Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 03.12.2014, 21:46   #16
Krazerack
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Addition

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-12-2014
Ran by Bo at 2014-12-03 21:28:29
Running from C:\Users\Bo\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 4.8.1245.73583 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 4.8.1245.73583 - Alcor Micro Corp.) Hidden
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.100.303.509 - Alps Electric)
Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon)
AMD Catalyst Install Manager (HKLM\...\{5D42947B-E961-C0B5-5A70-EA0F753331EB}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.4.2 - AppEx Networks)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Atheros)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5577 - AVG Technologies)
AVG 2015 (Version: 15.0.4235 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5577 - AVG Technologies) Hidden
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Dropbox (HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\Dropbox) (Version: 2.10.52 - Dropbox, Inc.)
DTS Sound (HKLM-x32\...\{2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}) (Version: 1.01.2700 - DTS, Inc.)
Empress of the Deep - The Darkest Secret (x32 Version: 2.2.0.98 - WildTangent) Hidden
Firefox Packages (HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\Firefox Packages) (Version:  - ) <==== ATTENTION
IDT Audio Driver (HKLM\...\{588A747E-CFF6-46B3-9207-CD754F9473AF}) (Version: 6.10.6491.0 - IDT)
Island Tribe (x32 Version: 2.2.0.98 - WildTangent) Hidden
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6CE5BAE9-D3CA-4B99-891A-1DC6C118A5FC}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{d07b0db5-8dad-40e1-be90-88026298a46b}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{2749c485-3a8b-4533-92ff-7cf6e8221cff}) (Version: 11.0.61030.0 - Microsoft Corporation)
OEM Application Profile (HKLM-x32\...\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.306 - Qualcomm Atheros)
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.)
resident evil 4 / biohazard 4 (HKLM-x32\...\Steam App 254700) (Version:  - Capcom)
Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.106 - Skype Technologies S.A.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
TOSHIBA Addendum (HKLM-x32\...\{C1569944-FAD6-4B3B-85E5-C213C2FF8EFC}) (Version: 1.00 - TOSHIBA)
TOSHIBA Desktop Assist (HKLM\...\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.02.01.6407 - Toshiba Corporation)
TOSHIBA Display Utility (HKLM\...\{5F6AC07E-50EF-422E-B56E-6521E5B35139}) (Version: 1.1.12.0 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\...\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.2.0.6404 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\...\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.1.0001.6403 - Toshiba Corporation)
TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.10 - TOSHIBA)
TOSHIBA Password Utility (HKLM-x32\...\InstallShield_{78931270-BC9E-441A-A52B-73ECD4ACFAB5}) (Version: 3.00.346 - Toshiba Corporation)
TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.9.09.6400 - Toshiba Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.1.02.55065006 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation)
TOSHIBA Start Screen Option (HKLM\...\{06B71035-F19F-4F76-9875-FFCCD4FC3F83}) (Version: 1.00.00.6403 - Toshiba Corporation)
TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0030 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\...\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.1.2.32001 - Toshiba Corporation)
Toshiba TEMPRO (HKLM-x32\...\{F76F5214-83A8-4030-80C9-1EF57391D72A}) (Version: 4.5.0 - Toshiba Europe GmbH)
TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.3.27.102 - Toshiba Corporation)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.9.7 - WildTangent) Hidden
Windows Essentials Codec Pack 5.0 (HKLM-x32\...\Windows Essentials Codec Pack) (Version: 5.0 - Windows Essentials Codec Pack)
WinZip Malware Protector (HKLM-x32\...\WinZip Malware Protector_is1) (Version: 2.1.1000.14260 - WinZip International LLC)
Yahoo Community Smartbar (HKLM-x32\...\{C9AC6061-68A8-475E-B75E-E59C35AF0972}) (Version: 11.123.66.20439 - Linkury Inc.) <==== ATTENTION
Yahoo Community Smartbar Engine (HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\{baae938f-c7b1-4489-bd91-c9d5edc349ec}) (Version: 11.123.66.20439 - Linkury Inc.) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================

23-11-2014 09:54:46 Microsoft Visual C++ 2005 Redistributable (x64) wird installiert
25-11-2014 12:21:56 OpenOffice 4.1.1 wird installiert
02-12-2014 18:18:44 Geplanter Prüfpunkt

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2014-12-02 12:47 - 00000867 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1			d3oxij66pru1i3.cloudfront.net

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {31475E8B-6649-48DD-8602-BDDE5C03E2F9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-10-31] (Microsoft Corporation)
Task: {3F5085EE-497E-45EB-AC3E-4E737F7BB3E5} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation)
Task: {CE98562D-C775-4ED1-B6D7-E5CDB16340CF} - System32\Tasks\mgsUpd => C:\Program Files\shopperz\btsc.bat
Task: {D54FDB5D-2736-4850-9811-EE7F985F57CC} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe
Task: {F0CAFEF7-B749-4E9B-9F1D-F64E2AE096AA} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-07-19] (Toshiba Europe GmbH)

==================== Loaded Modules (whitelisted) =============

2013-03-27 21:53 - 2013-03-27 21:53 - 00163168 _____ () C:\Program Files (x86)\TOSHIBA\PasswordUtility\GFNEXSrv.exe
2013-08-31 04:47 - 2013-08-31 04:47 - 00099328 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
2013-09-10 21:54 - 2013-09-10 21:54 - 00019792 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2014-11-18 22:41 - 2014-11-18 08:02 - 00626688 _____ () C:\Users\Bo\AppData\Roaming\Windows Open Service\OpenService.exe
2014-11-18 22:41 - 2014-11-18 22:41 - 00374272 _____ () C:\Users\Bo\AppData\Roaming\Windows Open Service\sub\default.dll
2014-12-03 21:20 - 2014-12-03 21:20 - 00043008 _____ () c:\users\bo\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp4wocij.dll
2014-11-19 01:24 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Bo\AppData\Roaming\Dropbox\bin\libcef.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Bo\OneDrive:ms-properties
AlternateDataStreams: C:\Users\Bo\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "TecoResident"
HKLM\...\StartupApproved\Run: => "TCrdMain"
HKLM\...\StartupApproved\Run: => "TSSSrv"
HKLM\...\StartupApproved\Run: => "TosWaitSrv"
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\StartupApproved\Run: => "Steam"

========================= Accounts: ==========================

Administrator (S-1-5-21-2163812055-3742141728-2804637470-500 - Administrator - Disabled)
Bo (S-1-5-21-2163812055-3742141728-2804637470-1001 - Administrator - Enabled) => C:\Users\Bo
Gast (S-1-5-21-2163812055-3742141728-2804637470-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2163812055-3742141728-2804637470-1003 - Limited - Enabled)

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/03/2014 07:53:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Spotify.exe, Version 0.9.14.13 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: ed8

Startzeit: 01d00ef664b6ed6e

Endzeit: 4294967295

Anwendungspfad: C:\Users\Bo\AppData\Roaming\Spotify\Spotify.exe

Berichts-ID: b19d56fc-7b1d-11e4-8269-28e34703191e

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (12/03/2014 06:17:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17416, Zeitstempel: 0x5452fe91
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17278, Zeitstempel: 0x53eebd22
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000095358
ID des fehlerhaften Prozesses: 0x2070
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Vollständiger Name des fehlerhaften Pakets: iexplore.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: iexplore.exe5

Error: (12/03/2014 05:45:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17416, Zeitstempel: 0x5452fe91
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17278, Zeitstempel: 0x53eebd22
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000f0d6c
ID des fehlerhaften Prozesses: 0x1308
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Vollständiger Name des fehlerhaften Pakets: iexplore.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: iexplore.exe5

Error: (12/03/2014 01:41:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.8428, Zeitstempel: 0x520b1060
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0xd28
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5

Error: (12/03/2014 01:35:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.8428, Zeitstempel: 0x520b1060
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x2bfc
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5

Error: (12/03/2014 01:35:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.8428, Zeitstempel: 0x520b1060
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x21d8
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5

Error: (12/03/2014 01:34:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.8428, Zeitstempel: 0x520b1060
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x2848
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5

Error: (12/03/2014 01:22:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm LiveComm.exe, Version 17.5.9600.20689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: f28

Startzeit: 01d00ef31c8a6329

Endzeit: 4294967295

Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe

Berichts-ID: 141dc0ed-7ae7-11e4-8268-28e34703191e

Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe

Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1

Error: (12/03/2014 01:18:42 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MEINER)
Description: Bei der Aktivierung der App „Microsoft.BingSports_8wekyb3d8bbwe!AppexSports“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (12/03/2014 01:18:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wwahost.exe, Version 6.3.9600.17031 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1f00

Startzeit: 01d00ef3361ad2bb

Endzeit: 4294967295

Anwendungspfad: C:\Windows\system32\wwahost.exe

Berichts-ID: 7e9154b3-7ae6-11e4-8268-28e34703191e

Vollständiger Name des fehlerhaften Pakets: Microsoft.BingSports_3.0.4.244_x64__8wekyb3d8bbwe

Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AppexSports


System errors:
=============
Error: (12/03/2014 09:21:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee VirusScan Announcer" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (12/03/2014 09:19:05 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "McAfee Anti-Malware Core" ist von folgendem Dienst abhängig: mfevtp. Dieser Dienst ist möglicherweise nicht installiert.

Error: (12/03/2014 09:19:05 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "McAfee AP Service" ist von folgendem Dienst abhängig: mfevtp. Dieser Dienst ist möglicherweise nicht installiert.

Error: (12/03/2014 09:18:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "8289E50D-56DB-4d17-B156-DBFDA1CA80B7" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (12/03/2014 08:05:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee VirusScan Announcer" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (12/03/2014 08:03:44 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "McAfee Anti-Malware Core" ist von folgendem Dienst abhängig: mfevtp. Dieser Dienst ist möglicherweise nicht installiert.

Error: (12/03/2014 08:03:44 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "McAfee AP Service" ist von folgendem Dienst abhängig: mfevtp. Dieser Dienst ist möglicherweise nicht installiert.

Error: (12/03/2014 08:03:39 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "8289E50D-56DB-4d17-B156-DBFDA1CA80B7" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (12/03/2014 08:01:14 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "TOSHIBA eco Utility Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (12/03/2014 08:01:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "TEMPRO Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


Microsoft Office Sessions:
=========================
Error: (12/03/2014 07:53:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Spotify.exe0.9.14.13ed801d00ef664b6ed6e4294967295C:\Users\Bo\AppData\Roaming\Spotify\Spotify.exeb19d56fc-7b1d-11e4-8269-28e34703191e

Error: (12/03/2014 06:17:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174165452fe91ntdll.dll6.3.9600.1727853eebd22c00000050000000000095358207001d00f1cfa039a9aC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\SYSTEM32\ntdll.dll41bea704-7b10-11e4-8269-28e34703191e

Error: (12/03/2014 05:45:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174165452fe91ntdll.dll6.3.9600.1727853eebd22c000037400000000000f0d6c130801d00f1873a91665C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\SYSTEM32\ntdll.dllc38fa968-7b0b-11e4-8269-28e34703191e

Error: (12/03/2014 01:41:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.8428520b1060c000000500012f4bd2801d00ef6632f72ebC:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\MSVCR80.dlla20c7676-7ae9-11e4-8269-28e34703191e

Error: (12/03/2014 01:35:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.8428520b1060c000000500012f4b2bfc01d00ef5a95e0ac9C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\MSVCR80.dlle73c1639-7ae8-11e4-8268-28e34703191e

Error: (12/03/2014 01:35:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.8428520b1060c000000500012f4b21d801d00ef595425cb6C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\MSVCR80.dlld3340cea-7ae8-11e4-8268-28e34703191e

Error: (12/03/2014 01:34:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.8428520b1060c000000500012f4b284801d00ef58a6c5aa9C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\MSVCR80.dllc8dab2b5-7ae8-11e4-8268-28e34703191e

Error: (12/03/2014 01:22:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.20689f2801d00ef31c8a63294294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe141dc0ed-7ae7-11e4-8268-28e34703191emicrosoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (12/03/2014 01:18:42 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MEINER)
Description: Microsoft.BingSports_8wekyb3d8bbwe!AppexSports-2144927142

Error: (12/03/2014 01:18:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.170311f0001d00ef3361ad2bb4294967295C:\Windows\system32\wwahost.exe7e9154b3-7ae6-11e4-8268-28e34703191eMicrosoft.BingSports_3.0.4.244_x64__8wekyb3d8bbweAppexSports


==================== Memory info =========================== 

Processor: AMD A4-5000 APU with Radeon(TM) HD Graphics 
Percentage of memory in use: 38%
Total physical RAM: 3523.07 MB
Available physical RAM: 2151.64 MB
Total Pagefile: 6211.07 MB
Available Pagefile: 4419.08 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB

==================== Drives ================================

Drive c: (TI31251100A) (Fixed) (Total:687.54 GB) (Free:633.52 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End Of Log ============================
         

Alt 04.12.2014, 17:42   #17
M-K-D-B
/// TB-Ausbilder
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Sieht schon besser aus.


So geht es weiter:




Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:
ATTFilter
start
CloseProcesses:
HKLM\...\Run: [] => [X]
HKLM\...\Run: [shopperz] => C:\Program Files\shopperz\bntf.exe
HKLM\...\Run: [shopperz64] => C:\Program Files\shopperz\bntf64.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:54992;https=127.0.0.1:54992
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
BHO-x32: No Name -> {E6D66045-F951-4DBF-962E-993B4FB6A9E0} -> C:\Users\Bo\AppData\LocalLow\IE-BHO\bho.dll ()
C:\Users\Bo\AppData\LocalLow\IE-BHO
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
CHR HomePage: Default -> hxxp://Vosteran.com/?f=1&a=vst_orinteract_14_47_ff&cd=2XzuyEtN2Y1L1QzutBzz0EtAyEyBtDtAtCzytC0EtDzyzyyBtN0D0Tzu0StCtDyDtAtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtC0CyEyDzz0CtCtGtDtCyD0CtG0AzyzyyCtG0AyBzyyBtGyDzztB0ByCyBtByBtB0Ezy0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtC0A0B0D0B0E0BtG0AtBtDyDtGyEtC0BtDtGzz0Czy0FtG0AyDtCzz0BzzyC0C0F0DyEzy2Q&cr=1779294075&ir=
CHR RestoreOnStartup: Default -> "hxxp://Vosteran.com/?f=7&a=vst_orinteract_14_47_ff&cd=2XzuyEtN2Y1L1QzutBzz0EtAyEyBtDtAtCzytC0EtDzyzyyBtN0D0Tzu0StCtDyDtAtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtC0CyEyDzz0CtCtGtDtCyD0CtG0AzyzyyCtG0AyBzyyBtGyDzztB0ByCyBtByBtB0Ezy0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtC0A0B0D0B0E0BtG0AtBtDyDtGyEtC0BtDtGzz0Czy0FtG0AyDtCzz0BzzyC0C0F0DyEzy2Q&cr=1779294075&ir="
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR HKLM\...\Chrome\Extension: [Ìÿ] - No Path
CHR HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\Chrome\Extension: [Ìÿ] - No Path
CHR HKLM-x32\...\Chrome\Extension: [Ìÿ] - No Path
S2 8289E50D-56DB-4d17-B156-DBFDA1CA80B7; "C:\Program Files\shopperz\brbsrv.exe" [X]
C:\Windows\System32\Tasks\WinZip Malware Protector_startup
C:\Users\Public\Desktop\WinZip Malware Protector.lnk
C:\Users\Bo\AppData\Roaming\Nico Mak Computing
C:\ProgramData\Nico Mak Computing
C:\Windows\system32\wsusnative64.exe
Task: {CE98562D-C775-4ED1-B6D7-E5CDB16340CF} - System32\Tasks\mgsUpd => C:\Program Files\shopperz\btsc.bat
Task: {D54FDB5D-2736-4850-9811-EE7F985F57CC} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe
C:\Windows\system32\Drivers\etc\hosts
Hosts:
EmptyTemp:
end
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.







Schritt 2
Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop:
SystemLook (32 bit) | SystemLook (64 bit)
  • Doppelklicke auf die SystemLook.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:

    Code:
    ATTFilter
    :regfind
    LPTSystemUpdater
    Orbiter
    shopperz
    savernet
    SuperManCoupon
    WinZip Malware Protector
    FLVM Player
    WordProser_1.10.0.2
    WSE_Vosteran
    InetStat
    Nico Mak Computing
    Linkury
    Firefox Packages
             
  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auch auf dem Desktop als SystemLook.txt gespeichert.







Schritt 3
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Scan.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.




Bitte poste mit deiner nächsten Antwort
  • die Logdatei des FRST-Fix,
  • die Logdatei von SystemLook,
  • die beiden neuen Logdateien von FRST.
__________________


Alt 04.12.2014, 20:27   #18
Krazerack
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Fixlog


Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2014
Ran by Bo at 2014-12-04 19:40:54 Run:1
Running from C:\Users\Bo\Desktop
Loaded Profile: Bo (Available profiles: Bo)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
HKLM\...\Run: [] => [X]
HKLM\...\Run: [shopperz] => C:\Program Files\shopperz\bntf.exe
HKLM\...\Run: [shopperz64] => C:\Program Files\shopperz\bntf64.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:54992;https=127.0.0.1:54992
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
BHO-x32: No Name -> {E6D66045-F951-4DBF-962E-993B4FB6A9E0} -> C:\Users\Bo\AppData\LocalLow\IE-BHO\bho.dll ()
C:\Users\Bo\AppData\LocalLow\IE-BHO
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
CHR HomePage: Default -> hxxp://Vosteran.com/?f=1&a=vst_orinteract_14_47_ff&cd=2XzuyEtN2Y1L1QzutBzz0EtAyEyBtDtAtCzytC0EtDzyzyyBtN0D0Tzu0StCtDyDtAtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtC0CyEyDzz0CtCtGtDtCyD0CtG0AzyzyyCtG0AyBzyyBtGyDzztB0ByCyBtByBtB0Ezy0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtC0A0B0D0B0E0BtG0AtBtDyDtGyEtC0BtDtGzz0Czy0FtG0AyDtCzz0BzzyC0C0F0DyEzy2Q&cr=1779294075&ir=
CHR RestoreOnStartup: Default -> "hxxp://Vosteran.com/?f=7&a=vst_orinteract_14_47_ff&cd=2XzuyEtN2Y1L1QzutBzz0EtAyEyBtDtAtCzytC0EtDzyzyyBtN0D0Tzu0StCtDyDtAtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtC0CyEyDzz0CtCtGtDtCyD0CtG0AzyzyyCtG0AyBzyyBtGyDzztB0ByCyBtByBtB0Ezy0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtC0A0B0D0B0E0BtG0AtBtDyDtGyEtC0BtDtGzz0Czy0FtG0AyDtCzz0BzzyC0C0F0DyEzy2Q&cr=1779294075&ir="
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR HKLM\...\Chrome\Extension: [Ìÿ] - No Path
CHR HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\Chrome\Extension: [Ìÿ] - No Path
CHR HKLM-x32\...\Chrome\Extension: [Ìÿ] - No Path
S2 8289E50D-56DB-4d17-B156-DBFDA1CA80B7; "C:\Program Files\shopperz\brbsrv.exe" [X]
C:\Windows\System32\Tasks\WinZip Malware Protector_startup
C:\Users\Public\Desktop\WinZip Malware Protector.lnk
C:\Users\Bo\AppData\Roaming\Nico Mak Computing
C:\ProgramData\Nico Mak Computing
C:\Windows\system32\wsusnative64.exe
Task: {CE98562D-C775-4ED1-B6D7-E5CDB16340CF} - System32\Tasks\mgsUpd => C:\Program Files\shopperz\btsc.bat
Task: {D54FDB5D-2736-4850-9811-EE7F985F57CC} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe
C:\Windows\system32\Drivers\etc\hosts
Hosts:
EmptyTemp:
end
         
*****************

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\shopperz => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\shopperz64 => value deleted successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => Key deleted successfully.
"HKCR\CLSID\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6D66045-F951-4DBF-962E-993B4FB6A9E0}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{E6D66045-F951-4DBF-962E-993B4FB6A9E0}" => Key deleted successfully.
C:\Users\Bo\AppData\LocalLow\IE-BHO => Moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} not found.
Chrome HomePage deleted successfully.
Chrome RestoreOnStartup deleted successfully.
Chrome DefaultSuggestURL deleted successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\Ìÿ" => Key deleted successfully.
"HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\SOFTWARE\Google\Chrome\Extensions\Ìÿ" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\Ìÿ" => Key deleted successfully.
8289E50D-56DB-4d17-B156-DBFDA1CA80B7 => Service deleted successfully.
C:\Windows\System32\Tasks\WinZip Malware Protector_startup => Moved successfully.
C:\Users\Public\Desktop\WinZip Malware Protector.lnk => Moved successfully.
C:\Users\Bo\AppData\Roaming\Nico Mak Computing => Moved successfully.
C:\ProgramData\Nico Mak Computing => Moved successfully.
C:\Windows\system32\wsusnative64.exe => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE98562D-C775-4ED1-B6D7-E5CDB16340CF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE98562D-C775-4ED1-B6D7-E5CDB16340CF}" => Key deleted successfully.
C:\Windows\System32\Tasks\mgsUpd => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\mgsUpd" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D54FDB5D-2736-4850-9811-EE7F985F57CC}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D54FDB5D-2736-4850-9811-EE7F985F57CC}" => Key deleted successfully.
C:\Windows\System32\Tasks\WinZip Malware Protector_startup not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinZip Malware Protector_startup" => Key deleted successfully.
C:\Windows\system32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.1 GB temporary data.


The system needed a reboot. 

==== End of Fixlog ====
         

Code:
ATTFilter
SystemLook 30.07.11 by jpshortstuff
Log created at 19:54 on 04/12/2014 by Bo
Administrator - Elevation successful

========== regfind ==========

Searching for "LPTSystemUpdater"
No data found.

