Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7 - Browser Hijack

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 20.08.2015, 20:47   #1
mezzomix
 
Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



Meine Mutter hat mir heute ihren Laptop übergeben mit den Worten "Schmuddelbilder". Einmal alle 3 Browser (IE, Firefox, Chrome) aufgemacht und schon habe ich folgendes gesehen:



Was habe ich bereits gemacht?
*) Windows Updates geladen und installiert
*) AWDcleaner laufen lassen (siehe Log)
*) Malwarebytes laufen lassen (siehe Log)
*) Defogger, FRST und GMER laut Anleitung laufen lassen
*) Avira läuft noch

AdwCleaner:

Code:
ATTFilter
# AdwCleaner v5.000 - Logfile created 20/08/2015 at 17:44:47
# Updated 14/08/2015 by Xplode
# Database : 2015-08-18.2 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : Lore ******* - NB*******
# Running from : D:\adwcleaner_5.000.exe
# Option : Scan

***** [ Services ] *****


***** [ Folders ] *****

Folder Found : C:\Program Files\Babylon
Folder Found : C:\Program Files (x86)\Babylon
Folder Found : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\Ask
Folder Found : C:\Users\Lore *******\AppData\Local\PackageAware
Folder Found : C:\Users\Lore *******\AppData\Roaming\Uniblue
Folder Found : C:\Users\LOREBE~1\AppData\Local\Temp\apn

***** [ Files ] *****

File Found : C:\windows\Sysnative\roboot64.exe

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE
Key Found : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search\ask.com
Key Found : HKCU\Software\5e28f8de139ea44
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ocr@babylon.com]
Key Found : HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
Key Found : HKLM\SOFTWARE\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{947217BD-E967-400A-B14A-BA851A8EDCBB}
Key Found : HKU\.DEFAULT\Software\APN
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\BABSOLUTION
Key Found : HKCU\Software\YahooPartnerToolbar
Key Found : HKLM\SOFTWARE\DeviceVM
Key Found : HKLM\SOFTWARE\Uniblue
Key Found : [x64] HKCU\Software\BABSOLUTION
Key Found : [x64] HKCU\Software\YahooPartnerToolbar
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\D2A425F405350054677A7A857BC0D100
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\D2A425F405350054677A7A857BC0D100
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D2A425F405350054677A7A857BC0D100
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{50F36A48-2A77-48B7-A2C4-FE98351AF315}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{50F36A48-2A77-48B7-A2C4-FE98351AF315}
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll

***** [ Web browsers ] *****

[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("avira.safe_search.installed", "[\"safesearch\"]");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("avira.safe_search.prev_newtab", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...]
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"147efee2a4b120-0759ef9815db95-42504136-0-147efee2a6781\"");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("extensions.safesearch.SAUTH_expires_at", "1432451046");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("extensions.safesearch.SAUTH_rndsnr", "\"91fffba014b75106001e992d72122865df6e3372\"");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("extensions.safesearch.SAUTH_userid", "4300179412");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("extensions.safesearch.SAUTH_utoken", "\"ea0c1b0c3f0c5e64817b9151e8a4d44a52ed5fd9\"");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("extensions.safesearch.install", "1408479668901");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("extensions.safesearch.search_offer_disabled", "true");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("searchreset.backup.browser.newtab.url", "hxxps://safesearch.avira.com/#?source=newtab");
[C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\prefs.js] [Preference] Found : user_pref("searchreset.backup.browser.search.defaultenginename", "Avira SafeSearch");

*************************

C:\AdwCleaner[S1].txt - [5444 octets] - [20/08/2015 17:44:47]

########## EOF - C:\AdwCleaner[S1].txt - [5507 octets] ##########
         
Malwarebytes:
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 20.08.2015
Suchlaufzeit: 19:32
Protokolldatei: Malwarebytes.txt
Administrator: Ja

Version: 2.1.8.1057
Malware-Datenbank: v2015.08.20.04
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Aktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Lore *******

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 433688
Abgelaufene Zeit: 42 Min., 4 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         
Defogger:
Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 19:01 on 20/08/2015 (Lore *******)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         

Alt 20.08.2015, 20:48   #2
mezzomix
 
Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



FRST:
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:20-08-2015
durchgeführt von Lore ******* (Administrator) auf NB******* (20-08-2015 19:25:11)
Gestartet von C:\Users\Lore *******\Desktop
Geladene Profile: Lore ******* (Verfügbare Profile: Lore *******)
Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(Microsoft Corporation) C:\Windows\System32\lpksetup.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(B.H.A Corporation) C:\Windows\SysWOW64\bgsvcgen.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Sun Microsystems, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\jre\bin\javaw.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\HPHotkeyMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSyncMAPI.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(SEIKO EPSON CORPORATION) C:\Windows\SysWOW64\SAgent4.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Smith Micro Software, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\SMManager.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Panasonic Corporation) C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\lpksetup.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-04-05] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2011-02-09] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-07-21] (Hewlett-Packard Company)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [489472 2011-02-09] (IDT, Inc.)
HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [3488640 2012-03-14] (Hewlett-Packard Company)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\...\Run: [File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11268096 2010-05-06] (Hewlett-Packard)
HKLM-x32\...\Run: [AppleSyncNotifier] => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [334240 2012-09-12] (Hewlett-Packard Company)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Connection Manager.exe] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66936 2015-08-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [782008 2015-07-15] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [EPSON692B84] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEKE.EXE [221696 2008-03-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [EPSON SX600FW Series (Kopie 2)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEKE.EXE [221696 2008-03-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [EPSON SX600FW Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEKE.EXE [221696 2008-03-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [Syncables] => C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe [530736 2010-05-18] (Hewlett-Packard)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2015-03-18] (Microsoft Corporation)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [BingSvc] => C:\Users\Lore *******\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation)
AppInit_DLLs: c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll => c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll Datei nicht gefunden
AppInit_DLLs:  c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll => c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll Datei nicht gefunden
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-12-04]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 4.0 HD Edition.lnk [2011-02-11]
ShortcutTarget: PHOTOfunSTUDIO 4.0 HD Edition.lnk -> C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe (Panasonic Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)

AutoConfigURL: [S-1-5-21-3921111220-2900040076-1547133076-1003] => https://guard-safe.net/a2tunnel.js
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/4
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=de-AT&Src=MSE&Tid=00033BB0&OHP=http%3A%2F%2Fg.uk.msn.com%2FHPCOM%2F4&OSP=
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/4
SearchScopes: HKLM -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3921111220-2900040076-1547133076-1003 -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3921111220-2900040076-1547133076-1003 -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
BHO: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2011-05-02] (DigitalPersona, Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: File Sanitizer for HP ProtectTools -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2010-05-06] (Hewlett-Packard)
BHO-x32: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2011-05-02] (DigitalPersona, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-05-08] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-08] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{F4FF26DF-9FE9-4F91-A720-687E53208FA1}: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Bing 
FF NetworkProxy: "autoconfig_url", "https://guard-safe.net/a2tunnel.js"
FF NetworkProxy: "no_proxies_on", "*.local"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-13] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-13] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\system32\Adobe\Director\np32dsw.dll [Keine Datei]
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-08] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Extension: Avira Browser Safety - C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\Extensions\abs@avira.com [2015-08-20]
FF Extension: GMX MailCheck - C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\Extensions\mailcheck@gmx.net [2015-08-19]
FF Extension: Kein Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-19]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-08-19]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2011-12-09]

Chrome: 
=======
CHR Profile: C:\Users\Lore *******\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [887128 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [461672 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [461672 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [227592 2015-08-03] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R3 DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [704512 2010-02-02] (McAfee, Inc.) [Datei ist nicht signiert]
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462160 2010-07-16] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [362040 2010-04-28] (Hewlett-Packard Ltd)
S2 HP ProtectTools Service; C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [32768 2010-10-19] (Hewlett-Packard Development Company, L.P) [Datei ist nicht signiert]
R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [90112 2010-06-14] (Hewlett-Packard Company) [Datei ist nicht signiert]
R2 HpFkCryptService; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [281192 2010-02-02] (McAfee, Inc.)
R2 HPFSService; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [298496 2010-05-06] (Hewlett-Packard) [Datei ist nicht signiert]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-09-12] (Hewlett-Packard Company)
S2 KMService; C:\windows\SysWOW64\srvany.exe [8192 2014-03-31] () [Datei ist nicht signiert]
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 QDLService2kHP; C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe [1687360 2011-04-29] (QUALCOMM, Inc.)
R2 SMManager; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\SMManager.exe [84808 2010-09-17] (Smith Micro Software, Inc.)
R2 StatusAgent4; C:\windows\SysWOW64\SAgent4.exe [131072 2006-12-20] (SEIKO EPSON CORPORATION) [Datei ist nicht signiert]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R5 ACPI; C:\Windows\System32\drivers\ACPI.sys [334208 2010-11-20] (Microsoft Corporation)
R5 amdxata; C:\Windows\System32\drivers\amdxata.sys [27008 2011-03-11] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162528 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [141416 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 cdrbsdrv; C:\Windows\System32\Drivers\cdrbsdrv.sys [39208 2006-08-25] (B.H.A Corporation)
R5 CLFS; C:\Windows\System32\CLFS.sys [367552 2015-03-04] (Microsoft Corporation)
R5 CNG; C:\Windows\System32\Drivers\cng.sys [459336 2015-01-31] (Microsoft Corporation)
R5 Compbatt; C:\Windows\System32\DRIVERS\compbatt.sys [21584 2009-07-14] (Microsoft Corporation)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [40760 2010-03-09] (Hewlett-Packard Development Company L.P.)
R5 Disk; C:\Windows\System32\DRIVERS\disk.sys [73280 2009-07-14] (Microsoft Corporation)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.)
R5 FileInfo; C:\Windows\System32\drivers\fileinfo.sys [70224 2009-07-14] (Microsoft Corporation)
R5 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [289664 2010-11-20] (Microsoft Corporation)
U5 Fs_Rec; C:\Windows\System32\Drivers\Fs_Rec.sys [23408 2012-03-01] (Microsoft Corporation)
R5 fvevol; C:\Windows\System32\DRIVERS\fvevol.sys [223752 2013-01-24] (Microsoft Corporation)
R5 hpdskflt; C:\Windows\System32\DRIVERS\hpdskflt.sys [30008 2011-05-13] (Hewlett-Packard Company)
R5 hwpolicy; C:\Windows\System32\drivers\hwpolicy.sys [14720 2010-11-20] (Microsoft Corporation)
R5 iaStor; C:\Windows\System32\DRIVERS\iaStor.sys [409624 2010-04-05] (Intel Corporation)
R5 KSecDD; C:\Windows\System32\Drivers\ksecdd.sys [95680 2015-07-23] (Microsoft Corporation)
R5 KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [155584 2015-07-23] (Microsoft Corporation)
R1 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [109272 2015-06-18] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-20] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R5 mountmgr; C:\Windows\System32\drivers\mountmgr.sys [94656 2015-07-15] (Microsoft Corporation)
R5 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R5 msisadrv; C:\Windows\System32\drivers\msisadrv.sys [15424 2009-07-14] (Microsoft Corporation)
R5 Mup; C:\Windows\System32\Drivers\mup.sys [60496 2009-07-14] (Microsoft Corporation)
R5 NDIS; C:\Windows\System32\drivers\ndis.sys [950128 2012-08-22] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R5 partmgr; C:\Windows\System32\drivers\partmgr.sys [75120 2012-03-17] (Microsoft Corporation)
R5 pci; C:\Windows\System32\drivers\pci.sys [184704 2010-11-20] (Microsoft Corporation)
R5 pcw; C:\Windows\System32\drivers\pcw.sys [50768 2009-07-14] (Microsoft Corporation)
R5 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [55856 2010-03-19] (Sonic Solutions)
R3 qcfilterhp2k; C:\Windows\System32\DRIVERS\qcfilterhp2k.sys [6400 2011-04-29] (QUALCOMM Incorporated)
R3 qcombushp; C:\Windows\System32\DRIVERS\qcombushp.sys [160328 2011-04-29] (MCCI)
R3 qcusbnethp2k; C:\Windows\System32\DRIVERS\qcusbnethp2k.sys [444416 2011-04-29] (QUALCOMM Incorporated)
R3 qcusbserhp2k; C:\Windows\System32\DRIVERS\qcusbserhp2k.sys [230784 2011-04-29] (QUALCOMM Incorporated)
R5 rdyboost; C:\Windows\System32\drivers\rdyboost.sys [213888 2010-11-20] (Microsoft Corporation)
R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [58184 2010-02-02] (McAfee, Inc.)
R1 RsvLock; C:\Windows\SysWow64\Drivers\RsvLock.sys [40088 2010-02-02] (McAfee, Inc.)
R5 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [56648 2010-02-02] ()
R5 SafeBoot; C:\Windows\SysWow64\Drivers\SafeBoot.sys [110520 2010-02-02] (McAfee, Inc.)
R5 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2009-06-04] (McAfee, Inc.)
R5 SbAlg; C:\Windows\SysWow64\Drivers\SbAlg.sys [51800 2010-02-02] (McAfee, Inc.)
R5 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15688 2010-02-02] (McAfee, Inc.)
R5 SbFsLock; C:\Windows\SysWow64\Drivers\SbFsLock.sys [13256 2010-02-02] (McAfee, Inc.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1803904 2010-04-27] ()
R5 spldr; C:\Windows\System32\Drivers\spldr.sys [19008 2009-07-14] (Microsoft Corporation)
R5 storflt; C:\Windows\System32\drivers\vmstorfl.sys [46464 2010-11-20] (Microsoft Corporation)
R5 Tcpip; C:\Windows\System32\drivers\tcpip.sys [1903552 2014-04-05] (Microsoft Corporation)
R5 vdrvroot; C:\Windows\System32\drivers\vdrvroot.sys [36432 2009-07-14] (Microsoft Corporation)
R5 vmbus; C:\Windows\System32\drivers\vmbus.sys [199552 2010-11-20] (Microsoft Corporation)
R5 volmgr; C:\Windows\System32\drivers\volmgr.sys [71552 2010-11-20] (Microsoft Corporation)
R5 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [363392 2010-11-20] (Microsoft Corporation)
R5 volsnap; C:\Windows\System32\drivers\volsnap.sys [296320 2011-02-25] (Microsoft Corporation)
R5 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [785624 2013-06-26] (Microsoft Corporation)
S3 ARCVCAM; system32\DRIVERS\ArcSoftVCapture.sys [X]
S3 CpqDfw; system32\drivers\CpqDfw.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-20 19:25 - 2015-08-20 19:28 - 00031710 _____ C:\Users\Lore *******\Desktop\FRST.txt
2015-08-20 19:00 - 2015-08-20 19:01 - 00000480 _____ C:\Users\Lore *******\Desktop\defogger_disable.log
2015-08-20 19:00 - 2015-08-20 19:00 - 00000000 _____ C:\Users\Lore *******\defogger_reenable
2015-08-20 18:59 - 2015-08-20 17:58 - 00380416 _____ C:\Users\Lore *******\Desktop\Gmer-19357.exe
2015-08-20 18:59 - 2015-08-20 17:58 - 00050477 _____ C:\Users\Lore *******\Desktop\Defogger.exe
2015-08-20 18:50 - 2015-08-20 19:25 - 00000000 ____D C:\FRST
2015-08-20 18:49 - 2015-08-20 17:45 - 02173952 _____ (Farbar) C:\Users\Lore *******\Desktop\FRST64.exe
2015-08-20 18:33 - 2015-08-20 18:33 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\Avira
2015-08-20 18:23 - 2015-08-11 03:20 - 25191936 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-08-20 18:23 - 2015-08-11 03:14 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-08-20 18:23 - 2015-08-11 02:33 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-08-20 18:23 - 2015-08-11 02:20 - 19871232 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-08-20 18:21 - 2015-08-20 18:21 - 00003432 _____ C:\windows\System32\Tasks\Avira Browser Safety Updater Task
2015-08-20 18:16 - 2015-07-15 08:37 - 00162528 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00141416 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00044088 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2015-08-20 18:13 - 2015-08-20 18:13 - 00001210 _____ C:\Users\Public\Desktop\Avira Launcher.lnk
2015-08-20 18:12 - 2015-08-20 18:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-08-20 18:11 - 2015-08-20 18:12 - 00000000 ____D C:\ProgramData\Package Cache
2015-08-20 17:46 - 2015-08-20 17:47 - 00005939 _____ C:\AdwCleaner[C1].txt
2015-08-20 17:44 - 2015-08-20 18:06 - 00000000 ____D C:\AdwCleaner
2015-08-20 17:44 - 2015-08-20 17:46 - 00005604 _____ C:\AdwCleaner[S1].txt
2015-08-20 17:38 - 2015-07-23 02:06 - 05568960 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-08-20 17:38 - 2015-07-23 02:06 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-08-20 17:38 - 2015-07-23 02:06 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-08-20 17:38 - 2015-07-23 02:03 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01390592 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-08-20 17:38 - 2015-07-23 02:02 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-08-20 17:38 - 2015-07-23 02:02 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-08-20 17:38 - 2015-07-23 02:01 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-08-20 17:38 - 2015-07-23 02:01 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-08-20 17:38 - 2015-07-23 02:01 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-08-20 17:38 - 2015-07-23 01:58 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-08-20 17:38 - 2015-07-23 01:57 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:51 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-08-20 17:38 - 2015-07-22 19:57 - 03989952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-08-20 17:38 - 2015-07-22 19:57 - 03934656 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-08-20 17:38 - 2015-07-22 19:54 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00641536 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00635392 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-08-20 17:38 - 2015-07-22 19:52 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-08-20 17:38 - 2015-07-22 19:52 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-08-20 17:38 - 2015-07-22 19:47 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-08-20 17:38 - 2015-07-22 19:46 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:48 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2015-08-20 17:38 - 2015-07-22 18:45 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-08-20 17:38 - 2015-07-22 18:44 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-08-20 17:38 - 2015-07-22 18:44 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-08-20 17:38 - 2015-07-22 18:34 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-08-20 17:38 - 2015-07-22 18:34 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-08-20 17:38 - 2015-07-22 18:31 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-20 17:37 - 2015-07-15 05:17 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-08-20 17:37 - 2015-07-15 04:54 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2015-08-20 17:37 - 2015-07-09 19:58 - 01632256 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2015-08-20 17:37 - 2015-07-09 19:58 - 00082944 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll
2015-08-20 17:37 - 2015-07-09 19:42 - 01372160 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2015-08-20 17:37 - 2015-07-09 19:42 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll
2015-08-20 17:33 - 2015-06-25 12:06 - 00115136 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-08-20 17:33 - 2015-06-25 12:01 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-08-20 17:33 - 2015-06-25 12:01 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-08-20 17:33 - 2015-06-25 11:44 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-08-20 11:42 - 2015-08-20 19:24 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-08-20 11:42 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-08-20 11:42 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-08-20 11:42 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-08-19 18:00 - 2015-08-20 16:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-13 11:03 - 2015-07-30 15:13 - 00124624 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 11:03 - 2015-07-30 15:13 - 00103120 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 10:19 - 2015-07-28 22:09 - 00017344 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-08-13 10:19 - 2015-07-28 22:05 - 01116672 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00774656 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00743424 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00437760 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-08-13 10:19 - 2015-07-28 21:55 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-08-13 10:19 - 2015-07-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-08-13 10:18 - 2015-07-15 20:15 - 00094656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-08-13 10:18 - 2015-07-15 20:10 - 01743360 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2015-08-13 10:18 - 2015-07-15 20:10 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-08-13 10:17 - 2015-07-21 02:39 - 00389840 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-08-13 10:17 - 2015-07-21 02:12 - 00342736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-08-13 10:17 - 2015-07-16 22:54 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-08-13 10:17 - 2015-07-16 22:36 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-08-13 10:17 - 2015-07-16 22:35 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-08-13 10:17 - 2015-07-16 22:26 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-08-13 10:17 - 2015-07-16 22:21 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-08-13 10:17 - 2015-07-16 22:12 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-08-13 10:17 - 2015-07-16 22:00 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 10:17 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-08-13 10:17 - 2015-07-16 21:51 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-08-13 10:17 - 2015-07-16 21:50 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-08-13 10:17 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-08-13 10:17 - 2015-07-16 21:43 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-08-13 10:17 - 2015-07-16 21:43 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-08-13 10:17 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-08-13 10:17 - 2015-07-16 21:39 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-08-13 10:17 - 2015-07-16 21:38 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-08-13 10:17 - 2015-07-16 21:35 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-08-13 10:17 - 2015-07-16 21:24 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-13 10:17 - 2015-07-16 21:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-08-13 10:17 - 2015-07-16 21:17 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-08-13 10:17 - 2015-07-16 21:06 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-08-13 10:17 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-08-13 10:17 - 2015-07-16 21:01 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-08-13 10:17 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-08-13 10:17 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-08-13 10:17 - 2015-07-15 05:19 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\basesrv.dll
2015-08-13 10:16 - 2015-07-16 22:37 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-08-13 10:16 - 2015-07-16 22:36 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-08-13 10:16 - 2015-07-16 22:36 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-08-13 10:16 - 2015-07-16 22:35 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-08-13 10:16 - 2015-07-16 22:27 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-08-13 10:16 - 2015-07-16 22:26 - 05923328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-08-13 10:16 - 2015-07-16 22:23 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-08-13 10:16 - 2015-07-16 22:08 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-08-13 10:16 - 2015-07-16 21:55 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-08-13 10:16 - 2015-07-16 21:54 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-08-13 10:16 - 2015-07-16 21:51 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-08-13 10:16 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-08-13 10:16 - 2015-07-16 21:49 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-08-13 10:16 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-08-13 10:16 - 2015-07-16 21:36 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-08-13 10:16 - 2015-07-16 21:34 - 14451200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-08-13 10:16 - 2015-07-16 21:33 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-08-13 10:16 - 2015-07-16 21:32 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-08-13 10:16 - 2015-07-16 21:29 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-08-13 10:16 - 2015-07-16 21:20 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-08-13 10:16 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-08-13 10:16 - 2015-07-16 21:12 - 02427904 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-08-13 10:16 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-08-13 10:16 - 2015-07-16 21:05 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-08-13 10:16 - 2015-07-16 20:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-08-13 10:16 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 01648128 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 01180160 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 01251328 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-08-13 10:15 - 2015-07-30 19:55 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-08-13 10:15 - 2015-07-30 18:56 - 03208192 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-08-13 10:15 - 2015-07-30 18:52 - 00372736 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-08-13 10:15 - 2015-07-30 18:49 - 00299520 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 03154944 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 02606080 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-08-13 10:15 - 2015-07-20 20:12 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-08-13 10:15 - 2015-07-20 20:12 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00173056 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00093184 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-08-13 10:15 - 2015-07-20 19:56 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-08-13 10:15 - 2015-07-15 05:19 - 02004992 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-08-13 10:15 - 2015-07-15 05:19 - 01887232 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-08-13 10:15 - 2015-07-15 05:14 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-08-13 10:15 - 2015-07-15 05:13 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-08-13 10:15 - 2015-07-15 04:55 - 01390592 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-08-13 10:15 - 2015-07-15 04:55 - 01241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-08-13 10:15 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2015-08-13 10:15 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-08-13 10:15 - 2015-07-10 19:51 - 14177280 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-08-13 10:15 - 2015-07-10 19:34 - 12875776 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-08-13 10:15 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\notepad.exe
2015-08-13 10:15 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\notepad.exe
2015-08-13 10:15 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
2015-08-13 10:15 - 2015-07-01 22:49 - 00260096 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-08-13 10:15 - 2015-07-01 22:48 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-08-13 10:15 - 2015-07-01 22:30 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-08-13 10:15 - 2015-07-01 22:30 - 00082432 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-08-13 10:15 - 2015-05-09 20:26 - 00493504 _____ (Microsoft Corporation) C:\windows\system32\mcupdate_GenuineIntel.dll
2015-07-31 21:53 - 2015-07-31 21:53 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-07-31 21:53 - 2015-07-31 21:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-07-31 21:52 - 2015-07-31 21:53 - 00000000 ____D C:\Program Files\iTunes
2015-07-31 21:52 - 2015-07-31 21:52 - 00000000 ____D C:\Program Files\iPod
2015-07-31 21:52 - 2015-07-31 21:52 - 00000000 ____D C:\Program Files (x86)\iTunes

