-Eichberg\appdata\local\google\chrome\user data\default\local storage\https_www.superfish.com_0.localstorage
Successfully deleted: [File] C:\Users\HelmGerhard-Eichberg\appdata\local\google\chrome\user data\default\local storage\https_www.superfish.com_0.localstorage-journal
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{00551257-2DAD-4338-9101-4C4FF08C73ED}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{0414A0B8-21F0-4217-B1F1-262EE9A59C9D}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{05D9A285-28DA-4D25-A4D5-FDFCEACBAD6A}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{07B33081-6098-4540-BAC8-386200C73DB7}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{0990388F-EC0A-44E4-BED7-C51CA04C7B9C}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{0A888F5C-4E24-4D8A-8630-51C9F9D7044A}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{115A62CF-A410-4F17-9270-27F63D2AA4B9}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{1436C43D-879A-448F-BEA8-FC9EA0407FEA}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{1583A7CC-BBF8-4A47-988A-D72DD74209E2}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{242DC535-E9EC-42F1-888E-A988B1BEDB5A}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{2717BCB4-99F0-477A-8888-CB784A48D8EB}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{29E0CBB3-53DF-444C-8607-B7C48237C04F}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{2AA09EBC-3A83-4984-96A4-4531FAB6ADCD}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{2B04DE06-316E-478A-808B-C7FAC68326BF}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{31A2988C-0589-4342-886C-5E016E10BC93}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{31E7BD52-9F2B-4BA5-8C15-5B2A5DBA50B1}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{341F3B47-5F37-4761-AC8B-4963FD26CBB2}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{38CC9B25-6CD5-43E4-B2B6-2A1ED622C82F}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{3FAB4B15-E500-44D4-9FD0-7D9647302FD6}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{4A1B87EC-4A3B-4DB8-A6CA-16E1CFA9E3BA}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{4E04B490-D7C3-418C-AC1D-2472E143EA95}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{4F5CB9F1-246A-4FB0-8379-C737AF36944E}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{5152E088-7388-40AF-946B-F64F3E255984}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{5298C1B2-A3E2-4DE7-8E80-C9037CFFC7D9}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{5694968C-7EA4-4C94-B27A-FAC562DEDB37}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{56F6B084-E012-46E5-856F-2D0D8CC333C9}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{5CE607EB-D89E-46DF-8AA0-5DB62A292418}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{5CF3FD9D-C598-4F20-A570-9DA21FF2FB79}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{5DDECF11-2E4E-4CCD-8BE7-3AFC738F759E}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{616F4344-4E74-4D82-A4BA-835B40905902}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{65E28D56-97D5-450B-A274-8CBF8E8D8243}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{67D7CE8D-CF8E-4058-8ACE-780D9C1EF711}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{6A5012E1-F588-4722-BDCA-7BFE967D2003}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{6BBE678E-BB66-43DC-9B4D-3F41B20AE2B4}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{6CF56135-5D71-4EA4-9AE8-8CFD1DBA6DC5}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{736CB9F6-D3E1-4B59-9EF0-E6E963B1ABCF}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{744997CA-D6EF-4968-A0B3-125EC3FE89E5}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{756C4FC8-632C-468B-82FC-E1DC07653F13}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{76A7014F-10FC-4AC2-87BA-F150DEED9178}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{7E1E1EAD-1072-4644-94ED-937C44028EE7}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{8183D4A8-4375-460E-B61C-D7EFA2D99433}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{8278FB61-8B7A-40DB-B2E4-7A5F3A4390BA}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{85D64F43-0730-40A0-B844-ECC8C5EB49CA}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{8667ED31-D18F-4FED-AB4C-1B5719099B63}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{8920D708-05D6-46E4-B99C-37C75C966018}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{894DD5E3-4520-4148-B56E-2CED06BF5010}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{896B75D6-1BC5-475F-B186-8B45B993E10C}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{8BB09D4D-3670-463E-A02C-B7963EBBE919}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{8BB6D0D5-8BAF-4A9C-9E9A-C57C50EB5026}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{8BE0E46C-65EA-41D6-AB82-9A6706897AEA}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{8CBB22F8-98BC-4B73-A3B1-18BAB77F0815}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{8F429DBE-0D10-4C30-BC77-ABB58E3505B7}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{A40E3C51-0E42-408B-AC0A-1745DF04113A}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{B0B34B0D-BCF8-4A92-81F8-9BCDF28A7950}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{B65DEE74-906E-4C20-A3BD-B8ABD18DD390}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{BA5AA444-5ACE-46E3-BC8A-F4542EA740E4}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{BEB4D305-F102-44A3-8328-43BF6361B2DF}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{CCCD4F79-C247-4A97-9515-0B80AFFA4CEF}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{D48B7D1E-8369-40EB-9A5D-D61CFA486D24}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{D521E66B-FD1F-45F0-9F9B-2D089F0F7F01}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{DAE217CF-11B2-48FF-81AB-E0D40EDCC65C}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{DB7AC93D-3A0D-4C87-9B01-8B7E6C1B8AD8}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{DCFB76DB-8238-485C-AC85-74F590EEFBD2}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{E102C5BA-629B-4CAC-847F-87F658D5373F}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{E3ED5A74-C99B-4283-91BC-3FF60F85F7B2}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{E7DDF346-5A26-457D-BC9B-377A04CE916D}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{EB778676-D14F-42BF-B77B-01E817E22D83}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{F29BEFA2-F01C-419A-93F9-92C79B7DFC20}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{F67E277A-BB7F-4721-AB1E-735D3CD55D06}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{F83EC010-08F5-4394-A18C-7ECCA86A0B75}
Successfully deleted: [Empty Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\{FC260586-E58D-49F5-9EEF-3C94CA2C86A5}
Successfully deleted: [Folder] C:\Users\HelmGerhard-Eichberg\appdata\locallow\ytd
Successfully deleted: [Folder] C:\ProgramData\Browese2ssaaviee
Successfully deleted: [Folder] C:\ProgramData\conatiinuaeotaoassaVe
~~~ Chrome
Successfully deleted: [Folder] C:\Users\HelmGerhard-Eichberg\appdata\local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.05.2015 at 23:23:05,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Dann der erneute Scan mit Farbar's Recovery Scan Tool. Hier die neue Datei FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2015