Searching for "Orbiter"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost]
"ORBTR"="Orbiter"

Searching for "shopperz"
[HKEY_CURRENT_USER\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}]
"Name"="C:\Program Files\shopperz\bntf.exe"
[HKEY_CURRENT_USER\Software\Classes\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}]
"Name"="C:\Program Files\shopperz\bntf.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}\1.0\0\win32]
@="C:\Program Files\shopperz\brbsrv.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}\1.0\HELPDIR]
@="C:\Program Files\shopperz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40064F2B-BE74-40c0-B30F-1AF103872638}\LocalServer32]
@=""C:\Program Files\shopperz\brbsrv.exe""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40064F2B-BE74-40c0-B30F-1AF103872638}\LocalServer32]
"ServerExecutable"="C:\Program Files\shopperz\brbsrv.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}\1.0\0\win32]
@="C:\Program Files\shopperz\brbsrv.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}\1.0\HELPDIR]
@="C:\Program Files\shopperz"
[HKEY_LOCAL_MACHINE\SOFTWARE\shopperz]
[HKEY_LOCAL_MACHINE\SOFTWARE\shopperz]
"product_name"="shopperz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\shopperz]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\shopperz]
"product_name"="shopperz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{40064F2B-BE74-40c0-B30F-1AF103872638}\LocalServer32]
@=""C:\Program Files\shopperz\brbsrv.exe""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{40064F2B-BE74-40c0-B30F-1AF103872638}\LocalServer32]
"ServerExecutable"="C:\Program Files\shopperz\brbsrv.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}\1.0\0\win32]
@="C:\Program Files\shopperz\brbsrv.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}\1.0\HELPDIR]
@="C:\Program Files\shopperz"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-18\Software\shopperz]
[HKEY_USERS\.DEFAULT\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}]
"Name"="C:\Program Files\shopperz\bntf.exe"
[HKEY_USERS\S-1-5-19\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}]
"Name"="C:\Program Files\shopperz\bntf.exe"
[HKEY_USERS\S-1-5-20\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}]
"Name"="C:\Program Files\shopperz\bntf.exe"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}]
"Name"="C:\Program Files\shopperz\bntf.exe"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Classes\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}]
"Name"="C:\Program Files\shopperz\bntf.exe"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}]
"Name"="C:\Program Files\shopperz\bntf.exe"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-18\Software\shopperz]
[HKEY_USERS\S-1-5-18\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}]
"Name"="C:\Program Files\shopperz\bntf.exe"

Searching for "savernet"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{52b6decd-b602-42e8-a034-d1c5010cfcce}]
@="savernet"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{52b6decd-b602-42e8-a034-d1c5010cfcce}\InprocServer32]
@="C:\ProgramData\savernet\sDx57o4MoNNNps.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{52b6decd-b602-42e8-a034-d1c5010cfcce}]
@="savernet"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{52b6decd-b602-42e8-a034-d1c5010cfcce}\InprocServer32]
@="C:\ProgramData\savernet\sDx57o4MoNNNps.dll"

Searching for "SuperManCoupon"
No data found.

Searching for "WinZip Malware Protector"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UFH\SHC]
"0"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Malware Protector\Register WinZip Malware Protector.lnk C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe openregister"
[HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip Malware Protector]
[HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip Malware Protector]
"InstalledPath"="C:\Program Files (x86)\WinZip Malware Protector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\shell\openas\command]
@="C:\Program Files (x86)\WinZip Malware Protector\filetypehelper.exe -scanunknown "%1""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\shell\openas\command]
"WinZip Malware Protector.bak"="C:\Windows\SysWow64\OpenWith.exe "%1""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\shell\OpenWithSetDefaultOn\command]
@="C:\Program Files (x86)\WinZip Malware Protector\filetypehelper.exe -scanunknown "%1""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\shell\OpenWithSetDefaultOn\command]
"WinZip Malware Protector.bak"="C:\Windows\SysWow64\OpenWith.exe -override "%1""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1]
"Inno Setup: App Path"="C:\Program Files (x86)\WinZip Malware Protector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1]
"InstallLocation"="C:\Program Files (x86)\WinZip Malware Protector\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1]
"Inno Setup: Icon Group"="WinZip Malware Protector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1]
"DisplayName"="WinZip Malware Protector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1]
"DisplayIcon"="C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1]
"UninstallString"=""C:\Program Files (x86)\WinZip Malware Protector\unins000.exe" /silent"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1]
"QuietUninstallString"=""C:\Program Files (x86)\WinZip Malware Protector\unins000.exe" /SILENT"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip Malware Protector]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip Malware Protector]
"InstalledPath"="C:\Program Files (x86)\WinZip Malware Protector"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Windows\CurrentVersion\UFH\SHC]
"0"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Malware Protector\Register WinZip Malware Protector.lnk C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe openregister"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Nico Mak Computing\WinZip Malware Protector]
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Nico Mak Computing\WinZip Malware Protector]
"InstalledPath"="C:\Program Files (x86)\WinZip Malware Protector"

Searching for "FLVM Player"
No data found.

Searching for "WordProser_1.10.0.2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}\1.0\0\win32]
@="C:\Program Files (x86)\WordProser_1.10.0.2\IE\WordProserClientIE.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}\1.0\0\win64]
@="C:\Program Files\WordProser_1.10.0.2\IE\WordProserClientIE.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}\1.0\HELPDIR]
@="C:\Program Files (x86)\WordProser_1.10.0.2\IE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}\1.0\0\win32]
@="C:\Program Files (x86)\WordProser_1.10.0.2\IE\WordProserClientIE.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}\1.0\0\win64]
@="C:\Program Files\WordProser_1.10.0.2\IE\WordProserClientIE.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}\1.0\HELPDIR]
@="C:\Program Files (x86)\WordProser_1.10.0.2\IE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}\1.0\0\win32]
@="C:\Program Files (x86)\WordProser_1.10.0.2\IE\WordProserClientIE.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}\1.0\0\win64]
@="C:\Program Files\WordProser_1.10.0.2\IE\WordProserClientIE.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}\1.0\HELPDIR]
@="C:\Program Files (x86)\WordProser_1.10.0.2\IE"

Searching for "WSE_Vosteran"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy]
"AppPath"="C:\Program Files (x86)\WSE_Vosteran\\"

Searching for "InetStat"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ShowFullPath]
"RegPath"="Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]

Searching for "Nico Mak Computing"
[HKEY_CURRENT_USER\Software\Nico Mak Computing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing]
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Nico Mak Computing]

Searching for "Linkury"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{baae938f-c7b1-4489-bd91-c9d5edc349ec}]
"Publisher"="Linkury Inc."
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2163812055-3742141728-2804637470-1001\Products\1606CA9C8A86E5747BE55EC953FA9027\InstallProperties]
"HelpLink"="hxxp://www.linkury.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2163812055-3742141728-2804637470-1001\Products\1606CA9C8A86E5747BE55EC953FA9027\InstallProperties]
"Publisher"="Linkury Inc."
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2163812055-3742141728-2804637470-1001\Products\1606CA9C8A86E5747BE55EC953FA9027\InstallProperties]
"URLInfoAbout"="hxxp://www.linkury.com/index-8_faq.html"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C9AC6061-68A8-475E-B75E-E59C35AF0972}]
"HelpLink"="hxxp://www.linkury.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C9AC6061-68A8-475E-B75E-E59C35AF0972}]
"Publisher"="Linkury Inc."
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C9AC6061-68A8-475E-B75E-E59C35AF0972}]
"URLInfoAbout"="hxxp://www.linkury.com/index-8_faq.html"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\{baae938f-c7b1-4489-bd91-c9d5edc349ec}]
"Publisher"="Linkury Inc."

Searching for "Firefox Packages"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
"DisplayIcon"="C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z\Firefox Packages\uninstaller.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
"UninstallString"="C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z\Firefox Packages\uninstaller.exe /Uninstall /NM="Firefox Packages" /AN="1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z" /MBN="Firefox Packages""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
"DisplayName"="Firefox Packages"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
"UninstallerPath"="C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z\Firefox Packages"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
"DisplayIcon"="C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z\Firefox Packages\uninstaller.exe"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
"UninstallString"="C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z\Firefox Packages\uninstaller.exe /Uninstall /NM="Firefox Packages" /AN="1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z" /MBN="Firefox Packages""
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
"DisplayName"="Firefox Packages"
[HKEY_USERS\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages]
"UninstallerPath"="C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z\Firefox Packages"

-= EOF =-
         

Ist es richtig das die Fixlist am ende weg ist und nur Fixlog da ist?
__________________

Alt 04.12.2014, 20:29   #19
Krazerack
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2014
Ran by Bo (administrator) on MEINER on 04-12-2014 20:07:29
Running from C:\Users\Bo\Desktop
Loaded Profile: Bo (Available profiles: Bo)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
() C:\Program Files (x86)\TOSHIBA\PasswordUtility\GFNEXSrv.exe
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
() C:\Users\Bo\AppData\Roaming\Windows Open Service\OpenService.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(AppEx Networks Corporation) C:\Program Files\AMD Quick Stream\AMDQuickStream.exe
(Dropbox, Inc.) C:\Users\Bo\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\PasswordUtility\readLM.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\hidfind.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\WinStore\WSHost.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17499_x64__8wekyb3d8bbwe\glcnd.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [688472 2013-07-23] (Alps Electric Co., Ltd.)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-08-18] (TOSHIBA Corporation)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [178016 2013-08-21] (TOSHIBA Corporation)
HKLM\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296520 2013-09-12] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [354144 2013-08-14] (TOSHIBA Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-31] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [383768 2002-04-12] (Alcor Micro Corp.)
HKLM-x32\...\Run: [1.TPUReg] => C:\Program Files (x86)\TOSHIBA\PasswordUtility\readLM.exe [2216800 2013-03-27] (TOSHIBA)
HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516512 2013-07-23] (TOSHIBA)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3653136 2014-11-09] (AVG Technologies CZ, s.r.o.)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1199576 2013-11-27] (Spotify Ltd)
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [429792 2013-04-11] (AppEx Networks Corporation)
Startup: C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://toshiba.eu/symbaloo_c
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://toshiba.eu/symbaloo_c
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Bo\AppData\Roaming\Mozilla\Firefox\Profiles\0xus0d86.default-1417357380246
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]

Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxp://Vosteran.com/?f=1&a=vst_orinteract_14_47_ff&cd=2XzuyEtN2Y1L1QzutBzz0EtAyEyBtDtAtCzytC0EtDzyzyyBtN0D0Tzu0StCtDyDtAtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtC0CyEyDzz0CtCtGtDtCyD0CtG0AzyzyyCtG0AyBzyyBtGyDzztB0ByCyBtByBtB0Ezy0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtC0A0B0D0B0E0BtG0AtBtDyDtGyEtC0BtDtGzz0Czy0FtG0AyDtCzz0BzzyC0C0F0DyEzy2Q&cr=1779294075&ir=
CHR RestoreOnStartup: Default -> "hxxp://Vosteran.com/?f=7&a=vst_orinteract_14_47_ff&cd=2XzuyEtN2Y1L1QzutBzz0EtAyEyBtDtAtCzytC0EtDzyzyyBtN0D0Tzu0StCtDyDtAtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtC0CyEyDzz0CtCtGtDtCyD0CtG0AzyzyyCtG0AyBzyyBtGyDzztB0ByCyBtByBtB0Ezy0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtC0A0B0D0B0E0BtG0AtBtDyDtGyEtC0BtDtGzz0Czy0FtG0AyDtCzz0BzzyC0C0F0DyEzy2Q&cr=1779294075&ir="
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR Profile: C:\Users\Bo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Bo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-18]
CHR Extension: (Google Drive) - C:\Users\Bo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-18]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Bo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-18]
CHR Extension: (YouTube) - C:\Users\Bo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-18]
CHR Extension: (Google Search) - C:\Users\Bo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-18]
CHR Extension: (Unsocialize  The Link Unsocializer) - C:\Users\Bo\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdogcpghhdcocgdjogbglgejhdeedijn [2014-11-18]
CHR Extension: (Gmail) - C:\Users\Bo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-18]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [99328 2013-08-31] () [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-10-01] (Windows (R) Win 7 DDK provider)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3488784 2014-11-09] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-11-09] (AVG Technologies CZ, s.r.o.)
R2 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [19792 2013-09-10] ()
R2 GFNEXSrv; C:\Program Files (x86)\TOSHIBA\PasswordUtility\GFNEXSrv.exe [163168 2013-03-27] ()
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 OpenService; C:\Users\Bo\AppData\Roaming\Windows Open Service\OpenService.exe [626688 2014-11-18] () [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-08-16] (IDT, Inc.) [File not signed]
R3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [116088 2013-07-19] (Toshiba Europe GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
S2 McAPExe; "C:\Program Files\McAfee\MSC\McAPExe.exe" [X]
S4 McMPFSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McNaiAnn; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S3 McODS; "C:\ProgramData\McAfee\msc\Updates\Installs\1\vso\%VSINSTALL_DIR64%\mcods.exe" [X]
S2 mfecore; "C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe" [X]
S4 MSK80Service; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17504 2013-02-06] (Advanced Micro Devices, INC.)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [219360 2013-04-18] (AppEx Networks Corporation)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3858944 2013-10-24] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [263960 2014-10-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [277784 2014-09-24] (AVG Technologies CZ, s.r.o.)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-04] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
U5 mfencbdc; C:\Windows\System32\Drivers\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.)
R2 PEGAGFN; C:\Program Files (x86)\TOSHIBA\PasswordUtility\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
S3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1936088 2013-07-31] (Realtek Semiconductor Corporation                           )
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [32624 2013-08-19] (Windows (R) Win 7 DDK provider)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-04 19:54 - 2014-12-04 20:05 - 00027382 _____ () C:\Users\Bo\Desktop\SystemLook.txt
2014-12-04 19:52 - 2014-12-04 19:52 - 00165376 _____ () C:\Users\Bo\Desktop\SystemLook_x64.exe
2014-12-03 21:24 - 2014-12-03 21:24 - 00000000 ____D () C:\Users\Bo\Desktop\FRST-OlderVersion
2014-12-03 21:22 - 2014-12-03 21:22 - 00004205 _____ () C:\Users\Bo\Desktop\mbam1.txt
2014-12-03 20:09 - 2014-12-04 19:51 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-03 20:07 - 2014-12-03 20:07 - 00001129 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-12-03 20:07 - 2014-12-03 20:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-12-03 20:07 - 2014-12-03 20:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-03 20:07 - 2014-12-03 20:07 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-12-03 20:07 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-03 20:07 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-03 20:07 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-03 20:05 - 2014-12-03 20:05 - 00018607 _____ () C:\Users\Bo\Desktop\AdwCleaner[S0].txt
2014-12-03 19:54 - 2014-12-03 20:01 - 00000000 ____D () C:\AdwCleaner
2014-12-03 19:51 - 2014-12-03 19:52 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Bo\Desktop\mbam-setup-2.0.4.1028.exe
2014-12-03 19:47 - 2014-12-03 19:47 - 02154496 _____ () C:\Users\Bo\Desktop\AdwCleaner_4.103.exe
2014-12-03 18:02 - 2014-12-03 21:30 - 00030688 _____ () C:\Users\Bo\Desktop\Addition.txt
2014-12-03 17:57 - 2014-12-04 20:08 - 00015708 _____ () C:\Users\Bo\Desktop\FRST.txt
2014-12-03 17:57 - 2014-12-03 21:24 - 02117632 _____ (Farbar) C:\Users\Bo\Desktop\FRST64.exe
2014-12-02 17:50 - 2014-12-04 20:07 - 00000000 ____D () C:\FRST
2014-12-02 14:19 - 2014-12-02 14:20 - 00000000 ____D () C:\Users\Bo\Documents\Neuer Ordner
2014-12-02 13:47 - 2014-12-02 13:47 - 00000000 ____D () C:\Users\Bo\AppData\Local\AppEx Networks
2014-12-02 12:55 - 2014-12-02 12:55 - 00022528 _____ () C:\Users\Bo\AppData\Local\dsisetup3587056872.exe
2014-12-02 12:55 - 2014-12-02 12:55 - 00000002 _____ () C:\Users\Bo\AppData\Local\DSI.DAT
2014-11-28 09:18 - 2014-12-04 19:47 - 00027314 _____ () C:\Windows\PFRO.log
2014-11-27 14:56 - 2014-07-24 10:44 - 16874496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2014-11-27 14:55 - 2014-07-24 10:16 - 12730880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2014-11-27 14:54 - 2014-07-24 16:03 - 02141920 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2014-11-27 14:54 - 2014-07-24 14:36 - 02145472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2014-11-27 14:54 - 2014-07-24 09:53 - 01261056 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2014-11-27 14:54 - 2014-07-24 08:28 - 01600000 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll
2014-11-27 14:54 - 2014-06-14 07:03 - 02389504 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-11-27 14:53 - 2014-07-24 16:28 - 00412992 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2014-11-27 14:53 - 2014-07-24 16:28 - 00143680 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-11-27 14:53 - 2014-07-24 16:20 - 00645592 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-11-27 14:53 - 2014-07-24 16:16 - 02574208 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-11-27 14:53 - 2014-07-24 16:07 - 02009920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-11-27 14:53 - 2014-07-24 16:05 - 01660048 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-11-27 14:53 - 2014-07-24 16:05 - 01519560 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-11-27 14:53 - 2014-07-24 16:05 - 01488008 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-11-27 14:53 - 2014-07-24 16:05 - 01356840 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-11-27 14:53 - 2014-07-24 16:03 - 00882136 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-11-27 14:53 - 2014-07-24 14:48 - 02410976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-11-27 14:53 - 2014-07-24 14:46 - 00477200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-11-27 14:53 - 2014-07-24 14:36 - 00707536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-11-27 14:53 - 2014-07-24 12:44 - 00674816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-11-27 14:53 - 2014-07-24 12:43 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-11-27 14:53 - 2014-07-24 12:05 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\usbmon.dll
2014-11-27 14:53 - 2014-07-24 11:20 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2014-11-27 14:53 - 2014-07-24 10:52 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2014-11-27 14:53 - 2014-07-24 10:39 - 00770048 _____ (Microsoft Corporation) C:\Windows\system32\WorkfoldersControl.dll
2014-11-27 14:53 - 2014-07-24 10:10 - 00540672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2014-11-27 14:53 - 2014-07-24 10:03 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-11-27 14:53 - 2014-07-24 09:53 - 00449536 _____ (Microsoft Corporation) C:\Windows\system32\defragsvc.dll
2014-11-27 14:53 - 2014-07-24 09:39 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi.dll
2014-11-27 14:53 - 2014-07-24 09:32 - 01532416 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2014-11-27 14:53 - 2014-07-24 09:22 - 00487936 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2014-11-27 14:53 - 2014-07-24 09:21 - 01231872 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2014-11-27 14:53 - 2014-07-24 09:18 - 00795136 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-11-27 14:53 - 2014-07-24 09:10 - 00889344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2014-11-27 14:53 - 2014-07-24 09:01 - 01992192 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-11-27 14:53 - 2014-07-24 08:50 - 01182208 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll
2014-11-27 14:53 - 2014-07-24 05:11 - 00513544 _____ () C:\Windows\SysWOW64\locale.nls
2014-11-27 14:53 - 2014-07-24 05:11 - 00513544 _____ () C:\Windows\system32\locale.nls
2014-11-27 14:53 - 2014-07-12 06:55 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\wisp.dll
2014-11-27 14:53 - 2014-07-04 10:30 - 00544768 _____ (Microsoft Corporation) C:\Windows\system32\AppxPackaging.dll
2014-11-27 14:53 - 2014-06-19 03:13 - 00310080 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-11-27 14:53 - 2014-06-14 06:46 - 02071552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-11-27 14:53 - 2014-06-05 11:18 - 01018368 _____ (Microsoft Corporation) C:\Windows\system32\aclui.dll
2014-11-27 14:53 - 2014-05-31 06:00 - 01463808 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll
2014-11-27 14:53 - 2014-05-06 05:41 - 00486744 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2014-11-27 14:52 - 2014-07-24 16:28 - 00419648 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-11-27 14:52 - 2014-07-24 16:28 - 00280384 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2014-11-27 14:52 - 2014-07-24 16:23 - 00125472 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2014-11-27 14:52 - 2014-07-24 16:20 - 00263400 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2014-11-27 14:52 - 2014-07-24 16:16 - 00211216 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe
2014-11-27 14:52 - 2014-07-24 16:03 - 00360480 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2014-11-27 14:52 - 2014-07-24 16:03 - 00233888 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-11-27 14:52 - 2014-07-24 16:03 - 00205512 _____ (Microsoft Corporation) C:\Windows\system32\mftranscode.dll
2014-11-27 14:52 - 2014-07-24 14:50 - 00098048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2014-11-27 14:52 - 2014-07-24 14:48 - 00180208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SndVol.exe
2014-11-27 14:52 - 2014-07-24 14:36 - 00355800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2014-11-27 14:52 - 2014-07-24 14:36 - 00180720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mftranscode.dll
2014-11-27 14:52 - 2014-07-24 12:46 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-11-27 14:52 - 2014-07-24 12:45 - 00076800 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-11-27 14:52 - 2014-07-24 12:42 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2014-11-27 14:52 - 2014-07-24 12:42 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NdisImPlatform.sys
2014-11-27 14:52 - 2014-07-24 12:06 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\iasnap.dll
2014-11-27 14:52 - 2014-07-24 12:05 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-11-27 14:52 - 2014-07-24 11:49 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersGPExt.dll
2014-11-27 14:52 - 2014-07-24 11:18 - 01089024 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2014-11-27 14:52 - 2014-07-24 11:12 - 00878592 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll
2014-11-27 14:52 - 2014-07-24 11:10 - 01844224 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2014-11-27 14:52 - 2014-07-24 11:10 - 00834560 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-11-27 14:52 - 2014-07-24 11:10 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-11-27 14:52 - 2014-07-24 11:10 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasnap.dll
2014-11-27 14:52 - 2014-07-24 11:05 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersShell.dll
2014-11-27 14:52 - 2014-07-24 10:33 - 01741824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2014-11-27 14:52 - 2014-07-24 10:32 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2014-11-27 14:52 - 2014-07-24 10:27 - 00779264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-11-27 14:52 - 2014-07-24 10:24 - 01817088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll
2014-11-27 14:52 - 2014-07-24 10:12 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\WiFiDisplay.dll
2014-11-27 14:52 - 2014-07-24 10:11 - 00356864 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-11-27 14:52 - 2014-07-24 10:11 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2014-11-27 14:52 - 2014-07-24 10:02 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-11-27 14:52 - 2014-07-24 09:49 - 01287680 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2014-11-27 14:52 - 2014-07-24 09:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2014-11-27 14:52 - 2014-07-24 09:47 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2014-11-27 14:52 - 2014-07-24 09:38 - 00371200 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2014-11-27 14:52 - 2014-07-24 09:30 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2014-11-27 14:52 - 2014-07-24 09:29 - 00439296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2014-11-27 14:52 - 2014-07-24 09:28 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
2014-11-27 14:52 - 2014-07-24 09:23 - 01404416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storagewmi.dll
2014-11-27 14:52 - 2014-07-24 09:21 - 00302080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2014-11-27 14:52 - 2014-07-24 09:16 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\VAN.dll
2014-11-27 14:52 - 2014-07-24 09:16 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2014-11-27 14:52 - 2014-07-24 09:15 - 00721408 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.dll
2014-11-27 14:52 - 2014-07-24 09:15 - 00432128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2014-11-27 14:52 - 2014-07-24 09:10 - 00371712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2014-11-27 14:52 - 2014-07-24 09:08 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2014-11-27 14:52 - 2014-07-24 09:05 - 00448000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VAN.dll
2014-11-27 14:52 - 2014-07-24 08:58 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2014-11-27 14:52 - 2014-07-24 08:54 - 01290752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-11-27 14:52 - 2014-07-24 08:47 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2014-11-27 14:52 - 2014-07-24 08:44 - 01057792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\printui.dll
2014-11-27 14:52 - 2014-07-24 08:41 - 00459264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2014-11-27 14:52 - 2014-07-12 05:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wisp.dll
2014-11-27 14:52 - 2014-07-04 13:59 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-11-27 14:52 - 2014-07-04 11:29 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\AppxSip.dll
2014-11-27 14:52 - 2014-07-04 11:20 - 01656832 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2014-11-27 14:52 - 2014-07-04 11:06 - 00095232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxSip.dll
2014-11-27 14:52 - 2014-07-04 10:27 - 00474112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxPackaging.dll
2014-11-27 14:52 - 2014-06-27 07:22 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-11-27 14:52 - 2014-06-26 01:32 - 01029632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
2014-11-27 14:52 - 2014-06-26 01:29 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\dab.dll
2014-11-27 14:52 - 2014-06-20 00:37 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-11-27 14:52 - 2014-06-07 13:46 - 00216368 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll
2014-11-27 14:52 - 2014-06-07 11:20 - 00189016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2014-11-27 14:52 - 2014-06-05 15:00 - 01118040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-11-27 14:52 - 2014-06-05 10:42 - 00889856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aclui.dll
2014-11-27 14:52 - 2014-05-31 05:18 - 01319936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsecedit.dll
2014-11-27 14:52 - 2014-05-29 07:23 - 00427008 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2014-11-27 14:52 - 2014-05-29 06:25 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2014-11-27 14:52 - 2014-05-26 08:26 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\AppxSysprep.dll
2014-11-27 14:52 - 2014-05-10 11:12 - 00387896 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2014-11-27 14:52 - 2014-05-10 09:46 - 00335680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2014-11-27 14:52 - 2014-05-06 01:55 - 00391000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcfgx.dll
2014-11-27 14:52 - 2014-03-25 03:27 - 00160600 _____ (Microsoft Corporation) C:\Windows\system32\winmmbase.dll
2014-11-27 14:52 - 2014-03-25 03:27 - 00123920 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2014-11-27 14:52 - 2014-03-25 02:20 - 00128568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2014-11-27 14:52 - 2014-03-25 02:20 - 00127544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll
2014-11-27 14:51 - 2014-07-24 12:51 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\KBDRUM.DLL
2014-11-27 14:51 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-11-27 14:51 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTT102.DLL
2014-11-27 14:51 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-11-27 14:51 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-11-27 14:51 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-11-27 14:51 - 2014-07-24 12:51 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-11-27 14:51 - 2014-07-24 12:41 - 00118272 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthpan.sys
2014-11-27 14:51 - 2014-07-24 11:52 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-11-27 14:51 - 2014-07-24 11:52 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTT102.DLL
2014-11-27 14:51 - 2014-07-24 11:52 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-11-27 14:51 - 2014-07-24 11:51 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRUM.DLL
2014-11-27 14:51 - 2014-07-24 11:51 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-11-27 14:51 - 2014-07-24 11:51 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-11-27 14:51 - 2014-07-24 11:51 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-11-27 14:51 - 2014-07-24 11:32 - 00207360 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.cpl
2014-11-27 14:51 - 2014-07-24 10:42 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powercfg.cpl
2014-11-27 14:51 - 2014-07-24 10:40 - 00557056 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs.dll
2014-11-27 14:51 - 2014-07-24 10:25 - 00832512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActionCenter.dll
2014-11-27 14:51 - 2014-07-24 10:21 - 00134144 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-11-27 14:51 - 2014-07-24 10:18 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wlansvcpal.dll
2014-11-27 14:51 - 2014-07-24 10:14 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2014-11-27 14:51 - 2014-07-24 10:04 - 00492032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintDialogs.dll
2014-11-27 14:51 - 2014-07-24 10:04 - 00183808 _____ (Microsoft Corp.) C:\Windows\system32\Defrag.exe
2014-11-27 14:51 - 2014-07-24 09:58 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\BluetoothApis.dll
2014-11-27 14:51 - 2014-07-24 09:48 - 00659968 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
2014-11-27 14:51 - 2014-07-24 09:43 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshbth.dll
2014-11-27 14:51 - 2014-07-24 09:36 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BluetoothApis.dll
2014-11-27 14:51 - 2014-07-24 09:18 - 01144320 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2014-11-27 14:51 - 2014-07-24 09:13 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll
2014-11-27 14:51 - 2014-07-24 09:00 - 02100736 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2014-11-27 14:51 - 2014-07-24 08:58 - 00288768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2014-11-27 14:51 - 2014-07-04 11:00 - 01351168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2014-11-27 13:55 - 2014-11-27 13:55 - 00000000 ____D () C:\ProgramData\TOSHIBA Tempro
2014-11-27 13:55 - 2014-11-27 13:55 - 00000000 ____D () C:\ProgramData\IsolatedStorage
2014-11-27 13:54 - 2014-11-27 13:54 - 00000000 __SHD () C:\Users\Bo\AppData\Local\EmieBrowserModeList
2014-11-27 13:44 - 2014-11-20 21:51 - 00714208 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-27 13:44 - 2014-11-20 21:51 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-26 21:53 - 2014-11-26 21:53 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-26 19:03 - 2014-04-14 04:29 - 01018880 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-26 18:00 - 2014-08-15 01:36 - 00146752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys
2014-11-26 18:00 - 2014-07-30 02:56 - 00299520 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll
2014-11-26 18:00 - 2014-07-29 06:22 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\tcpmon.dll
2014-11-26 17:59 - 2014-10-13 03:33 - 00116032 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-11-26 17:59 - 2014-10-11 01:58 - 03320320 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-26 17:59 - 2014-10-11 01:53 - 03607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-26 17:59 - 2014-10-08 08:30 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-11-26 17:59 - 2014-10-08 08:09 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-11-26 17:59 - 2014-10-08 07:27 - 00325120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-11-26 17:59 - 2014-10-08 06:32 - 02773504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-11-26 17:59 - 2014-10-08 06:19 - 02459136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-11-26 17:58 - 2014-06-13 02:15 - 00517528 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-11-26 17:58 - 2014-06-13 02:14 - 01557848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-11-26 17:58 - 2014-06-13 01:10 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-11-26 17:58 - 2014-06-06 12:34 - 02133504 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-11-26 17:58 - 2014-05-30 04:03 - 00563200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-11-26 17:56 - 2014-09-22 05:38 - 01519488 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2014-11-26 17:56 - 2014-09-22 04:06 - 00258368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2014-11-26 17:56 - 2014-09-22 04:06 - 00114496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys
2014-11-26 17:56 - 2014-09-22 03:49 - 00035320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2014-11-26 17:56 - 2014-09-19 01:16 - 01346048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2014-11-26 17:56 - 2014-09-02 23:08 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\winshfhc.dll
2014-11-26 17:56 - 2014-09-02 23:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winshfhc.dll
2014-11-26 17:54 - 2014-09-27 08:13 - 00104336 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2014-11-26 17:54 - 2014-09-27 06:24 - 00088800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2014-11-26 17:54 - 2014-09-27 04:38 - 00426496 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-26 17:54 - 2014-09-27 04:30 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2014-11-26 17:54 - 2014-09-27 04:17 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-26 17:54 - 2014-06-20 02:48 - 01273184 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-11-26 17:54 - 2014-06-20 00:52 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-11-26 17:52 - 2014-03-13 08:42 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-11-26 17:52 - 2014-03-13 07:51 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-11-26 17:50 - 2014-10-31 06:28 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-26 17:50 - 2014-10-31 04:42 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-26 17:47 - 2014-10-31 04:59 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-26 17:47 - 2014-10-31 03:30 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-26 17:46 - 2014-10-31 06:06 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-26 17:46 - 2014-10-31 06:05 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-26 17:46 - 2014-10-31 05:53 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-26 17:46 - 2014-10-31 05:51 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-11-26 17:46 - 2014-10-31 05:50 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-26 17:46 - 2014-10-31 05:50 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-26 17:46 - 2014-10-31 05:38 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-26 17:46 - 2014-10-31 05:30 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-26 17:46 - 2014-10-31 05:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-26 17:46 - 2014-10-31 05:15 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-11-26 17:46 - 2014-10-31 05:08 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-11-26 17:46 - 2014-10-31 05:06 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-26 17:46 - 2014-10-31 05:05 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-26 17:46 - 2014-10-31 05:05 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-26 17:46 - 2014-10-31 05:03 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-26 17:46 - 2014-10-31 04:45 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-26 17:46 - 2014-10-31 04:44 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-11-26 17:46 - 2014-10-31 04:32 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-26 17:46 - 2014-10-31 04:24 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-26 17:46 - 2014-10-31 04:20 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-26 17:46 - 2014-10-31 04:18 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-26 17:46 - 2014-10-31 04:13 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-26 17:46 - 2014-10-31 04:12 - 00661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-11-26 17:46 - 2014-10-31 04:11 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-26 17:46 - 2014-10-31 04:02 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-26 17:46 - 2014-10-31 03:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-26 17:46 - 2014-10-31 03:50 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-26 17:46 - 2014-10-31 03:46 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-26 17:46 - 2014-10-31 03:46 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-11-26 17:46 - 2014-10-31 03:42 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-11-26 17:46 - 2014-10-31 03:40 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-26 17:46 - 2014-10-31 03:40 - 00325632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-26 17:46 - 2014-10-31 03:39 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-26 17:46 - 2014-10-31 03:17 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-26 17:46 - 2014-10-31 03:13 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-26 17:46 - 2014-10-31 03:11 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-26 17:45 - 2014-10-31 06:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-11-26 17:45 - 2014-10-31 06:12 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-11-26 17:45 - 2014-10-31 06:10 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-11-26 17:45 - 2014-10-31 06:09 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-11-26 17:45 - 2014-10-31 06:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-11-26 17:45 - 2014-10-31 06:06 - 00237568 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-11-26 17:45 - 2014-10-31 06:06 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-26 17:45 - 2014-10-31 06:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-26 17:45 - 2014-10-31 06:05 - 00417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-11-26 17:45 - 2014-10-31 06:04 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-26 17:45 - 2014-10-31 05:57 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-26 17:45 - 2014-10-31 05:56 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-26 17:45 - 2014-10-31 05:54 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-11-26 17:45 - 2014-10-31 05:52 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2014-11-26 17:45 - 2014-10-31 05:51 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-26 17:45 - 2014-10-31 05:51 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-26 17:45 - 2014-10-31 05:40 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-11-26 17:45 - 2014-10-31 05:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-11-26 17:45 - 2014-10-31 05:29 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-11-26 17:45 - 2014-10-31 05:28 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-11-26 17:45 - 2014-10-31 05:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-26 17:45 - 2014-10-31 05:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-26 17:45 - 2014-10-31 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-11-26 17:45 - 2014-10-31 05:23 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-11-26 17:45 - 2014-10-31 05:19 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-11-26 17:45 - 2014-10-31 04:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-11-26 17:45 - 2014-10-31 04:28 - 00137728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-11-26 17:45 - 2014-10-31 04:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-11-26 17:45 - 2014-10-31 04:27 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-11-26 17:45 - 2014-10-31 04:26 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-11-26 17:45 - 2014-10-31 04:25 - 00011264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-11-26 17:45 - 2014-10-31 04:24 - 00235520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-11-26 17:45 - 2014-10-31 04:24 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-26 17:45 - 2014-10-31 04:23 - 00340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-11-26 17:45 - 2014-10-31 04:23 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-26 17:45 - 2014-10-31 04:22 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-26 17:45 - 2014-10-31 04:16 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-26 17:45 - 2014-10-31 04:15 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-26 17:45 - 2014-10-31 04:14 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-11-26 17:45 - 2014-10-31 04:13 - 00099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2014-11-26 17:45 - 2014-10-31 04:12 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-26 17:45 - 2014-10-31 04:03 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-11-26 17:45 - 2014-10-31 03:56 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-11-26 17:45 - 2014-10-31 03:56 - 00090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-11-26 17:45 - 2014-10-31 03:56 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-11-26 17:45 - 2014-10-31 03:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-26 17:45 - 2014-10-31 03:53 - 00052736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-11-26 17:45 - 2014-10-31 03:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-26 17:45 - 2014-10-31 03:51 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-11-26 17:45 - 2014-10-31 03:48 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-11-26 17:45 - 2014-10-31 03:26 - 01042944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-11-26 17:45 - 2014-10-31 03:24 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-11-26 17:45 - 2014-08-31 01:15 - 21197152 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-11-26 17:45 - 2014-08-30 23:59 - 18723112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-11-26 17:45 - 2014-08-28 03:55 - 07484224 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-11-26 17:45 - 2014-08-23 06:14 - 13424128 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-11-26 17:45 - 2014-08-23 06:04 - 11820544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-11-26 17:44 - 2014-09-10 07:25 - 00474432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-11-26 17:44 - 2014-09-08 04:07 - 02497344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-11-26 17:44 - 2014-09-08 04:07 - 00428864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-11-26 17:44 - 2014-09-07 23:08 - 00389176 _____ () C:\Windows\system32\ApnDatabase.xml
2014-11-26 17:44 - 2014-09-04 23:30 - 00822272 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-11-26 17:44 - 2014-09-04 23:21 - 01053184 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-11-26 17:44 - 2014-09-04 04:05 - 00836176 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2014-11-26 17:44 - 2014-09-04 03:22 - 00670384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2014-11-26 17:44 - 2014-09-04 02:01 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2014-11-26 17:44 - 2014-09-04 01:32 - 00334336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2014-11-26 17:44 - 2014-09-04 01:10 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll
2014-11-26 17:44 - 2014-09-04 00:57 - 00921600 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-11-26 17:44 - 2014-09-04 00:49 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2014-11-26 17:44 - 2014-08-31 01:17 - 00148800 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-11-26 17:44 - 2014-08-30 23:05 - 00615424 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOMEX.dll
2014-11-26 17:44 - 2014-08-30 22:58 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\FXSAPI.dll
2014-11-26 17:44 - 2014-08-30 22:04 - 00941568 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2014-11-26 17:44 - 2014-08-30 21:53 - 00239104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSAPI.dll
2014-11-26 17:44 - 2014-08-30 21:17 - 00799744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2014-11-26 17:44 - 2014-08-28 01:21 - 02480128 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-11-26 17:44 - 2014-08-28 01:06 - 02030592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-11-26 17:44 - 2014-08-23 05:50 - 02714112 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2014-11-26 17:44 - 2014-08-02 01:51 - 00545792 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2014-11-26 17:44 - 2014-08-02 01:35 - 00485376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2014-11-26 17:44 - 2014-07-24 12:22 - 00308736 _____ (Microsoft Corporation) C:\Windows\system32\compstui.dll
2014-11-26 17:44 - 2014-07-24 10:53 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\prnntfy.dll
2014-11-26 17:44 - 2014-07-24 10:13 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prnntfy.dll
2014-11-26 17:44 - 2014-07-24 09:20 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll
2014-11-26 17:44 - 2014-07-24 09:08 - 00162816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiapi.dll
2014-11-26 17:44 - 2014-07-24 08:49 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\DafPrintProvider.dll
2014-11-26 17:44 - 2014-07-24 08:43 - 00200192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DafPrintProvider.dll
2014-11-26 17:44 - 2014-05-13 08:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\BulkOperationHost.exe
2014-11-26 17:41 - 2014-05-03 06:08 - 00301056 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2014-11-26 17:41 - 2014-04-30 07:41 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-11-26 17:41 - 2014-04-30 05:23 - 00353280 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2014-11-26 17:41 - 2014-04-30 05:23 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-11-26 17:41 - 2014-04-30 04:46 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2014-11-26 17:41 - 2014-04-30 04:42 - 00403968 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2014-11-26 17:41 - 2014-04-26 17:39 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll
2014-11-26 17:41 - 2014-04-14 10:37 - 02125344 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2014-11-26 17:41 - 2014-04-14 09:08 - 01797896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2014-11-26 17:40 - 2014-05-03 06:19 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\ncobjapi.dll