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-20 19:25 - 2011-02-11 11:25 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\Skype
2015-08-20 19:21 - 2014-12-04 10:45 - 00006904 _____ C:\windows\setupact.log
2015-08-20 19:21 - 2011-05-15 18:12 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-20 19:21 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-08-20 19:20 - 2011-01-11 14:33 - 02066823 _____ C:\windows\WindowsUpdate.log
2015-08-20 19:16 - 2013-12-15 14:50 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-08-20 19:00 - 2011-02-07 10:48 - 00000000 ____D C:\Users\Lore *******
2015-08-20 18:53 - 2009-07-14 06:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-20 18:53 - 2009-07-14 06:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-20 18:32 - 2011-05-15 18:12 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-20 18:26 - 2010-09-08 00:27 - 05462744 _____ C:\windows\PFRO.log
2015-08-20 18:21 - 2013-09-21 14:57 - 00000000 ____D C:\Program Files (x86)\Avira
2015-08-20 18:16 - 2013-09-21 14:57 - 00000000 ____D C:\ProgramData\Avira
2015-08-20 18:08 - 2010-09-07 23:49 - 00000000 ____D C:\ProgramData\HPQLOG
2015-08-20 17:57 - 2010-09-07 23:55 - 00702028 _____ C:\windows\system32\perfh007.dat
2015-08-20 17:57 - 2010-09-07 23:55 - 00150638 _____ C:\windows\system32\perfc007.dat
2015-08-20 17:57 - 2009-07-14 07:13 - 01622300 _____ C:\windows\system32\PerfStringBackup.INI
2015-08-20 16:24 - 2013-04-30 19:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-20 16:24 - 2009-07-14 05:20 - 00000000 ____D C:\windows\L2Schemas
2015-08-20 16:22 - 2013-09-21 13:49 - 00000000 ____D C:\Users\Lore *******\Documents\Outlook-Dateien
2015-08-20 16:22 - 2011-02-09 16:31 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\SoftGrid Client
2015-08-20 12:14 - 2011-05-15 18:19 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-20 12:14 - 2011-04-20 07:36 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-08-20 12:14 - 2011-04-20 07:36 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-08-20 12:14 - 2011-02-07 10:59 - 00001425 _____ C:\Users\Lore *******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-19 18:20 - 2011-02-11 12:46 - 00000000 ____D C:\Users\Lore *******\Documents\Eigene Dateien
2015-08-17 17:48 - 2015-06-12 22:52 - 00000348 _____ C:\windows\Tasks\HPCeeScheduleForLore *******.job
2015-08-17 08:34 - 2011-02-11 11:25 - 00000000 ____D C:\ProgramData\Skype
2015-08-17 07:57 - 2015-06-12 22:52 - 00003210 _____ C:\windows\System32\Tasks\HPCeeScheduleForLore *******
2015-08-17 07:56 - 2011-02-10 14:32 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2015-08-13 19:06 - 2011-02-07 18:42 - 00000000 ____D C:\windows\rescache
2015-08-13 17:10 - 2011-02-07 10:59 - 00000000 ___RD C:\Users\Lore *******\Virtual Machines
2015-08-13 17:08 - 2009-07-14 06:45 - 00413936 _____ C:\windows\system32\FNTCACHE.DAT
2015-08-13 17:05 - 2015-04-15 22:59 - 00000000 ____D C:\windows\system32\appraiser
2015-08-13 17:05 - 2014-05-06 16:01 - 00000000 ___SD C:\windows\system32\CompatTel
2015-08-13 11:03 - 2013-03-14 09:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-13 11:02 - 2013-03-14 09:02 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-13 11:02 - 2013-03-14 09:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-13 11:00 - 2011-02-13 09:25 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 10:54 - 2009-07-14 04:34 - 00000478 _____ C:\windows\win.ini
2015-08-13 10:53 - 2013-07-24 00:50 - 00000000 ____D C:\windows\system32\MRT
2015-08-13 10:47 - 2011-02-07 18:45 - 132483416 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-08-13 10:16 - 2013-12-15 14:50 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-08-13 10:16 - 2012-04-13 18:28 - 00778440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-08-13 10:16 - 2011-06-17 15:47 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-31 21:52 - 2011-02-11 12:02 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-07-31 17:26 - 2011-02-13 09:25 - 00000000 ____D C:\Users\Lore *******\AppData\Local\Microsoft Help
2015-07-25 11:00 - 2015-04-04 22:56 - 00000000 ___SD C:\windows\system32\GWX
2015-07-23 13:48 - 2011-02-11 15:00 - 00003214 _____ C:\windows\System32\Tasks\HPCeeScheduleForNB*******$
2015-07-23 13:48 - 2011-02-11 15:00 - 00000338 _____ C:\windows\Tasks\HPCeeScheduleForNB*******$.job

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-03-30 18:19 - 2015-07-19 06:43 - 0000121 _____ () C:\Users\Lore *******\AppData\Roaming\default.rss
2011-04-15 22:57 - 2011-06-03 09:07 - 0001854 _____ () C:\Users\Lore *******\AppData\Roaming\GhostObjGAFix.xml
2013-09-21 14:33 - 2013-09-21 14:33 - 0022216 _____ () C:\Users\Lore *******\AppData\Roaming\Kommagetrennte Werte (DOS).ADR
2013-09-21 14:21 - 2013-09-21 16:35 - 0022405 _____ () C:\Users\Lore *******\AppData\Roaming\Kommagetrennte Werte (Windows).ADR

Einige Dateien in TEMP:
====================
C:\Users\Lore *******\AppData\Local\Temp\avgnt.exe
C:\Users\Lore *******\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Lore *******\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\Lore *******\AppData\Local\Temp\rvbtrscc.dll
C:\Users\Lore *******\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Lore *******\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-08-13 18:58

==================== Ende von Ergebnis ============================
         
Addition:
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:20-08-2015
durchgeführt von Lore ******* (2015-08-20 19:29:58)
Gestartet von C:\Users\Lore *******\Desktop
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3921111220-2900040076-1547133076-500 - Administrator - Disabled)
Gast (S-1-5-21-3921111220-2900040076-1547133076-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3921111220-2900040076-1547133076-1004 - Limited - Enabled)
Lore ******* (S-1-5-21-3921111220-2900040076-1547133076-1003 - Administrator - Enabled) => C:\Users\Lore *******

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Avira Antivirus (Enabled - Out of date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Avira Antivirus (Enabled - Out of date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