Ran by HelmGerhard-Eichberg (administrator) on HELMGERHARD-EIC on 20-05-2015 23:48:00
Running from D:\Daten\Heruntergeladene Programme\Farbar's Recovery Scan Tool (64 Bit)\von filepony.de - download-frst64 - get-mirror-server.html
Loaded Profiles: HelmGerhard-Eichberg (Available profiles: HelmGerhard-Eichberg)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(mquadr.at software engineering and consulting GmbH, web: www.mquadr.at, mail: office@mquadr.at) C:\Program Files (x86)\A1 Dashboard\Dashboard.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(RealNetworks, Inc.) C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-11] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-17] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-04-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-01-25] (cyberlink)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2014-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HPConnectionManager] => C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [103992 2011-05-23] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-01-20] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2012-11-13] ()
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263512 2012-11-30] ()
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Ad-Aware Antivirus] => "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [296520 2015-04-23] (RealNetworks, Inc.)
HKLM-x32\...\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [560192 2014-10-29] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2013-01-16] (Hewlett-Packard Company)
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\...\Run: [WinEjectAutoStart1] => C:\Program Files (x86)\WinEject\WinEject.exe [96768 2001-05-10] (Ingo Heeskens)
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\...\Run: [WinEjectAutoStart6] => C:\Program Files (x86)\WinEject\WinEject.exe [96768 2001-05-10] (Ingo Heeskens)
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\...\Run: [Steam] => C:\Spiele\Steam\Steam.exe [2888896 2015-03-24] (Valve Corporation)
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\...\Run: [EADM] => D:\Spiele\Origin\Origin.exe [3600216 2014-09-03] (Electronic Arts)
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2014-08-26] (Google Inc.)
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.Exe [77112 2011-05-27] (Hewlett-Packard Company)
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\...\RunOnce: [Adobe Speed Launcher] => 1432148351
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\...\Policies\system: [DisableChangePassword] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2015-04-23]
ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)
Startup: C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk [2011-10-13]
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bit
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3939595492-2884219484-1246490395-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM-x32 -> {6D11BC5D-4CF2-4D9C-BE12-1A27A8A8973E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-10-26] (RealDownloader)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-05-19] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-19] (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-10-26] (RealDownloader)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
Toolbar: HKLM-x32 - No Name - !{F3FEE66E-E034-436a-86E4-9690573BEE8A} - No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-3939595492-2884219484-1246490395-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-3939595492-2884219484-1246490395-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
DPF: HKLM {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
Tcpip\..\Interfaces\{10D67CF3-FB1C-452B-89F2-DA7BE14E854B}: [NameServer] 194.48.128.199 194.48.139.254
Tcpip\..\Interfaces\{2098BF6E-5954-4252-AB00-9732BBEE6C44}: [NameServer] 194.48.128.199 194.48.139.254
Tcpip\..\Interfaces\{B05A8D60-957C-4F60-8E42-2895DB38D546}: [NameServer] 194.48.139.254 194.48.128.199
Tcpip\..\Interfaces\{BC825217-8138-4E46-A022-87D4998F6CE2}: [NameServer] 194.48.128.199 194.48.139.254
Tcpip\..\Interfaces\{FA98CF6D-FCF7-4B44-ACA4-92638A10D499}: [NameServer] 194.48.139.254 194.48.124.200
FireFox:
========
FF ProfilePath: C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Mozilla\Firefox\Profiles\5mtpiq13.default
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2011-06-20] (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-19] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-12-13] (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2011-06-20] (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-19] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2011-12-02] (Nero AG)
FF Plugin-x32: @real.com/nppl3260;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2015-04-23] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.15 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-10-26] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2015-04-23] (RealPlayer Cloud)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-03-17] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\33\NP_wtapp.dll [2014-12-05] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3939595492-2884219484-1246490395-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\HelmGerhard-Eichberg\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-01-26] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3939595492-2884219484-1246490395-1001: @www.flatcast.com/FlatViewer 5.2 -> C:\Users\HELMGE~1\AppData\Roaming\Flatcast\NpFv522.dll [2009-09-21] (1 mal 1 Software GmbH)
FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com [2013-10-13]
FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2013-01-16]
FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2013-01-16]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &video& - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-01-16]
FF HKLM-x32\...\Firefox\Extensions: [{338950EA-82DB-44C1-930D-0C28E023C9F0}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2015-04-23]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Website Logon) - C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe [2011-12-16]
CHR Extension: (YouTube) - C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-19]
CHR Extension: (Freemake Video Downloader) - C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2013-01-16]
CHR Extension: (Google Search) - C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-19]
CHR Extension: (Bookmark Manager) - C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-06]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-06]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-01-16]
CHR Extension: (Gmail) - C:\Users\HelmGerhard-Eichberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-19]
CHR HKLM-x32\...\Chrome\Extension: [aepeildmfnnehghlknddebgjghlompfe] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-02-11]
CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-01-16]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-04-01] (Advanced Micro Devices, Inc.) [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2014-07-23] (BlueStack Systems, Inc.)