2014-11-26 17:40 - 2014-05-03 06:07 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2014-11-26 17:40 - 2014-05-03 05:46 - 00052736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncobjapi.dll
2014-11-26 17:40 - 2014-05-03 05:37 - 00235008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedynos.dll
2014-11-26 17:40 - 2014-05-03 05:37 - 00207360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedyn.dll
2014-11-26 17:40 - 2014-04-30 07:43 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vwififlt.sys
2014-11-26 17:40 - 2014-04-30 07:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\agilevpn.sys
2014-11-26 17:40 - 2014-04-30 07:41 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vwifimp.sys
2014-11-26 17:40 - 2014-04-30 06:45 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe
2014-11-26 17:40 - 2014-04-30 05:48 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2014-11-26 17:40 - 2014-04-30 05:24 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-11-26 17:40 - 2014-04-30 05:23 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll
2014-11-26 17:40 - 2014-04-30 05:14 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2014-11-26 17:40 - 2014-04-30 04:59 - 01063424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-11-26 17:40 - 2014-04-30 04:46 - 00229888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-11-26 17:40 - 2014-04-30 04:46 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-11-26 17:40 - 2014-04-30 04:45 - 00062976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc.dll
2014-11-26 17:40 - 2014-04-28 23:40 - 00721408 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2014-11-26 17:40 - 2014-04-14 06:18 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d8thk.dll
2014-11-26 17:39 - 2014-05-03 06:36 - 00997888 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2014-11-26 17:39 - 2014-05-03 00:26 - 00050745 _____ () C:\Windows\system32\srms.dat
2014-11-26 17:28 - 2014-03-18 06:00 - 07173120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2014-11-26 17:28 - 2014-03-18 05:52 - 05104640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2014-11-26 17:27 - 2014-04-06 17:20 - 01403856 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2014-11-26 17:27 - 2014-04-06 17:20 - 01379064 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-11-26 17:27 - 2014-04-06 17:20 - 00765408 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2014-11-26 17:27 - 2014-04-06 16:16 - 00669856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2014-11-26 17:27 - 2014-03-28 16:58 - 00407016 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2014-11-26 17:26 - 2014-04-18 15:57 - 00032600 _____ (Microsoft Corporation) C:\Windows\system32\ploptin.dll
2014-11-26 17:26 - 2014-04-14 10:20 - 00324888 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2014-11-26 17:26 - 2014-04-14 09:01 - 00285144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2014-11-26 17:26 - 2014-04-09 12:53 - 00337240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-11-26 17:26 - 2014-04-08 03:01 - 00589656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-11-26 17:26 - 2014-04-06 17:34 - 00275800 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-11-26 17:26 - 2014-04-06 17:30 - 00201920 _____ (Microsoft Corporation) C:\Windows\system32\MSVideoDSP.dll
2014-11-26 17:26 - 2014-04-06 17:20 - 00491744 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2014-11-26 17:26 - 2014-04-06 16:16 - 01209616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2014-11-26 17:26 - 2014-04-06 16:16 - 00387896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2014-11-26 17:26 - 2014-04-06 13:33 - 00335872 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2014-11-26 17:26 - 2014-04-06 11:05 - 01222656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2014-11-26 17:26 - 2014-04-06 10:59 - 00982016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2014-11-26 17:26 - 2014-04-03 09:12 - 00130144 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2014-11-26 17:26 - 2014-03-27 06:36 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2014-11-26 17:26 - 2014-03-27 04:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll
2014-11-26 17:26 - 2014-03-27 04:10 - 01436160 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2014-11-26 17:26 - 2014-03-17 06:09 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-11-26 17:26 - 2014-03-17 05:11 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-11-26 17:26 - 2014-03-14 07:26 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\GeofenceMonitorService.dll
2014-11-26 17:26 - 2014-03-14 07:10 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GeofenceMonitorService.dll
2014-11-26 17:25 - 2014-04-18 10:44 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\energyprov.dll
2014-11-26 17:25 - 2014-04-11 05:51 - 00250368 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2014-11-26 17:25 - 2014-04-11 05:23 - 00209920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll
2014-11-26 17:25 - 2014-04-09 07:39 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2014-11-26 17:25 - 2014-04-09 06:44 - 00144384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2014-11-26 17:25 - 2014-04-09 04:33 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2014-11-26 17:25 - 2014-04-06 17:34 - 00372568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-11-26 17:25 - 2014-04-06 17:24 - 00360792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2014-11-26 17:25 - 2014-04-06 17:20 - 00609448 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-11-26 17:25 - 2014-04-06 17:20 - 00028408 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-11-26 17:25 - 2014-04-06 16:22 - 00178184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVideoDSP.dll
2014-11-26 17:25 - 2014-04-06 16:16 - 00518544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-11-26 17:25 - 2014-04-06 13:58 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-11-26 17:25 - 2014-04-06 13:51 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-11-26 17:25 - 2014-04-06 13:24 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-11-26 17:25 - 2014-04-06 13:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-11-26 17:25 - 2014-04-06 12:26 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
2014-11-26 17:25 - 2014-04-03 09:12 - 00307304 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-11-26 17:25 - 2014-04-03 05:03 - 00230808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-11-26 17:25 - 2014-04-03 05:03 - 00111528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2014-11-26 17:25 - 2014-04-03 03:23 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tlscsp.dll
2014-11-26 17:25 - 2014-04-03 03:22 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\tlscsp.dll
2014-11-26 17:25 - 2014-03-27 05:48 - 00219136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2014-11-26 17:25 - 2014-03-19 09:15 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2014-11-26 17:25 - 2014-03-19 08:24 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-11-26 17:25 - 2014-03-19 08:17 - 00011264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2014-11-26 17:21 - 2014-11-05 00:38 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-26 17:21 - 2014-11-04 01:10 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-26 17:21 - 2014-10-31 05:53 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-11-26 17:21 - 2014-10-31 05:49 - 00537088 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-26 17:21 - 2014-10-31 05:24 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-11-26 17:11 - 2014-10-10 02:58 - 00177472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-26 17:11 - 2014-10-10 02:58 - 00027456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-11-26 17:11 - 2014-10-10 02:44 - 00563976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-11-26 17:11 - 2014-10-08 08:37 - 00736768 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-26 17:11 - 2014-10-08 08:37 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-26 17:11 - 2014-10-08 08:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-11-26 17:11 - 2014-10-08 08:24 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\rfxvmt.dll
2014-11-26 17:11 - 2014-10-08 07:56 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2014-11-26 17:11 - 2014-10-08 07:51 - 00736768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-26 17:11 - 2014-10-08 07:51 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-26 17:11 - 2014-10-08 07:18 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2014-11-26 17:11 - 2014-10-08 07:17 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-26 17:11 - 2014-10-08 06:23 - 03547648 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-11-26 17:11 - 2014-08-07 03:12 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-11-26 17:11 - 2014-08-02 04:56 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-11-26 17:11 - 2014-07-15 19:16 - 03048880 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2014-11-26 17:11 - 2014-07-15 09:29 - 03118080 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-11-26 17:11 - 2014-07-15 09:22 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2014-11-26 17:11 - 2014-07-15 09:03 - 02344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-11-26 17:11 - 2014-04-11 04:54 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2014-11-26 17:11 - 2014-04-11 03:57 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-11-26 17:10 - 2014-08-02 01:18 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-11-26 17:09 - 2014-10-18 10:55 - 00055776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-11-26 17:09 - 2014-10-18 09:09 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-11-26 17:09 - 2014-10-18 09:09 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-11-26 17:09 - 2014-10-18 08:25 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-11-26 17:09 - 2014-10-18 07:50 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-11-26 17:09 - 2014-10-18 07:38 - 03557376 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-11-26 17:09 - 2014-10-18 07:27 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-11-26 17:09 - 2014-10-18 07:26 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-11-26 17:09 - 2014-10-18 07:23 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-11-26 17:09 - 2014-10-18 07:23 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-11-26 17:09 - 2014-10-18 07:21 - 00894976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-11-26 17:09 - 2014-10-18 07:20 - 01714176 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-11-26 17:09 - 2014-10-18 07:14 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-11-26 17:09 - 2014-10-18 07:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-11-26 17:09 - 2014-10-18 07:12 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-11-26 17:09 - 2014-10-18 07:11 - 00723968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-11-26 17:09 - 2014-09-04 01:12 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-11-26 17:09 - 2014-09-04 01:01 - 00514048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-11-26 17:08 - 2014-10-17 08:01 - 00789184 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-26 17:08 - 2014-10-17 07:58 - 00602768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-26 17:08 - 2014-08-23 08:48 - 02374784 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-11-26 17:08 - 2014-08-23 08:13 - 02084520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-11-26 17:08 - 2014-08-23 07:10 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-11-26 17:08 - 2014-08-23 06:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-11-26 17:08 - 2014-08-23 05:33 - 00796672 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2014-11-26 17:04 - 2014-07-24 04:20 - 00875688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2014-11-26 17:04 - 2014-07-24 04:20 - 00869544 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2014-11-26 17:03 - 2014-08-16 04:58 - 01112512 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-11-26 17:03 - 2014-08-16 01:22 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll
2014-11-26 17:03 - 2014-08-16 01:18 - 04758528 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
2014-11-26 17:03 - 2014-08-16 01:17 - 08757760 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2014-11-26 17:03 - 2014-08-16 01:14 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll
2014-11-26 17:03 - 2014-08-16 01:13 - 05902848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2014-11-26 17:03 - 2014-08-16 01:11 - 00920064 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-11-26 17:03 - 2014-08-16 01:10 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
2014-11-26 17:03 - 2014-08-16 01:07 - 00756224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-11-26 17:02 - 2014-08-16 05:08 - 01507648 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-11-26 17:02 - 2014-08-16 05:01 - 01710184 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-11-26 17:02 - 2014-08-16 04:16 - 01205976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2014-11-26 17:02 - 2014-08-16 04:03 - 01467384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-11-26 17:02 - 2014-08-16 02:31 - 00838144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-11-26 17:02 - 2014-08-16 02:04 - 00359424 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2014-11-26 17:02 - 2014-08-16 01:58 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll
2014-11-26 17:02 - 2014-08-16 01:53 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\httpprxm.dll
2014-11-26 17:02 - 2014-08-16 01:46 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\ProximityService.dll
2014-11-26 17:02 - 2014-08-16 01:45 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2014-11-26 17:02 - 2014-08-16 01:43 - 00321024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2014-11-26 17:02 - 2014-08-16 01:43 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\adhsvc.dll
2014-11-26 17:02 - 2014-08-16 01:31 - 00914432 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-11-26 17:02 - 2014-08-16 01:31 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\pcsvDevice.dll
2014-11-26 17:02 - 2014-08-16 01:29 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-11-26 17:02 - 2014-08-16 01:23 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-11-26 17:02 - 2014-08-16 01:22 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
2014-11-26 17:02 - 2014-08-16 01:19 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-11-26 17:02 - 2014-08-16 01:13 - 06649344 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-11-26 17:02 - 2014-08-16 01:13 - 00840192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2014-11-26 17:02 - 2014-08-16 01:08 - 05777408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-11-26 17:02 - 2014-07-24 16:28 - 00468288 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2014-11-26 17:02 - 2014-07-24 12:42 - 01200640 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2014-11-26 17:02 - 2014-07-24 12:41 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys
2014-11-26 17:02 - 2014-07-24 11:09 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-11-26 17:02 - 2014-07-24 10:27 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-11-26 17:01 - 2014-06-09 23:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-11-26 17:01 - 2014-06-09 23:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-11-26 16:48 - 2014-11-10 00:19 - 00991232 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-26 16:48 - 2014-11-10 00:19 - 00806400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-26 16:48 - 2014-11-10 00:18 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-26 16:48 - 2014-11-10 00:18 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-26 16:48 - 2014-10-23 06:48 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-26 16:48 - 2014-10-23 06:05 - 00072192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-26 16:48 - 2014-10-07 07:28 - 00500016 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-26 16:48 - 2014-10-07 07:27 - 00482872 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-26 16:48 - 2014-10-07 07:27 - 00394120 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-26 16:48 - 2014-10-07 07:27 - 00272248 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-11-26 16:48 - 2014-10-07 07:27 - 00108432 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-26 16:48 - 2014-10-07 04:34 - 00370424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-26 16:48 - 2014-10-07 04:34 - 00344536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-26 16:48 - 2014-10-07 04:33 - 00424544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-26 16:48 - 2014-10-07 04:30 - 04182016 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-26 16:48 - 2014-10-07 02:54 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2014-11-26 16:48 - 2014-10-07 02:46 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-26 16:48 - 2014-08-23 06:18 - 02149376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-26 16:48 - 2014-08-23 06:03 - 01346048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-26 16:48 - 2014-05-19 07:31 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\drvcfg.exe
2014-11-26 16:48 - 2014-05-19 07:21 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe
2014-11-26 16:48 - 2014-05-19 06:23 - 00098816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-11-26 16:48 - 2014-04-08 23:46 - 00086688 _____ (Microsoft Corporation) C:\Windows\system32\mrt_map.dll
2014-11-26 16:48 - 2014-04-08 23:46 - 00028320 _____ (Microsoft Corporation) C:\Windows\system32\mrt100.dll
2014-11-26 16:48 - 2014-04-08 19:54 - 00080032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mrt_map.dll
2014-11-26 16:48 - 2014-04-08 19:54 - 00026784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mrt100.dll
2014-11-26 16:47 - 2014-06-02 03:10 - 00423768 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-11-26 16:47 - 2014-05-31 11:07 - 00440664 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-11-26 16:47 - 2014-05-31 11:07 - 00089944 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-11-26 16:47 - 2014-05-31 11:07 - 00027480 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-11-26 16:47 - 2014-05-31 07:30 - 00037376 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-11-26 16:47 - 2014-05-31 07:27 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-11-26 16:47 - 2014-05-31 07:26 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-11-26 16:47 - 2014-05-31 05:01 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-11-26 16:47 - 2014-05-31 05:01 - 00209408 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-11-26 16:47 - 2014-05-31 05:01 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-11-26 16:47 - 2014-05-27 10:56 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\DaOtpCredentialProvider.dll
2014-11-26 16:47 - 2014-05-27 10:53 - 00270848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DaOtpCredentialProvider.dll
2014-11-26 16:47 - 2014-04-30 05:43 - 01975296 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-11-26 16:47 - 2014-04-30 05:26 - 01345536 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-11-26 16:47 - 2014-04-30 04:47 - 01509888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-11-26 16:45 - 2014-11-26 16:45 - 00000000 ____D () C:\Users\Bo\AppData\Local\Skype
2014-11-26 16:45 - 2014-06-06 14:04 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-11-26 16:45 - 2014-06-06 13:18 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-11-26 16:45 - 2014-05-01 14:31 - 00055328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wpcfltr.sys
2014-11-26 16:45 - 2014-05-01 06:24 - 02834944 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2014-11-26 16:44 - 2014-12-04 19:36 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Skype
2014-11-26 16:44 - 2014-07-12 05:17 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe
2014-11-26 16:32 - 2014-05-31 11:06 - 00555736 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2014-11-26 16:32 - 2014-05-31 03:37 - 01054208 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2014-11-26 16:32 - 2014-05-31 03:35 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2014-11-26 16:32 - 2014-04-11 09:25 - 00419928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2014-11-26 16:32 - 2014-04-11 06:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\WSReset.exe
2014-11-26 07:19 - 2014-11-26 07:19 - 00000000 __SHD () C:\Users\Bo\AppData\Local\EmieUserList
2014-11-26 07:19 - 2014-11-26 07:19 - 00000000 __SHD () C:\Users\Bo\AppData\Local\EmieSiteList
2014-11-26 07:14 - 2014-12-04 19:49 - 00000000 ___DO () C:\Users\Bo\OneDrive
2014-11-25 16:38 - 2014-02-08 02:08 - 00139600 _____ () C:\Windows\system32\systemsf.ebd
2014-11-25 16:36 - 2014-02-22 16:53 - 03394384 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2014-11-25 16:35 - 2014-02-22 13:08 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\OobeFldr.dll
2014-11-25 16:35 - 2014-02-22 12:17 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OobeFldr.dll
2014-11-25 16:35 - 2014-02-22 11:34 - 11742720 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll
2014-11-25 16:35 - 2014-02-22 11:02 - 08946688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
2014-11-25 16:34 - 2014-02-22 16:55 - 01435304 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2014-11-25 16:34 - 2014-02-22 10:01 - 13933568 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-11-25 16:33 - 2014-02-22 10:47 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2014-11-25 16:33 - 2014-02-22 10:23 - 03494912 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2014-11-25 16:33 - 2014-02-22 10:16 - 11776000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-11-25 16:33 - 2014-02-22 09:40 - 02368512 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2014-11-25 16:32 - 2014-02-22 16:46 - 01927600 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2014-11-25 16:32 - 2014-02-22 16:46 - 01445616 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2014-11-25 16:32 - 2014-02-22 10:28 - 02643456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2014-11-25 16:32 - 2014-02-22 10:23 - 01576960 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2014-11-25 16:32 - 2014-02-22 10:23 - 00628224 _____ (Microsoft Corporation) C:\Windows\system32\msTextPrediction.dll
2014-11-25 16:32 - 2014-02-22 10:13 - 01728000 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
2014-11-25 16:32 - 2014-02-22 09:37 - 01716736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2014-11-25 16:31 - 2014-02-22 17:15 - 01929608 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2014-11-25 16:31 - 2014-02-22 16:41 - 01215832 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2014-11-25 16:31 - 2014-02-22 16:41 - 00800552 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2014-11-25 16:31 - 2014-02-22 15:38 - 01374384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2014-11-25 16:31 - 2014-02-22 15:38 - 01077944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2014-11-25 16:31 - 2014-02-22 13:24 - 02825216 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2014-11-25 16:31 - 2014-02-22 11:38 - 00390656 _____ (Microsoft Corporation) C:\Windows\system32\DfpCommon.dll
2014-11-25 16:31 - 2014-02-22 10:52 - 01132032 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2014-11-25 16:31 - 2014-02-22 10:38 - 00753664 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2014-11-25 16:31 - 2014-02-22 10:35 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\WofTasks.dll
2014-11-25 16:31 - 2014-02-22 10:14 - 00584704 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2014-11-25 16:31 - 2014-02-22 10:11 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2014-11-25 16:31 - 2014-02-22 10:00 - 01341440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dui70.dll
2014-11-25 16:31 - 2014-02-22 09:59 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll
2014-11-25 16:31 - 2014-02-22 09:54 - 00647168 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2014-11-25 16:31 - 2014-02-22 09:06 - 01640960 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2014-11-25 16:30 - 2014-02-22 17:59 - 01290688 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2014-11-25 16:30 - 2014-02-22 17:59 - 00526304 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-11-25 16:30 - 2014-02-22 16:44 - 00539992 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2014-11-25 16:30 - 2014-02-22 15:52 - 01767440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2014-11-25 16:30 - 2014-02-22 15:04 - 01011280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2014-11-25 16:30 - 2014-02-22 15:04 - 00650736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2014-11-25 16:30 - 2014-02-22 12:28 - 02428928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2014-11-25 16:30 - 2014-02-22 10:53 - 00825344 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2014-11-25 16:30 - 2014-02-22 10:00 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2014-11-25 16:30 - 2014-02-22 09:22 - 00777728 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2014-11-25 16:30 - 2014-02-22 09:03 - 01496576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2014-11-25 16:30 - 2014-01-29 09:53 - 01653352 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-11-25 16:29 - 2014-02-22 17:15 - 01206000 _____ (Microsoft Corporation) C:\Windows\system32\Taskmgr.exe
2014-11-25 16:29 - 2014-02-22 17:00 - 00249688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2014-11-25 16:29 - 2014-02-22 16:46 - 01000424 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2014-11-25 16:29 - 2014-02-22 16:46 - 00669896 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-11-25 16:29 - 2014-02-22 16:41 - 00391008 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
2014-11-25 16:29 - 2014-02-22 15:51 - 01063976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Taskmgr.exe
2014-11-25 16:29 - 2014-02-22 15:42 - 01017936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2014-11-25 16:29 - 2014-02-22 15:42 - 00422968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-11-25 16:29 - 2014-02-22 13:22 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-11-25 16:29 - 2014-02-22 13:07 - 00545792 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2014-11-25 16:29 - 2014-02-22 11:25 - 01428480 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2014-11-25 16:29 - 2014-02-22 11:18 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-11-25 16:29 - 2014-02-22 10:57 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2014-11-25 16:29 - 2014-02-22 10:34 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\energy.dll
2014-11-25 16:29 - 2014-02-22 10:26 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2014-11-25 16:29 - 2014-02-22 10:26 - 00366080 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2014-11-25 16:29 - 2014-02-22 10:10 - 00569856 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2014-11-25 16:29 - 2014-02-22 10:04 - 01107456 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2014-11-25 16:29 - 2014-02-22 09:59 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2014-11-25 16:29 - 2014-02-22 09:51 - 01258496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RacEngn.dll
2014-11-25 16:29 - 2014-02-22 09:45 - 00845824 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2014-11-25 16:29 - 2014-02-22 09:01 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2014-11-25 16:29 - 2014-02-22 09:00 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2014-11-25 16:29 - 2014-02-22 05:33 - 00262335 _____ () C:\Windows\system32\dfpinc.dat
2014-11-25 16:29 - 2014-01-29 08:44 - 01369736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-11-25 16:28 - 2014-02-22 15:04 - 00296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll
2014-11-25 16:28 - 2014-02-22 12:16 - 00617472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2014-11-25 16:28 - 2014-02-22 11:36 - 00441344 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-11-25 16:28 - 2014-02-22 11:09 - 01224192 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2014-11-25 16:28 - 2014-02-22 11:01 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2014-11-25 16:28 - 2014-02-22 10:45 - 00562176 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-11-25 16:28 - 2014-02-22 10:35 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-11-25 16:28 - 2014-02-22 10:33 - 00653312 _____ (Microsoft Corporation) C:\Windows\system32\DismApi.dll
2014-11-25 16:28 - 2014-02-22 09:47 - 00517120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2014-11-25 16:28 - 2014-02-22 09:21 - 00600576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2014-11-25 16:27 - 2014-02-22 16:55 - 00244848 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2014-11-25 16:27 - 2014-02-22 16:50 - 00761792 _____ (Microsoft Corporation) C:\Windows\system32\iuilp.dll
2014-11-25 16:27 - 2014-02-22 16:48 - 01791752 ____C (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll
2014-11-25 16:27 - 2014-02-22 13:07 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\WofUtil.dll
2014-11-25 16:27 - 2014-02-22 12:25 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\recimg.exe
2014-11-25 16:27 - 2014-02-22 11:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\dfp.exe
2014-11-25 16:27 - 2014-02-22 11:41 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-11-25 16:27 - 2014-02-22 10:24 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2014-11-25 16:27 - 2014-02-22 10:14 - 00752640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-11-25 16:27 - 2014-02-22 10:10 - 00747008 _____ (Microsoft Corporation) C:\Windows\system32\wlidcli.dll
2014-11-25 16:27 - 2014-02-22 09:51 - 00716288 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-11-25 16:27 - 2014-02-22 09:51 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2014-11-25 16:27 - 2014-02-22 09:39 - 00556032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.dll
2014-11-25 16:27 - 2014-02-22 09:37 - 00658432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2014-11-25 16:26 - 2014-02-22 15:11 - 00490136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-11-25 16:26 - 2014-02-22 13:02 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2014-11-25 16:26 - 2014-02-22 12:57 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\slc.dll
2014-11-25 16:26 - 2014-02-22 12:06 - 00148992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slc.dll
2014-11-25 16:26 - 2014-02-22 11:37 - 00912384 _____ (Microsoft Corporation) C:\Windows\system32\nettrace.dll
2014-11-25 16:26 - 2014-02-22 11:05 - 01757184 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
2014-11-25 16:26 - 2014-02-22 10:48 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2014-11-25 16:26 - 2014-02-22 10:44 - 00675328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2014-11-25 16:26 - 2014-02-22 10:36 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\Dism.exe
2014-11-25 16:26 - 2014-02-22 10:34 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll
2014-11-25 16:26 - 2014-02-22 10:07 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2014-11-25 16:26 - 2014-02-22 09:53 - 00876544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-11-25 16:26 - 2014-02-22 09:33 - 00609792 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2014-11-25 16:26 - 2014-02-22 09:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\MrmIndexer.dll
2014-11-25 16:26 - 2013-12-10 08:35 - 00530944 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2014-11-25 16:25 - 2014-02-22 17:59 - 00461176 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2014-11-25 16:25 - 2014-02-22 17:59 - 00289752 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2014-11-25 16:25 - 2014-02-22 16:55 - 00152848 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2014-11-25 16:25 - 2014-02-22 16:41 - 00372360 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2014-11-25 16:25 - 2014-02-22 15:04 - 00317584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2014-11-25 16:25 - 2014-02-22 13:11 - 00272896 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-11-25 16:25 - 2014-02-22 12:54 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2014-11-25 16:25 - 2014-02-22 11:56 - 02862592 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2014-11-25 16:25 - 2014-02-22 11:52 - 02288640 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2014-11-25 16:25 - 2014-02-22 11:15 - 01543680 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2014-11-25 16:25 - 2014-02-22 11:14 - 02811392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2014-11-25 16:25 - 2014-02-22 11:02 - 00258560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2014-11-25 16:25 - 2014-02-22 11:00 - 00217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2014-11-25 16:25 - 2014-02-22 10:59 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\mdmregistration.dll
2014-11-25 16:25 - 2014-02-22 10:54 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll
2014-11-25 16:25 - 2014-02-22 10:43 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll
2014-11-25 16:25 - 2014-02-22 10:15 - 00211968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Dism.exe
2014-11-25 16:25 - 2014-02-22 10:12 - 00459776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DismApi.dll
2014-11-25 16:25 - 2014-02-22 09:54 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\rdbui.dll
2014-11-25 16:25 - 2014-02-22 09:54 - 00286720 _____ (Microsoft Corporation) C:\Windows\system32\wlidcredprov.dll
2014-11-25 16:25 - 2014-02-22 09:49 - 00755200 _____ (Microsoft Corporation) C:\Windows\system32\msctfuimanager.dll
2014-11-25 16:25 - 2014-02-22 09:47 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\WlanMM.dll
2014-11-25 16:25 - 2014-02-22 09:45 - 00169472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2014-11-25 16:25 - 2014-02-22 09:43 - 00644608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2014-11-25 16:25 - 2014-02-22 09:43 - 00469504 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2014-11-25 16:25 - 2014-02-22 09:43 - 00117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2014-11-25 16:25 - 2014-02-22 09:36 - 00232448 _____ (Microsoft Corporation) C:\Windows\system32\InputSwitch.dll
2014-11-25 16:25 - 2014-02-22 09:29 - 00191488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputSwitch.dll
2014-11-25 16:25 - 2014-02-22 09:21 - 00518144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmIndexer.dll
2014-11-25 16:25 - 2014-01-31 10:55 - 03596800 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-11-25 16:25 - 2014-01-31 10:10 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll
2014-11-25 16:25 - 2014-01-29 09:52 - 00551256 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2014-11-25 16:25 - 2014-01-17 18:24 - 00388096 _____ (Microsoft Corporation) C:\Windows\system32\ninput.dll
2014-11-25 16:24 - 2014-02-22 17:59 - 00407536 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2014-11-25 16:24 - 2014-02-22 17:59 - 00139464 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2014-11-25 16:24 - 2014-02-22 17:15 - 00531128 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-11-25 16:24 - 2014-02-22 17:02 - 00170952 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2014-11-25 16:24 - 2014-02-22 17:02 - 00083120 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-11-25 16:24 - 2014-02-22 17:00 - 00236888 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2014-11-25 16:24 - 2014-02-22 15:42 - 00410568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2014-11-25 16:24 - 2014-02-22 15:38 - 00506120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2014-11-25 16:24 - 2014-02-22 13:20 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-system-events.dll
2014-11-25 16:24 - 2014-02-22 13:14 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys
2014-11-25 16:24 - 2014-02-22 13:09 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-11-25 16:24 - 2014-02-22 12:41 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe
2014-11-25 16:24 - 2014-02-22 12:34 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\dmdskmgr.dll
2014-11-25 16:24 - 2014-02-22 12:05 - 00095232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2014-11-25 16:24 - 2014-02-22 11:56 - 00350720 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll
2014-11-25 16:24 - 2014-02-22 11:18 - 00722432 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeui.exe
2014-11-25 16:24 - 2014-02-22 11:17 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\fhcfg.dll
2014-11-25 16:24 - 2014-02-22 11:14 - 02165760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncCenter.dll
2014-11-25 16:24 - 2014-02-22 11:12 - 00797696 _____ (Microsoft Corporation) C:\Windows\system32\PurchaseWindowsLicense.dll
2014-11-25 16:24 - 2014-02-22 11:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-11-25 16:24 - 2014-02-22 11:04 - 00935424 _____ (Microsoft Corporation) C:\Windows\system32\rasgcw.dll
2014-11-25 16:24 - 2014-02-22 11:04 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\WLanConn.dll
2014-11-25 16:24 - 2014-02-22 10:45 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2014-11-25 16:24 - 2014-02-22 10:45 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-11-25 16:24 - 2014-02-22 10:32 - 01162752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2014-11-25 16:24 - 2014-02-22 10:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll
         