A1 Dashboard (x32 Version: 1.15.1.0 - A1 Telekom Austria AG) Hidden
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.5 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.5.9.620 - Adobe Systems, Inc.)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Apple Application Support (32-Bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft Camera Suite (HKLM-x32\...\ArcSoft Camera Suite) (Version: 2.0.30.60 - ArcSoft)
ArcSoft Camera Suite (x32 Version: 1.0.27.60 - ArcSoft) Hidden
ArcSoft Webcam Sharing Manager (HKLM-x32\...\{190A7D93-3823-439C-91B9-ADCE3EC2A6A2}) (Version: 2.0.0.26 - ArcSoft)
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.12.408 - Avira Operations GmbH & Co. KG)
Avira Browser Safety (HKLM-x32\...\{9E10EA90-5E97-43B7-A246-FC7B4F5E9493}) (Version: 1.4.5.509 - Avira Operations GmbH & Co KG)
Avira Launcher (HKLM-x32\...\{b76c0d12-422c-44e3-9daa-9363451e24cd}) (Version: 1.1.44.15481 - Avira Operations GmbH & Co. KG)
Avira Launcher (x32 Version: 1.1.44.15481 - Avira Operations GmbH & Co. KG) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 2070 Bluetooth 3.0 (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.6300 - Broadcom Corporation)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.350.6 - Broadcom Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Device Access Manager for HP ProtectTools (HKLM\...\{55B52830-024A-443E-AF61-61E1E71AFA1B}) (Version: 5.0.1.9 - Hewlett-Packard)
Drive Encryption for HP ProtectTools (HKLM-x32\...\Drive Encryption) (Version: 5.0.6.0 - Hewlett-Packard)
Drive Encryption for HP ProtectTools (Version: 5.0.6.0 - Hewlett-Packard) Hidden
EasyBits GO (HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Game Organizer) (Version:  - EasyBits Media)
Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON SX600FW Series Printer Uninstall (HKLM\...\EPSON SX600FW Series) (Version:  - SEIKO EPSON Corporation)
EpsonNet Config V3 (HKLM-x32\...\{2B0CDD4D-5C1A-47F7-89E2-9BF604670ABC}) (Version: 3.5c - SEIKO EPSON CORPORATION)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4j - SEIKO EPSON CORPORATION)
Face Recognition for HP ProtectTools (HKLM\...\{E793990C-90BE-4B69-AC29-BF5E8FD4ED54}) (Version: 2.05.4140 - Hewlett-Packard)
File Sanitizer For HP ProtectTools (HKLM-x32\...\{6D6ADF03-B257-4EA5-BBC1-1D145AF8D514}) (Version: 5.0.1.4 - Hewlett-Packard)
Free YouTube to MP3 Converter version 3.12.1.320 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.1.320 - DVDVideoSoft Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{8F258628-2E18-4C2E-8127-EF4EFAF5F75C}) (Version: 4.1.10.1 - Hewlett-Packard Company)
HP Advisor (HKLM-x32\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.12850.3526 - Hewlett-Packard)
HP Connection Manager (HKLM-x32\...\{0F97EBF6-1A51-4A15-ABFA-6240588EE9E3}) (Version: 3.3.2 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{03E92718-EC13-40B7-9CA4-A972B682B8FA}) (Version: 1.2.1.0 - Hewlett-Packard)
HP ESU for Microsoft Windows 7 (HKLM-x32\...\{A6365256-0FBA-4DCD-88CE-D92A4DC9328E}) (Version: 2.0.1.1 - Hewlett-Packard Company)
HP Hotkey Support (HKLM-x32\...\{C97CC14E-4789-4FC5-BC75-79191F7CE009}) (Version: 4.6.11.2 - Hewlett-Packard Company)
HP Power Assistant (HKLM\...\{682FBA83-2CCA-4CFA-A08A-6767DAB2FC9C}) (Version: 2.5.0.16 - Hewlett-Packard Company)
HP Power Data (HKLM\...\{339F5747-BED1-44AF-8583-8BBA2B342703}) (Version: 1.0.27.174 - Hewlett-Packard)
HP ProtectTools Security Manager (HKLM\...\HPProtectTools) (Version: 5.12.754 - Hewlett-Packard Company)
HP QuickLook (HKLM\...\{E6BEE2A9-04CF-42FF-B95B-BB70FAD2DC3E}) (Version: 3.3.1.4 - Hewlett-Packard Company)
HP QuickSync (HKLM-x32\...\{43C0E134-CD5A-4CE5-B3EF-C45C929DF285}) (Version: 6.2.683.10454 - Hewlett-Packard Company)
HP QuickWeb (HKLM-x32\...\{7861911B-4270-498A-8F7A-FCF0570F48A8}) (Version: 1.0.1.66 - DeviceVM, Inc.)
HP Setup (HKLM-x32\...\{96AC1B0B-02D1-4FAA-9C1E-C92ECA74921A}) (Version: 8.2.4130.3367 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{344A1AA2-AC8E-4741-BDB0-65B68FDA883C}) (Version: 3.2.0.0 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{18F4179A-385F-40EE-AE2D-FA0E1BE62753}) (Version: 4.5.12.1 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\...\{C689F3AD-85D9-47CA-AC42-29DDC53F428E}) (Version: 7.1.1.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
HP Webcam Driver (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.50014.0 - Sonix)
HP Wireless Assistant (HKLM\...\{9EA86AD9-FB32-4B9E-BD56-3068F9B8031F}) (Version: 4.0.10.0 - Hewlett-Packard)
iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6300.0 - IDT)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
iTunes (HKLM\...\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)
Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Menu Templates - Pack 1 (x32 Version: 9.6.0.0 - Nero AG) Hidden
Menu Templates - Starter Kit (x32 Version: 9.6.0.0 - Nero AG) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP1 English (HKLM-x32\...\{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}) (Version: 3.5.5692.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP1 x64 English (HKLM\...\{F83779DF-E1F5-43A2-A7BE-732F856FADB7}) (Version: 3.5.5692.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation)
MobileMe Control Panel (HKLM\...\{6DD01FF3-63CE-436B-96DB-61363EAA4EB8}) (Version: 3.1.8.0 - Apple Inc.)
Movie Templates - Starter Kit (x32 Version: 9.6.0.0 - Nero AG) Hidden
Mozilla Firefox 40.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 40.0 (x86 de)) (Version: 40.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.0.5697 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 9 Essentials (HKLM-x32\...\{865ca7a5-2056-43ad-a026-b6c325f6879b}) (Version:  - Nero AG)
PHOTOfunSTUDIO 4.0 HD Edition (HKLM-x32\...\{381D847E-7E56-4E82-B261-F799E0F40EB4}) (Version: 4.00.140 - Panasonic Corporation)
Privacy Manager for HP ProtectTools (HKLM\...\{32394B71-1E8E-4233-8958-B84F4CDC8F4D}) (Version: 5.11.814 - Hewlett-Packard Company)
Qualcomm Gobi 2000 Package for HP (HKLM-x32\...\{5A771AE0-513F-4EC5-AB09-A7D3D22A2E20}) (Version: 1.1.240 - QUALCOMM)
QuickTime 7 (HKLM-x32\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 1.12.0011 - Realtek)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30113 - Realtek Semiconductor Corp.)
Roxio Creator Business (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3.56.21 - Roxio)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SDK (x32 Version: 2.30.042 - Portrait Displays, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.7 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.7.103 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.24.0 - Synaptics Incorporated)
TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.20935 - TeamViewer)
Theft Recovery (HKLM-x32\...\InstallShield_{33C9F24B-1D92-4632-A915-81E3BB1D5D6B}) (Version: 5.1.0.21 - Hewlett-Packard)
Theft Recovery (x32 Version: 5.1.0.21 - Hewlett-Packard) Hidden
Tour Your PC (HKLM-x32\...\{6725EABF-A984-4D87-8A09-694F8547E5C8}) (Version: 1.00.0000 - HP)
Validity Fingerprint Driver (HKLM\...\{DD966CEF-5EA9-4BA2-B210-490FEBC27EA7}) (Version: 4.0.15.0 - Validity Sensors, Inc.)
Windows 7 Default Setting (HKLM-x32\...\{5BF8E079-D6E2-4323-B794-75152371122A}) (Version: 1.0.1.7 - Hewlett-Packard Company)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Wiederherstellungspunkte =========================

09-08-2015 00:26:43 Windows Update
13-08-2015 10:19:05 Windows Update
13-08-2015 10:46:29 Windows Update
17-08-2015 08:13:21 Windows Update
20-08-2015 17:38:44 Windows Update
20-08-2015 18:22:18 Windows Update

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {166FC27F-D109-418A-92B5-97B8EEEB5D66} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {173F1A5E-D17A-47C1-BE07-1FDF1E5FC397} - System32\Tasks\HPCeeScheduleForNB*******$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard)
Task: {1F712F85-F4CD-412A-8308-9AE8761C596C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {287A73AC-1C67-4DBA-A7DC-6BA4F7F4E8EC} - System32\Tasks\{3ED75B74-5E71-4BC8-9149-09AE7BDF04CC} => C:\Program Files (x86)\A1 Dashboard\Dashboard.exe [2011-05-05] (mquadr.at software engineering and consulting GmbH, web: www.mquadr.at, mail: office@mquadr.at)
Task: {369B3BE4-4540-4759-9DD8-ABF93BFFC737} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-04-30] (Oracle Corporation)
Task: {4087E57E-C1F2-467C-8BA1-E494F18011A0} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {5912AC92-960D-4DEF-933B-E45C7BB2E965} - System32\Tasks\{B166BF21-0A05-4592-B303-594DEF1D3702} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2015-07-28] (Skype Technologies S.A.)
Task: {5DF0B0B5-42C0-4A2F-8B27-A020ECB32151} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {65BDFEED-BAD6-4A6C-A9FB-A8008DF12915} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {6E3AE5D6-7E67-4242-85D3-6129FA94D790} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13] (Adobe Systems Incorporated)
Task: {7B62C2F7-673A-47EE-889A-217F0320BEA5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {7F3F53DD-17AE-466E-9EF6-59F3A240A800} - System32\Tasks\HPCeeScheduleForLore ******* => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard)
Task: {8690CF69-F2A3-473E-952E-AAC102FDF781} - System32\Tasks\{6B14C671-FC8A-49A0-8A77-37373EA2377F} => C:\Program Files (x86)\A1 Dashboard\Dashboard.exe [2011-05-05] (mquadr.at software engineering and consulting GmbH, web: www.mquadr.at, mail: office@mquadr.at)
Task: {93D3657B-F6EB-492F-AAD5-89E6397395D1} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {A24551EB-A6B2-463E-B023-F12D38ACD391} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {AAE9770A-CBB6-422B-B178-9C49C3B2B19F} - \AdobeFlashPlayerUpdate -> Keine Datei <==== ACHTUNG
Task: {BB94E993-30B3-4C6C-8B0C-73DBFB41B3E6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18] (Google Inc.)
Task: {C5339496-42C1-4AE9-96A4-3AC859F30C2B} - \AdobeFlashPlayerUpdate 2 -> Keine Datei <==== ACHTUNG
Task: {C60090A2-CAAA-49A4-9769-C63267E3E67C} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {D9F7C150-C460-4CE5-91A0-ADD2E7703679} - System32\Tasks\Registry Reviver starten => C:\Program Files (x86)\Reviversoft\Registry Reviver\RegistryReviver.exe
Task: {E123A7D7-67A1-4CA2-B350-479462E49A09} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {F72FF1AC-0414-43D5-BC72-5A03BCECB71F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18] (Google Inc.)
Task: {F9F88EAA-C760-4F96-ACD9-55F2840DC825} - System32\Tasks\Avira Browser Safety Updater Task => C:\Program Files (x86)\Avira\Browser Safety\AviraBrowserSafetyUpdater.exe [2015-03-11] (Avira Operations GmbH & Co. KG)
Task: {FEA63404-B7D8-46AA-B3D1-423712908A34} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {FFF10AFB-5918-40D5-AB93-317AC1C6C362} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForLore *******.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\windows\Tasks\HPCeeScheduleForNB*******$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2010-05-24 10:58 - 2010-05-24 10:58 - 00750864 _____ () C:\windows\system32\SUPSDK.dll
2009-11-23 10:24 - 2009-11-23 10:24 - 01412608 ____R () C:\windows\system32\LIBEAY32.dll
2010-04-20 09:10 - 2010-04-20 09:10 - 00100352 _____ () C:\Program Files\Hewlett-Packard\Pre-Boot Security for HP ProtectTools\BIOSDomainPlugin.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2015-02-13 05:20 - 2015-02-13 05:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-05-25 01:04 - 2013-05-25 01:04 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2010-07-21 15:33 - 2010-07-21 15:33 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll
2010-07-21 15:33 - 2010-07-21 15:33 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-09-17 19:47 - 2010-09-17 19:47 - 00904704 ____R () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\System.Data.SQLite.DLL
2010-09-17 19:50 - 2010-09-17 19:50 - 00122368 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\SMDataAccessLayer.dll
2010-09-17 19:58 - 2010-09-17 19:58 - 00170840 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\SMBIOSController.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\ProgramData\TEMP:D287FACF

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Lore *******\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{09345856-920B-41A7-A3CB-3D56AAABE96F}] => (Allow) LPort=5353
FirewallRules: [{93F5BA9D-08FA-4A22-91C5-06E487C2E3B4}] => (Allow) LPort=8182
FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [{27960756-60E9-459A-A20E-EF1849409BE1}] => (Allow) LPort=5353
FirewallRules: [{C06D229F-438A-42FC-9B84-D73B7EF05F70}] => (Allow) LPort=8182
FirewallRules: [{4ACC970B-A73D-4594-8304-810F3969DE07}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{5D37754B-68F9-45E0-A064-D05EF9E426E5}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Config V3\ENConfig.exe
FirewallRules: [{B8C2D200-910B-44B9-9EA5-33AA97454FB5}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Config V3\ENConfig.exe
FirewallRules: [TCP Query User{AF61E404-5A0F-4750-A5B4-4D980DB2B7BA}C:\windows\explorer.exe] => (Allow) C:\windows\explorer.exe
FirewallRules: [UDP Query User{2DB00EB6-9787-43AD-8C4E-7CE55347B702}C:\windows\explorer.exe] => (Allow) C:\windows\explorer.exe
FirewallRules: [TCP Query User{BAEF273F-C06C-4D02-9BEF-EB0E67B19E0E}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{4DAD06D3-2420-46DA-9427-81DDD34B15C8}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{BD9FD0F8-B1CC-429A-9C10-8C43901C7536}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A01D7C24-0A9E-45D0-823B-3B8745A640A3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{87FAA25C-BC00-41F3-98AE-4B0206667225}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B70E2C9A-CFF9-4F70-A8D8-41169D1E305F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C9FAAF61-159A-4C90-9941-14F9D0C112B3}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Config V3\ENConfig.exe
FirewallRules: [{8879E0FA-FE9A-4320-8251-022608163D6A}] => (Allow) C:\Program Files (x86)\EpsonNet\EpsonNet Config V3\ENConfig.exe
FirewallRules: [{A0BEA36A-CB1A-4981-B2FD-C9C759F625A1}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9754AA6F-31A2-4DC1-B9C9-F917AC8BEF58}] => (Allow) LPort=2869
FirewallRules: [{5CA08415-A4EF-4EE5-8F46-7A402D83DAA7}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{35788F34-F996-4040-B272-E20C18DD3750}C:\users\lore *******\appdata\local\temp\c82.tmp\kmservice.exe] => (Allow) C:\users\lore *******\appdata\local\temp\c82.tmp\kmservice.exe
FirewallRules: [UDP Query User{1C937235-3446-45B0-829E-F65D86011055}C:\users\lore *******\appdata\local\temp\c82.tmp\kmservice.exe] => (Allow) C:\users\lore *******\appdata\local\temp\c82.tmp\kmservice.exe
FirewallRules: [{25B64A7B-4918-4189-9EF6-A61A48E416C4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D2D165D7-4D12-41BD-9AD3-DC93F0BF0BCA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{48DA3D1C-A0D4-48EE-97D4-F938BDFA87D5}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{479AAD3D-158D-409A-9FE5-49E3AF8BB059}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{E674CEA6-8FAF-466A-8C80-DEB2FDAE8516}C:\users\lore *******\appdata\local\temp\db79.tmp\kmservice.exe] => (Allow) C:\users\lore *******\appdata\local\temp\db79.tmp\kmservice.exe
FirewallRules: [UDP Query User{CE15BCD3-6AC7-41C2-8571-E5BF736ACA36}C:\users\lore *******\appdata\local\temp\db79.tmp\kmservice.exe] => (Allow) C:\users\lore *******\appdata\local\temp\db79.tmp\kmservice.exe
FirewallRules: [{0A2B2A42-4E80-45DC-BDF6-A3AB28F3B746}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{03E8E2D1-DFBD-4474-AE50-D02820119B57}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (08/20/2015 07:25:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AppleSyncNotifier.exe, Version: 1.6.77.0, Zeitstempel: 0x4e8235f7
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6195, Zeitstempel: 0x4dcddbf3
Ausnahmecode: 0xc000000d
Fehleroffset: 0x00008aa0
ID des fehlerhaften Prozesses: 0x18ec
Startzeit der fehlerhaften Anwendung: 0xAppleSyncNotifier.exe0
Pfad der fehlerhaften Anwendung: AppleSyncNotifier.exe1
Pfad des fehlerhaften Moduls: AppleSyncNotifier.exe2
Berichtskennung: AppleSyncNotifier.exe3

Error: (08/20/2015 07:19:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm avscan.exe, Version 15.0.12.402 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 2300

Startzeit: 01d0db6602eedde6

Endzeit: 60000

Anwendungspfad: C:\Program Files (x86)\Avira\Antivirus\avscan.exe

Berichts-ID: 77e641f0-475f-11e5-9d00-e02a82351c95

Error: (08/20/2015 06:30:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AppleSyncNotifier.exe, Version: 1.6.77.0, Zeitstempel: 0x4e8235f7
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6195, Zeitstempel: 0x4dcddbf3
Ausnahmecode: 0xc000000d
Fehleroffset: 0x00008aa0
ID des fehlerhaften Prozesses: 0x19a4
Startzeit der fehlerhaften Anwendung: 0xAppleSyncNotifier.exe0
Pfad der fehlerhaften Anwendung: AppleSyncNotifier.exe1
Pfad des fehlerhaften Moduls: AppleSyncNotifier.exe2
Berichtskennung: AppleSyncNotifier.exe3

Error: (08/20/2015 06:20:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: setup.exe_Avira Product Family, Version: 15.0.12.402, Zeitstempel: 0x559fa759
Name des fehlerhaften Moduls: MSVCR120.dll, Version: 12.0.21005.1, Zeitstempel: 0x524f7ce6
Ausnahmecode: 0xc0000417
Fehleroffset: 0x000a46bb
ID des fehlerhaften Prozesses: 0x1710
Startzeit der fehlerhaften Anwendung: 0xsetup.exe_Avira Product Family0
Pfad der fehlerhaften Anwendung: setup.exe_Avira Product Family1
Pfad des fehlerhaften Moduls: setup.exe_Avira Product Family2
Berichtskennung: setup.exe_Avira Product Family3

Error: (08/20/2015 06:11:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AppleSyncNotifier.exe, Version: 1.6.77.0, Zeitstempel: 0x4e8235f7
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6195, Zeitstempel: 0x4dcddbf3
Ausnahmecode: 0xc000000d
Fehleroffset: 0x00008aa0
ID des fehlerhaften Prozesses: 0x19f8
Startzeit der fehlerhaften Anwendung: 0xAppleSyncNotifier.exe0
Pfad der fehlerhaften Anwendung: AppleSyncNotifier.exe1
Pfad des fehlerhaften Moduls: AppleSyncNotifier.exe2
Berichtskennung: AppleSyncNotifier.exe3

Error: (08/20/2015 05:52:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AppleSyncNotifier.exe, Version: 1.6.77.0, Zeitstempel: 0x4e8235f7
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6195, Zeitstempel: 0x4dcddbf3
Ausnahmecode: 0xc000000d
Fehleroffset: 0x00008aa0
ID des fehlerhaften Prozesses: 0x10c4
Startzeit der fehlerhaften Anwendung: 0xAppleSyncNotifier.exe0
Pfad der fehlerhaften Anwendung: AppleSyncNotifier.exe1
Pfad des fehlerhaften Moduls: AppleSyncNotifier.exe2
Berichtskennung: AppleSyncNotifier.exe3

Error: (08/20/2015 05:28:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1354026

Error: (08/20/2015 05:28:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1354026

Error: (08/20/2015 05:28:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (08/20/2015 05:05:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9875


Systemfehler:
=============
Error: (08/20/2015 07:25:24 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst hpqwmiex erreicht.