S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384728 2014-07-23] (BlueStack Systems, Inc.)
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [773848 2014-07-23] (BlueStack Systems, Inc.)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-01-25] (CyberLink)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1254400 2015-04-27] (Microsoft Corporation)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101376 2013-01-10] (Freemake) [File not signed]
S2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-01-10] (Ellora Assets Corp.) [File not signed]
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [373824 2015-05-19] (WildTangent)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
S2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2375168 2011-03-08] (Realsil Microelectronics Inc.) [File not signed]
S2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2013-01-16] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-10-26] ()
S2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2015-04-23] (RealNetworks, Inc.)
S2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31856 2014-10-30] ()
S2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S4 WTGService; C:\Program Files (x86)\3DataManager\WTGService.exe [267720 2008-10-21] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-07-23] (BlueStack Systems)
R3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-07-05] (GFI Software)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [47632 2013-04-29] (Panda Security, S.L.)
S4 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [68608 2005-08-10] (Protection Technology) [File not signed]
S4 sfhlp02; C:\Windows\System32\drivers\sfhlp02.sys [7168 2005-05-16] (Protection Technology) [File not signed]
S4 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [89600 2005-11-03] (Protection Technology) [File not signed]
S3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 23:23 - 2015-05-20 23:23 - 00011186 _____ () C:\Users\HelmGerhard-Eichberg\Desktop\JRT - 2015-05-20 23.23.txt
2015-05-20 23:17 - 2015-05-20 23:17 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-HELMGERHARD-EIC-Windows-7-Home-Premium-(64-bit).dat
2015-05-20 23:17 - 2015-05-20 23:17 - 00000000 ____D () C:\RegBackup
2015-05-20 22:02 - 2015-05-20 22:02 - 00001971 _____ () C:\Users\HelmGerhard-Eichberg\Desktop\AdwCleaner[S1] - 2015-05-20 20.55.txt
2015-05-20 20:00 - 2015-05-20 20:00 - 00000810 _____ () C:\Users\HelmGerhard-Eichberg\Desktop\Edna bricht aus Demo.lnk
2015-05-20 20:00 - 2015-05-20 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xider
2015-05-20 16:51 - 2015-05-20 16:51 - 00006782 _____ () C:\Users\HelmGerhard-Eichberg\Desktop\mbam - 2015-05-20 14.16.txt
2015-05-20 16:11 - 2015-05-20 20:57 - 00010416 _____ () C:\Windows\PFRO.log
2015-05-20 14:15 - 2015-05-20 16:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-20 14:14 - 2015-05-20 14:14 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-20 14:14 - 2015-05-20 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-20 14:14 - 2015-05-20 14:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-20 14:14 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-20 14:14 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-20 14:14 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-19 08:41 - 2015-05-19 08:41 - 00041378 _____ () C:\ComboFix.txt
2015-05-17 19:10 - 2015-05-19 08:42 - 00000000 ____D () C:\Qoobox
2015-05-17 19:10 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-05-17 19:10 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-05-17 19:10 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-05-17 19:10 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-05-17 19:10 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-05-17 19:10 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-05-17 19:10 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-05-17 19:10 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-05-17 19:09 - 2015-05-19 08:36 - 00000000 ____D () C:\Windows\erdnt
2015-05-15 23:27 - 2015-05-15 23:31 - 00000000 ____D () C:\Windows\rescache
2015-05-14 08:40 - 2015-05-01 15:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 08:40 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 19:59 - 2015-05-05 03:29 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 19:59 - 2015-05-05 03:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-13 19:59 - 2015-04-22 04:28 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 19:59 - 2015-04-22 03:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-13 19:59 - 2015-04-21 19:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-13 19:59 - 2015-04-21 19:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 19:59 - 2015-04-21 18:51 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-13 19:59 - 2015-04-21 18:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-13 19:59 - 2015-04-21 18:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-13 19:59 - 2015-04-21 18:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-13 19:59 - 2015-04-21 18:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 19:59 - 2015-04-21 18:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-05-13 19:59 - 2015-04-21 18:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-13 19:59 - 2015-04-21 18:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 19:59 - 2015-04-21 18:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-13 19:59 - 2015-04-21 18:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-05-13 19:59 - 2015-04-21 18:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-05-13 19:59 - 2015-04-21 18:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-05-13 19:59 - 2015-04-21 18:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 19:59 - 2015-04-21 18:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-13 19:59 - 2015-04-21 18:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-05-13 19:59 - 2015-04-21 18:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-05-13 19:59 - 2015-04-21 18:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-05-13 19:59 - 2015-04-21 17:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-13 19:59 - 2015-04-21 17:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-05-13 19:59 - 2015-04-21 17:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-05-13 19:59 - 2015-04-21 17:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 19:59 - 2015-04-21 17:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 19:59 - 2015-04-21 17:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-05-13 19:59 - 2015-04-21 17:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-05-13 19:59 - 2015-04-21 17:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-13 19:59 - 2015-04-21 17:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-13 19:59 - 2015-04-21 17:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-13 19:59 - 2015-04-21 17:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-13 19:59 - 2015-04-21 17:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-13 19:59 - 2015-04-21 17:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 19:59 - 2015-04-21 17:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 19:59 - 2015-04-21 16:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-13 19:59 - 2015-04-21 16:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-13 19:59 - 2015-04-18 05:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-13 19:59 - 2015-04-18 04:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-13 19:58 - 2015-04-27 21:28 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-13 19:58 - 2015-04-27 21:28 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-13 19:58 - 2015-04-27 21:28 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-13 19:58 - 2015-04-27 21:26 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 01254400 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-05-13 19:58 - 2015-04-27 21:23 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-05-13 19:58 - 2015-04-27 21:22 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-05-13 19:58 - 2015-04-27 21:22 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-05-13 19:58 - 2015-04-27 21:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-13 19:58 - 2015-04-27 21:22 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-13 19:58 - 2015-04-27 21:22 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-05-13 19:58 - 2015-04-27 21:22 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-05-13 19:58 - 2015-04-27 21:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-05-13 19:58 - 2015-04-27 21:22 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-13 19:58 - 2015-04-27 21:22 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-05-13 19:58 - 2015-04-27 21:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-13 19:58 - 2015-04-27 21:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-13 19:58 - 2015-04-27 21:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 21:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-05-13 19:58 - 2015-04-27 21:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-05-13 19:58 - 2015-04-27 21:08 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-05-13 19:58 - 2015-04-27 21:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-05-13 19:58 - 2015-04-27 21:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-05-13 19:58 - 2015-04-27 21:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-05-13 19:58 - 2015-04-27 21:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-05-13 19:58 - 2015-04-27 21:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-05-13 19:58 - 2015-04-27 21:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-05-13 19:58 - 2015-04-27 21:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-05-13 19:58 - 2015-04-27 21:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-05-13 19:58 - 2015-04-27 21:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-05-13 19:58 - 2015-04-27 21:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-05-13 19:58 - 2015-04-27 21:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-05-13 19:58 - 2015-04-27 21:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-05-13 19:58 - 2015-04-27 21:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-05-13 19:58 - 2015-04-27 21:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-05-13 19:58 - 2015-04-27 21:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-05-13 19:58 - 2015-04-27 21:04 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-05-13 19:58 - 2015-04-27 21:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-05-13 19:58 - 2015-04-27 21:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-05-13 19:58 - 2015-04-27 21:03 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-05-13 19:58 - 2015-04-27 21:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-05-13 19:58 - 2015-04-27 21:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-05-13 19:58 - 2015-04-27 21:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-05-13 19:58 - 2015-04-27 21:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-05-13 19:58 - 2015-04-27 21:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-05-13 19:58 - 2015-04-27 21:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 20:06 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-13 19:58 - 2015-04-27 19:57 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-05-13 19:58 - 2015-04-27 19:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-05-13 19:58 - 2015-04-27 19:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 19:58 - 2015-04-27 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-13 19:58 - 2015-04-21 19:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 19:58 - 2015-04-21 18:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 19:58 - 2015-04-21 18:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 19:58 - 2015-04-21 18:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 19:58 - 2015-04-21 18:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-13 19:58 - 2015-04-21 18:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-13 19:58 - 2015-04-21 18:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 19:58 - 2015-04-21 18:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 19:58 - 2015-04-21 18:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-13 19:58 - 2015-04-21 18:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-13 19:58 - 2015-04-21 18:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 19:58 - 2015-04-21 18:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-13 19:58 - 2015-04-21 18:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-13 19:58 - 2015-04-21 18:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-13 19:58 - 2015-04-21 18:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 19:58 - 2015-04-21 17:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-13 19:58 - 2015-04-21 17:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 19:58 - 2015-04-21 17:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 19:58 - 2015-04-21 17:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-05-13 19:58 - 2015-04-21 17:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-13 19:58 - 2015-04-21 17:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 19:58 - 2015-04-21 17:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-05-13 19:58 - 2015-04-21 17:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-13 19:58 - 2015-04-13 05:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 19:57 - 2015-04-20 05:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 19:57 - 2015-04-20 05:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 19:57 - 2015-04-20 04:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-13 19:57 - 2015-04-20 04:11 - 03204608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 19:57 - 2015-04-08 05:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-13 19:57 - 2015-04-08 05:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-05-13 19:57 - 2015-03-04 06:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-13 19:57 - 2015-03-04 06:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-13 19:57 - 2015-03-04 06:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-13 19:57 - 2015-03-04 06:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-13 19:57 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-05-13 19:57 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-05-13 19:57 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-13 19:57 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-05-13 19:57 - 2015-02-18 09:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-13 19:57 - 2015-01-29 05:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-13 19:57 - 2015-01-29 05:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-05-09 00:25 - 2015-05-09 00:25 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Local\CDex
2015-05-09 00:24 - 2015-05-09 00:24 - 00000973 _____ () C:\Users\Public\Desktop\CDex.lnk
2015-05-09 00:24 - 2015-05-09 00:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex
2015-05-09 00:23 - 2015-05-09 00:23 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Lavasoft
2015-05-09 00:22 - 2015-05-09 00:24 - 00000000 ____D () C:\Program Files (x86)\CDex
2015-05-07 17:21 - 2015-05-07 17:21 - 00001270 _____ () C:\Users\HelmGerhard-Eichberg\Desktop\Revo Uninstaller.lnk
2015-05-07 17:21 - 2015-05-07 17:21 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-05-06 19:19 - 2015-05-20 23:48 - 00000000 ____D () C:\FRST
2015-05-01 03:35 - 2015-05-16 09:26 - 00003384 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3939595492-2884219484-1246490395-1001
2015-05-01 03:35 - 2015-05-16 09:26 - 00003280 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3939595492-2884219484-1246490395-1001
2015-04-26 16:26 - 2015-04-26 16:28 - 00004266 _____ () C:\Users\HelmGerhard-Eichberg\Desktop\Mit Geld nicht umgehen können.txt
2015-04-23 22:27 - 2015-04-23 22:27 - 00003468 _____ () C:\Windows\System32\Tasks\RealDownloader Update Check
2015-04-23 22:23 - 2015-04-23 22:23 - 00001136 _____ () C:\Users\Public\Desktop\RealPlayer Cloud.lnk
2015-04-23 22:22 - 2015-04-23 22:22 - 00000000 ____D () C:\Program Files (x86)\RealNetworks
2015-04-23 22:21 - 2015-04-23 22:21 - 00201800 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2015-04-23 22:20 - 2015-04-23 22:20 - 00505416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2015-04-23 22:20 - 2015-04-23 22:20 - 00278600 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2015-04-23 21:50 - 2015-04-23 22:22 - 00003406 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3939595492-2884219484-1246490395-1001