Alt 04.12.2014, 20:30   #20
Krazerack
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Code:
ATTFilter
2014-11-25 16:24 - 2014-02-22 10:25 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\wscinterop.dll
2014-11-25 16:24 - 2014-02-22 10:09 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\dwm.exe
2014-11-25 16:24 - 2014-02-22 09:52 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2014-11-25 16:24 - 2014-02-22 09:42 - 00943104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WlanMM.dll
2014-11-25 16:24 - 2014-02-22 09:42 - 00709120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctfuimanager.dll
2014-11-25 16:24 - 2014-01-31 10:35 - 03085824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-11-25 16:23 - 2014-02-22 17:59 - 00209160 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll
2014-11-25 16:23 - 2014-02-22 17:15 - 00275312 _____ (Microsoft Corporation) C:\Windows\system32\powrprof.dll
2014-11-25 16:23 - 2014-02-22 17:15 - 00188464 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe
2014-11-25 16:23 - 2014-02-22 17:02 - 00080048 _____ (Microsoft Corporation) C:\Windows\system32\taskhostex.exe
2014-11-25 16:23 - 2014-02-22 17:00 - 00151384 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2014-11-25 16:23 - 2014-02-22 17:00 - 00079192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fileinfo.sys
2014-11-25 16:23 - 2014-02-22 16:50 - 00101216 _____ (Microsoft Corporation) C:\Windows\system32\RestoreOptIn.exe
2014-11-25 16:23 - 2014-02-22 16:50 - 00043408 _____ (Microsoft Corporation) C:\Windows\system32\CloudNotifications.exe
2014-11-25 16:23 - 2014-02-22 16:50 - 00032544 _____ (Microsoft Corporation) C:\Windows\system32\UserAccountBroker.exe
2014-11-25 16:23 - 2014-02-22 16:49 - 00079192 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\sdstor.sys
2014-11-25 16:23 - 2014-02-22 16:44 - 00924504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refs.sys
2014-11-25 16:23 - 2014-02-22 16:43 - 00142576 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-11-25 16:23 - 2014-02-22 15:52 - 00251504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powrprof.dll
2014-11-25 16:23 - 2014-02-22 15:51 - 00140456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2014-11-25 16:23 - 2014-02-22 15:42 - 00369288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2014-11-25 16:23 - 2014-02-22 15:42 - 00232896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqmapi.dll
2014-11-25 16:23 - 2014-02-22 15:42 - 00137344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2014-11-25 16:23 - 2014-02-22 15:18 - 00041320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudNotifications.exe
2014-11-25 16:23 - 2014-02-22 13:20 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-kernel-power-events.dll
2014-11-25 16:23 - 2014-02-22 13:14 - 00033280 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\BasicRender.sys
2014-11-25 16:23 - 2014-02-22 12:50 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2014-11-25 16:23 - 2014-02-22 12:47 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
2014-11-25 16:23 - 2014-02-22 12:16 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2014-11-25 16:23 - 2014-02-22 12:15 - 00137728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imm32.dll
2014-11-25 16:23 - 2014-02-22 12:05 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\RASMM.dll
2014-11-25 16:23 - 2014-02-22 12:02 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContent.dll
2014-11-25 16:23 - 2014-02-22 12:01 - 00112640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe
2014-11-25 16:23 - 2014-02-22 11:59 - 01283584 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2014-11-25 16:23 - 2014-02-22 11:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\dmvdsitf.dll
2014-11-25 16:23 - 2014-02-22 11:52 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\newdev.dll
2014-11-25 16:23 - 2014-02-22 11:51 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\spwizeng.dll
2014-11-25 16:23 - 2014-02-22 11:41 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\netid.dll
2014-11-25 16:23 - 2014-02-22 11:27 - 00397824 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2014-11-25 16:23 - 2014-02-22 11:14 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2014-11-25 16:23 - 2014-02-22 11:13 - 00897024 _____ (Microsoft Corporation) C:\Windows\system32\sdclt.exe
2014-11-25 16:23 - 2014-02-22 11:01 - 01227776 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-11-25 16:23 - 2014-02-22 10:49 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftAccountTokenProvider.dll
2014-11-25 16:23 - 2014-02-22 10:40 - 02537472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2014-11-25 16:23 - 2014-02-22 10:36 - 01392640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPDMC.exe
2014-11-25 16:23 - 2014-02-22 10:31 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mdmregistration.dll
2014-11-25 16:23 - 2014-02-22 10:25 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\das.dll
2014-11-25 16:23 - 2014-02-22 10:22 - 00336384 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2014-11-25 16:23 - 2014-02-22 10:18 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\UserLanguagesCpl.dll
2014-11-25 16:23 - 2014-02-22 10:02 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2014-11-25 16:23 - 2014-02-22 09:55 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2014-11-25 16:23 - 2014-02-22 09:54 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2014-11-25 16:23 - 2014-02-22 09:48 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\BioCredProv.dll
2014-11-25 16:23 - 2014-02-22 09:47 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\AltTab.dll
2014-11-25 16:23 - 2014-02-22 09:44 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-11-25 16:23 - 2014-02-22 09:40 - 00322048 _____ (Microsoft Corporation) C:\Windows\system32\fhcpl.dll
2014-11-25 16:23 - 2014-02-22 09:38 - 00470016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2014-11-25 16:23 - 2014-02-22 08:54 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SndVolSSO.dll
2014-11-25 16:23 - 2014-01-31 10:15 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2014-11-25 16:23 - 2014-01-31 10:04 - 00409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2014-11-25 16:23 - 2014-01-29 01:36 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2014-11-25 16:23 - 2014-01-27 20:53 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-11-25 16:23 - 2014-01-17 18:04 - 00292864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ninput.dll
2014-11-25 16:23 - 2013-12-04 19:41 - 00226304 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\BthLEEnum.sys
2014-11-25 16:23 - 2013-11-11 00:41 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\vmrdvcore.dll
2014-11-25 16:22 - 2014-02-22 17:15 - 00071888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpfve.sys
2014-11-25 16:22 - 2014-02-22 16:55 - 00162176 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe
2014-11-25 16:22 - 2014-02-22 16:55 - 00131168 _____ (Microsoft Corporation) C:\Windows\system32\easinvoker.exe
2014-11-25 16:22 - 2014-02-22 16:49 - 00325464 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2014-11-25 16:22 - 2014-02-22 16:49 - 00189784 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS
2014-11-25 16:22 - 2014-02-22 16:43 - 00094560 _____ (Microsoft Corporation) C:\Windows\system32\bcd.dll
2014-11-25 16:22 - 2014-02-22 15:18 - 00089848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RestoreOptIn.exe
2014-11-25 16:22 - 2014-02-22 15:18 - 00029912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserAccountBroker.exe
2014-11-25 16:22 - 2014-02-22 15:08 - 00079496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcd.dll
2014-11-25 16:22 - 2014-02-22 13:07 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\clrhost.dll
2014-11-25 16:22 - 2014-02-22 12:27 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\dot3mm.dll
2014-11-25 16:22 - 2014-02-22 12:17 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\DAMM.dll
2014-11-25 16:22 - 2014-02-22 12:14 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\cleanmgr.exe
2014-11-25 16:22 - 2014-02-22 11:33 - 00402944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2014-11-25 16:22 - 2014-02-22 11:30 - 00213504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cleanmgr.exe
2014-11-25 16:22 - 2014-02-22 11:16 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srchadmin.dll
2014-11-25 16:22 - 2014-02-22 11:13 - 00307200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\newdev.dll
2014-11-25 16:22 - 2014-02-22 10:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2014-11-25 16:22 - 2014-02-22 10:36 - 00835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasgcw.dll
2014-11-25 16:22 - 2014-02-22 10:36 - 00391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WLanConn.dll
2014-11-25 16:22 - 2014-02-22 10:25 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll
2014-11-25 16:22 - 2014-02-22 10:07 - 00109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscinterop.dll
2014-11-25 16:22 - 2014-02-22 09:54 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2014-11-25 16:22 - 2014-02-22 09:46 - 03312128 _____ (Microsoft Corporation) C:\Windows\system32\bootux.dll
2014-11-25 16:22 - 2014-02-22 09:44 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\provsvc.dll
2014-11-25 16:22 - 2014-02-22 09:39 - 00356352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2014-11-25 16:22 - 2014-01-31 10:08 - 00507392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSDApi.dll
2014-11-25 16:22 - 2014-01-29 01:18 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2014-11-25 16:22 - 2014-01-29 01:17 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll
2014-11-25 16:22 - 2014-01-22 07:21 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll
2014-11-25 16:22 - 2013-11-27 10:10 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\netiohlp.dll
2014-11-25 16:21 - 2014-02-22 17:58 - 00036200 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2014-11-25 16:21 - 2014-02-22 15:41 - 00033056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2014-11-25 16:21 - 2014-02-22 13:17 - 00902144 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2014-11-25 16:21 - 2014-02-22 13:03 - 00349696 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2014-11-25 16:21 - 2014-02-22 12:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-11-25 16:21 - 2014-02-22 12:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll
2014-11-25 16:21 - 2014-02-22 12:42 - 00038680 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentServer.exe
2014-11-25 16:21 - 2014-02-22 12:25 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
2014-11-25 16:21 - 2014-02-22 12:22 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
2014-11-25 16:21 - 2014-02-22 12:16 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clrhost.dll
2014-11-25 16:21 - 2014-02-22 12:02 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\acppage.dll
2014-11-25 16:21 - 2014-02-22 11:57 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-11-25 16:21 - 2014-02-22 11:47 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmdskmgr.dll
2014-11-25 16:21 - 2014-02-22 11:46 - 00283136 _____ (Microsoft Corporation) C:\Windows\system32\wbadmin.exe
2014-11-25 16:21 - 2014-02-22 11:21 - 00045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\acppage.dll
2014-11-25 16:21 - 2014-02-22 11:20 - 01152512 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
2014-11-25 16:21 - 2014-02-22 11:16 - 00151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2014-11-25 16:21 - 2014-02-22 11:04 - 00098304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netid.dll
2014-11-25 16:21 - 2014-02-22 10:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\winbrand.dll
2014-11-25 16:21 - 2014-02-22 10:44 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\korwbrkr.dll
2014-11-25 16:21 - 2014-02-22 10:43 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Sockets.PushEnabledApplication.dll
2014-11-25 16:21 - 2014-02-22 10:30 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2014-11-25 16:21 - 2014-02-22 10:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2014-11-25 16:21 - 2014-02-22 10:23 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll
2014-11-25 16:21 - 2014-02-22 10:08 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2014-11-25 16:21 - 2014-02-22 10:06 - 00251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2014-11-25 16:21 - 2014-02-22 10:04 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\slpts.dll
2014-11-25 16:21 - 2014-02-22 09:51 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll
2014-11-25 16:21 - 2014-02-22 09:45 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2014-11-25 16:21 - 2014-02-22 09:44 - 00154624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netplwiz.dll
2014-11-25 16:21 - 2014-02-22 09:43 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BioCredProv.dll
2014-11-25 16:21 - 2014-02-22 09:30 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\wpnprv.dll
2014-11-25 16:21 - 2014-02-22 09:20 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\AuthBroker.dll
2014-11-25 16:21 - 2014-02-22 09:17 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\CloudStorageWizard.exe
2014-11-25 16:21 - 2014-01-29 09:40 - 00994136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2014-11-25 16:21 - 2014-01-27 20:48 - 00167424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys
2014-11-25 16:21 - 2014-01-22 06:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2014-11-25 16:21 - 2013-11-27 09:56 - 00167936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netiohlp.dll
2014-11-25 16:20 - 2014-02-22 16:59 - 00027480 _____ (Microsoft Corporation) C:\Windows\system32\SysResetErr.exe
2014-11-25 16:20 - 2014-02-22 13:17 - 00890880 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2014-11-25 16:20 - 2014-02-22 13:17 - 00874496 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2014-11-25 16:20 - 2014-02-22 13:14 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\watchdog.sys
2014-11-25 16:20 - 2014-02-22 13:07 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-11-25 16:20 - 2014-02-22 13:03 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2014-11-25 16:20 - 2014-02-22 13:01 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\spcompat.dll
2014-11-25 16:20 - 2014-02-22 12:59 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgrade.exe
2014-11-25 16:20 - 2014-02-22 12:47 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2014-11-25 16:20 - 2014-02-22 12:45 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\fhevents.dll
2014-11-25 16:20 - 2014-02-22 12:37 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe
2014-11-25 16:20 - 2014-02-22 12:32 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2014-11-25 16:20 - 2014-02-22 12:29 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\RelPost.exe
2014-11-25 16:20 - 2014-02-22 12:25 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\sppnp.dll
2014-11-25 16:20 - 2014-02-22 12:24 - 00800256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2014-11-25 16:20 - 2014-02-22 12:24 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2014-11-25 16:20 - 2014-02-22 12:24 - 00780288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2014-11-25 16:20 - 2014-02-22 12:16 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-11-25 16:20 - 2014-02-22 12:11 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spbcd.dll
2014-11-25 16:20 - 2014-02-22 12:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\pnpclean.dll
2014-11-25 16:20 - 2014-02-22 11:59 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2014-11-25 16:20 - 2014-02-22 11:58 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll
2014-11-25 16:20 - 2014-02-22 11:58 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\DAConn.dll
2014-11-25 16:20 - 2014-02-22 11:57 - 00165376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrobj.dll
2014-11-25 16:20 - 2014-02-22 11:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PkgMgr.exe
2014-11-25 16:20 - 2014-02-22 11:47 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\migisol.dll
2014-11-25 16:20 - 2014-02-22 11:40 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
2014-11-25 16:20 - 2014-02-22 11:34 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2014-11-25 16:20 - 2014-02-22 11:25 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StorageContextHandler.dll
2014-11-25 16:20 - 2014-02-22 11:16 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sud.dll
2014-11-25 16:20 - 2014-02-22 11:12 - 00352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwizeng.dll
2014-11-25 16:20 - 2014-02-22 10:52 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.exe
2014-11-25 16:20 - 2014-02-22 10:45 - 00453632 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2014-11-25 16:20 - 2014-02-22 10:25 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winbrand.dll
2014-11-25 16:20 - 2014-02-22 10:19 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Sockets.PushEnabledApplication.dll
2014-11-25 16:20 - 2014-02-22 09:55 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\energytask.dll
2014-11-25 16:20 - 2014-02-22 09:55 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slpts.dll
2014-11-25 16:20 - 2014-02-22 09:48 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2014-11-25 16:20 - 2014-02-22 09:47 - 00185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcredprov.dll
2014-11-25 16:20 - 2014-02-22 09:43 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Renewal.dll
2014-11-25 16:20 - 2014-02-22 09:39 - 00321536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\provsvc.dll
2014-11-25 16:20 - 2014-02-22 09:31 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\IdCtrls.dll
2014-11-25 16:20 - 2014-02-22 09:19 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthBroker.dll
2014-11-25 16:20 - 2014-02-01 07:00 - 00002255 _____ () C:\Windows\SysWOW64\WimBootCompress.ini
2014-11-25 16:20 - 2014-02-01 07:00 - 00002255 _____ () C:\Windows\system32\WimBootCompress.ini
2014-11-25 16:20 - 2014-01-31 13:09 - 00081920 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2014-11-25 16:20 - 2014-01-31 10:19 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\dafBth.dll
2014-11-25 16:19 - 2014-02-22 13:17 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\f3ahvoas.dll
2014-11-25 16:19 - 2014-02-22 13:08 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2014-11-25 16:19 - 2014-02-22 13:04 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\offreg.dll
2014-11-25 16:19 - 2014-02-22 13:00 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe
2014-11-25 16:19 - 2014-02-22 12:50 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\ActionQueue.dll
2014-11-25 16:19 - 2014-02-22 12:47 - 00589312 _____ (Microsoft Corporation) C:\Windows\system32\vdsdyn.dll
2014-11-25 16:19 - 2014-02-22 12:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SSShim.dll
2014-11-25 16:19 - 2014-02-22 12:16 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-11-25 16:19 - 2014-02-22 12:13 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offreg.dll
2014-11-25 16:19 - 2014-02-22 12:09 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgentc.exe
2014-11-25 16:19 - 2014-02-22 12:08 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
2014-11-25 16:19 - 2014-02-22 12:05 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentHost.dll
2014-11-25 16:19 - 2014-02-22 12:04 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\dfrgui.exe
2014-11-25 16:19 - 2014-02-22 11:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\srrstr.dll
2014-11-25 16:19 - 2014-02-22 11:55 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\SrTasks.exe
2014-11-25 16:19 - 2014-02-22 11:41 - 02566656 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll
2014-11-25 16:19 - 2014-02-22 11:38 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll
2014-11-25 16:19 - 2014-02-22 11:35 - 00504832 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
2014-11-25 16:19 - 2014-02-22 11:21 - 00561664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfrgui.exe
2014-11-25 16:19 - 2014-02-22 11:17 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2014-11-25 16:19 - 2014-02-22 11:09 - 00097280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\migisol.dll
2014-11-25 16:19 - 2014-02-22 10:54 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\deviceassociation.dll
2014-11-25 16:19 - 2014-02-22 10:48 - 01136128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl
2014-11-25 16:19 - 2014-02-22 10:46 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\winsku.dll
2014-11-25 16:19 - 2014-02-22 10:39 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\dasHost.exe
2014-11-25 16:19 - 2014-02-22 10:28 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceassociation.dll
2014-11-25 16:19 - 2014-02-22 10:26 - 00299008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2014-11-25 16:19 - 2014-02-22 10:26 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powercfg.exe
2014-11-25 16:19 - 2014-02-22 10:22 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsku.dll
2014-11-25 16:19 - 2014-02-22 10:02 - 00559104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserLanguagesCpl.dll
2014-11-25 16:19 - 2014-02-22 09:58 - 00544768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcli.dll
2014-11-25 16:19 - 2014-02-22 09:55 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2014-11-25 16:19 - 2014-02-22 09:54 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\AepRoam.dll
2014-11-25 16:19 - 2014-02-22 09:49 - 00468480 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.Handlers.dll
2014-11-25 16:19 - 2014-02-22 09:45 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\PlayToDevice.dll
2014-11-25 16:19 - 2014-02-22 09:40 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2014-11-25 16:19 - 2014-02-22 09:35 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\SettingMonitor.dll
2014-11-25 16:19 - 2014-02-22 09:33 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingMonitor.dll
2014-11-25 16:19 - 2014-02-22 09:24 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IdCtrls.dll
2014-11-25 16:19 - 2014-02-22 09:17 - 00109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudStorageWizard.exe
2014-11-25 16:18 - 2014-02-22 12:24 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\ext-ms-win-session-winsta-l1-1-0.dll
2014-11-25 16:18 - 2014-02-22 12:07 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-11-25 16:18 - 2014-02-22 11:50 - 00136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskpart.exe
2014-11-25 16:18 - 2014-02-22 11:47 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupugc.exe
2014-11-25 16:18 - 2014-02-22 11:32 - 00118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-11-25 16:18 - 2014-02-22 10:48 - 00355328 _____ (Microsoft Corporation) C:\Windows\system32\wincorlib.dll
2014-11-25 16:18 - 2014-02-22 10:23 - 00256000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincorlib.dll
2014-11-25 16:18 - 2014-02-22 10:16 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxshared.dll
2014-11-25 16:18 - 2014-02-22 10:09 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2014-11-25 16:18 - 2014-02-22 09:55 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\ConfigureExpandedStorage.dll
2014-11-25 16:18 - 2014-02-22 09:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ConfigureExpandedStorage.dll
2014-11-25 16:18 - 2014-02-22 09:48 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2014-11-25 16:17 - 2014-02-22 13:17 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\ext-ms-win-session-winsta-l1-1-0.dll
2014-11-25 16:17 - 2014-02-22 13:17 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\ext-ms-win-kernel32-package-l1-1-1.dll
2014-11-25 16:17 - 2014-02-22 13:08 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\syncui.dll
2014-11-25 16:17 - 2014-02-22 12:48 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\ocsetapi.dll
2014-11-25 16:17 - 2014-02-22 12:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\ext-ms-win-kernel32-package-l1-1-1.dll
2014-11-25 16:17 - 2014-02-22 12:08 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll
2014-11-25 16:17 - 2014-02-22 12:07 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\StorageContextHandler.dll
2014-11-25 16:17 - 2014-02-22 11:59 - 00163328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ocsetapi.dll
2014-11-25 16:17 - 2014-02-22 11:35 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\aitagent.exe
2014-11-25 16:17 - 2014-02-22 11:03 - 02544128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themecpl.dll
2014-11-25 16:17 - 2014-02-22 10:59 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\wmpdxm.dll
2014-11-25 16:17 - 2014-02-22 10:54 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\GlobCollationHost.dll
2014-11-25 16:17 - 2014-02-22 10:27 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GlobCollationHost.dll
2014-11-25 16:17 - 2014-02-22 10:19 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\korwbrkr.dll
2014-11-25 16:17 - 2014-02-22 09:55 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\dataclen.dll
2014-11-25 16:17 - 2014-02-22 09:22 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncPolicy.dll
2014-11-25 16:17 - 2014-02-22 09:20 - 00027648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncPolicy.dll
2014-11-25 16:17 - 2014-02-22 05:37 - 00000369 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-11-25 16:17 - 2014-02-22 05:37 - 00000369 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-11-25 16:17 - 2014-02-22 05:37 - 00000369 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-11-25 16:17 - 2014-02-22 05:37 - 00000369 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-11-25 16:17 - 2014-02-08 02:08 - 00100197 _____ () C:\Windows\SysWOW64\RacRules.xml
2014-11-25 16:17 - 2014-02-08 02:08 - 00100197 _____ () C:\Windows\system32\RacRules.xml
2014-11-25 16:17 - 2014-02-01 07:00 - 00007762 _____ () C:\Windows\SysWOW64\connectedsearch-suggestions.searchconnector-ms
2014-11-25 16:17 - 2014-02-01 07:00 - 00007762 _____ () C:\Windows\system32\connectedsearch-suggestions.searchconnector-ms
2014-11-25 16:17 - 2014-02-01 07:00 - 00007130 _____ () C:\Windows\SysWOW64\connectedsearch-zeroinput.searchconnector-ms
2014-11-25 16:17 - 2014-02-01 07:00 - 00007130 _____ () C:\Windows\system32\connectedsearch-zeroinput.searchconnector-ms
2014-11-25 16:17 - 2013-11-27 10:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\finger.exe
2014-11-25 16:16 - 2014-02-22 13:17 - 00008192 ____H (Microsoft Corporation) C:\Windows\system32\ext-ms-win-ntuser-private-l1-1-1.dll
2014-11-25 16:16 - 2014-02-22 13:17 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\ext-ms-win-ntuser-private-l1-1-0.dll
2014-11-25 16:16 - 2014-02-22 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2014-11-25 16:16 - 2014-02-22 13:08 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-11-25 16:16 - 2014-02-22 13:08 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-11-25 16:16 - 2014-02-22 13:00 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\lpksetupproxyserv.dll
2014-11-25 16:16 - 2014-02-22 12:39 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\fhsvcctl.dll
2014-11-25 16:16 - 2014-02-22 12:25 - 00028160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\f3ahvoas.dll
2014-11-25 16:16 - 2014-02-22 12:25 - 00008192 ____H (Microsoft Corporation) C:\Windows\SysWOW64\ext-ms-win-ntuser-private-l1-1-1.dll
2014-11-25 16:16 - 2014-02-22 12:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\ext-ms-win-ntuser-private-l1-1-0.dll
2014-11-25 16:16 - 2014-02-22 12:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\ext-ms-win-networking-wcmapi-l1-1-0.dll
2014-11-25 16:16 - 2014-02-22 10:51 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\fveskybackup.dll
2014-11-25 16:16 - 2014-02-22 09:48 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dataclen.dll
2014-11-25 16:16 - 2014-02-22 09:39 - 00193024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl
2014-11-25 16:16 - 2014-02-22 05:43 - 00002440 ___RS () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileManager.lnk
2014-11-25 16:16 - 2014-02-01 07:00 - 00011109 _____ () C:\Windows\SysWOW64\connectedsearch-results.searchconnector-ms
2014-11-25 16:16 - 2014-02-01 07:00 - 00011109 _____ () C:\Windows\system32\connectedsearch-results.searchconnector-ms
2014-11-25 16:16 - 2013-11-27 10:47 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\finger.exe
2014-11-25 15:53 - 2014-11-26 16:44 - 00002533 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-11-25 15:53 - 2014-11-26 16:44 - 00000000 ____D () C:\ProgramData\Skype
2014-11-25 15:53 - 2014-11-26 16:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-11-25 15:53 - 2014-11-25 15:53 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-11-25 14:43 - 2014-03-06 15:34 - 02331000 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-11-25 14:43 - 2014-03-06 10:19 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.Search.UriHandler.dll
2014-11-25 14:43 - 2014-03-06 09:20 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Shell.Search.UriHandler.dll
2014-11-25 14:43 - 2014-03-06 07:51 - 02900992 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2014-11-25 14:42 - 2014-03-20 05:19 - 01291200 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-11-25 14:42 - 2014-03-20 04:41 - 00376152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2014-11-25 14:42 - 2014-03-20 01:53 - 00950784 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2014-11-25 14:42 - 2014-03-20 01:48 - 00201216 _____ (Microsoft Corporation) C:\Windows\system32\ReInfo.dll
2014-11-25 14:42 - 2014-03-20 00:55 - 01036288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-11-25 14:42 - 2014-03-20 00:39 - 00800256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2014-11-25 14:42 - 2014-03-20 00:36 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReInfo.dll
2014-11-25 14:42 - 2014-03-19 06:50 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\w32tm.exe
2014-11-25 14:42 - 2014-03-19 06:20 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\w32tm.exe
2014-11-25 14:42 - 2014-03-13 13:35 - 00157016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wof.sys
2014-11-25 14:42 - 2014-03-11 16:45 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\BdeHdCfgLib.dll
2014-11-25 14:42 - 2014-03-11 16:02 - 00794112 _____ (Microsoft Corporation) C:\Windows\system32\fvewiz.dll
2014-11-25 14:42 - 2014-03-11 15:25 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerDeviceEncryption.exe
2014-11-25 14:42 - 2014-03-11 15:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2014-11-25 14:42 - 2014-03-08 21:40 - 00136024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2014-11-25 14:42 - 2014-03-08 21:38 - 01542768 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-11-25 14:42 - 2014-03-08 16:29 - 00356848 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2014-11-25 14:42 - 2014-03-08 12:34 - 01095488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2014-11-25 14:42 - 2014-03-08 10:02 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\sxproxy.dll
2014-11-25 14:42 - 2014-03-08 09:33 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll
2014-11-25 14:42 - 2014-03-08 09:25 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\SetNetworkLocation.dll
2014-11-25 14:42 - 2014-03-08 09:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxproxy.dll
2014-11-25 14:42 - 2014-03-08 08:47 - 00222720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spp.dll
2014-11-25 14:42 - 2014-03-08 08:04 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2014-11-25 14:42 - 2014-03-08 07:48 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2014-11-25 14:42 - 2014-03-08 07:41 - 00412672 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-11-25 14:42 - 2014-03-08 07:40 - 00139776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2014-11-25 14:42 - 2014-03-08 07:31 - 00222720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2014-11-25 14:42 - 2014-03-08 07:30 - 00197632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2014-11-25 14:42 - 2014-03-08 07:25 - 00264192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-11-25 14:42 - 2014-03-08 07:04 - 00717312 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-11-25 14:42 - 2014-03-08 06:58 - 00567296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-11-25 14:42 - 2014-03-08 06:41 - 01306624 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2014-11-25 14:42 - 2014-03-08 06:11 - 00924160 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2014-11-25 14:42 - 2014-03-06 15:34 - 00113648 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2014-11-25 14:42 - 2014-03-06 13:53 - 02141912 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-11-25 14:42 - 2014-03-06 13:51 - 00379224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-11-25 14:42 - 2014-03-06 13:39 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-11-25 14:42 - 2014-03-06 12:19 - 00094016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\userenv.dll
2014-11-25 14:42 - 2014-03-06 12:13 - 01779800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-11-25 14:42 - 2014-03-06 11:46 - 01679128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-11-25 14:42 - 2014-03-06 10:24 - 00111616 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-11-25 14:42 - 2014-03-06 10:24 - 00033280 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2014-11-25 14:42 - 2014-03-06 10:22 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-11-25 14:42 - 2014-03-06 10:22 - 00134144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-11-25 14:42 - 2014-03-06 10:19 - 00283648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-11-25 14:42 - 2014-03-06 10:19 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-11-25 14:42 - 2014-03-06 10:19 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-11-25 14:42 - 2014-03-06 10:08 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\l2gpstore.dll
2014-11-25 14:42 - 2014-03-06 09:41 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\DevPropMgr.dll
2014-11-25 14:42 - 2014-03-06 09:38 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-11-25 14:42 - 2014-03-06 09:10 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\l2gpstore.dll
2014-11-25 14:42 - 2014-03-06 09:00 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2014-11-25 14:42 - 2014-03-06 08:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-11-25 14:42 - 2014-03-06 08:16 - 00171008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2014-11-25 14:42 - 2014-03-06 08:02 - 00834560 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2014-11-25 14:42 - 2014-03-06 07:29 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2014-11-25 14:42 - 2014-03-06 07:27 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-11-25 14:42 - 2014-03-06 07:24 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll
2014-11-25 14:42 - 2014-03-06 07:23 - 02270208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2014-11-25 14:42 - 2014-03-06 07:23 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\dafWfdProvider.dll
2014-11-25 14:42 - 2014-03-06 07:21 - 00291840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
2014-11-25 14:42 - 2014-03-06 07:09 - 01764864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2014-11-25 14:42 - 2014-03-06 07:06 - 00386560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlangpui.dll
2014-11-25 14:42 - 2014-03-06 07:04 - 00226304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
2014-11-25 14:42 - 2014-03-06 07:01 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll
2014-11-25 14:42 - 2014-03-06 06:51 - 00151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2014-11-25 14:42 - 2014-03-06 06:47 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2014-11-25 14:42 - 2014-03-06 06:42 - 00280576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SessEnv.dll
2014-11-25 14:42 - 2014-03-04 08:16 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-11-25 14:42 - 2014-03-04 08:13 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-11-25 14:42 - 2014-03-04 08:08 - 00299008 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2014-11-25 14:42 - 2014-03-04 08:00 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\wlidprov.dll
2014-11-25 14:42 - 2014-03-04 07:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RMapi.dll
2014-11-25 14:42 - 2014-03-04 07:42 - 00494592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-11-25 14:42 - 2014-03-04 07:39 - 00254976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2014-11-25 14:42 - 2014-03-04 07:32 - 00356864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidprov.dll
2014-11-25 14:42 - 2014-03-04 07:15 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.dll
2014-11-25 14:42 - 2014-03-04 07:05 - 00402432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.dll
2014-11-25 14:42 - 2014-03-04 07:03 - 00669696 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2014-11-25 14:42 - 2014-03-04 07:03 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\CredentialMigrationHandler.dll
2014-11-25 14:42 - 2014-03-04 06:54 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredentialMigrationHandler.dll