Error: (08/20/2015 07:24:21 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
cdrom

Error: (08/20/2015 07:23:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Avira Browser-Schutz" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (08/20/2015 07:22:45 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (08/20/2015 07:22:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "HP ProtectTools Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (08/20/2015 07:22:41 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst HP ProtectTools Service erreicht.

Error: (08/20/2015 07:20:30 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {51FA2736-5DEE-11D4-98E8-006008BF430C}

Error: (08/20/2015 06:30:57 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst hpqwmiex erreicht.

Error: (08/20/2015 06:30:01 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
cdrom

Error: (08/20/2015 06:29:46 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)


Microsoft Office:
=========================
Error: (08/20/2015 07:25:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AppleSyncNotifier.exe1.6.77.04e8235f7MSVCR80.dll8.0.50727.61954dcddbf3c000000d00008aa018ec01d0db6d12cddd10C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exeC:\windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll725f6d27-4760-11e5-8625-e02a82351c95

Error: (08/20/2015 07:19:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: avscan.exe15.0.12.402230001d0db6602eedde660000C:\Program Files (x86)\Avira\Antivirus\avscan.exe77e641f0-475f-11e5-9d00-e02a82351c95

Error: (08/20/2015 06:30:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AppleSyncNotifier.exe1.6.77.04e8235f7MSVCR80.dll8.0.50727.61954dcddbf3c000000d00008aa019a401d0db657c6f8380C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exeC:\windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dlld0462de4-4758-11e5-9d00-e02a82351c95

Error: (08/20/2015 06:20:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: setup.exe_Avira Product Family15.0.12.402559fa759MSVCR120.dll12.0.21005.1524f7ce6c0000417000a46bb171001d0db638d638088C:\windows\TEMP\RarSFX0\setup.exeC:\windows\TEMP\RarSFX0\MSVCR120.dll60d21a9e-4757-11e5-b02d-e02a82351c95

Error: (08/20/2015 06:11:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AppleSyncNotifier.exe1.6.77.04e8235f7MSVCR80.dll8.0.50727.61954dcddbf3c000000d00008aa019f801d0db62d2d22ebcC:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exeC:\windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll239c4dde-4756-11e5-b02d-e02a82351c95

Error: (08/20/2015 05:52:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AppleSyncNotifier.exe1.6.77.04e8235f7MSVCR80.dll8.0.50727.61954dcddbf3c000000d00008aa010c401d0db603a018caeC:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exeC:\windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll8608a8a0-4753-11e5-9e3e-00a0c6000000

Error: (08/20/2015 05:28:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1354026

Error: (08/20/2015 05:28:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1354026

Error: (08/20/2015 05:28:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (08/20/2015 05:05:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9875


==================== Speicherinformationen =========================== 

Processor: Intel(R) Core(TM) i5 CPU M 450 @ 2.40GHz
Prozentuale Nutzung des RAM: 60%
Installierter physikalischer RAM: 3887.43 MB
Verfügbarer physikalischer RAM: 1538.39 MB
Summe virtueller Speicher: 7773.06 MB
Verfügbarer virtueller Speicher: 4535.3 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:448.46 GB) (Free:282.6 GB) NTFS ==>[System mit Startkomponenten (eingeholt von lesen Laufwerk)]
Drive d: (UNTITLED) (Removable) (Total:14.9 GB) (Free:10.19 GB) FAT32
Drive f: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.48 GB) FAT32

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: D688CB5D)
Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=448.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=0C)

========================================================
Disk: 1 (Size: 14.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== Ende von Ergebnis ============================
         
__________________


Alt 21.08.2015, 13:47   #3
mezzomix
 
Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



GMER:
Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-08-20 20:33:49
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST950042 rev.0006 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\LOREBE~1\AppData\Local\Temp\pfldqpow.sys


---- User code sections - GMER 2.1 ----

.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                0000000075851401 2 bytes JMP 759cb20b C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                  0000000075851419 2 bytes JMP 759cb336 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                0000000075851431 2 bytes JMP 75a48f39 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                000000007585144a 2 bytes CALL 759a4885 C:\windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                            * 9
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                   00000000758514dd 2 bytes JMP 75a48832 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                            00000000758514f5 2 bytes JMP 75a48a08 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                   000000007585150d 2 bytes JMP 75a48728 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                            0000000075851525 2 bytes JMP 75a48af2 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                  000000007585153d 2 bytes JMP 759bfc98 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                       0000000075851555 2 bytes JMP 759c68df C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                000000007585156d 2 bytes JMP 75a48ff1 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                  0000000075851585 2 bytes JMP 75a48b52 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                     000000007585159d 2 bytes JMP 75a486ec C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                  00000000758515b5 2 bytes JMP 759bfd31 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                00000000758515cd 2 bytes JMP 759cb2cc C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                            00000000758516b2 2 bytes JMP 75a48eb4 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe[3712] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                            00000000758516bd 2 bytes JMP 75a48681 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                        0000000075851401 2 bytes JMP 759cb20b C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                          0000000075851419 2 bytes JMP 759cb336 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                        0000000075851431 2 bytes JMP 75a48f39 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                        000000007585144a 2 bytes CALL 759a4885 C:\windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                            * 9
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                           00000000758514dd 2 bytes JMP 75a48832 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                    00000000758514f5 2 bytes JMP 75a48a08 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                           000000007585150d 2 bytes JMP 75a48728 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                    0000000075851525 2 bytes JMP 75a48af2 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                          000000007585153d 2 bytes JMP 759bfc98 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                               0000000075851555 2 bytes JMP 759c68df C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                        000000007585156d 2 bytes JMP 75a48ff1 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                          0000000075851585 2 bytes JMP 75a48b52 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                             000000007585159d 2 bytes JMP 75a486ec C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                          00000000758515b5 2 bytes JMP 759bfd31 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                        00000000758515cd 2 bytes JMP 759cb2cc C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                    00000000758516b2 2 bytes JMP 75a48eb4 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[4912] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                    00000000758516bd 2 bytes JMP 75a48681 C:\windows\syswow64\kernel32.dll
?        C:\windows\system32\mssprxy.dll [4912] entry point in ".rdata" section                                                                                                                         000000005a3a71e6
.text    C:\windows\SysWOW64\SAgent4.exe[2952] C:\windows\SysWOW64\WSOCK32.dll!recv + 82                                                                                                                000000006c2c17fa 2 bytes CALL 759a11a9 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\SAgent4.exe[2952] C:\windows\SysWOW64\WSOCK32.dll!recvfrom + 88                                                                                                            000000006c2c1860 2 bytes CALL 759a11a9 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\SAgent4.exe[2952] C:\windows\SysWOW64\WSOCK32.dll!setsockopt + 98                                                                                                          000000006c2c1942 2 bytes JMP 767c7089 C:\windows\syswow64\WS2_32.dll
.text    C:\windows\SysWOW64\SAgent4.exe[2952] C:\windows\SysWOW64\WSOCK32.dll!setsockopt + 109                                                                                                         000000006c2c194d 2 bytes JMP 767ccba6 C:\windows\syswow64\WS2_32.dll
?        C:\windows\system32\mssprxy.dll [2880] entry point in ".rdata" section                                                                                                                         000000005a3a71e6
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                           0000000075851401 2 bytes JMP 759cb20b C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                             0000000075851419 2 bytes JMP 759cb336 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                           0000000075851431 2 bytes JMP 75a48f39 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                           000000007585144a 2 bytes CALL 759a4885 C:\windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                            * 9
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                              00000000758514dd 2 bytes JMP 75a48832 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                       00000000758514f5 2 bytes JMP 75a48a08 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                              000000007585150d 2 bytes JMP 75a48728 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                       0000000075851525 2 bytes JMP 75a48af2 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                             000000007585153d 2 bytes JMP 759bfc98 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                  0000000075851555 2 bytes JMP 759c68df C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                           000000007585156d 2 bytes JMP 75a48ff1 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                             0000000075851585 2 bytes JMP 75a48b52 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                000000007585159d 2 bytes JMP 75a486ec C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                             00000000758515b5 2 bytes JMP 759bfd31 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                           00000000758515cd 2 bytes JMP 759cb2cc C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                       00000000758516b2 2 bytes JMP 75a48eb4 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[6176] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                       00000000758516bd 2 bytes JMP 75a48681 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                    0000000075851401 2 bytes JMP 759cb20b C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                      0000000075851419 2 bytes JMP 759cb336 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                    0000000075851431 2 bytes JMP 75a48f39 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                    000000007585144a 2 bytes CALL 759a4885 C:\windows\syswow64\KERNEL32.dll
.text    ...                                                                                                                                                                                            * 9
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                       00000000758514dd 2 bytes JMP 75a48832 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                00000000758514f5 2 bytes JMP 75a48a08 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                       000000007585150d 2 bytes JMP 75a48728 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                0000000075851525 2 bytes JMP 75a48af2 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                      000000007585153d 2 bytes JMP 759bfc98 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                           0000000075851555 2 bytes JMP 759c68df C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                    000000007585156d 2 bytes JMP 75a48ff1 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                      0000000075851585 2 bytes JMP 75a48b52 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                         000000007585159d 2 bytes JMP 75a486ec C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                      00000000758515b5 2 bytes JMP 759bfd31 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                    00000000758515cd 2 bytes JMP 759cb2cc C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                00000000758516b2 2 bytes JMP 75a48eb4 C:\windows\syswow64\KERNEL32.dll
.text    C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe[6592] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                00000000758516bd 2 bytes JMP 75a48681 C:\windows\syswow64\KERNEL32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                                                 0000000075851401 2 bytes JMP 759cb20b C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                                                   0000000075851419 2 bytes JMP 759cb336 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                                                 0000000075851431 2 bytes JMP 75a48f39 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                                                 000000007585144a 2 bytes CALL 759a4885 C:\windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                            * 9
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                                                    00000000758514dd 2 bytes JMP 75a48832 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                                             00000000758514f5 2 bytes JMP 75a48a08 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                                                    000000007585150d 2 bytes JMP 75a48728 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                                             0000000075851525 2 bytes JMP 75a48af2 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                                                   000000007585153d 2 bytes JMP 759bfc98 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                                        0000000075851555 2 bytes JMP 759c68df C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                                                 000000007585156d 2 bytes JMP 75a48ff1 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                                                   0000000075851585 2 bytes JMP 75a48b52 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                                                      000000007585159d 2 bytes JMP 75a486ec C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                                                   00000000758515b5 2 bytes JMP 759bfd31 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                                                 00000000758515cd 2 bytes JMP 759cb2cc C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                                             00000000758516b2 2 bytes JMP 75a48eb4 C:\windows\syswow64\kernel32.dll
.text    C:\windows\SysWOW64\RunDll32.exe[4192] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                                             00000000758516bd 2 bytes JMP 75a48681 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                   0000000075851401 2 bytes JMP 759cb20b C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                     0000000075851419 2 bytes JMP 759cb336 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                   0000000075851431 2 bytes JMP 75a48f39 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                   000000007585144a 2 bytes CALL 759a4885 C:\windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                            * 9
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                      00000000758514dd 2 bytes JMP 75a48832 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                               00000000758514f5 2 bytes JMP 75a48a08 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                      000000007585150d 2 bytes JMP 75a48728 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                               0000000075851525 2 bytes JMP 75a48af2 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                     000000007585153d 2 bytes JMP 759bfc98 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                          0000000075851555 2 bytes JMP 759c68df C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                   000000007585156d 2 bytes JMP 75a48ff1 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                     0000000075851585 2 bytes JMP 75a48b52 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                        000000007585159d 2 bytes JMP 75a486ec C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                     00000000758515b5 2 bytes JMP 759bfd31 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                   00000000758515cd 2 bytes JMP 759cb2cc C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                               00000000758516b2 2 bytes JMP 75a48eb4 C:\windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[7700] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                               00000000758516bd 2 bytes JMP 75a48681 C:\windows\syswow64\kernel32.dll

---- Threads - GMER 2.1 ----

Thread   c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2108:2672]                                                                                                                     000007fef438c680
Thread   c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2140:3912]                                                                                                                    000007fef62b838c
Thread   c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2140:3920]                                                                                                                    000007fef438c680
Thread   C:\windows\SysWOW64\ntdll.dll [2524:2528]                                                                                                                                                      000000000133eabf
Thread   C:\windows\SysWOW64\ntdll.dll [2524:2972]                                                                                                                                                      0000000072c732fb
---- Processes - GMER 2.1 ----

Process  C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (*** suspicious ***) @ C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE [2200] (EPSON Status Monitor 3/SEIKO EPSON CORPORATION)(2011-02-11 09:51:30)  0000000100000000
Process  C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (*** suspicious ***) @ C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [3184] (EPSON Status Monitor 3/SEIKO EPSON CORPORATION)(2011-02-11 09:51:30)  0000000100000000

---- Registry - GMER 2.1 ----

Reg      HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\e02a82351c95                                                                                                                    
Reg      HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\e02a82351c95 (not active ControlSet)                                                                                                

---- EOF - GMER 2.1 ----
         
Malwarebytes Anti-Rootkit Tool:

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 20.08.2015
Suchlaufzeit: 19:32
Protokolldatei: Malwarebytes.txt
Administrator: Ja

Version: 2.1.8.1057
Malware-Datenbank: v2015.08.20.04
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Aktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Lore *******

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 433688
Abgelaufene Zeit: 42 Min., 4 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         
Ich weiß langsam wirklich nicht mehr wo ich noch suchen soll...
__________________

Alt 21.08.2015, 21:34   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 21.08.2015, 23:29   #5
mezzomix
 
Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



Hallo Schrauber,

vielen Dank fürs reinschaun. Hier ist das Combofix Log

Code:
ATTFilter
ComboFix 15-08-20.01 - Lore ******* 21.08.2015  22:58:20.1.4 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1252.43.1031.18.3887.1120 [GMT 2:00]
ausgeführt von:: c:\users\Lore *******\Desktop\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.pol
C:\Thumbs.db
c:\users\Lore *******\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\LOREBE~1\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
.
.
(((((((((((((((((((((((   Dateien erstellt von 2015-07-21 bis 2015-08-21  ))))))))))))))))))))))))))))))
.
.
2015-08-21 20:43 . 2015-08-21 20:43	0	----a-w-	c:\windows\SysWow64\sho9FE1.tmp
2015-08-21 17:19 . 2015-07-31 09:21	11745192	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{12CB335B-7D66-4B43-AB09-EEB01A10E906}\mpengine.dll
2015-08-21 10:55 . 2015-08-21 11:35	--------	d-----w-	c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-08-20 16:50 . 2015-08-20 17:31	--------	d-----w-	C:\FRST
2015-08-20 16:33 . 2015-08-20 16:33	--------	d-----w-	c:\users\Lore *******\AppData\Roaming\Avira
2015-08-20 16:23 . 2015-08-11 01:20	25191936	----a-w-	c:\windows\system32\mshtml.dll
2015-08-20 16:23 . 2015-08-11 01:14	2724864	----a-w-	c:\windows\system32\mshtml.tlb
2015-08-20 16:23 . 2015-08-11 00:33	2724864	----a-w-	c:\windows\SysWow64\mshtml.tlb
2015-08-20 16:16 . 2015-07-15 06:37	44088	----a-w-	c:\windows\system32\drivers\avnetflt.sys
2015-08-20 16:16 . 2015-07-15 06:37	28600	----a-w-	c:\windows\system32\drivers\avkmgr.sys
2015-08-20 16:16 . 2015-07-15 06:37	141416	----a-w-	c:\windows\system32\drivers\avipbb.sys
2015-08-20 16:16 . 2015-07-15 06:37	162528	----a-w-	c:\windows\system32\drivers\avgntflt.sys
2015-08-20 16:11 . 2015-08-20 16:12	--------	d-----w-	c:\programdata\Package Cache
2015-08-20 15:44 . 2015-08-20 18:15	--------	d-----w-	C:\AdwCleaner
2015-08-20 15:43 . 2015-07-15 01:12	12222168	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-08-20 15:37 . 2015-07-15 03:17	2048	----a-w-	c:\windows\system32\tzres.dll
2015-08-20 15:37 . 2015-07-15 02:54	2048	----a-w-	c:\windows\SysWow64\tzres.dll
2015-08-20 15:37 . 2015-07-09 17:58	82944	----a-w-	c:\windows\system32\dwmapi.dll
2015-08-20 15:37 . 2015-07-09 17:58	1632256	----a-w-	c:\windows\system32\dwmcore.dll
2015-08-20 15:37 . 2015-07-09 17:42	1372160	----a-w-	c:\windows\SysWow64\dwmcore.dll
2015-08-20 15:37 . 2015-07-09 17:42	67584	----a-w-	c:\windows\SysWow64\dwmapi.dll
2015-08-20 15:33 . 2015-06-25 10:06	115136	----a-w-	c:\windows\system32\consent.exe
2015-08-20 15:33 . 2015-06-25 10:01	1941504	----a-w-	c:\windows\system32\authui.dll
2015-08-20 15:33 . 2015-06-25 09:44	1805824	----a-w-	c:\windows\SysWow64\authui.dll
2015-08-20 15:33 . 2015-06-25 10:01	70656	----a-w-	c:\windows\system32\appinfo.dll
2015-08-20 09:42 . 2015-08-21 21:14	113880	----a-w-	c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-20 09:42 . 2015-06-18 06:41	63704	----a-w-	c:\windows\system32\drivers\mwac.sys
2015-08-20 09:42 . 2015-06-18 06:41	109272	----a-w-	c:\windows\system32\drivers\mbamchameleon.sys
2015-08-20 09:42 . 2015-06-18 06:41	25816	----a-w-	c:\windows\system32\drivers\mbam.sys
2015-08-20 09:42 . 2015-08-20 09:42	--------	d-----w-	c:\program files (x86)\ Malwarebytes Anti-Malware 
2015-08-20 09:42 . 2015-08-20 09:42	--------	d-----w-	c:\programdata\Malwarebytes
2015-08-13 09:03 . 2015-07-30 13:13	103120	----a-w-	c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 09:03 . 2015-07-30 13:13	124624	----a-w-	c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 08:21 . 2015-07-02 06:33	1190000	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{53154181-5572-4F52-8E9E-67473031A264}\gapaengine.dll
2015-08-13 08:18 . 2015-07-15 18:10	1743360	----a-w-	c:\windows\system32\sysmain.dll
2015-08-13 08:18 . 2015-07-15 18:15	94656	----a-w-	c:\windows\system32\drivers\mountmgr.sys
2015-08-13 08:18 . 2015-07-15 18:10	11264	----a-w-	c:\windows\system32\msmmsp.dll
2015-08-13 08:18 . 2015-07-15 20:23	2560	----a-w-	c:\windows\system32\drivers\de-DE\mountmgr.sys.mui
2015-08-13 08:16 . 2015-07-16 19:51	316928	----a-w-	c:\windows\system32\dxtrans.dll
2015-08-13 08:15 . 2015-07-01 20:49	260096	----a-w-	c:\windows\system32\WebClnt.dll
2015-07-31 19:52 . 2015-07-31 19:52	--------	d-----w-	c:\program files (x86)\iTunes
2015-07-31 19:52 . 2015-07-31 19:52	--------	d-----w-	c:\program files\iPod
2015-07-31 19:52 . 2015-07-31 19:53	--------	d-----w-	c:\program files\iTunes
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-08-13 08:47 . 2011-02-07 16:45	132483416	----a-w-	c:\windows\system32\MRT.exe
2015-08-13 08:16 . 2012-04-13 16:28	778440	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2015-08-13 08:16 . 2011-06-17 13:47	142536	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-07-22 17:53 . 2015-08-20 15:38	44032	----a-w-	c:\windows\apppatch\acwow64.dll
2015-07-05 10:08 . 2011-02-08 14:11	300704	------w-	c:\windows\system32\MpSigStub.exe
2015-07-04 18:07 . 2015-07-15 06:45	2087424	----a-w-	c:\windows\system32\ole32.dll
2015-07-04 17:48 . 2015-07-15 06:45	1414656	----a-w-	c:\windows\SysWow64\ole32.dll
2015-07-02 06:33 . 2014-07-21 20:24	1190000	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2015-06-23 23:29 . 2015-06-23 23:29	1217192	----a-w-	c:\windows\SysWow64\FM20.DLL
2015-06-17 17:47 . 2015-07-15 06:45	404992	----a-w-	c:\windows\system32\gdi32.dll
2015-06-17 17:37 . 2015-07-15 06:45	312320	----a-w-	c:\windows\SysWow64\gdi32.dll
2015-06-16 22:23 . 2015-06-16 22:23	94208	----a-w-	c:\windows\SysWow64\QuickTimeVR.qtx
2015-06-16 22:23 . 2015-06-16 22:23	69632	----a-w-	c:\windows\SysWow64\QuickTime.qts
2015-06-15 21:45 . 2015-07-15 06:10	3242496	----a-w-	c:\windows\system32\msi.dll
2015-06-15 21:45 . 2015-07-15 06:10	504320	----a-w-	c:\windows\system32\msihnd.dll
2015-06-15 21:44 . 2015-07-15 06:10	128000	----a-w-	c:\windows\system32\msiexec.exe
2015-06-15 21:43 . 2015-07-15 06:10	2364416	----a-w-	c:\windows\SysWow64\msi.dll
2015-06-15 21:43 . 2015-07-15 06:10	337408	----a-w-	c:\windows\SysWow64\msihnd.dll
2015-06-15 21:42 . 2015-07-15 06:10	73216	----a-w-	c:\windows\SysWow64\msiexec.exe
2015-06-15 21:42 . 2015-07-15 06:10	25088	----a-w-	c:\windows\system32\msimsg.dll
2015-06-15 21:37 . 2015-07-15 06:10	25088	----a-w-	c:\windows\SysWow64\msimsg.dll
2015-06-10 21:08 . 2015-06-10 21:08	6112072	----a-w-	c:\windows\system32\usbaaplrc.dll
2015-06-10 21:08 . 2015-06-10 21:08	54784	----a-w-	c:\windows\system32\drivers\usbaapl64.sys
2015-06-09 18:03 . 2015-07-15 06:47	3180544	----a-w-	c:\windows\system32\rdpcorets.dll
2015-06-09 18:03 . 2015-07-15 06:47	16384	----a-w-	c:\windows\system32\RdpGroupPolicyExtension.dll
2015-06-02 00:07 . 2015-07-15 06:43	254976	----a-w-	c:\windows\system32\cewmdm.dll
2015-06-01 23:47 . 2015-07-15 06:43	210432	----a-w-	c:\windows\SysWow64\cewmdm.dll
2015-05-25 18:19 . 2015-06-12 15:11	113664	----a-w-	c:\windows\system32\sechost.dll
2015-05-25 18:18 . 2015-06-12 15:11	404992	----a-w-	c:\windows\system32\tracerpt.exe
2015-05-25 18:18 . 2015-06-12 15:11	47104	----a-w-	c:\windows\system32\typeperf.exe
2015-05-25 18:18 . 2015-06-12 15:11	43008	----a-w-	c:\windows\system32\relog.exe
2015-05-25 18:18 . 2015-06-12 15:11	104448	----a-w-	c:\windows\system32\logman.exe
2015-05-25 18:18 . 2015-06-12 15:11	19456	----a-w-	c:\windows\system32\diskperf.exe
2015-05-25 18:01 . 2015-06-12 15:11	92160	----a-w-	c:\windows\SysWow64\sechost.dll
2015-05-25 18:00 . 2015-06-12 15:11	40448	----a-w-	c:\windows\SysWow64\typeperf.exe
2015-05-25 18:00 . 2015-06-12 15:11	364544	----a-w-	c:\windows\SysWow64\tracerpt.exe
2015-05-25 18:00 . 2015-06-12 15:11	37888	----a-w-	c:\windows\SysWow64\relog.exe
2015-05-25 18:00 . 2015-06-12 15:11	82944	----a-w-	c:\windows\SysWow64\logman.exe
2015-05-25 18:00 . 2015-06-12 15:11	17408	----a-w-	c:\windows\SysWow64\diskperf.exe
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"Syncables"="c:\program files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe" [2010-05-18 530736]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-07-28 53655680]
"OfficeSyncProcess"="c:\program files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [2015-03-18 720064]
"BingSvc"="c:\users\Lore *******\AppData\Local\Microsoft\BingSvc\BingSvc.exe" [2015-04-07 144008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"File Sanitizer"="c:\program files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2010-05-06 11268096]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2015-05-15 60712]
"QLBController"="c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe" [2012-09-12 334240]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-04-30 334896]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2015-06-16 421888]
"Avira SystrayStartTrigger"="c:\program files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe" [2015-08-03 66936]
"avgnt"="c:\program files (x86)\Avira\Antivirus\avgnt.exe" [2015-07-15 782008]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-7-29 1132320]
PHOTOfunSTUDIO 4.0 HD Edition.lnk - c:\program files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe -e "c:\program files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\PHOTOfunSTUDIO.exe" [2011-2-11 146264]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2010-04-28 17:39	75320	----a-w-	c:\windows\System32\DeviceNP.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages	REG_MULTI_SZ   	DPPassFilter scecli
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 AntiVirMailService;Avira Mail Protection;c:\program files (x86)\Avira\Antivirus\avmailc7.exe;c:\program files (x86)\Avira\Antivirus\avmailc7.exe [x]
R2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [x]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [x]
R2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe;c:\windows\SYSNATIVE\vcsFPService.exe [x]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftVCapture.sys [x]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys;c:\windows\SYSNATIVE\DRIVERS\DAMDrv64.sys [x]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe;c:\windows\SysWOW64\flcdlock.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 massfilter;Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys;c:\windows\SYSNATIVE\drivers\massfilter.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\drivers\WSDScan.sys;c:\windows\SYSNATIVE\drivers\WSDScan.sys [x]
R4 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 SafeBoot;SafeBoot; [x]
S0 SbAlg;SbAlg; [x]
S0 SbFsLock;SbFsLock; [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys;c:\windows\SYSNATIVE\drivers\mbamchameleon.sys [x]
S1 RsvLock;RsvLock; [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\Antivirus\sched.exe;c:\program files (x86)\Avira\Antivirus\sched.exe [x]
S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
S2 Avira.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 HP ProtectTools Service;HP ProtectTools Service;c:\program files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe;c:\program files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [x]
S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe;c:\program files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [x]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [x]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [x]
S2 QDLService2kHP;Qualcomm Gobi 2000 Download Service (HP);c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe;c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 SMManager;HP Connection Manager Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\SMManager.exe;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\SMManager.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 DEBridge;DEBridge;c:\program files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe;c:\program files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 qcfilterhp2k;HP un2420 Mobile Broadband Module USB Device Filter;c:\windows\system32\DRIVERS\qcfilterhp2k.sys;c:\windows\SYSNATIVE\DRIVERS\qcfilterhp2k.sys [x]
S3 qcombushp;Gobi 2000 USB Composite Device Driver(03F0-251D);c:\windows\system32\DRIVERS\qcombushp.sys;c:\windows\SYSNATIVE\DRIVERS\qcombushp.sys [x]
S3 qcusbnethp2k;Gobi 2000 USB-NDIS miniport(03F0-251D);c:\windows\system32\DRIVERS\qcusbnethp2k.sys;c:\windows\SYSNATIVE\DRIVERS\qcusbnethp2k.sys [x]
S3 qcusbserhp2k;Gobi 2000 USB Device for Legacy Serial Communication(03F0-251D);c:\windows\system32\DRIVERS\qcusbserhp2k.sys;c:\windows\SYSNATIVE\DRIVERS\qcusbserhp2k.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MBAMSWISSARMY
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-08-13 07:46	995144	----a-w-	c:\program files (x86)\Google\Chrome\Application\44.0.2403.155\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-08-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-15 08:16]
.
2015-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-15 20:26]
.
2015-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-15 20:26]
.
2015-08-21 c:\windows\Tasks\HPCeeScheduleForLore *******.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 10:53]
.
2015-07-23 c:\windows\Tasks\HPCeeScheduleForNB*******$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 10:53]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2010-04-05 186904]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-07-21 8192]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-02-09 489472]
"HPPowerAssistant"="c:\program files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe" [2012-03-14 15232]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-05-24 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-05-24 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-05-24 416024]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-04-29 1337000]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2015-07-11 170280]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{d8f67242-b229-4065-95fa-391b077ed6ca} - {d8f67242-b229-4065-95fa-391b077ed6ca} - mscoree.dll
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 192.168.1.254
Handler: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - c:\windows\System32\mscoree.dll
FF - ProfilePath - c:\users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\
FF - prefs.js: browser.search.selectedEngine - Bing 
FF - prefs.js: network.proxy.type - 2
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-HP Connection Manager.exe - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Internet Explorer\Approved Extensions]
@DACL=(02 0000)
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,3b,1b,0c,15,c4,
   03,9b,ba,ed,0e,bb,9f,b8,17,8e,64,f8,df
"{3134413B-49B4-425C-98A5-893C1F195601}"=hex:51,66,7a,6c,4c,1d,3b,1b,2b,5c,2f,
   2a,82,1b,32,0e,86,ac,cb,7c,1d,53,13,1d
"{395610AE-C624-4F58-B89E-23733EA00F9A}"=hex:51,66,7a,6c,4c,1d,3b,1b,be,0d,4d,
   22,12,94,36,03,a6,97,61,33,3c,ea,4a,86
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,3b,1b,74,c9,2b,
   8b,34,1e,d1,06,90,c5,13,24,74,42,26,da
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,3b,1b,79,45,9b,
   b5,6a,7c,ba,02,91,72,b3,b7,87,50,01,8b
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1d,d3,
   c0,73,f6,35,0f,a2,7d,de,65,c3,8f,cd,b5
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,3b,1b,ab,8a,0f,
   6d,c6,84,42,0a,a8,e2,96,9a,f3,93,68,5f
"{4D2D3B0F-69BE-477A-90F5-FDDB05357975}"=hex:51,66,7a,6c,4c,1d,3b,1b,1f,26,36,
   56,88,3b,14,0b,8e,fc,bf,9b,07,7f,3c,69
.
[HKEY_USERS\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (S-1-5-21-3921111220-2900040076-1547133076-1003)
@Denied: (2) (LocalSystem)
"Progid"="Outlook.File.eml.14"
.
[HKEY_USERS\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (S-1-5-21-3921111220-2900040076-1547133076-1003)
@Denied: (2) (LocalSystem)
"Progid"="Outlook.File.vcf.14"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_232_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_232_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_232_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_232_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.18"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\r?\ÃLïWo***]
@="\08r?\\??o?\04"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*
]
@="?"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\Antivirus\avguard.exe
c:\windows\SysWOW64\bgsvcgen.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files (x86)\ Malwarebytes Anti-Malware \mbam.exe
c:\windows\SysWOW64\SAgent4.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-08-21  23:24:15 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2015-08-21 21:24
.
Vor Suchlauf: 13 Verzeichnis(se), 308.583.989.248 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 308.628.742.144 Bytes frei
.
- - End Of File - - D126161745A85C41F52B0A1976C7CAA2
A36C5E4F47E84449FF07ED3517B43A31
         


Alt 22.08.2015, 18:05   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
--> Windows 7 - Browser Hijack

Alt 22.08.2015, 20:45   #7
mezzomix
 
Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



MBAM
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 22.08.2015
Suchlaufzeit: 19:18
Protokolldatei: mbam.txt
Administrator: Ja

Version: 2.1.8.1057
Malware-Datenbank: v2015.08.22.03
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Aktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Lore *******

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 463246
Abgelaufene Zeit: 35 Min., 46 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         
AdwCleaner
Code:
ATTFilter
# AdwCleaner v5.002 - Bericht erstellt 22/08/2015 um 20:18:25
# Aktualisiert 18/08/2015 von Xplode
# Datenbank : 2015-08-20.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x64)
# Benutzername : Lore ******* - NB*******
# Gestarted von : C:\Users\Lore *******\Desktop\adwcleaner_5.002.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Ordner ] *****


***** [ Dateien ] *****


***** [ Verknüpfungen ] *****


***** [ Geplante Tasks ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Internetbrowser ] *****


*************************

:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht

*************************

C:\AdwCleaner[S1].txt - [5604 Bytes] - [20/08/2015 17:44:47]

########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [810 Bytes] ##########
         