2015-04-23 21:39 - 2015-04-23 21:39 - 00003052 _____ () C:\Windows\System32\Tasks\{BE8C02AD-B07A-4D30-AC0A-2E3205ACBF33}
2015-04-23 21:38 - 2015-04-23 21:38 - 00003052 _____ () C:\Windows\System32\Tasks\{260DCA7D-7122-4175-AC43-1A2335250BA0}
2015-04-22 18:57 - 2015-04-22 18:57 - 00001031 _____ () C:\Users\Public\Desktop\Tomb Raider - Underworld Demo.lnk
2015-04-22 18:10 - 2015-04-22 18:10 - 00002074 _____ () C:\Users\HelmGerhard-Eichberg\Desktop\3D SexVilla 2 - Everlust starten.lnk
2015-04-22 18:10 - 2015-04-22 18:10 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\thriXXX
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 23:25 - 2012-10-19 01:04 - 00239066 _____ () C:\Users\HelmGerhard-Eichberg\Desktop\Verbindungszeiten A1 - alt.txt
2015-05-20 23:24 - 2012-12-12 22:51 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-20 22:15 - 2013-02-07 16:45 - 01649306 _____ () C:\Windows\WindowsUpdate.log
2015-05-20 22:05 - 2014-07-03 13:52 - 00003276 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForHelmGerhard-Eichberg
2015-05-20 22:05 - 2014-07-03 13:52 - 00000392 _____ () C:\Windows\Tasks\HPCeeScheduleForHelmGerhard-Eichberg.job
2015-05-20 22:04 - 2014-06-18 21:43 - 00000000 ____D () C:\ProgramData\Origin
2015-05-20 22:04 - 2011-08-26 21:27 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg
2015-05-20 21:08 - 2009-07-14 06:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-20 21:08 - 2009-07-14 06:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-20 21:00 - 2011-09-30 10:08 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-05-20 20:58 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-20 20:57 - 2013-02-07 16:36 - 00035774 _____ () C:\Windows\setupact.log
2015-05-20 20:56 - 2015-04-16 17:45 - 00000000 ____D () C:\AdwCleaner
2015-05-20 18:24 - 2011-08-26 21:43 - 00004018 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{FDFBD11B-4412-4ECA-B749-7A528BA2C8DB}
2015-05-20 16:20 - 2011-05-08 01:56 - 00700118 _____ () C:\Windows\system32\perfh007.dat
2015-05-20 16:20 - 2011-05-08 01:56 - 00149968 _____ () C:\Windows\system32\perfc007.dat
2015-05-20 16:20 - 2009-07-14 07:13 - 00905922 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-20 16:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas
2015-05-20 16:09 - 2015-04-15 13:32 - 00000000 ____D () C:\Program Files (x86)\We Love Deals
2015-05-20 16:09 - 2015-03-31 23:26 - 00000000 ____D () C:\Program Files (x86)\Sprucemarks
2015-05-20 16:09 - 2014-10-28 22:58 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Local\Lexmark Drivers Update Utility
2015-05-20 16:09 - 2013-03-07 23:08 - 00000000 ____D () C:\ProgramData\InstallMate
2015-05-20 14:14 - 2013-02-03 15:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-19 22:40 - 2011-08-30 22:10 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Local\CrashDumps
2015-05-19 21:58 - 2011-05-07 16:39 - 00000000 ____D () C:\Program Files (x86)\Java
2015-05-19 21:53 - 2015-03-01 11:45 - 00110688 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2015-05-19 21:53 - 2011-05-07 16:39 - 00000000 ____D () C:\Program Files\Java
2015-05-19 21:52 - 2014-10-30 23:18 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-05-19 18:27 - 2011-05-07 16:21 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2015-05-19 08:41 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2015-05-19 08:28 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2015-05-19 08:24 - 2009-07-14 04:34 - 85458944 _____ () C:\Windows\system32\config\software.bak
2015-05-19 08:24 - 2009-07-14 04:34 - 20185088 _____ () C:\Windows\system32\config\system.bak
2015-05-19 08:24 - 2009-07-14 04:34 - 00786432 _____ () C:\Windows\system32\config\default.bak
2015-05-19 08:24 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\security.bak
2015-05-19 08:24 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\sam.bak
2015-05-18 14:10 - 2011-12-16 22:34 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-18 14:10 - 2011-12-16 22:34 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-18 14:10 - 2011-12-16 22:34 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-18 14:10 - 2011-12-16 22:34 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-18 04:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2015-05-18 03:22 - 2014-12-10 19:03 - 00000000 ____D () C:\Windows\system32\appraiser
2015-05-18 03:22 - 2014-05-07 07:19 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-05-17 16:56 - 2013-07-05 00:23 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Ad-Aware Antivirus
2015-05-17 13:23 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-16 09:26 - 2014-10-03 21:48 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\Desktop\original
2015-05-16 09:25 - 2012-03-17 09:25 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\Desktop\diverse Texte
2015-05-16 09:23 - 2012-05-30 23:22 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\Desktop\Installationsdateien
2015-05-15 22:26 - 2009-07-14 06:45 - 00300856 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-15 22:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-15 22:03 - 2012-05-17 09:12 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-05-15 22:03 - 2012-05-17 09:12 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-05-14 09:16 - 2011-09-09 10:29 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2015-05-14 09:16 - 2011-07-22 12:56 - 00933540 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-05-14 09:13 - 2013-02-07 17:15 - 00001912 _____ () C:\Windows\epplauncher.mif