2014-11-25 14:42 - 2014-03-04 06:52 - 00605184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2014-11-25 14:42 - 2013-12-24 00:28 - 00262656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2014-11-25 14:42 - 2013-12-24 00:26 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll
2014-11-25 13:33 - 2014-11-25 13:35 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-11-25 13:33 - 2014-11-25 13:33 - 00001132 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk
2014-11-25 12:29 - 2014-11-25 23:01 - 00000000 ____D () C:\Users\TEMP
2014-11-24 07:12 - 2014-11-24 21:09 - 00000000 ___RD () C:\Windows\BrowserChoice
2014-11-24 07:01 - 2014-11-24 07:01 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\LolClient
2014-11-23 21:51 - 2014-11-23 21:56 - 00000000 ____D () C:\Users\Bo\Downloads\Alligatoah - Schlaftabletten, Rotwein 4
2014-11-23 19:56 - 2014-11-26 12:11 - 00000000 ____D () C:\Users\Bo\Desktop\Musik
2014-11-23 19:53 - 2014-11-23 19:53 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-11-23 18:05 - 2014-11-23 18:05 - 00009216 ___SH () C:\Users\Bo\Thumbs.db
2014-11-23 17:14 - 2014-11-23 17:53 - 00008144 _____ () C:\Users\Bo\AppData\Roaming\TheHunterSettings_live.bin
2014-11-23 17:02 - 2014-11-23 17:02 - 00000039 _____ () C:\Users\Bo\AppData\Roaming\TheHunterSettings_steam_live.cfg
2014-11-23 17:02 - 2014-11-23 17:02 - 00000000 ____D () C:\Users\Bo\Documents\theHunter
2014-11-23 17:02 - 2014-11-23 17:02 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\theHunter
2014-11-23 17:02 - 2014-11-23 17:02 - 00000000 ____D () C:\Users\Bo\AppData\Local\theHunter
2014-11-23 16:58 - 2014-11-23 17:35 - 00000096 _____ () C:\Users\Bo\AppData\Roaming\LauncherSettings_live.cfg
2014-11-23 16:58 - 2014-11-23 16:58 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\theHunterSteam
2014-11-23 16:58 - 2014-11-23 16:58 - 00000000 ____D () C:\ProgramData\Hunter
2014-11-23 14:22 - 2014-11-23 14:30 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-23 14:21 - 2014-10-31 23:26 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-23 11:14 - 2014-11-23 11:14 - 00000000 ____D () C:\ProgramData\Riot Games
2014-11-23 11:00 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2014-11-23 11:00 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2014-11-23 11:00 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2014-11-23 10:59 - 2014-11-23 10:59 - 00001625 _____ () C:\Users\Public\Desktop\League of Legends.lnk
2014-11-23 10:59 - 2014-11-23 10:59 - 00000000 ____D () C:\Riot Games
2014-11-23 10:53 - 2014-11-23 11:00 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Riot Games
2014-11-23 10:44 - 2014-11-23 10:49 - 30668968 _____ (Riot Games) C:\Users\Bo\Downloads\LeagueofLegends_EUW_Installer_9_15_2014.exe
2014-11-21 13:50 - 2013-11-27 16:34 - 03210528 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-11-21 13:50 - 2013-11-27 14:47 - 02804528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-11-21 13:49 - 2013-11-27 13:02 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ipnat.sys
2014-11-21 13:49 - 2013-11-27 11:24 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-11-21 13:49 - 2013-11-27 10:46 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-11-21 13:49 - 2013-11-27 10:10 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.dll
2014-11-21 13:49 - 2013-11-27 09:56 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll
2014-11-21 13:49 - 2013-11-23 08:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\bi.dll
2014-11-21 13:49 - 2013-11-23 08:13 - 00019456 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\BtaMPM.sys
2014-11-21 13:49 - 2013-11-21 07:58 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\deviceregistration.dll
2014-11-21 13:49 - 2013-11-15 15:59 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2014-11-21 13:49 - 2013-11-15 15:25 - 00433664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2014-11-21 13:38 - 2013-09-17 10:06 - 01067080 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2014-11-21 13:38 - 2013-09-17 07:31 - 00883184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2014-11-21 13:37 - 2013-10-23 12:13 - 00171864 _____ (Microsoft Corporation) C:\Windows\system32\kd_02_8086.dll
2014-11-21 13:37 - 2013-10-08 06:09 - 01160704 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Http.dll
2014-11-21 13:37 - 2013-10-08 05:50 - 00762368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Http.dll
2014-11-21 13:37 - 2013-10-05 15:21 - 00699840 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-11-21 13:37 - 2013-10-05 13:05 - 00578952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-11-21 13:37 - 2013-10-05 10:18 - 01011712 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-11-21 13:37 - 2013-10-05 09:56 - 01147904 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2014-11-21 13:37 - 2013-10-05 09:40 - 00795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-11-21 13:37 - 2013-10-05 09:21 - 00920064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2014-11-21 13:37 - 2013-10-05 08:43 - 00578560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2014-11-21 13:37 - 2013-10-05 08:35 - 00411648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2014-11-21 13:37 - 2013-09-14 15:00 - 00391512 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2014-11-21 13:37 - 2013-09-14 13:33 - 00345552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2014-11-21 13:37 - 2013-09-12 09:08 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2014-11-21 13:37 - 2013-09-12 08:44 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2014-11-21 13:37 - 2013-09-12 08:21 - 00262144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
2014-11-21 13:37 - 2013-09-10 05:52 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\msched.dll
2014-11-21 13:36 - 2013-10-23 12:29 - 00044936 _____ (Microsoft Corporation) C:\Windows\system32\wldp.dll
2014-11-21 13:36 - 2013-10-08 06:58 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shsetup.dll
2014-11-21 13:36 - 2013-10-05 16:25 - 00057176 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2014-11-21 13:36 - 2013-10-05 10:36 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-11-21 13:36 - 2013-10-05 09:55 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\miutils.dll
2014-11-21 13:36 - 2013-10-05 09:24 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\miutils.dll
2014-11-21 13:36 - 2013-09-14 11:05 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2014-11-21 13:36 - 2013-09-14 10:11 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll
2014-11-21 13:36 - 2013-09-13 09:22 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe
2014-11-21 13:36 - 2013-09-13 08:47 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ftp.exe
2014-11-21 13:36 - 2013-09-12 09:45 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2014-11-21 13:36 - 2013-09-12 09:02 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
2014-11-21 13:36 - 2013-09-12 08:37 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
2014-11-21 13:36 - 2013-09-12 08:16 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll
2014-11-21 13:36 - 2013-09-12 08:01 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll
2014-11-21 13:32 - 2013-11-11 03:48 - 00039768 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\intelpep.sys
2014-11-21 13:32 - 2013-11-01 12:39 - 00086872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2014-11-21 13:32 - 2013-10-26 02:54 - 00146776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\SerCx2.sys
2014-11-21 13:22 - 2013-12-31 00:32 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\sti.dll
2014-11-21 13:22 - 2013-12-27 09:57 - 00842752 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll
2014-11-21 13:22 - 2013-12-27 08:03 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll
2014-11-21 13:22 - 2013-12-21 08:21 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2014-11-21 13:22 - 2013-12-17 08:21 - 00408576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2014-11-21 13:21 - 2014-01-04 16:54 - 00138240 _____ () C:\Windows\system32\OEMLicense.dll
2014-11-21 13:21 - 2014-01-04 16:08 - 00103936 _____ () C:\Windows\SysWOW64\OEMLicense.dll
2014-11-21 13:21 - 2013-12-31 00:34 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sti.dll
2014-11-21 12:05 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-21 12:05 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-21 12:05 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-21 11:55 - 2013-12-09 01:19 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-11-21 11:55 - 2013-12-09 00:55 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-11-21 11:55 - 2013-11-23 05:34 - 00393216 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-11-21 11:55 - 2013-11-23 05:13 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-11-21 11:50 - 2014-01-27 20:07 - 04175360 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2014-11-21 11:50 - 2014-01-27 19:23 - 02873344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2014-11-21 11:50 - 2014-01-27 19:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-11-21 11:50 - 2014-01-27 18:18 - 01486848 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2014-11-21 11:50 - 2014-01-27 18:00 - 01238016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2014-11-21 11:50 - 2013-12-21 15:51 - 06353960 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2014-11-21 11:50 - 2013-12-21 09:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll
2014-11-21 11:49 - 2013-10-19 09:53 - 00075360 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-11-21 11:49 - 2013-10-19 08:14 - 00070680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-11-21 11:42 - 2014-02-22 13:16 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-11-21 11:42 - 2014-02-22 12:24 - 00124416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-11-21 11:41 - 2013-11-21 07:42 - 04604416 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-11-21 11:41 - 2013-11-21 06:44 - 03936256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-11-20 22:17 - 2013-11-27 12:41 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\WSCollect.exe
2014-11-20 22:11 - 2013-10-16 16:58 - 01943536 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-11-20 22:11 - 2013-10-16 14:54 - 01581968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-11-20 22:10 - 2014-01-07 08:03 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe
2014-11-20 22:10 - 2014-01-07 06:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe
2014-11-20 21:51 - 2014-11-23 11:18 - 00000797 _____ () C:\Windows\setupact.log
2014-11-19 20:46 - 2014-12-02 12:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-19 19:04 - 2014-11-19 19:04 - 00000000 ____D () C:\Users\Bo\Documents\My Games
2014-11-19 19:03 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2014-11-19 19:03 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2014-11-19 19:03 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2014-11-19 19:03 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2014-11-19 19:03 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2014-11-19 19:03 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2014-11-19 19:03 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2014-11-19 19:03 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2014-11-19 19:03 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2014-11-19 19:03 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2014-11-19 19:03 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2014-11-19 19:03 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2014-11-19 19:03 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2014-11-19 19:03 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2014-11-19 19:03 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2014-11-19 19:03 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2014-11-19 19:03 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2014-11-19 19:03 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2014-11-19 19:03 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2014-11-19 19:03 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2014-11-19 19:03 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2014-11-19 19:03 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2014-11-19 19:03 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2014-11-19 19:03 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2014-11-19 19:03 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2014-11-19 19:03 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2014-11-19 19:03 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2014-11-19 19:03 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2014-11-19 19:03 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2014-11-19 19:03 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2014-11-19 19:03 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2014-11-19 19:03 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2014-11-19 19:03 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2014-11-19 19:03 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2014-11-19 19:03 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2014-11-19 19:03 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2014-11-19 19:03 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2014-11-19 19:03 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2014-11-19 19:03 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2014-11-19 19:03 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2014-11-19 19:03 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2014-11-19 19:03 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2014-11-19 19:03 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2014-11-19 19:03 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2014-11-19 19:03 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2014-11-19 19:03 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2014-11-19 19:03 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2014-11-19 19:03 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2014-11-19 19:03 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2014-11-19 19:03 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2014-11-19 19:03 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2014-11-19 19:03 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2014-11-19 19:03 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2014-11-19 19:03 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2014-11-19 19:03 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2014-11-19 19:03 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2014-11-19 19:03 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2014-11-19 19:03 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2014-11-19 19:03 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2014-11-19 19:03 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2014-11-19 19:03 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2014-11-19 19:03 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2014-11-19 19:03 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2014-11-19 19:03 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2014-11-19 19:03 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2014-11-19 19:03 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2014-11-19 19:03 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2014-11-19 19:03 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2014-11-19 19:03 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2014-11-19 19:03 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2014-11-19 19:03 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2014-11-19 19:03 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2014-11-19 19:03 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2014-11-19 19:03 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2014-11-19 19:03 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2014-11-19 19:03 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2014-11-19 19:03 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2014-11-19 19:03 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2014-11-19 19:03 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2014-11-19 19:03 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2014-11-19 19:03 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2014-11-19 19:03 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2014-11-19 19:03 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2014-11-19 19:03 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2014-11-19 19:03 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2014-11-19 19:03 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2014-11-19 19:03 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2014-11-19 19:03 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2014-11-19 19:03 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2014-11-19 19:03 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2014-11-19 19:03 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2014-11-19 19:03 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2014-11-19 19:03 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2014-11-19 19:03 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2014-11-19 19:03 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2014-11-19 19:03 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2014-11-19 19:03 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2014-11-19 19:03 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2014-11-19 19:03 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2014-11-19 19:03 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2014-11-19 19:03 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2014-11-19 19:03 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2014-11-19 19:03 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2014-11-19 19:03 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2014-11-19 19:03 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2014-11-19 19:03 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2014-11-19 19:03 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2014-11-19 19:03 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2014-11-19 19:03 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2014-11-19 19:03 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2014-11-19 19:03 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2014-11-19 19:03 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2014-11-19 19:03 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2014-11-19 19:03 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2014-11-19 19:03 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2014-11-19 19:03 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2014-11-19 19:03 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2014-11-19 19:03 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2014-11-19 19:03 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2014-11-19 19:03 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2014-11-19 19:02 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2014-11-19 19:02 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2014-11-19 19:02 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2014-11-19 19:02 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2014-11-19 19:02 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2014-11-19 19:02 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2014-11-19 19:02 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2014-11-19 19:02 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2014-11-19 19:02 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2014-11-19 19:02 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2014-11-19 19:02 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2014-11-19 19:02 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2014-11-19 19:02 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2014-11-19 19:02 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2014-11-19 19:02 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2014-11-19 19:02 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2014-11-19 19:02 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2014-11-19 19:02 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2014-11-19 19:02 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2014-11-19 19:02 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2014-11-19 19:02 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2014-11-19 19:02 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2014-11-19 19:02 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2014-11-19 19:02 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2014-11-19 19:02 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2014-11-19 19:02 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2014-11-19 19:02 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2014-11-19 19:02 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2014-11-19 19:02 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2014-11-19 19:02 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2014-11-19 19:02 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2014-11-19 19:02 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2014-11-19 19:02 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2014-11-19 19:02 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2014-11-19 19:02 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2014-11-19 19:02 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2014-11-19 19:02 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2014-11-19 19:02 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2014-11-19 19:02 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2014-11-19 19:02 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2014-11-19 18:07 - 2014-11-19 18:07 - 00000000 ____D () C:\Users\Public\Documents\sun
2014-11-19 18:05 - 2014-11-19 18:05 - 00001208 _____ () C:\Users\Bo\Desktop\OpenOffice 4.1.1.lnk
2014-11-19 18:05 - 2014-11-19 18:05 - 00000000 ___SD () C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-11-19 18:04 - 2014-11-25 13:28 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-11-19 18:03 - 2014-11-19 18:03 - 00000000 ____D () C:\Users\Bo\Desktop\OpenOffice 4.1.1 (de) Installation Files
2014-11-19 17:36 - 2014-11-19 18:00 - 164858324 _____ () C:\Users\Bo\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de(2).exe
2014-11-19 17:03 - 2014-11-19 17:18 - 96900332 _____ () C:\Users\Bo\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de(1).exe
2014-11-19 16:19 - 2014-11-19 16:49 - 131533496 _____ () C:\Users\Bo\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de.exe
2014-11-19 15:32 - 2014-11-19 15:32 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-11-19 14:59 - 2014-11-19 14:59 - 00000222 _____ () C:\Users\Bo\Desktop\resident evil 4  biohazard 4.url
2014-11-19 13:57 - 2014-12-04 16:33 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-11-19 13:57 - 2014-11-19 13:57 - 00000940 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-11-19 13:57 - 2014-11-19 13:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-11-19 08:55 - 2014-12-03 13:55 - 00000162 _____ () C:\Users\Bo\AppData\Roaming\WB.CFG
2014-11-19 08:52 - 2014-11-19 08:52 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\OpenOffice
2014-11-19 08:47 - 2014-11-19 08:47 - 134845821 _____ () C:\Users\Bo\Downloads\install-openoffice [1].exe
2014-11-19 08:18 - 2014-11-19 08:18 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\QuickScan
2014-11-19 02:36 - 2014-11-19 02:36 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\AVG2015
2014-11-19 02:34 - 2014-11-19 02:37 - 00000000 ____D () C:\ProgramData\AVG2015
2014-11-19 02:34 - 2014-11-19 02:34 - 00001008 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2014-11-19 02:34 - 2014-11-19 02:34 - 00000000 ___HD () C:\$AVG
2014-11-19 02:34 - 2014-11-19 02:34 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\TuneUp Software
2014-11-19 02:34 - 2014-11-19 02:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-11-19 02:33 - 2014-11-19 02:33 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-11-19 02:21 - 2014-11-19 02:44 - 00000000 ____D () C:\Users\Bo\AppData\Local\Avg2015
2014-11-19 02:19 - 2014-12-04 15:58 - 00000000 ____D () C:\ProgramData\MFAData
2014-11-19 02:19 - 2014-11-19 02:19 - 00000000 ____D () C:\Users\Bo\AppData\Local\MFAData
2014-11-19 02:19 - 2014-11-19 02:19 - 00000000 ____D () C:\Users\Bo\AppData\Local\Avg2014
2014-11-19 01:57 - 2014-11-19 01:57 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Windows Essentials Codec Pack
2014-11-19 01:57 - 2014-11-19 01:57 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Essentials Codec Pack
2014-11-19 01:57 - 2014-11-19 01:57 - 00000000 ____D () C:\Program Files (x86)\Windows Essentials Codec Pack
2014-11-19 01:39 - 2014-11-19 01:39 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-11-19 01:39 - 2014-11-19 01:39 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-11-19 01:39 - 2014-11-19 01:39 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-11-19 01:39 - 2014-11-19 01:39 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-11-19 01:39 - 2014-11-19 01:39 - 00000000 ____D () C:\ProgramData\Sun
2014-11-19 01:39 - 2014-11-19 01:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-11-19 01:39 - 2014-11-19 01:39 - 00000000 ____D () C:\Program Files (x86)\Java
2014-11-19 01:26 - 2014-12-04 19:49 - 00000000 ___RD () C:\Users\Bo\Dropbox
2014-11-19 01:26 - 2014-11-19 01:26 - 00001096 _____ () C:\Users\Bo\Desktop\Dropbox.lnk
2014-11-19 01:25 - 2014-11-19 01:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-11-19 01:24 - 2014-11-19 01:24 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-11-19 01:24 - 2014-11-19 01:24 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-11-19 01:20 - 2014-11-19 01:20 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\EurekaLab s.a.s
2014-11-19 01:19 - 2014-11-19 08:14 - 00000000 ____D () C:\ProgramData\HitAyShKX
2014-11-19 01:19 - 2014-11-19 01:19 - 00000000 ____D () C:\Users\Bo\AppData\Local\Macromedia
2014-11-19 01:16 - 2014-11-19 01:19 - 00000000 ____D () C:\Users\Bo\AppData\Local\PCP_100_v3
2014-11-19 01:13 - 2014-11-19 03:06 - 00000000 ____D () C:\ProgramData\SmartOnes
2014-11-19 01:13 - 2014-11-19 03:05 - 00000000 ____D () C:\Program Files (x86)\SmartOnes
2014-11-19 01:11 - 2014-11-19 01:11 - 00002222 _____ () C:\Windows\patsearch.bin
2014-11-19 01:11 - 2014-11-19 01:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrT_01009.Wdf
2014-11-19 01:10 - 2014-12-03 20:00 - 00000000 ____D () C:\Program Files\shopperz
2014-11-19 01:08 - 2014-11-19 01:19 - 00000000 ____D () C:\Users\Bo\AppData\Local\Adobe
2014-11-19 01:05 - 2014-12-04 19:49 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Dropbox
2014-11-19 01:03 - 2014-11-19 01:03 - 00003132 _____ () C:\Windows\System32\Tasks\{3BF8DB46-B092-4E5F-B9A9-FB0E9FADB432}
2014-11-19 00:38 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2014-11-19 00:08 - 2014-11-19 03:00 - 00000000 ____D () C:\ProgramData\ddc24aa9-6c5d-44d0-8c40-9bed83bb2ab7
2014-11-18 23:43 - 2014-11-18 23:43 - 00323712 _____ (Dropbox, Inc.) C:\Users\Bo\Downloads\DropboxInstaller.exe
2014-11-18 23:36 - 2014-11-18 23:37 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Mozilla
2014-11-18 23:36 - 2014-11-18 23:37 - 00000000 ____D () C:\Users\Bo\AppData\Local\Mozilla
2014-11-18 23:35 - 2014-11-18 23:35 - 00000000 ____D () C:\ProgramData\Mozilla
2014-11-18 23:31 - 2014-11-18 23:31 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z
2014-11-18 23:28 - 2014-11-18 23:28 - 24656704 _____ (Mozilla) C:\Users\Bo\Downloads\FirefoxSetup [1].exe
2014-11-18 23:27 - 2014-11-18 23:27 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\dlg
2014-11-18 22:41 - 2014-11-18 22:41 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Windows Open Service
2014-11-18 22:18 - 2014-11-18 22:18 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\sMedio
2014-11-18 21:42 - 2014-11-18 21:42 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-11-18 21:36 - 2014-11-18 23:15 - 00000000 ____D () C:\Program Files (x86)\Google
2014-11-18 21:36 - 2014-11-18 21:40 - 00000000 ____D () C:\Users\Bo\AppData\Local\Google
2014-11-18 21:36 - 2014-11-18 21:36 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Macromedia
2014-11-18 19:25 - 2014-12-04 15:11 - 00003910 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{324C78EB-98DC-434C-A392-621E04E250A9}
2014-11-18 19:20 - 2014-12-04 19:36 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Spotify
2014-11-18 19:20 - 2014-12-04 15:07 - 00000000 ____D () C:\Users\Bo\AppData\Local\Spotify
2014-11-18 19:19 - 2014-11-24 05:21 - 00000000 ___RD () C:\Users\Bo\SkyDrive
2014-11-18 19:18 - 2014-11-18 19:18 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\ATI
2014-11-18 19:18 - 2014-11-18 19:18 - 00000000 ____D () C:\Users\Bo\AppData\Local\ATI
2014-11-18 19:17 - 2014-11-18 19:17 - 00000000 ____D () C:\ProgramData\ToshibaEurope
2014-11-18 19:16 - 2014-12-03 20:23 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2163812055-3742141728-2804637470-1001
2014-11-18 19:13 - 2014-11-19 00:45 - 00000000 ____D () C:\Users\Bo\AppData\Local\TOSHIBA
2014-11-18 19:13 - 2014-11-18 19:13 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-18 19:10 - 2014-12-02 12:49 - 00001465 _____ () C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-18 19:10 - 2014-11-26 07:14 - 00000000 ____D () C:\Users\Bo\AppData\Local\Packages
2014-11-18 19:10 - 2014-11-18 19:10 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Adobe
2014-11-18 19:10 - 2014-11-18 19:10 - 00000000 ____D () C:\Users\Bo\AppData\Local\VirtualStore
2014-11-18 19:07 - 2014-11-26 07:14 - 00000000 ____D () C:\Users\Bo
2014-11-18 19:07 - 2014-11-18 19:07 - 00000020 ___SH () C:\Users\Bo\ntuser.ini
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\Vorlagen
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\Startmenü
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\Netzwerkumgebung
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\Lokale Einstellungen
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\Eigene Dateien
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\Druckumgebung
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\Documents\Eigene Musik
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\Documents\Eigene Bilder
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\AppData\Local\Verlauf
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\AppData\Local\Anwendungsdaten
2014-11-18 19:07 - 2014-11-18 19:07 - 00000000 _SHDL () C:\Users\Bo\Anwendungsdaten
2014-11-18 19:07 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-18 19:07 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-18 19:07 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-11-18 19:07 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\Bo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-04 20:04 - 2014-01-18 15:07 - 01710676 _____ () C:\Windows\WindowsUpdate.log
2014-12-04 20:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2014-12-04 19:48 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-04 19:47 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-12-03 22:12 - 2014-01-18 15:08 - 00065536 _____ () C:\Windows\system32\spu_storage.bin
2014-12-03 13:45 - 2013-11-27 18:01 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-03 13:45 - 2013-08-28 10:59 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2014-12-03 13:45 - 2013-08-28 10:59 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2014-12-03 13:39 - 2013-08-22 15:44 - 00362896 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-03 13:22 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-12-02 17:29 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-02 12:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-11-28 09:31 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2014-11-28 09:13 - 2013-08-22 16:36 - 00000000 ___RD () C:\Windows\ToastData
2014-11-28 09:13 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-11-28 09:13 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-11-28 09:12 - 2013-08-22 20:11 - 00000000 ____D () C:\Program Files\Windows Journal
2014-11-28 09:12 - 2013-08-22 16:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2014-11-28 09:12 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\SysWOW64\setup
2014-11-28 09:12 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\SysWOW64\InputMethod
2014-11-28 09:12 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\setup
2014-11-28 09:12 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\system32\oobe
2014-11-27 18:14 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-11-26 21:54 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-26 21:54 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-26 21:54 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-11-26 21:54 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-11-26 21:53 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\WinStore
2014-11-26 21:53 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-11-26 21:53 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\MediaViewer
2014-11-26 21:53 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\FileManager
2014-11-26 21:53 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Camera
2014-11-25 23:04 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-25 23:04 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-11-25 23:04 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2014-11-25 23:04 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2014-11-25 23:04 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Multimedia Platform
2014-11-25 23:04 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\servicing
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\uk-UA
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\th-TH
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\SystemResetPlatform
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sl-SI
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sk-SK
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\ro-RO
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\migwiz
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\lv-LV
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\lt-LT
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\hr-HR
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\he-IL
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\et-EE
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\en-GB
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\bg-BG
2014-11-25 23:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\ar-SA
2014-11-25 23:03 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\SysWOW64\oobe
2014-11-25 23:03 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-11-25 23:03 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\system32\Sysprep
2014-11-25 23:03 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\system32\Dism
2014-11-24 07:15 - 2013-08-28 10:58 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2014-11-24 07:15 - 2013-08-22 20:09 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2014-11-24 07:15 - 2013-08-22 20:09 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2014-11-24 07:15 - 2013-08-22 20:09 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2014-11-24 07:15 - 2013-08-22 20:09 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2014-11-24 07:15 - 2013-08-22 20:09 - 00000000 ____D () C:\Windows\system32\winrm
2014-11-24 07:15 - 2013-08-22 20:09 - 00000000 ____D () C:\Windows\system32\WCN
2014-11-24 07:15 - 2013-08-22 20:09 - 00000000 ____D () C:\Windows\system32\slmgr
2014-11-24 07:15 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2014-11-24 07:15 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\SysWOW64\Com
2014-11-24 07:15 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\MUI
2014-11-24 07:15 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\IME
2014-11-24 07:15 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-11-24 07:15 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\System
2014-11-24 07:15 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2014-11-24 07:14 - 2013-08-22 20:09 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2014-11-24 07:14 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\Com
2014-11-24 07:14 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Help
2014-11-24 07:13 - 2013-08-22 16:36 - 00000000 ___SD () C:\Windows\system32\dsc
2014-11-23 14:33 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-11-23 14:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-11-19 02:34 - 2013-08-22 16:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-11-19 01:22 - 2013-08-22 14:25 - 00000289 _____ () C:\Windows\win.ini
2014-11-19 00:44 - 2014-01-18 15:35 - 00000000 ____D () C:\ProgramData\McAfee
2014-11-18 22:32 - 2014-01-18 15:55 - 00000000 ____D () C:\Users\Public\TOSHIBA
2014-11-18 22:16 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\restore
2014-11-18 21:36 - 2014-01-18 15:08 - 00000000 ____D () C:\ProgramData\AMD
2014-11-18 19:14 - 2014-01-18 15:26 - 00000000 ____D () C:\Windows\System32\Tasks\TOSHIBA
2014-11-18 19:14 - 2013-11-27 18:02 - 00000000 ____D () C:\ProgramData\Toshiba
2014-11-18 19:09 - 2013-08-22 20:09 - 00000000 ____D () C:\Windows\SysWOW64\sysprep