JRT Part 1
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.7 (08.18.2015:1)
OS: Windows 7 Professional x64
Ran by Lore ******* on 22.08.2015 at 20:28:05,13
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Classes\TypeLib\{006ad7b2-968a-11de-88c9-5bde55d89593}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer



~~~ Files

Successfully deleted: [File] C:\windows\SysWOW64\sho23DB.tmp
Successfully deleted: [File] C:\windows\SysWOW64\sho3E1D.tmp
Successfully deleted: [File] C:\windows\SysWOW64\sho4E39.tmp
Successfully deleted: [File] C:\windows\SysWOW64\sho9DAB.tmp
Successfully deleted: [File] C:\windows\SysWOW64\sho9FE1.tmp



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{00010BE0-4ABF-492C-9538-B11CB72D3120}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{00398B4E-FA13-4094-AA93-3D7CA5AEF05E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0081FB93-15DB-46BB-B96A-BB228B82405B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{01115CCA-2314-4451-90F4-E1AA4B6523E8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{014BBCD7-0EBA-4984-9538-0CF9DF0B5C6A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0199E560-A855-42D9-BDC7-3BBF6249E53B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{01A85BDC-6733-461B-B15C-6FB1CEA9434D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{01B7C4F0-AF03-4C8F-B147-B8FA6940DEC8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0217CE8A-7AF9-41D1-9065-1FF35F0D7CC5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{021C3B81-C107-4053-AA02-1A77A64600EE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{02910769-AF3E-42EE-970A-C3BA529642C2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{029752D3-65E1-48C7-820B-0534C9156004}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{02B05202-9A44-43D7-BFCC-931FBA852FAA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{02BB4BB9-1299-40EE-B49F-CD95D8791B2E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{02C30E40-948E-4EB7-B0CE-D232A40DFB9A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{02CFDC68-2757-4154-B7E1-F53E95806D0F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{031751AA-B3EA-44E3-98EA-CCD1EB88F353}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{03537DC8-18ED-4CC6-A61E-783AE962F0DD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0394BD0B-6156-4C80-892C-7489210B6D0F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{03B9E678-CB35-4CB5-8444-4F21E95E4E97}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{03CA4340-D48D-4C59-83A9-8982D9EA5736}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{03DE9684-D24D-4893-88AB-FB228C8F35E0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{03E3AAA2-F32A-437E-92DE-D04302E45001}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{040EF0F1-9E4A-4DBC-B55B-07F631EDBA82}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{041101E7-CE4A-451F-B211-7E333F100D05}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{049B2501-BAD1-47B8-B730-4A3017B050CA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{04C12CE5-43E4-4C27-BDAF-6AA461957F68}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{04EC0B30-058B-4249-A48F-79B70EACF6AF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{051505ED-DCCF-4D3D-8FEF-0C012C41F1C0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0534EBCC-587D-4F90-98BF-3C66A793BDA6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{05359943-D437-4227-9F66-DF8260CCD677}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0539BF93-EA68-4DFE-A128-77323B72B19E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{057C1446-7239-4462-8BF9-A2D29DC8BFEE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{05B7C8B7-BBFE-47CA-BDF4-550333176FD6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{05C3AEBD-C1E2-4C15-AD2A-2B7681F0D531}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0609DF2C-A299-456A-87DE-4F7CBB36B054}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{063F3A66-D904-489F-B281-31D95847C9DB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{064257CD-6AFC-4DC2-9EE0-EF1C041BF51F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0673CEF4-0BC4-42EA-AA7B-A2F9B46E8C9F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{067C0FC4-6D4A-483E-88B0-FCA0DD03825E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{06CB1E9B-D99A-453D-B3C2-03C96260C43C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{06DE4CE3-4EEC-4987-A397-22F5C97BE5AD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{06EEF080-8C03-42D8-B2D3-8A0EB68492FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0718E36A-AC91-45C1-A56A-0A2CAA74335F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0759B19B-AA4C-4559-96CF-B283326984EC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0768D91A-D46E-45E7-8E8C-1FAD27A80689}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{07C8B083-09D8-42FB-A826-7955E33A609C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{080FD83F-36F1-4C75-A6F9-760877020E7D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0821DB9E-0DAF-4517-8117-6F4693A05EC6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0845192E-A05C-4C7C-A9EB-AAA25B50B1EC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{084AEB2B-0286-45A6-B93B-2760FF63CDEF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0867C3CE-D32E-4471-BE84-7AD423D9E00A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0888A462-FBC3-4700-BF71-A4D538359054}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{08A4332A-87E0-408F-977C-E55D9F885D43}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{08BD9307-1C5F-4B84-8011-831CA0151630}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{09BFD4D0-6CD7-4C59-8F49-6459AE7B46CA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{09E3D8FF-B686-4E42-B7A3-85A7C75E68D5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0A016F7B-4BCB-44A8-A7DD-0B0B502C5A8D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0A1FAF65-3AC0-4648-9032-E9724B2D01CC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0A575E31-F6CD-4BB6-B826-699A4CB2DB67}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0A9D06A8-BACE-4BB8-B33B-65C653050F18}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0ADCCF02-A116-4F7B-B242-A185F52AAEF0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0AFDD550-2109-497F-9CA2-91A3749C4107}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0B8A65AD-AE9C-42AB-9A75-8FCD928A3810}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0BCCA4CA-385D-47C5-AF40-9576634E3A6A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0BDFE1FC-12FA-48D2-BA3B-49C46D96B137}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0C053A65-CBEC-4ACD-9356-EB3DF75A5407}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0D276C79-8F55-49E5-978A-904531CFE70A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0D28A4D5-3108-4C6D-8B71-2BD8F6DD4403}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0D939B28-4F79-4E42-BB9D-352265BC672B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0DB8E7CA-3F99-4FB8-9EAB-A6AE74EC1599}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0DCABBC1-473F-48ED-83F8-6AD27CA9A596}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0DE35FEC-FB46-4B5D-8F6A-E338FEFDC01B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0E6044FE-B361-43C7-B3A6-95D7FABC70CB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0EA146E8-ABA2-4ABF-8479-E5D77B9AB3B2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0EF41E3E-8030-4CA9-8382-E268A9AEDCCF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0F0D99A7-8482-4263-8E84-9717FB9732F0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0F1F12DC-787B-4A2F-B924-D96549D5A750}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0F568A97-9328-4E6B-86A7-147D03A08CE2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0F579316-FCD3-4924-811E-5C36BEFC1E4B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0F69F8FE-56A8-4CDF-BB5A-76F0B62F74FD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0F6AC879-5B0A-4DF7-B418-47D3DB3669A9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0F819A00-B092-432F-AF00-6835FAC7FFD6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0F9E53CE-804B-4ACB-9E6D-88E1030E3A16}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0FC1F6A3-AFC8-44D5-9769-8AA614460672}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0FDE4F74-E0B6-4BA9-9A31-04AF00467BDE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0FF70CC2-2C6D-43B7-ACBC-520502D1DD1E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{0FFC9CF3-D551-4508-A59B-FEB60B2671AE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{100BC4DB-7BD3-46C9-B6B9-132B2250F061}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1010F9C2-EDD9-4DF5-9374-689780A37ECD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1070468F-DCCC-4B1F-BE40-7CB41CAD81FD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{10798341-D565-4F43-AA4A-7E3D0140ACD7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{107DEFEA-7306-412C-986B-5F697469CF95}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{10B11DEC-A3AE-4FD8-A4C4-F449F3541876}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{10C0B248-2B0D-4B79-B51F-B7038EA5A8E3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{10C6316F-F3D8-4137-BF46-DF7FEC44AEDD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{10F07B80-D11C-4363-82A7-2AF0BFA3AA93}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1108DB17-9ECC-455C-B5AB-9A9535783494}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{110E5166-917D-4713-A48D-B29179316008}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1112FE08-0F95-47C8-BF8C-E0ED28963FFF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1121B9E0-D5FE-4920-8589-4DE7AD557829}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1181BFB1-FCFD-40AF-B5AC-87307613FF90}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{11989703-11F5-4252-86BF-886BE36BD12F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{11AB4C0C-53EF-49A8-A9E2-281376ADEA83}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{11D70D34-2C17-4CAC-8024-5929D1C1F865}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{12310073-3899-4A34-820E-7916A8FDEDC8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{125BFE6C-5515-4819-BE71-CCEAB2763394}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{126AB116-8438-470A-826D-3652CFF0A49B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{12790253-430D-4A8E-83F0-2ADF89CD9FC7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{12C49CA4-A809-4D51-A8DB-AC9902AEEA40}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{12E85C2C-FE4E-4734-9601-F9D185AC2260}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1302A653-7F71-4A68-B366-70C9D84F1474}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{13121151-C157-43D1-908B-4777B441E8B3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{131CA998-FC16-48C3-AB7C-992117891F4F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{13214F88-7796-4036-998B-D8DCE7B77146}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1359BC76-603E-4750-979A-05A65B4D9462}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{13936628-D9AF-451F-A93C-530F88725661}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{13A0C365-E9DA-4DEF-A131-7C9578E35CCE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{13AC9A37-CBFD-43EB-B91D-8D6DD4EB2B84}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{13DE38EB-D82F-4241-9331-34A676D92E7D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{14059791-55DD-4CEF-812A-A2DC6419894B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{146905C9-ADB5-47AD-930D-A8A851737AC4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{14CE3DF4-9AC6-473C-BE71-D28E520B26A2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1531C103-D4DD-40E4-9C63-54E9DA991D62}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{15AED539-8395-439A-B3A8-E397C0A0400E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{163092F5-30CC-4DF2-9036-70507473A5BB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{16764096-F38E-4955-A897-2FD098867929}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{167CC17B-EC4D-4BBA-B24F-63B1EE8706DC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{168DB16A-A37C-4B07-9715-17DAC0570C5C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{16D74D18-9363-4BEB-9EF4-0A07E3E16425}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{16E0E4EA-18F4-422D-ADF7-D546FED27438}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{16E2558F-D2D3-4A5B-B3DE-BD6DCEE5DB42}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1732B5BA-3F71-4289-AFEF-6EBF3081B83E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{17436FB4-F637-4D39-B196-B69FBA83E779}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1766A084-7791-405A-9160-26EC4C478482}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{178C43D1-5E11-4B0B-9A18-8B4F920EBAAE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{17A65F1E-D43B-4377-AE10-E375095150C3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{17A7569A-22BA-4DEA-A539-42830C80C628}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{17B3DF15-0D63-40C6-A8AB-CAF9548965AB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{17DA16B3-53EC-40F4-A38F-67F8EB035B42}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{18871ECF-BC2F-41AD-BE35-888F90B67E20}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{188EE9C7-7228-4229-80C6-7673C8EE1EA1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{18D1E292-F07F-4EDF-8320-48BB6B8DE358}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{18FA4ECA-79F3-464F-8425-B4C2F4B62AA0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{190A07AE-7742-4245-9DE6-A2DCF2BA7D43}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{193C90A6-69EA-450C-8C02-152FC44AACE3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{195889B8-3A3A-4DAD-AAF6-27DFE29E60DD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{196CD81D-C9D0-4DE9-AD7E-CA85E180A022}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1988EE91-5743-4B67-9618-B9D265ACB568}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1993402B-6727-442B-BDAB-30D03C1846F5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{19E46131-3160-416C-8D62-0D71362D4116}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{19F7A46D-DB8D-43C7-B4DB-C28CCDAB9B8B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1A0102E8-B918-466D-B8AC-63509B0CFBF0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1A274289-25EE-42E0-8195-DDB704A1A4A6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1A60EDDB-D27F-41DF-9DA3-2E46B9352A3E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1A730E4E-1EAB-4F85-8243-169C5B0763C7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1A84FAC5-0E12-4DD4-9FFC-002585CBBBA3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1A8CC882-2834-4C13-9EBF-ED5FE4A00BC7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1B47EE1A-0146-4031-A2C0-07C164D2084E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1BC26575-E431-4E11-9FA3-106F117D656A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1BC53A9F-E1AA-4114-AF12-ED9C0CCD3165}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1BC76188-95D4-49A2-940C-587DE97F4141}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1BD17BCE-F1EA-454A-A144-FEA9A5957D8C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1BE02651-E108-4B68-8747-F935C86FCD12}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1BEBD0C2-4400-4200-A922-9EC8A13FB4C1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1C29B958-B702-4531-A980-11A071DEB5F2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1C36728C-AFF7-412F-B69D-7F3F8D31FDBA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1C98650D-3D9F-445D-9AD0-5E60252E0C7E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1C997ECE-A38D-4EF0-9931-C4AE1782A9F9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1CA15065-31EA-4DCC-A373-6ACA4D336A6E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1CA21CC9-FE44-45F5-8BC9-3FD0CE43DB51}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1CA2D6C5-E13D-4EA0-8B96-C033C3556224}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1CABFA5C-2576-4EFA-9871-52693A9004ED}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1D1D34B1-D16C-4B57-87BA-74A109285C22}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1D3750D9-EFBC-41CC-AC91-BF81B3D306E8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1D50F69C-EA35-4933-9F6F-CBCECACCD173}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1D72F79D-7D81-4314-9864-11FB216596B0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1DAB375A-479A-4CCB-A24E-E7480107D94A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1DC3ACD5-007E-4875-B685-95C668646BC9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1E13D86F-688A-4D24-91BC-068B54A8494E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1E2A3C27-E971-4846-A7AC-F6312EE7F9D4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1E7EE4D9-4356-4E3E-8223-92C52F975719}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1E863004-3576-4F77-A486-4454DAB9C3FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1E879CD5-2935-40CD-AAC3-5967F8F89584}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1EBE7203-BBB8-4B91-BD4B-27FDF06FC605}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1F8A06C5-6E5A-4F25-9E9E-E89F25994EEC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1FAA5045-FE3C-4316-B5A7-71665D48B893}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1FBE5A53-6794-4192-87B8-2771DD134E94}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1FC12283-F88C-40F3-9D50-1518D60812BF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1FE2193E-EDDC-4FA1-85DA-3A6AC7BAFF27}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1FED1AE2-2CC4-4B9C-8CDC-DA8D87F918A3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{1FF8C995-8056-4A43-A526-6D6FD7772BEF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{200189F4-2F16-4018-9FFC-2970142344C9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2006C9E9-0C26-4554-BD82-489656CC2CDC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{203F2CA5-F2AB-4AAB-85D8-8C3B249614C1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2041A56F-83A0-4301-AAB8-F5F53294120C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{20508C57-952E-4E44-8AAF-4215831835C4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{208A9B36-4B7F-44AC-B70A-B61FDD8B9005}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{209DA9DF-49B2-4676-B233-E63EFF0ED3AF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{20DDFE09-54A0-4112-B3A6-B5A2F7E36F10}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{20F384CB-B294-4C5B-8C25-449D9DF7A8E0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{211BC33C-FAC7-4B6A-9A4C-CFC77720D09F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{218149D4-6817-4048-A37E-A9CAF9E17F24}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{21831299-080E-4D4E-A91D-F3FB398C30F7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{219C41E6-A2AF-4F52-9457-C7C4D17FAA00}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{220C5B08-A322-4BFD-8C0F-085E33DE4A4D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{220E1F9D-8970-411F-A375-78368C1603B5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{22489F5D-55A0-4EF1-B1ED-2988F8A121DA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{224C5F93-9501-4A60-B428-BE3F69435D16}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{225022EA-BE58-4425-8C26-C1A505990CF1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2251ED4A-DCCB-40FF-A847-30B484B741B2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{22695B3F-1ABF-467F-AFCB-40F3CB9C389D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2273567D-772F-4EEF-8780-B1E1575FEAEF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2283BE07-2C37-462E-8506-D6BA22261FE1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{22862E26-9569-4A67-BA7B-08E6B4FFFDE3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2292AD8F-86EA-4998-9804-B8F476D5055D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{22B23D14-463C-421C-BF10-02DFAD95D3FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{22CE2A4A-A914-4C50-B80C-BE8442CD56C3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{22EDFFC3-9706-42B9-9A6E-4EF15977C370}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{22EFE19B-B796-4740-B972-83AC08423EDF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{22FE0B8E-D082-4183-9067-0E1F15D718F8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2315FE08-7B5D-44A6-8920-0515F6AAC8F8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{23239C20-6743-4E6E-BE04-937808239122}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{234F5EFC-82E5-4E32-B100-04EF7D42B0F6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{23C3E24A-97F4-4EA2-9BB6-2FF931A0F322}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{23DCA690-71D4-4EF1-8E64-40D140625B1F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{23F27BE3-3EE0-4C74-ACDA-A56E6FF3ECC4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{24699FD8-E357-4975-A833-8C940DED940F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{247BB9FB-10B1-4DA9-AEF3-ECD02F464C88}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{24825B75-833A-4018-893B-6D75BCCFC719}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{249CDA92-CA04-4164-983F-A880D51AC185}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{24F8637F-C646-4425-AABD-CFA433B3911C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{24FAE840-68D8-4A99-821D-14167D75E236}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{24FCA236-B814-4697-88AF-CE9308738447}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{251BC8AA-9756-4CA1-8F4C-B8EF544C5419}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2592EA2C-C37A-4DBF-AD3A-140C41470EAC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{25D5E50D-9359-4E1F-A082-44E2781DBA4E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{25F0CD49-908B-4A4D-AD3B-A79BA71AA986}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{25F3E5EA-C79A-4