2015-05-14 09:13 - 2013-02-07 17:14 - 00002119 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-05-14 09:13 - 2013-02-07 17:14 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-05-14 09:13 - 2013-02-07 17:14 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2015-05-14 09:10 - 2013-08-03 08:08 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-14 08:49 - 2011-09-27 22:29 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-14 08:40 - 2012-05-17 09:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-14 01:40 - 2012-04-30 18:08 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\vlc
2015-05-11 01:39 - 2012-04-28 00:06 - 00007671 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Local\resmon.resmoncfg
2015-05-09 21:08 - 2011-11-27 01:22 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Audacity
2015-05-09 09:47 - 2011-10-08 21:23 - 00033280 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-09 00:47 - 2011-09-28 08:54 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Swift Sound
2015-05-09 00:23 - 2014-06-30 23:33 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-09 00:23 - 2013-07-05 00:27 - 00000000 ____D () C:\ProgramData\Lavasoft
2015-05-09 00:20 - 2015-02-19 23:23 - 00003890 _____ () C:\Users\HelmGerhard-Eichberg\Desktop\TI-Treffen in Crewe.txt
2015-05-09 00:04 - 2011-07-22 13:06 - 00000000 ____D () C:\ProgramData\Temp
2015-05-06 07:09 - 2015-04-15 20:54 - 00000020 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\appdataFr3.bin
2015-05-06 07:09 - 2012-12-12 22:51 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-05-06 07:09 - 2012-12-12 22:50 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-05-06 07:09 - 2011-12-16 22:33 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-05-06 07:07 - 2014-08-27 22:08 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Local\Adobe
2015-04-30 14:02 - 2012-09-26 03:19 - 00003232 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForHELMGERHARD-EIC$
2015-04-30 14:02 - 2012-06-11 07:11 - 00000356 _____ () C:\Windows\Tasks\HPCeeScheduleForHELMGERHARD-EIC$.job
2015-04-25 20:55 - 2014-07-01 17:25 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\Real
2015-04-23 23:19 - 2014-07-01 17:38 - 00003426 _____ () C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3939595492-2884219484-1246490395-1001
2015-04-23 22:23 - 2014-07-01 17:27 - 00000000 ____D () C:\Program Files (x86)\Real
2015-04-23 22:22 - 2015-04-15 21:43 - 00003302 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3939595492-2884219484-1246490395-1001
2015-04-23 22:22 - 2014-07-01 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
2015-04-23 22:21 - 2014-07-01 17:27 - 00000000 ____D () C:\ProgramData\Real
2015-04-22 18:57 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-04-22 13:50 - 2011-10-08 10:29 - 00000000 ____D () C:\Daten
2015-04-21 06:32 - 2014-03-01 12:06 - 00000000 ____D () C:\Users\HelmGerhard-Eichberg\Desktop\Grafiken
==================== Files in the root of some directories =======
2015-04-15 20:54 - 2015-05-06 07:09 - 0000020 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\appdataFr3.bin
2012-12-03 21:33 - 2013-03-20 16:45 - 0804864 ____H () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\base_en.db
2014-08-14 13:54 - 2014-08-14 13:54 - 0071452 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\ExpressBurn.dmp
2014-06-14 20:52 - 2014-06-14 20:59 - 0016161 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Roaming\FishvsCrabs.sav
2013-02-04 10:46 - 2013-02-04 10:46 - 0155598 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Local\ars.cache
2013-02-04 10:58 - 2013-02-04 10:58 - 8253038 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Local\census.cache
2011-10-08 21:23 - 2015-05-09 09:47 - 0033280 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-28 00:06 - 2015-05-11 01:39 - 0007671 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Local\resmon.resmoncfg
2011-12-16 22:39 - 2011-12-16 22:39 - 0000000 _____ () C:\Users\HelmGerhard-Eichberg\AppData\Local\{BADEDD15-4412-430C-9B78-50768873D5DD}
2013-08-02 21:42 - 2013-08-02 21:42 - 0000165 _____ () C:\ProgramData\ljrtdxuboqqwjkkvbwg.reg
2014-07-10 01:00 - 2014-07-10 01:00 - 0000058 _____ () C:\ProgramData\RUNDLL32.EXE-1352-F.txt
2014-07-10 01:02 - 2014-07-10 01:02 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-1364-F.txt
2014-07-10 01:33 - 2014-07-10 01:33 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-1888-F.txt
2014-07-10 00:10 - 2014-07-10 00:10 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-2752-F.txt
2014-07-09 14:35 - 2014-07-09 14:35 - 0000116 _____ () C:\ProgramData\RUNDLL32.EXE-2764-F.txt
2014-07-09 21:19 - 2014-07-09 21:21 - 0243884 _____ () C:\ProgramData\RUNDLL32.EXE-2852-F.txt
2014-07-10 02:17 - 2014-07-10 02:17 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-2964-F.txt
2014-07-10 00:45 - 2014-07-10 00:45 - 0000054 _____ () C:\ProgramData\RUNDLL32.EXE-3004-F.txt
2014-07-10 00:22 - 2014-07-10 00:22 - 0000111 _____ () C:\ProgramData\RUNDLL32.EXE-3028-F.txt
2014-07-10 00:58 - 2014-07-10 00:58 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-3100-F.txt
2014-07-10 01:02 - 2014-07-10 01:02 - 0000054 _____ () C:\ProgramData\RUNDLL32.EXE-3244-F.txt