Some content of TEMP:
====================
C:\Users\Bo\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqgsxu5.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-28 14:05

==================== End Of Log ============================
         


Alt 04.12.2014, 20:30   #21
Krazerack
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-12-2014
Ran by Bo at 2014-12-04 20:11:37
Running from C:\Users\Bo\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 4.8.1245.73583 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 4.8.1245.73583 - Alcor Micro Corp.) Hidden
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.100.303.509 - Alps Electric)
Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon)
AMD Catalyst Install Manager (HKLM\...\{5D42947B-E961-C0B5-5A70-EA0F753331EB}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.4.2 - AppEx Networks)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Atheros)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5577 - AVG Technologies)
AVG 2015 (Version: 15.0.4235 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5577 - AVG Technologies) Hidden
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Dropbox (HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\Dropbox) (Version: 2.10.52 - Dropbox, Inc.)
DTS Sound (HKLM-x32\...\{2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}) (Version: 1.01.2700 - DTS, Inc.)
Empress of the Deep - The Darkest Secret (x32 Version: 2.2.0.98 - WildTangent) Hidden
Firefox Packages (HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\Firefox Packages) (Version:  - ) <==== ATTENTION
IDT Audio Driver (HKLM\...\{588A747E-CFF6-46B3-9207-CD754F9473AF}) (Version: 6.10.6491.0 - IDT)
Island Tribe (x32 Version: 2.2.0.98 - WildTangent) Hidden
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6CE5BAE9-D3CA-4B99-891A-1DC6C118A5FC}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{d07b0db5-8dad-40e1-be90-88026298a46b}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{2749c485-3a8b-4533-92ff-7cf6e8221cff}) (Version: 11.0.61030.0 - Microsoft Corporation)
OEM Application Profile (HKLM-x32\...\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.306 - Qualcomm Atheros)
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.)
resident evil 4 / biohazard 4 (HKLM-x32\...\Steam App 254700) (Version:  - Capcom)
Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.106 - Skype Technologies S.A.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
TOSHIBA Addendum (HKLM-x32\...\{C1569944-FAD6-4B3B-85E5-C213C2FF8EFC}) (Version: 1.00 - TOSHIBA)
TOSHIBA Desktop Assist (HKLM\...\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.02.01.6407 - Toshiba Corporation)
TOSHIBA Display Utility (HKLM\...\{5F6AC07E-50EF-422E-B56E-6521E5B35139}) (Version: 1.1.12.0 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\...\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.2.0.6404 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\...\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.1.0001.6403 - Toshiba Corporation)
TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.10 - TOSHIBA)
TOSHIBA Password Utility (HKLM-x32\...\InstallShield_{78931270-BC9E-441A-A52B-73ECD4ACFAB5}) (Version: 3.00.346 - Toshiba Corporation)
TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.9.09.6400 - Toshiba Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.1.02.55065006 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation)
TOSHIBA Start Screen Option (HKLM\...\{06B71035-F19F-4F76-9875-FFCCD4FC3F83}) (Version: 1.00.00.6403 - Toshiba Corporation)
TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0030 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\...\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.1.2.32001 - Toshiba Corporation)
Toshiba TEMPRO (HKLM-x32\...\{F76F5214-83A8-4030-80C9-1EF57391D72A}) (Version: 4.5.0 - Toshiba Europe GmbH)
TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.3.27.102 - Toshiba Corporation)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.9.7 - WildTangent) Hidden
Windows Essentials Codec Pack 5.0 (HKLM-x32\...\Windows Essentials Codec Pack) (Version: 5.0 - Windows Essentials Codec Pack)
WinZip Malware Protector (HKLM-x32\...\WinZip Malware Protector_is1) (Version: 2.1.1000.14260 - WinZip International LLC)
Yahoo Community Smartbar (HKLM-x32\...\{C9AC6061-68A8-475E-B75E-E59C35AF0972}) (Version: 11.123.66.20439 - Linkury Inc.) <==== ATTENTION
Yahoo Community Smartbar Engine (HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\{baae938f-c7b1-4489-bd91-c9d5edc349ec}) (Version: 11.123.66.20439 - Linkury Inc.) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2163812055-3742141728-2804637470-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Bo\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================

23-11-2014 09:54:46 Microsoft Visual C++ 2005 Redistributable (x64) wird installiert
25-11-2014 12:21:56 OpenOffice 4.1.1 wird installiert
02-12-2014 18:18:44 Geplanter Prüfpunkt

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2014-12-04 19:42 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {28D9AC66-8206-466F-9D2A-917560316EEE} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-10-31] (Microsoft Corporation)
Task: {3F5085EE-497E-45EB-AC3E-4E737F7BB3E5} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation)
Task: {F0CAFEF7-B749-4E9B-9F1D-F64E2AE096AA} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-07-19] (Toshiba Europe GmbH)

==================== Loaded Modules (whitelisted) =============

2013-03-27 21:53 - 2013-03-27 21:53 - 00163168 _____ () C:\Program Files (x86)\TOSHIBA\PasswordUtility\GFNEXSrv.exe
2013-08-31 04:47 - 2013-08-31 04:47 - 00099328 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
2013-09-10 21:54 - 2013-09-10 21:54 - 00019792 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2014-11-18 22:41 - 2014-11-18 08:02 - 00626688 _____ () C:\Users\Bo\AppData\Roaming\Windows Open Service\OpenService.exe
2013-08-31 04:47 - 2013-08-31 04:47 - 00016896 _____ () C:\Program Files\ATI Technologies\ATI.ACE\a4\AS4.NativeProxy.dll
2013-08-22 08:19 - 2013-08-22 07:54 - 00050176 _____ () C:\Windows\system32\WinMetadata\Windows.Data.winmd
2013-08-22 08:19 - 2013-08-22 07:54 - 00174592 _____ () C:\Windows\system32\WinMetadata\Windows.UI.winmd
2014-12-03 21:37 - 2014-12-03 21:37 - 00363520 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\6382e6f5ad8b7a9db4f5cd4817e70319\Windows.Foundation.ni.dll
2014-11-18 22:41 - 2014-11-18 22:41 - 00374272 _____ () C:\Users\Bo\AppData\Roaming\Windows Open Service\sub\default.dll
2014-12-04 19:49 - 2014-12-04 19:49 - 00043008 _____ () c:\users\bo\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqgsxu5.dll
2014-11-19 01:24 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Bo\AppData\Roaming\Dropbox\bin\libcef.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Bo\OneDrive:ms-properties
AlternateDataStreams: C:\Users\Bo\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "TecoResident"
HKLM\...\StartupApproved\Run: => "TCrdMain"
HKLM\...\StartupApproved\Run: => "TSSSrv"
HKLM\...\StartupApproved\Run: => "TosWaitSrv"
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2163812055-3742141728-2804637470-1001\...\StartupApproved\Run: => "Steam"

========================= Accounts: ==========================

Administrator (S-1-5-21-2163812055-3742141728-2804637470-500 - Administrator - Disabled)
Bo (S-1-5-21-2163812055-3742141728-2804637470-1001 - Administrator - Enabled) => C:\Users\Bo
Gast (S-1-5-21-2163812055-3742141728-2804637470-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2163812055-3742141728-2804637470-1003 - Limited - Enabled)

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/04/2014 03:49:28 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (12/03/2014 07:53:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Spotify.exe, Version 0.9.14.13 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: ed8

Startzeit: 01d00ef664b6ed6e

Endzeit: 4294967295

Anwendungspfad: C:\Users\Bo\AppData\Roaming\Spotify\Spotify.exe

Berichts-ID: b19d56fc-7b1d-11e4-8269-28e34703191e

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (12/03/2014 06:17:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17416, Zeitstempel: 0x5452fe91
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17278, Zeitstempel: 0x53eebd22
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000095358
ID des fehlerhaften Prozesses: 0x2070
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Vollständiger Name des fehlerhaften Pakets: iexplore.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: iexplore.exe5

Error: (12/03/2014 05:45:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17416, Zeitstempel: 0x5452fe91
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17278, Zeitstempel: 0x53eebd22
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000f0d6c
ID des fehlerhaften Prozesses: 0x1308
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Vollständiger Name des fehlerhaften Pakets: iexplore.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: iexplore.exe5

Error: (12/03/2014 01:41:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.8428, Zeitstempel: 0x520b1060
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0xd28
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5

Error: (12/03/2014 01:35:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.8428, Zeitstempel: 0x520b1060
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x2bfc
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5

Error: (12/03/2014 01:35:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.8428, Zeitstempel: 0x520b1060
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x21d8
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5

Error: (12/03/2014 01:34:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.8428, Zeitstempel: 0x520b1060
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x2848
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5

Error: (12/03/2014 01:22:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm LiveComm.exe, Version 17.5.9600.20689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: f28

Startzeit: 01d00ef31c8a6329

Endzeit: 4294967295

Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe

Berichts-ID: 141dc0ed-7ae7-11e4-8268-28e34703191e

Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe

Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1

Error: (12/03/2014 01:18:42 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MEINER)
Description: Bei der Aktivierung der App „Microsoft.BingSports_8wekyb3d8bbwe!AppexSports“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.


System errors:
=============
Error: (12/04/2014 07:50:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee VirusScan Announcer" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (12/04/2014 07:48:10 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "McAfee Anti-Malware Core" ist von folgendem Dienst abhängig: mfevtp. Dieser Dienst ist möglicherweise nicht installiert.

Error: (12/04/2014 07:48:10 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "McAfee AP Service" ist von folgendem Dienst abhängig: mfevtp. Dieser Dienst ist möglicherweise nicht installiert.

Error: (12/04/2014 07:47:31 PM) (Source: Microsoft-Windows-HAL) (EventID: 13) (User: NT-AUTORITÄT)
Description: Der Systemüberwachungszeitgeber wurde ausgelöst.