A1F-A314-12B76B3C102E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{26355BD9-6DDA-4511-B76A-D8861EF0F548}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2648CB63-9D4C-4A0E-A4E0-0B1BD18B2B74}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{265D8338-F232-4176-B97D-DD2D94BDA00B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{265EED7E-6307-499E-95A3-246324CC9DB9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{26686E03-AD0A-453F-82F3-6499E2AA179F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2694BFE6-622A-4B08-A173-05F0DDDCD2E9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{269C1B12-1B37-44B9-B8DC-D8AE8B7C5049}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{26EFFA6E-6265-443A-A77B-A569B25CEF9C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{26F15D9E-16EE-4B34-ABCE-C5CF57E666F5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{26F28890-826A-4892-9AD9-659928BFB57C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{26FB501D-F452-41DF-A29F-B10E6136CFC2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{270C11F3-539B-4637-9412-4436C3FA5D5E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{272436E4-CAF9-40D8-83AF-DA908B72FED6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{274A632C-2994-426E-BB81-B9AEAE941226}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{27538A3D-C024-41BC-97BE-C114B3489DF0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{275B5098-1879-415B-8716-BE6F66434288}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{27B4C0FA-BFBB-4E9F-BB4E-AF45CD2105C1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{27C7DA2E-BB17-40E0-B54C-209134A0B3DC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{27E64E34-C2CF-4E88-87F7-49DB29723F1B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{27FA453E-E762-4212-9D8F-C5CC21BF6442}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{282CBDB1-1735-46C8-8F38-E91FAA46AE6E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{28310235-E07C-4899-AEAC-93CC8B3F09B1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{284775D5-6C39-4A62-AF2A-E7AEDD489BB2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{284BA7FC-3BC6-4214-9D54-C3BA851585A4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2860B258-B379-42BB-AF30-B03EFC3650FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{287ABCD7-C5A3-4016-BA71-762E81CDD6D4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{28D7D5D6-D1A3-4D22-AE8F-B38D64C1FFB5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{28F9F9A9-3DF4-4351-ADEC-3BEEA4D87C9B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{299C58E6-7C7A-417A-8D8C-589F7D5F9D9F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{29E30BCF-5A87-4910-AB87-D561316B833A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2A166878-B1B8-440E-8AEE-7722D3D59696}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2A54EBB4-5F99-4DEB-8297-9E84E06CF123}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2AAFA0FF-B5D0-42F6-B5E4-0ED112D9F7CA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2AB7EE4A-0AD4-4911-B1C4-E4334BD8973C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2AD9DBA1-A6B1-417A-8B8B-A8A3E84A5525}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2AE6B68D-7B87-4662-915C-A93796FEC5EC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2B02316C-03F8-4EFB-9C9E-853C5587B237}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2B1CF294-AF6C-4F0B-8E10-624EF3C74C3C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2B5F14D5-16EC-4F70-9A5D-A131EF106A7C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2B60AF2B-843A-430C-936C-42CBB40265D3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2B760BD7-7377-425C-A0D6-72D77C0D7679}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2B818BFC-C034-4EF5-841E-E47799C571B1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2B93258C-3EAC-4965-AC4E-404B94C3318D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2BB5994D-EC4F-448D-9433-000DB8394679}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2BCE6602-4E07-4789-A03B-9D735962A5C9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2BDDD8A9-5ABD-4F79-9272-F80FD4142A2A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2C3BDA56-94A8-48FF-873A-4EA284C6032A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2C3D04D1-9FE4-4968-B43B-B1E7AF683513}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2C748B8D-90BD-463F-A3DB-986A5E2B9C8F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2CC1039F-BEF4-4988-B7DF-5426457FD7E0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2D0598FC-F2F8-4142-87CC-81C31A2599B9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2D2934C0-484D-4D4E-AB86-0FB0CB36CA66}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2D4088C0-C6B8-42D3-9CA4-A0BC04C7FAEA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2DD0D374-BFAB-4F16-92A8-D81279C475E3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2DDA4095-351E-4B4F-B92F-D8FAA889A44F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2DDDE7C4-D1EA-41F4-BAAE-269B236B8811}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2DE1DC66-7C61-4C71-82BE-8BA956804300}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2E46A74E-F0AC-47C7-A87D-F97B43070F23}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2F0E2466-4ACD-4A81-9F92-D51F7480221A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2F12CD9E-55DD-4A1C-A981-8E24F2436601}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2F5A5BB2-B394-4751-9028-D6C4462D79A7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2F7C9E83-B2F0-49FE-9A99-8ECACCBDC129}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2F7E5457-784B-41C2-BE98-E502CD450C35}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2FAD073C-D056-4A30-B594-93A8A8B8ED76}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2FDFD5E4-FBF8-4F88-AAA8-C0481C57E937}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2FE46CEF-2238-4A52-B551-5E94C5565F17}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{2FEB48B3-D489-4CD0-97F0-0BC0956F501E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3008A998-3615-44B4-937D-3733011B9808}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{306D0751-CB42-425D-BC50-1317D988D157}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{309F96EF-BB5C-49DB-A1AE-6EE348E44C6D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{30C20431-A311-4203-BA6B-75BA863B1419}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{30C8EDED-C130-45D1-BFD4-736DFBDFE0B2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{30E46569-EE78-4438-AE6E-A90FEF128E8A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{31229BA0-EE18-4CFC-8F25-8A24233CB2D0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{312663CB-E02E-4ED0-B23A-007186820CA0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{31431654-F6FF-44B5-9473-E26F99C8F562}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3155DCF7-270E-4D13-8454-9322C4A07D2D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{31621F9B-5982-410A-A881-E3E01C0E3183}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{31833220-4707-443E-A4DF-5DF54AD4F980}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{318F208A-A985-47A9-91B8-B2E9E315EC84}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{319E988B-0262-48A1-9A9C-0A2BB5364249}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{31D498B7-F3F1-4E2F-812A-EE8D271D042E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{31E437AA-3C9E-4C75-8A49-A47164EBDA9C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3207C410-2F70-43D7-8375-DA9D01D0C348}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{324148DA-955E-40D9-B0BB-72D732931A51}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{324C1DD7-5E8F-407B-9383-1D335DDDC4AB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{328CC9F1-AA72-4D35-8C95-495B699E28D6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{32918609-CE9B-4216-82EC-9EA3272E9139}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{329808AB-8C95-4462-A768-64DC8CEF069C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{32BD208C-2F00-4C21-9FA8-0D83A54B66D4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{32CE4D2C-802A-4A5C-8873-4BD2F357D7E9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{332460B2-8783-48D6-8F3B-5248387272E0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{337F3372-7697-49F0-9F43-F1D6FFBB8288}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{33900F2D-A1E2-4E83-B7C4-B6B24A01294F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{33C0BDAC-FE4F-44DC-8251-44A8AFBDCB16}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3413DBC7-1C91-485A-8166-04B51EBF49AA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{341EDFB7-F16C-449F-B3CF-A7476DD45C0D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{34578FF9-AFF0-4DD2-BCB2-858CD2C93F37}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3479BAE7-FB03-4EBA-810B-89F7BBA83AA9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{347C2154-BDCB-43F1-8203-EC7A681DACA4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{34A641C1-7E91-4565-B12F-DABAAC1DF58D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{34AE6214-F550-4372-9F54-072AB0C40A87}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{34C551E4-248E-47A1-8A4B-DEA64E580D5A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{34DE1D97-46F1-422D-9C49-C499ECA1BF36}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{34F8E6E9-8457-45DA-B122-C35F15C73564}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{350C16EB-A60B-4FD7-80AF-D422597D0FFC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{356C843E-CD21-47F0-91F9-01BF77B537B6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{35B17798-FAE0-4C27-BD86-1688E419914C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{35C4B7D0-75DB-4503-846C-1ABAC77FB208}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{35E41E68-C986-46C4-8347-6D7FB02A63D1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3613785E-C162-438B-8B65-BDCF8E1FB194}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{361622CD-9209-4E29-BE16-8512D6A2DC32}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3676FBC8-04CA-47A2-B13E-1A109EA55995}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3727B3F4-527B-4528-A7F9-C63F88C5C68D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{37472D78-ACDC-4A44-B3F2-4324FB0798FF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{37EB6D89-49FD-4C5D-AE77-E00D4E96067D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3804F0FC-C9D1-4C54-BCCF-CB2AB6B45E9A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{39203C9F-163E-4239-A1A7-8B2FA1370097}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{393EE95F-A787-431E-AAF2-57D3FF180022}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{39735403-EC21-4594-A3CB-A6EEFE2BED76}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{398C0D2A-343C-4272-8F92-4C264F04A4A4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{399BF888-770C-4B98-A392-08F80BC18833}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{39D2210B-B7B1-4391-A36C-4C9CAF57F708}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3A25B0C9-DB04-405D-BE81-7FFB8E1228CC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3A6EDAA7-49DA-4490-9EA7-D432F02EDCBD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3ADA9ED3-F528-4BA2-BA05-C48EB0CB5A07}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3AE3A180-516A-48DC-8BF0-9693FA47D937}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3AF206B5-5524-453F-BC4A-C230F78CFD40}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3B19587F-2E6C-4D89-BD44-C96F1547FAD7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3B210FDB-0696-4743-8D80-BB963E2CBFC9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3B712E64-06FF-407F-9AA6-F4C325D11FAD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3B9B18CC-3B65-4795-BF8E-DE7BF4BBCCD9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3BA4A68F-4B92-4FE3-A04B-50BDAE197A60}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3BBD74A0-356F-4FF4-871C-328ED0D47F7F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3BBE34BA-D254-4920-8BFC-5A0528E718B5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3BC18FCA-974F-4DC1-A4C5-9E48D40C53A1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3BD4C084-1A4B-474F-8756-AC41B13C5996}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3BF4BF8D-5CB7-42E4-84FA-07BE04D8EF75}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3C084AB5-9912-478F-8BBD-4A22D561B4AC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3C109D9A-AF67-462B-8900-914146FA1886}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3C21FC8C-10C1-47A5-B4A8-7DEFBE154DF3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3C72E16B-892E-486F-9E42-86ACE3CE3CB8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3C78D4DC-28C2-4A31-B67F-08BF9D5A037E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3C99780A-5622-44D4-87FF-FB8B6530050E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3CA19CF7-0511-48E0-8C37-0731CA8D5D67}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3CAA0309-DC36-4B63-B6B6-A68CB1B068FC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3CBC76BD-57FB-408C-B50C-260702A39D18}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3D0333FB-89B9-4691-8338-744EEE26698C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3D348359-0200-478E-9DA8-AB0B38DB9EBE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3D3E6CC8-D595-4915-944D-6D94017C6C64}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3D4B9327-E386-4474-B990-B3D94A9BF360}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3D7B636F-0041-4758-A4F7-8F49681EFA90}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3D96C924-ABA3-48F5-AFA0-6443D6954C12}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3DA2D04F-C654-4805-BBDD-A20B9FB2CCE6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3DC10D41-F72A-455F-912D-E2720100B5F7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3DE2921B-D3E9-4B22-AAA6-089DCC54A5BC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3E2C4C8D-E8A0-474A-8E8C-9B5B64D89FC1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3E384910-6287-4175-A74F-00CD1227305B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3E5EA75A-64CC-44B5-8C2F-00E98D7EB974}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3E981FA3-F118-4979-ABF3-A20151C61F19}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3EC2AED7-CE83-4372-B4CE-FE0D900E548F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3EE04E4A-0DD8-4495-8BE7-CFDBE902582C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3F0EC5C2-44CE-48E9-8681-37382312FE0C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3FB179C3-3032-436C-B10F-5D4C5F8EEA78}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3FC7BD71-36D3-4521-8316-06CAC973174D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3FDC713E-7F1F-4126-B905-B1D75B3C6D56}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3FE2140F-44E1-4795-A0F9-7AFAED5DBE33}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3FEE8B89-877D-42EF-BAD6-76EA5CFABC47}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3FF22931-8F17-48BF-9B0E-5B927D707ECC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{3FFC1EF2-C480-47D1-8B20-853959BA1044}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{40A3EF4B-C793-45DB-88D4-CF368AD49354}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{40CD2907-0FCC-4DCD-9713-BC56481266A1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{40FA4AB6-4242-401A-9FAB-00B6E7BB6528}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{40FE26D4-0BCE-43FD-8699-9C1F4D7AFCDE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{414BD09C-7EC7-4938-9E9D-2BECD0DEA5BA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4159F5BF-AA3B-4660-BCEB-C3DF458D90FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4163B76D-C882-408B-A9EF-1A307E392B38}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{41781C00-EACD-4719-9422-8B0C3183C37D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4194D9C0-AFEE-4C47-AEE8-E08B4E57715D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{419972EA-027D-4720-A2F3-33FD337CDEE9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{419DF128-315F-47DB-B98E-7418D0ABF118}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{41A375B6-F070-4520-9643-77D9BD1B3815}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{41AABA05-7ADC-43E5-A63C-A9F3B0A1CE01}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{41BAD39F-5DEC-470D-AF4C-00DA18F20EEB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4214D3F0-441E-4B0C-B650-032210F2A5A6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{422F5E0A-60C7-47D0-A4F7-72199D92F905}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4252A561-902D-4737-A9FC-F02B2AD6070E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{42945A6C-2867-4A0B-8EB1-DB1380014D2F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{42B223BB-982B-4B23-9F7A-434F47E96630}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{42C9D509-7239-4531-9F44-9DD5D795AD16}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4300B83E-5544-49CD-9C68-2C6076F6AC5B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4302BD91-9B16-488F-A4A8-45BC67C05D82}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{43074C64-DB88-48DD-8C9D-66D379C91B25}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4328D12D-9584-4A14-9AB5-409C536D8FDD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{432B60B1-A157-4FAC-A363-E0FF06CF5ECB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4330B413-4726-4728-844C-58795305E70A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4344C31D-AC1B-474E-9A9A-AC084D98831D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{43506134-4154-44FC-85C9-EF387AB02E9B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{43572EE2-4800-417B-AFDA-208FF96AC147}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{43AEE766-749A-476F-80C7-721032A87219}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{440438DC-0322-44FB-835B-774B3B5B7D2C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{44177F67-9B3E-4A82-8B3C-889DE7C619E5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{441D6193-0723-4625-A4DB-49A7F316B3B6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{44458183-ECA7-4136-AC38-5AD2DDD6EAF7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4449CB2E-3BCF-488A-9F30-B4381DE0B9FB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{449E5FC1-DB49-4880-964F-8224956EA712}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{44B38ED4-50C4-453D-8C72-F67A63DDAC96}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{44B63DEB-F774-4EC7-8952-3335218B7249}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{44B97ECD-C86D-451F-A9F0-5019087C9925}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{45188C6C-E5C7-466C-846E-830D92074BC3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{456434EA-85C9-49CB-B3ED-84CD26A4A99F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{45761180-34D2-4E12-9D12-B028EEB3BBEE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{45AFEE77-2228-4C3B-ACED-834085C58956}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{45E16771-DF01-48C8-A352-F0F0327254DF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{46033C1C-2E23-4482-89EB-C471387972C4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{465CF22A-60BB-41CC-BAE1-1D01D1886D74}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4664B156-E275-4281-A7B1-C6703D8F2A45}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{46714D2A-41C2-4F7B-9044-44DBAD2BBD78}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{468D8F59-FD89-455F-B20C-A6E7B4CD5425}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{46CC1CE1-BB9B-4063-969F-50F31058A8A9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4730983F-B2C2-4485-B1BA-CFA659158D21}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4739C6A8-FD89-4C11-80E3-14CD00CC614E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{473C2130-59C7-4A2A-8BD2-AEB0DDC6D805}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4745F8F1-65BF-43B5-BA13-D17CD4C6A2F4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{474CF847-ED47-425D-A321-22BCFB09A385}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{475D603F-33D6-42C2-A1AD-04DE1574EB47}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{475F56D3-F87E-4436-A0A2-6F6F211E8150}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{477FD46F-7E96-43CA-903C-F8E8DF48CE7D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{47885078-AB73-47AC-9569-E3D558877A64}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4792C639-2C47-4B87-A1AF-6C0C1F15CED6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{47AF2B27-7596-40B4-A72A-65C994F0136C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{48674C2C-F651-4378-83AD-A933C5376090}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{486B2E51-7836-481C-8CBE-00D7D6B090F5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{48A09D70-3C28-4DB7-A262-30479BECB81C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{48D76BAB-E86E-4283-8540-7B092627A826}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{48DE924B-1F69-4A0E-87D9-A6914D299E33}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4904F915-3277-490D-8B32-B577A21D0AED}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{490EE35D-FCA7-4ACA-8B4E-262433C2503F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4932C1B7-A26B-4E0B-A32D-5B8B6545AD70}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{498AE9FF-D3C2-4408-AC25-C7B43FD0E6B0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{49CFF4D2-17B1-4FA4-86B8-925A5969490D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4A0DA932-36ED-458D-AF53-3EC6A84408A3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4A2DC389-FEC1-4956-8D11-E91E1DB34E39}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4A507C77-C00B-46ED-B37B-5C3472960982}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4A715D1C-CA3C-4E55-9F9A-DAF520365560}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4A7195D5