2014-07-09 14:33 - 2014-07-09 14:35 - 0000230 _____ () C:\ProgramData\RUNDLL32.EXE-3252-F.txt
2014-07-10 01:32 - 2014-07-10 01:32 - 0000054 _____ () C:\ProgramData\RUNDLL32.EXE-3288-F.txt
2014-07-10 00:56 - 2014-07-10 00:57 - 0000108 _____ () C:\ProgramData\RUNDLL32.EXE-3436-F.txt
2014-07-10 00:23 - 2014-07-10 00:23 - 0000058 _____ () C:\ProgramData\RUNDLL32.EXE-3556-F.txt
2014-07-10 01:02 - 2014-07-10 01:02 - 0000058 _____ () C:\ProgramData\RUNDLL32.EXE-3640-F.txt
2014-07-10 01:32 - 2014-07-10 01:32 - 0000054 _____ () C:\ProgramData\RUNDLL32.EXE-3660-F.txt
2014-07-10 00:21 - 2014-07-10 00:21 - 0000115 _____ () C:\ProgramData\RUNDLL32.EXE-3724-F.txt
2014-07-09 15:01 - 2014-07-09 15:07 - 0000803 _____ () C:\ProgramData\RUNDLL32.EXE-4032-F.txt
2014-07-10 00:33 - 2014-07-10 00:34 - 0000111 _____ () C:\ProgramData\RUNDLL32.EXE-4036-F.txt
2014-07-09 15:15 - 2014-07-09 15:18 - 0000398 _____ () C:\ProgramData\RUNDLL32.EXE-4248-F.txt
2014-07-10 01:04 - 2014-07-10 01:04 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-4368-F.txt
2014-07-10 00:34 - 2014-07-10 00:34 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-4380-F.txt
2014-07-09 14:45 - 2014-07-09 15:01 - 0002160 _____ () C:\ProgramData\RUNDLL32.EXE-4424-F.txt
2014-07-10 00:20 - 2014-07-10 00:20 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-4504-F.txt
2014-07-10 01:46 - 2014-07-10 01:46 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-4612-F.txt
2014-07-10 00:44 - 2014-07-10 00:44 - 0000111 _____ () C:\ProgramData\RUNDLL32.EXE-4636-F.txt
2014-07-10 00:57 - 2014-07-10 00:57 - 0000114 _____ () C:\ProgramData\RUNDLL32.EXE-4684-F.txt
2014-07-10 01:03 - 2014-07-10 01:03 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-4796-F.txt
2014-07-10 00:23 - 2014-07-10 00:23 - 0000054 _____ () C:\ProgramData\RUNDLL32.EXE-4892-F.txt
2014-07-10 01:46 - 2014-07-10 01:46 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-4924-F.txt
2014-07-10 01:04 - 2014-07-10 01:04 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-5000-F.txt
2014-07-10 00:45 - 2014-07-10 00:47 - 0000347 _____ () C:\ProgramData\RUNDLL32.EXE-5080-F.txt
2014-07-10 01:33 - 2014-07-10 01:33 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-5100-F.txt
2014-07-10 01:01 - 2014-07-10 01:01 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-5144-F.txt
2014-09-15 00:08 - 2014-09-15 00:09 - 0000284 _____ () C:\ProgramData\RUNDLL32.EXE-5476-F.txt
2014-07-10 01:04 - 2014-07-10 01:04 - 0000054 _____ () C:\ProgramData\RUNDLL32.EXE-5480-F.txt
2014-07-10 00:23 - 2014-07-10 00:23 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-5484-F.txt
2014-09-15 00:10 - 2014-09-15 00:11 - 0000231 _____ () C:\ProgramData\RUNDLL32.EXE-5528-F.txt
2014-07-10 01:03 - 2014-07-10 01:03 - 0000058 _____ () C:\ProgramData\RUNDLL32.EXE-5540-F.txt
2014-07-10 00:58 - 2014-07-10 00:59 - 0000116 _____ () C:\ProgramData\RUNDLL32.EXE-5708-F.txt
2014-07-10 01:00 - 2014-07-10 01:01 - 0000174 _____ () C:\ProgramData\RUNDLL32.EXE-5816-F.txt
2014-09-15 00:25 - 2014-09-15 00:27 - 0000397 _____ () C:\ProgramData\RUNDLL32.EXE-5852-F.txt
2014-07-10 01:03 - 2014-07-10 01:03 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-5936-F.txt
2014-07-10 01:31 - 2014-07-10 01:31 - 0000058 _____ () C:\ProgramData\RUNDLL32.EXE-6044-F.txt
2014-07-10 00:20 - 2014-07-10 00:20 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-6088-F.txt
2014-07-10 01:46 - 2014-07-10 01:46 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-6112-F.txt
2014-07-10 01:05 - 2014-07-10 01:05 - 0000058 _____ () C:\ProgramData\RUNDLL32.EXE-6160-F.txt
2014-07-10 01:08 - 2014-07-10 01:30 - 0002938 _____ () C:\ProgramData\RUNDLL32.EXE-6196-F.txt
2014-07-10 01:32 - 2014-07-10 01:32 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-6256-F.txt
2014-07-10 01:05 - 2014-07-10 01:05 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-6424-F.txt
2014-07-10 01:07 - 2014-07-10 01:08 - 0000231 _____ () C:\ProgramData\RUNDLL32.EXE-6568-F.txt
2014-07-10 01:05 - 2014-07-10 01:05 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-6712-F.txt
2014-07-10 01:31 - 2014-07-10 01:31 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-6780-F.txt
2014-07-10 01:32 - 2014-07-10 01:32 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-6860-F.txt
2014-07-10 01:31 - 2014-07-10 01:31 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-6892-F.txt
2014-07-10 01:33 - 2014-07-10 01:33 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-6968-F.txt
2014-07-10 01:06 - 2014-07-10 01:07 - 0000170 _____ () C:\ProgramData\RUNDLL32.EXE-7068-F.txt
2014-07-10 01:33 - 2014-07-10 01:33 - 0000057 _____ () C:\ProgramData\RUNDLL32.EXE-7148-F.txt
2014-07-10 01:33 - 2014-07-10 01:33 - 0000054 _____ () C:\ProgramData\RUNDLL32.EXE-7268-F.txt
2014-07-10 01:34 - 2014-07-10 01:34 - 0000059 _____ () C:\ProgramData\RUNDLL32.EXE-7564-F.txt
2014-07-10 00:22 - 2014-07-10 00:22 - 0000058 _____ () C:\ProgramData\RUNDLL32.EXE-944-F.txt
Files to move or delete:
====================
C:\ProgramData\ljrtdxuboqqwjkkvbwg.reg
Some content of TEMP:
====================
C:\Users\HelmGerhard-Eichberg\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\HelmGerhard-Eichberg\AppData\Local\Temp\Quarantine.exe
C:\Users\HelmGerhard-Eichberg\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-15 23:20
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Ich kriege beim Versuch, Browserspiele zu spielen, immer noch die Meldung, daß der Adobe Flash-Player nicht vorhanden ist.
Gerhard |