Error: (12/04/2014 07:40:58 PM) (Source: DCOM) (EventID: 10010) (User: MEINER)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

Error: (12/04/2014 07:40:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (12/04/2014 07:40:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "TOSHIBA eco Utility Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (12/04/2014 07:40:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/04/2014 07:40:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "TEMPRO Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (12/04/2014 07:40:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


Microsoft Office Sessions:
=========================
Error: (12/04/2014 03:49:28 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (12/03/2014 07:53:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Spotify.exe0.9.14.13ed801d00ef664b6ed6e4294967295C:\Users\Bo\AppData\Roaming\Spotify\Spotify.exeb19d56fc-7b1d-11e4-8269-28e34703191e

Error: (12/03/2014 06:17:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174165452fe91ntdll.dll6.3.9600.1727853eebd22c00000050000000000095358207001d00f1cfa039a9aC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\SYSTEM32\ntdll.dll41bea704-7b10-11e4-8269-28e34703191e

Error: (12/03/2014 05:45:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174165452fe91ntdll.dll6.3.9600.1727853eebd22c000037400000000000f0d6c130801d00f1873a91665C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\SYSTEM32\ntdll.dllc38fa968-7b0b-11e4-8269-28e34703191e

Error: (12/03/2014 01:41:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.8428520b1060c000000500012f4bd2801d00ef6632f72ebC:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\MSVCR80.dlla20c7676-7ae9-11e4-8269-28e34703191e

Error: (12/03/2014 01:35:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.8428520b1060c000000500012f4b2bfc01d00ef5a95e0ac9C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\MSVCR80.dlle73c1639-7ae8-11e4-8268-28e34703191e

Error: (12/03/2014 01:35:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.8428520b1060c000000500012f4b21d801d00ef595425cb6C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\MSVCR80.dlld3340cea-7ae8-11e4-8268-28e34703191e

Error: (12/03/2014 01:34:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.8428520b1060c000000500012f4b284801d00ef58a6c5aa9C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\MSVCR80.dllc8dab2b5-7ae8-11e4-8268-28e34703191e

Error: (12/03/2014 01:22:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.20689f2801d00ef31c8a63294294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe141dc0ed-7ae7-11e4-8268-28e34703191emicrosoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (12/03/2014 01:18:42 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MEINER)
Description: Microsoft.BingSports_8wekyb3d8bbwe!AppexSports-2144927142


==================== Memory info =========================== 

Processor: AMD A4-5000 APU with Radeon(TM) HD Graphics 
Percentage of memory in use: 38%
Total physical RAM: 3523.07 MB
Available physical RAM: 2178.76 MB
Total Pagefile: 6211.07 MB
Available Pagefile: 4238.02 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB

==================== Drives ================================

Drive c: (TI31251100A) (Fixed) (Total:687.54 GB) (Free:630.83 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End Of Log ============================
         

Auch wenn ich nicht weis was du jetzt gemacht hasat D
danke nochmal
echt grooooooßes Danke

Alt 05.12.2014, 19:42   #22
M-K-D-B
/// TB-Ausbilder
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Servus,


naja, ich entferne lästige Adware für dich.




Wir entfernen die letzten Reste und kontrollieren nochmal alles. EEK und ESET können länger (> 2 h) dauern.
Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg.




Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:
ATTFilter
start
CloseProcesses:
C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z
DeleteKey: HKEY_CURRENT_USER\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}
DeleteKey: HKEY_CURRENT_USER\Software\Classes\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40064F2B-BE74-40c0-B30F-1AF103872638}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\shopperz
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\shopperz
DeleteKey: HKEY_USERS\.DEFAULT\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{52b6decd-b602-42e8-a034-d1c5010cfcce}
DeleteKey: HKEY_CURRENT_USER\Software\Nico Mak Computing
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{baae938f-c7b1-4489-bd91-c9d5edc349ec}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C9AC6061-68A8-475E-B75E-E59C35AF0972}
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost" /v ORBTR /f
EmptyTemp:
end
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.







Schritt 2

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset






Schritt 3
Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei des FRST-Fix,
  • die Logdatei von ESET,
  • die Logdatei von SecurityCheck.

Alt 05.12.2014, 20:13   #23
Krazerack
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Hey
danke danke danke

habe allerdings ein Problem, ich weiß leider nicht wie ich nicht wie man die AVG Antivirus Software deaktiviert .. könntest du mir da vllt sagen wie das geht?
bzw. weiß ich eh nicht ob der so gut ist .. soll ich den vllt einfach löschen? und mir dann danach einen vernünftigen runterladen .. hab leider keine Ahnung welche da gut und welche weniger gut sind?

ausserdem wollte ich wissen warum ich eine externe Festplatte anschließen soll.. ich besitze zwar eine, die ist aber rand voll und war auch noch nicht an diesem Rechner dran.
deswegen weis ich nicht ob es sich lohnt bzw ob es gut ist, die anzuschließen.


Danke Nochmals

Alt 06.12.2014, 10:12   #24
M-K-D-B
/// TB-Ausbilder
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Zitat:
Zitat von Krazerack Beitrag anzeigen
habe allerdings ein Problem, ich weiß leider nicht wie ich nicht wie man die AVG Antivirus Software deaktiviert .. könntest du mir da vllt sagen wie das geht?
In der Taskleite rechts unten sollte sich ein Symbol für AVG befinden, klicke darauf > dann kannst du normalerweise den Echtzeitschutz deaktiveren.



Zitat:
Zitat von Krazerack Beitrag anzeigen
bzw. weiß ich eh nicht ob der so gut ist .. soll ich den vllt einfach löschen? und mir dann danach einen vernünftigen runterladen .. hab leider keine Ahnung welche da gut und welche weniger gut sind?
Ich halte nicht so viel von AVG, weil es mir in der Vergangenheit bei einigen Usern zu viele Fehlalarme produziert hat. Das kannst du dir ja immer noch am Ende der Bereinigung überlegen.



Zitat:
Zitat von Krazerack Beitrag anzeigen
ausserdem wollte ich wissen warum ich eine externe Festplatte anschließen soll.. ich besitze zwar eine, die ist aber rand voll und war auch noch nicht an diesem Rechner dran.
deswegen weis ich nicht ob es sich lohnt bzw ob es gut ist, die anzuschließen.
Manche Schadsoftware verteilt sich über externe Medien, sobald diese angeschlossen werden. Wenn die externe Festplatte nicht am Rechner war, musst du sie auch nicht anschließen.

Alt 06.12.2014, 13:30   #25
Krazerack
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2014
Ran by Bo at 2014-12-05 19:50:15 Run:2
Running from C:\Users\Bo\Desktop
Loaded Profile: Bo (Available profiles: Bo)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z
DeleteKey: HKEY_CURRENT_USER\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}
DeleteKey: HKEY_CURRENT_USER\Software\Classes\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40064F2B-BE74-40c0-B30F-1AF103872638}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\shopperz
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\shopperz
DeleteKey: HKEY_USERS\.DEFAULT\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{52b6decd-b602-42e8-a034-d1c5010cfcce}
DeleteKey: HKEY_CURRENT_USER\Software\Nico Mak Computing
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{baae938f-c7b1-4489-bd91-c9d5edc349ec}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C9AC6061-68A8-475E-B75E-E59C35AF0972}
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost" /v ORBTR /f
EmptyTemp:
end
         
*****************

Processes closed successfully.
C:\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z => Moved successfully.
HKEY_CURRENT_USER\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911} => Key Deleted successfully.
HKEY_CURRENT_USER\Software\Classes\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911} => Key Deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79} => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79} => Key Deleted Successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40064F2B-BE74-40c0-B30F-1AF103872638} => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40064F2B-BE74-40c0-B30F-1AF103872638} => Key Deleted Successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{DD50911B-2767-4061-9B55-EF5F0AAB5A79} => Key not found.
HKEY_LOCAL_MACHINE\SOFTWARE\shopperz => Key Deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\shopperz => Key Deleted successfully.
HKEY_USERS\.DEFAULT\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911} => Key Deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{52b6decd-b602-42e8-a034-d1c5010cfcce} => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{52b6decd-b602-42e8-a034-d1c5010cfcce} => Key Deleted Successfully.
HKEY_CURRENT_USER\Software\Nico Mak Computing => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_CURRENT_USER\Software\Nico Mak Computing => Key Deleted Successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1 => Key Deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing => Key Deleted Successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931} => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931} => Key Deleted Successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{baae938f-c7b1-4489-bd91-c9d5edc349ec} => Key Deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C9AC6061-68A8-475E-B75E-E59C35AF0972} => Key Deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Firefox Packages => Key Deleted successfully.

========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost" /v ORBTR /f =========

Der Vorgang wurde erfolgreich beendet.



========= End of Reg: =========

EmptyTemp: => Removed 204.6 MB temporary data.


The system needed a reboot. 

==== End of Fixlog ====
         

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=e3292159b4c77644a3e819a1c60f172a
# engine=21410
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-12-06 12:15:13
# local_time=2014-12-06 01:15:13 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT 
# compatibility_mode_1='AVG AntiVirus Free Edition 2015'
# compatibility_mode=1055 16777213 100 100 92640 105002097 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 832852 42749406 0 0
# scanned=188381
# found=33
# cleaned=0
# scan_time=9336
sh=8C2439E8D9A3BBE3A1790C01CD9E212AFF790035 ft=1 fh=c907a1331702b73d vn="Variante von Win32/Toolbar.BitCocktail.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bjvkh.dll.vir"
sh=D11010E4EED9D0324F0E72B546D3AD80F1517B8E ft=1 fh=f12251822dd89e48 vn="Variante von Win64/Toolbar.Perion.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bjvkh64.dll.vir"
sh=A5D0D9FB2D04555945246A51EC3A7E58D96E23D2 ft=1 fh=8f98caf3bbf8c057 vn="Win32/Toolbar.BitCocktail.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\blnj32.dll.vir"
sh=58DC437A09A5F656052D295D548BF6825130B048 ft=1 fh=4db2d3ad4566f2f2 vn="Win64/Toolbar.Perion.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\blnj64.dll.vir"
sh=F4C9980BF1CD209E6F6E6A32E9BAF7C309D68F96 ft=1 fh=430038d1149beb5a vn="Variante von Win32/Toolbar.Perion.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bntf.exe.vir"
sh=7B7FEDE270EAE0E5B9719F9417A5D0D84A7F7EA4 ft=1 fh=64f6a8a64afa5750 vn="Variante von Win64/Toolbar.Perion.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bntf64.exe.vir"
sh=D12EC3E24E166E3F360DA5B65A828D114F29AA1D ft=1 fh=fd4b015062f8b4ca vn="Variante von Win32/Toolbar.BitCocktail.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\brbsrv.exe.vir"
sh=5A37606E544B59D411FA4E3C283DACFFBACAD582 ft=1 fh=0e6c10b7d4b47283 vn="Variante von Win32/Toolbar.BitCocktail.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\brgb.dll.vir"
sh=72FF0A87BD5FB80F102AA73D6B935FB294DC5F77 ft=1 fh=4226fd59860a2aff vn="Win64/Toolbar.Perion.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\brgb64.dll.vir"
sh=879A232C7553A5206B1AF01F170C018FF79A6D2D ft=1 fh=d0a16c35eb77a596 vn="Win32/VMDetect.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bvmn.exe.vir"
sh=C62D763B9C2CEAAED8FA9B7188ADADA4A47D8F66 ft=1 fh=ee4670e681195ba3 vn="Variante von Win32/Toolbar.BitCocktail.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bwbk.dll.vir"
sh=B598A7E97869C9E8A2A13AFDB53FCA522A33006F ft=1 fh=bc0504c92b3fc380 vn="Variante von Win64/Toolbar.Perion.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bwbk64.dll.vir"
sh=81701CBC8F1A816F7239704758F52BA4E0DC8BF8 ft=1 fh=6df414b049bce859 vn="Variante von Win32/Toolbar.BitCocktail.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\dfsrvex.exe.vir"
sh=AC20E1BF33265BB62BE21277F842DDC8ED6E0556 ft=1 fh=fa376bee96000a00 vn="Variante von Win64/Adware.Vitruvian.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\WordProser_1.10.0.2\IE\WordProserClientIE.dll.vir"
sh=642716AFDDFCAA41EEDB11070CE3191070ED685B ft=1 fh=2fd62bfc8ca2e705 vn="Variante von MSIL/Solimba.AC evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FLVM Player\FLVPlayerUninstaller.exe.vir"
sh=918F15C63656A40CF1E5A5208CC699B3F52A452E ft=1 fh=6cc8c842aa3db01e vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\mbot_de_291\mbot_de_291.exe.vir"
sh=7DAC3DF676BE2FCABB271C896A8210C9D9083C86 ft=1 fh=dfed4c4cb297ef44 vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\mbot_de_291\mybestofferstoday_widget.exe.vir"
sh=C9D423596AAEE367F3A86094B6D283269BDFF81C ft=1 fh=9d9bfd045959a8d2 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ORBTR\Orbt.ext.vir"
sh=12EBF6FC8AD543662053CA101C2D5DA175137EB2 ft=1 fh=c71c00119e5c1a87 vn="Win32/Thinknice.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader32.exe.vir"
sh=8F0ABE23DDA3F9DC04497B1A4F455AF8CE9D45B8 ft=1 fh=787e176d56997de7 vn="Win64/Thinknice.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader64.exe.vir"
sh=C0EFC428002360259876073B6C6BA87D0965C608 ft=1 fh=c71c00119353c300 vn="Variante von Win32/Adware.AddLyrics.DH Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver5SpeedChecker\183.dll.vir"
sh=CA3E73700E329EB8F692F5499972D43B3EB51F0E ft=1 fh=8f3c2c613f8dcb1a vn="Variante von Win32/Adware.AddLyrics.DB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver5SpeedChecker\Uninstall.exe.vir"
sh=26BD5415E43B1B91064A6833034EE51B0600F4D2 ft=1 fh=14cc467e54c019eb vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\WinZip Malware Protector\AppManager.exe.vir"
sh=4E5E84B58B0267D57D07AB3F97CF6F9A28A09BCA ft=1 fh=c52573aa99100db8 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\WinZip Malware Protector\filetypehelper.exe.vir"
sh=1B17EF1DD2376A4D929828BC00994D590BFB977D ft=1 fh=ce4dc8a856b9d6ee vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\WinZip Malware Protector\scandll.dll.vir"
sh=CE29A117A96DEED1BEA6B7C4E3DF506CA0D322A4 ft=1 fh=f579473727f97194 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe.vir"
sh=D9CC64A2636AB49726F0F28E6CD7819309D37EC3 ft=1 fh=193c1900ba5552d2 vn="Variante von Win32/AdWare.Vitruvian.D Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\WordProser_1.10.0.2\IE\WordProserClientIE.dll.vir"
sh=E9304196741996E6D60D33BC705C4B8462B6EE53 ft=1 fh=10108e78c78b0531 vn="Variante von Win32/AdWare.Vitruvian.D Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\WordProser_1.10.0.2\Service\wpsvc.exe.vir"
sh=DB91DA833CBB50B1EECB7F48010670A2677C7B31 ft=1 fh=3538a8a766da7672 vn="Variante von Win32/Adware.EoRezo.AJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Bo\AppData\Local\mbot_de_291\upmbot_de_291.exe.vir"
sh=0C31651891423B0D2FFF8280136C5BBA1B9B0121 ft=1 fh=e066469fd9c63ba8 vn="Win32/AdWare.EoRezo.AW Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Bo\AppData\Local\mbot_de_291\Download\majmp_gentleeu.exe.vir"
sh=77C41F7DE0C08A26E70826946D91A9DC9BDD1C33 ft=1 fh=eed3d5e2751d7146 vn="Variante von Win32/DealPly.U evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Bo\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe.vir"
sh=83F0543DF9233DBE19DCA183E2738C9A1F1036C2 ft=1 fh=34e7354aef346a57 vn="Variante von Win64/Toolbar.Perion.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Windows\SysWOW64\lsdprn.exe.vir"
sh=2DAAB83B0439BC76845E58F3F7DDB84EE8E210C4 ft=1 fh=855a37aa5dbeb36f vn="Win32/InstallCore.PC evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\Bo\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z\Firefox Packages\uninstaller.exe"
         
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.91  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
AVG AntiVirus Free Edition 2015   
Windows Defender                  
 Antivirus out of date!  
`````````Anti-malware/Other Utilities Check:````````` 
 Java 7 Update 71  
 Adobe Flash Player 	15.0.0.239  
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 AVG avgwdsvc.exe 
 Malwarebytes Anti-Malware mbamscheduler.exe   
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log``````````````````````
         

soo hat gedauert ist aber jetzt fertig

Alt 07.12.2014, 12:10   #26
M-K-D-B
/// TB-Ausbilder
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Wenn du keine Probleme mehr mit Malware hast, dann sind wir hier fertig. Deine Logdateien sind sauber.
Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern.





Schritt 1
Ändere regelmäßig alle deine Passwörter, jetzt nach der Bereinigung ist ein idealer Zeitpunkt dafür!
  • Verwende für jede Anwendung und jeden Account ein anderes Passwort.
  • Ändere regelmäßig dein Passwort, vor allem bei Onlinebanking oder deinem Emailpostfach ist das sehr wichtig.
  • Speichere keine Passwörter auf deinem PC, gib diese nicht an Dritte weiter.
  • Ein sicheres Passwort besteht aus mindestens 8 Zeichen und beinhaltet Groß- und Kleinbuchstaben, Zahlen und Sonderzeichen.
  • Benutze keine Zahlen- oder Buchstabenkombinationen, ( zB 12345678, qwertzui) auch keine Zahlen oder Buchstabenmuster.
  • Verwende keine Passwörter die einen Bezug zu dir, deinem Wohnort, Familienmitglied oder Haustier (Geburtsdatum, Postleitzahl, Adresse, Name) haben.





Schritt 2
Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.







Schritt 3
Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems.


Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti-Viren-Programm und zusätzlicher Schutz
  • Gehe sicher, dass du immer nur eine Anti-Viren Software installiert hast und dass diese auch up to date ist! Ein kostenloses Anti-Viren Programm, das wir empfehlen, wäre z. B. Avast! Free Antivirus oder Microsoft Security Essentials.
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt. Du kannst es zusätzlich zu deinem Anti-Viren Programm verwenden.
    Update das Tool und lasse es einmal in der Woche laufen. Die Kaufversion bietet zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • AdwCleaner
    Dieses Tool erkennt eine Vielzahl von Werbeprogrammen (Adware) und unerwünschten Programmen (PUPs).
    Starte das Tool einmal die Woche und lass es laufen. Sollte eine neue Version verfügbar sein, so wird dies angezeigt und du kannst dir die neueste Version direkt von der Herstellerseite auf den Desktop herunterladen. Auch dieses Programm kann parallel zu deinem Anti-Viren Programm verwendet werden.
  • SpywareBlaster
    Eine kurze Einführung findest du Hier


Alternative Browser
Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Mozilla Firefox
  • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
  • NoScript
    Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt, wenn Du es bestätigst.
  • AdblockPlus
    Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzuzufügen reicht und dieser wird nicht mehr geladen.
    Es spart außerdem Downloadkapazität.


Performance
  • Halte dich fern von Registry Cleanern.
    Diese Schaden deinem System mehr als dass sie helfen. Hier ein englischer Link:
    Miekemoes Blogspot ( MVP )


Was du vermeiden solltest:
  • Klicke nicht auf alles, nur weil es dich dazu auffordert und schön bunt ist.
  • Verwende keine P2P oder Filesharing Software (Emule, uTorrent,..).
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie z.B. deinFoto.jpg.exe.
  • Lade keine Software von Softonic oder Chip herunter, da diese Installer oft mit Adware oder unerünschter Software versehen sind!



Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen?

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.

Alt 08.12.2014, 15:48   #27
Krazerack
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Vielen vielen Dank,
aktuell siehts beim rechner sehr gut aus, und er läuft rassend schnell

aber ích hab noch ein paar fragen..

Microsoft Security Essentials ist das der Windows Defender?
den Adw cleaner nach der Löschung dann einfach nochmal runterladen?

das wärs

Vielen Dank nochmal, du bist echt meine Rettung

Alt 08.12.2014, 19:34   #28
M-K-D-B
/// TB-Ausbilder
 
Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Standard

Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung



Zitat:
Zitat von Krazerack Beitrag anzeigen
Microsoft Security Essentials ist das der Windows Defender?
Ja



Zitat:
Zitat von Krazerack Beitrag anzeigen
den Adw cleaner nach der Löschung dann einfach nochmal runterladen?
genau




Ich bin froh, dass wir helfen konnten

In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest:
Lob, Kritik und Wünsche
Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank!

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen.

Antwort

Themen zu Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung
fehlercode 0xc0000005, fehlercode 0xc0000374, fehlercode 40, firefox packages entfernen, flv player entfernen, foxy secure entfernen, msil/solimba.ac, mybestofferstoday 014.291 entfernen, pennybee entfernen, pennybeeupdate entfernen, search protect entfernen, video dimmer entfernen, win32/adware.addlyrics.dh, win32/adware.eorezo.au, win32/clientconnect.a, win32/thinknice.e, win32/toolbar.bitcocktail.c, win32/toolbar.perion.j, win32/vmdetect.d, win64/adware.vitruvian.b, win64/thinknice.e, win64/toolbar.perion.b, word proser 1.10.0.2 entfernen, wse_vosteran entfernen, yahoo community smartbar entfernen, youradexchange




Ähnliche Themen: Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung


  1. Browser Tabs öffnen sich von alleine in IE und FF
    Log-Analyse und Auswertung - 09.11.2015 (5)
  2. Tabs öffnen sich eigenständig(Werbung)
    Alles rund um Mac OSX & Linux - 05.10.2015 (10)
  3. Werbung und nervige Tabs die sich bei klick auf eine Seite öffnen sowie Blaue schricht im Brwoser mit Werbung
    Plagegeister aller Art und deren Bekämpfung - 06.01.2015 (6)
  4. Firefox öffnen sich Tabs mit Werbung selbstständig
    Log-Analyse und Auswertung - 26.10.2014 (9)
  5. Windows7: Bei Chrome öffnen sich neue Tabs mit Werbung
    Log-Analyse und Auswertung - 17.09.2014 (21)
  6. Windows 7: Webbrowser öffnen sich von alleine mit Werbung
    Log-Analyse und Auswertung - 14.09.2014 (9)
  7. Windows 7 Home Premium SP1 - Probleme mit Tabs die sich von alleine Öffnen mit http://srv123.com/ads-clicktrack/
    Log-Analyse und Auswertung - 12.06.2014 (11)
  8. Windows 7: Tabs öffnen sich von alleine
    Log-Analyse und Auswertung - 29.03.2014 (11)
  9. Tabs mit Werbung öffnen sich selbstständig
    Plagegeister aller Art und deren Bekämpfung - 11.03.2014 (10)
  10. Windows 7 - Beim Öffnen von Websites öffnen sich Popups und Tabs mit Werbung
    Log-Analyse und Auswertung - 27.01.2014 (3)
  11. IE öffnet sich alleine/Werbung
    Log-Analyse und Auswertung - 14.11.2010 (18)
  12. Firefox öffnet Tabs mit Werbung / Anstelle einer verlinkten URL öffnet sich Werbung
    Plagegeister aller Art und deren Bekämpfung - 08.08.2010 (4)
  13. Internet Explorer öffnet sich von alleine mit Werbung
    Plagegeister aller Art und deren Bekämpfung - 14.02.2010 (1)
  14. Internet Explorer öffnet sich mit Werbung von alleine
    Plagegeister aller Art und deren Bekämpfung - 14.02.2010 (1)
  15. Browser öffnet sich von alleine mit Werbung
    Mülltonne - 23.09.2008 (0)
  16. IE Fenster öffnen sich von alleine mit Werbung
    Log-Analyse und Auswertung - 24.01.2008 (3)
  17. IE Fenster öffnet sich von alleine mit verschiedener Werbung
    Plagegeister aller Art und deren Bekämpfung - 12.10.2006 (20)

Zum Thema Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung - Addition Code: Alles auswählen Aufklappen ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-12-2014 Ran by Bo at 2014-12-03 21:28:29 Running from C:\Users\Bo\Desktop Boot Mode: Normal ========================================================== - Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung...
Archiv
Du betrachtest: Inernet öffnet sich von alleine + Tabs öffnen sich mit Werbung auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.