-56F0-475B-AF4D-362C9F0A0ADC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4A72AF5E-1782-4D18-A8ED-E8361D3B833E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4A7C02BE-FD0D-47E6-A6E5-E74CB39A1424}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4A7E8829-168C-4EE2-A9A1-4DB3BFF825B4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4AA9BD1C-5B38-475E-9CFB-93C7E61BE893}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4ABBE8EC-916B-4AEA-B534-C95964557F1D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4ABCB051-4244-472B-BCB3-73561A8B565B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4AC1B3C7-3DEA-4AA4-A18F-BDC2B2D9239D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4AC7B9E2-ECA9-492B-B930-FFB6A51D9935}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4ADC5270-0783-43BC-BE39-B7CD590E6F20}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4AF4A29C-99B0-4110-B584-AE18C9E05B6D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4B10AA36-4E7F-496F-AEE0-EC0561991ED9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4B10B0D9-607D-433E-92DA-F01BC6393A64}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4B28DBBC-34B9-4E3C-927C-DCD5F7BEA24F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4B793447-6E22-468D-9ECC-CAAB1FFA3AA5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4B9AB022-DA36-4720-83DF-816FCB5BFE79}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4BBB3CC4-4137-4618-99B7-906AC5F5F7DA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4BC2E442-836F-4809-8A6F-78C122F8D330}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4BC3B298-A583-4938-A63B-E476B05D7F1B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4BF257DB-C4DF-482F-BD51-6B22C96426C6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4C397107-DFF2-4BD7-AFFB-20D9FA642DF5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4C909651-7481-4B93-BC48-251641BC6FCE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4CC3EF2B-6DFB-4EA8-9891-FD4773B63DD1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4CD01E25-0559-4F5F-9863-1EF61A199CCF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4CDCBFCC-3940-488A-9E71-267171FEF5EA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4D04BA62-4413-4CD2-B445-7E36043AA17A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4D2D3180-25CF-4267-ACE9-6586EE762869}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4D344921-EDC6-4D13-8E6C-4E63D6780E49}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4D42F0DB-AB90-4C33-8B8B-BA9CD59163D1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4D804069-C58A-4B8E-B736-94DE8C76C6D2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4D8744EE-E9AC-4E8D-BA0A-7741B22AF7C5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4DB24266-96E8-4A88-B45A-84E2D9B8817D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4DC9026D-CFAF-4E70-8AC4-1FC2B515D33C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4E19FA9C-E564-4FF4-818C-BD217B733B7B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4E3705F6-2475-400D-9273-146D338E96A3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4E3E6971-946E-4269-BE9E-365435F95C7B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4E5BE77F-A62A-4DA9-AAD2-7FA62265DA05}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4EE3FD35-48F8-41A1-A199-EF2D48B34942}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4EF213DE-37C5-4631-A691-AA1DF2D22A84}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4F534EFC-AD59-486A-B3BC-DDE1679EA9B3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4F58DA31-A618-4273-9043-AD56D97AE424}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4F86EF89-7228-48C4-BC0E-F53B2AC8534F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4F8BFEE7-4C63-4345-B4CF-CA1721B26740}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4F9185F8-76F6-44C3-94AE-AFDBDE867F68}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4F95D07C-0025-4C41-BA70-8614A2CC585C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4FAE3DCB-1717-49A7-B792-2425490BA11D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4FB887D0-1004-4059-9A78-75C5D3979B6F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4FB8CF24-43D2-4CDA-AEAC-E1965821BCC2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4FD0DF86-B9AB-4322-AF1F-54908C72369D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{4FF7A549-45B1-46F0-B0CD-EA600C1B22BA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{500951E4-4E32-41B8-9D3B-D71DE36CA224}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{50635678-BFFA-4044-A3A2-C3E6B4038ED6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{50F7E403-4F2A-4794-885B-6AFF4CEAAC29}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5110C796-59D8-441A-B81E-69630B1AC698}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5123017B-D2AD-4B7B-B28A-AA93506231EE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5134C7B8-E82C-4C17-91E6-D8EAB8F83E1D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5138546A-DBBF-4727-BF78-4C5F51033FB6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{51605063-DEA8-4DFD-85E2-ADF3B35B0853}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{517D0E23-476E-4200-BD10-0D7951072CDB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{51AC54BE-C45F-4697-A896-5285FCFB228C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{51ADBB15-2627-4756-B232-5ED8E3B7FB37}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{51CE8405-5AF6-4E1E-811E-10921B2EBB4B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5209C586-9944-400A-8227-4E2A8D0A7210}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{520AA005-1D5E-46CE-891A-D82C183D91E0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{522864EA-E745-4F95-8E61-5C51DC8B2216}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{52A488ED-4B05-42D7-9B49-29F87F3A0839}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{52A8E2A1-8EB2-494E-99D0-9C3C04E97D13}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{52A98CC5-5423-4FCE-9247-26C7F83FA15D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{52AF44BD-1CED-4985-802B-7BDDEDE67BC5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{52C60DEE-87A8-4754-83CD-E00617597D1E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{52D70F6A-4648-40B7-AB93-7D3C2F1B5251}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{52E17655-3087-4172-B75E-34342BD72C57}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{53537580-C39F-49F4-BA26-FE712E3D7676}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5387C543-A3B9-4380-9DB8-090C0CE12C59}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{53B5F7B3-6A16-45BB-BF5F-393AFFA6F33E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{53C8D575-D8A4-481F-B42E-7EE469EEB43D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{53E7050B-E205-46DC-BEAC-06C8031334AF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{53FD7380-A6D0-4B43-848E-D75AFEBCD11D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{540E8C11-6CB8-4FBF-A4F1-F6914ED223CF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{542D7819-994D-453B-B5AA-D2D1E51C1FA6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{543359B4-10BC-4535-BD31-D4976F147194}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{54916B06-67CB-4226-A5EF-F12ACF53BED6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{54BA249C-C9FD-4A7D-BE48-97DB4C1B9C3A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{54DED8D7-5AA3-4BDB-AC37-BF0848B1C0F0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{54FEE14D-F3A4-41BD-A837-6C5D11B0E348}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{551E974D-D30B-44F2-9FBB-51FD1CCAF6A3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{55688FA1-9610-4C4D-9984-8B007EDF5C49}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5579E718-3FD6-490F-AC2D-8147E1217155}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{55A31D70-33CC-4027-8A37-D7C165ECE87E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{55A4BEBB-03B1-496B-BB6E-60CF76563B6B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{56170C74-57D4-47A3-BB89-DD7385A8C296}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{56236664-2455-4333-9142-03CC398098C2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{56329FA6-BED5-45A0-8690-4EA4F70A756F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{56354172-83EC-4749-A630-493228E1AA62}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5642DC5E-70D2-4E5F-98BF-40407DC170B5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{564603B6-81CC-402E-B86A-BE4AD098F538}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{565AE627-E2F3-463D-92BE-BEC7C47CAA0C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{56903B41-8791-416A-B900-FF7477181E11}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{56AE5DC0-3731-4535-B5BA-E659BA861C18}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{56D3902D-187C-409B-A5EE-4B1C4ED5BFA0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5710104D-EF72-427E-A522-A49EEAAC7D20}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{572220C2-96C2-40DA-B5FB-F1EB0A5C8230}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{57ADD904-FA05-4AC2-B7C5-BC42E5CE2728}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{57D771A1-BDBD-49C3-B513-84E83222FBF1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{57E8A301-FFC6-47AE-9D03-FC207F95107B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{58541F20-C933-41D7-9AC0-ED7542BD90D7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{585FEAB0-696D-44C0-9948-E8ED12EEC5D5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{58DCF3BB-73C5-403B-B199-66173D057209}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{58DE4A23-0DA0-45EF-A8DA-7E857181EDAA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{58ECB8FD-BA72-4CB1-B165-70CAE3E0CAE9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{592BF73E-2392-4889-A3C6-37C4C2013DF8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5952C701-9F2B-4ABB-B814-64CD7052FB98}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5976599F-8E88-485B-A91D-DC56B94C1908}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5977D552-D6A0-4E63-ABFC-7E169DA49012}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{59805404-0CB8-485D-9884-D6D580354EC9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{59953A77-493C-4B26-AFC0-F9748C1F601F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{599F7C1F-D0FB-4AA4-9D14-1AF9F8F7F012}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{59D0B080-3F8D-4BB1-9B79-5D931FF51790}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{59DAD260-BBA8-4911-9EC2-7EAFC148EC7E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{59E01D4F-C362-4F34-A6C0-8385314A2A90}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{59E6DB56-4DC4-445A-8D5E-0B22C142DC80}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{59FA979F-64B3-4DC2-A050-6FDD257F94C3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5A3E64D5-8D79-4B21-B520-5C70EC8069F1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5A46BE6B-538A-4CC2-81ED-AC6086ED30BC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5ABB7440-931E-4070-BBC6-9C2668DF677C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5AD69B57-B937-4C89-B4FC-5161D36FF183}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5AEDAF1B-9B45-4694-9C34-37D94A69AB1A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5B78943B-1DD9-4CEE-BE34-5341445B7770}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5B87C1FC-9C65-4569-89DA-03CB9029C079}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5BEB6B4A-A605-46EB-B0E7-17824FE83929}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5C0C1101-A621-4B0B-9262-FF41B1DA124D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5C8C49AE-71D3-4B10-8005-7489A5917B60}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5C982192-2678-4836-A62A-4990ABEC7DEC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5CD5C048-94F5-4E3D-815E-9ECC8C75FB88}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5D060CDA-854B-47EA-924B-CC49FB6F4294}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5D09A1F0-C192-4F61-8CF3-358B8D38A031}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5D29E97B-AFF3-4799-85DC-604ECB30D894}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5D2C532C-273B-4DFA-93DF-DB05E98F0243}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5D397F95-F004-401A-9266-F7ADE76B69F5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5D55BDB4-677C-4EE1-B7F8-99ECC05955D5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5DC8A89C-3A66-450D-9112-0633766944BF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5DE5BA83-F6D2-4C29-8438-B6E3079848F6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5DEE1092-82B3-4905-A189-1FEFF21F9FE3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5E40175A-84AF-45F3-8C84-AE0C7B6E3AB5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5E51DEB8-3BAD-496B-93E6-610CC1226CC8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5E7A5B3B-8BE0-4AEA-ABB5-8B544D037222}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5E9ABFAD-EDE5-4970-8E7A-C6AAF8A54ED3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5EB0BF48-1C7C-48BD-90CD-CB5E583FCA85}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5EB9E751-F251-4756-ADED-3AC60393F29C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5ECA08F9-85BD-488F-992F-712E03D932B4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5ED25176-32C1-4B20-B386-DB0AE337D2B4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5EE4005A-87BF-4C8A-B697-F8A1DB204F7D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5F0888E0-1264-44BE-AE38-7507F01FA957}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5F2AB8B7-3601-4810-A3F3-FD6E3CCBDF08}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5F627A87-363C-4A48-80F8-2C55A9501B51}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5F7822A3-CBF0-419A-8B17-1AEFF0F4102D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5F83EE98-F3EF-4EAD-8565-9BCED18C0538}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5FA54145-A6B9-4461-838E-E3F1423B7FE2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5FBDD1AD-0215-4D47-9A96-7C073A36EB9A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{5FBEBA42-238F-442C-9DC6-099B007AB423}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6012FD22-63DD-4DDD-A896-631FA8BEB338}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{603CD844-4270-43AB-AC92-CCBB767244FC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6041ADE7-A9BF-4C13-9D8C-103399FD955C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{604FA102-954F-4E77-8EB3-3CAEBC483DA7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{605EF0FE-1EE3-46AC-85B4-39E322E8CC33}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{60AE28E7-B937-498A-9A2E-361D79650C17}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{60B6C135-0C95-4133-A252-FB044C99A9C8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{60B7E0F1-9B0C-4673-9D9F-28F3A031C30B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{60CA473C-5A44-4CF9-A3BA-B1E7EDD09DC4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{61B9D13A-1B79-44D0-B61E-4D4A2545DA37}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{61DA297E-1B74-4F1A-95CB-004852B10DA6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{61F213FF-E53F-4E36-A968-A0B28361BC4F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6237D13A-AD34-463C-99F8-11965D710FD8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{624803D3-80A3-4B79-A9DC-AD740FF6955F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6258091A-35CA-43A7-BC6E-74EE4348791F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{625A7F31-5229-4DD3-87B4-D5A1DA9F0403}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{629CC69A-164E-4113-805F-EB593A517938}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{62AFB03D-632D-41AC-8767-84D5B229D16C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{62D5304A-53AC-4D62-8478-0E0B9A88C120}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{635F7327-D33B-41BF-8BF7-D4524954AAF2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{63751509-97AA-4B6D-AFFF-24099074A168}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6386A625-49AA-4C6C-8BAB-5EAD47F52C6F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{63CF1174-51B2-4135-913E-62F27FBB59FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{63D16511-9541-4E6A-AD21-2DE626D0B171}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{63D188AA-89EB-4566-BC11-28CADECD4CF6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{63FB5FF3-7194-4346-BC4C-6CBEBB6C5E70}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{64500B0E-91C3-426A-90D2-A7BD688B9D9B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6453099F-8264-4D1A-BA5D-2F7DA3C308EA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{645B521D-6964-4476-998C-CB68605A5427}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{645DCD9D-F619-41EC-8337-C7988272F53B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{64631199-D009-4300-BB21-923C25C71D48}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{646DC4CF-8EC6-4E23-A91F-B5D130170F8F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{64B9D9B2-AC63-43CB-BA56-7407EBDB3915}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{64C0D281-B42B-4260-ADB5-5A2A3AD98876}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{64E6A0D4-8B2F-4716-9F9A-8457ADBBF2F9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{64E7C26F-0E04-472A-9C69-BF85D8F1CC62}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{64EC26CA-00BC-4CB2-8CCA-92B6C6ACA301}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6508D929-B96A-4A8B-B819-A4CDA73A67D1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6514F969-0D6F-43F7-9CE1-3299EE681D2A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{653E63F7-2E53-4568-BFE1-4D8E3402758B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{65770783-88DF-4305-9C21-E7D7538C00DF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{65A3FC31-1F10-4A01-9462-57B0B5D44C25}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{65CE35BA-D7ED-4EEE-9AE4-9000527ABC86}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{65D54686-4DC5-4808-A325-09A8C3BCCC08}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{65D8667B-91B5-41B5-90FE-78BF8CC51BC1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{65E978F6-930E-44E6-A936-59BB638020F9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{65F0BA06-B8D2-4045-AC4E-EB59FE9086AA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{661FB96D-F41A-45B0-A260-76003F8FDC10}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{664FFD80-BB46-4747-A8EA-7F761E8B2CA5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6661637A-EE43-464F-AE90-68296777B356}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6670704B-7DC8-4A6B-8308-51ADD2D2A052}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6689F87B-9EC5-485E-8B9A-170303FD688B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{66B3EB15-B87C-41CE-AF50-8BCB5EA4B430}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{66BDA8E0-1CFF-4D18-81D7-072DB4FFDADC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{66D39199-958B-424F-9068-0C4EDB41459A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{675F10CB-DEFC-464E-9328-A505CF616234}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{678C831D-950C-4DE1-AFBC-9763802AABF7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{67996069-CA2B-4DA5-B04B-4265924021C5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{67C86886-C2E7-4238-87BE-1F18B6644743}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{67CA7434-F73B-44BF-929C-F3262D60A11C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{67D17763-C62A-4259-8746-7D31F6AFB089}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{67E7387E-80BA-4564-8EB9-A4080821FFCC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{68161B0C-B6DB-4526-A504-35B22E76CC8E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6849D314-A316-4129-9353-1454FD2DF5AE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{68525FBD-3A1B-42D7-8965-4267DC7C6F18}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{68803D6D-FE78-45D0-ACDB-67E2B7339E7B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{68940094-D67F-4386-86D3-C90F7810C9D6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6897C6F2-8947-4B37-9EB9-93D6CCC032E9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{68A53839-29FE-49BF-AB3E-94240ED96F74}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{68D535D6-DBEE-4577-9A2E-1A1F5F86621C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{68EEDA73-4E5C-4688-A9DA-79E3AD01CAA4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{68FAA5BE-CDCC-4E75-9EE8-1982484D9C67}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6921537F-870D-4BF1-93F0-A38120768782}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{696B8E10-6798-46C9-971B-68AFC58268B4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{69918F37-A498-4772-B389-CC4173EB003A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{699B0D39-C79B-412E-AC0F-F0DEE11B6C51}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{69ABD6AF-59ED-4226-849E-492C5F106D6A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{69C12B68-1EE9-4574-83F7-CD69DDB3D51E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{69D85B7C-06F5-4905-A371-0B1676444CDE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6A001788-A09D-48DB-8114-F1C0273FD1B6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6A116352-E7C1-435E-8DA4-05B376C4021E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6A1FCEA9-8578-4673-B44B-EE84DCE91645}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6A774265-B7B3-48D0-AC16-27D2A829DC17}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6A8233AF-99C8-4054-AFD1-3BA71F37D47F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6A87F370-B20C-4F38-A8E1-EA02DA8DB25D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6AC5FC28-AC17-4A06-9CF8-68C441A2B172}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6ACAC4B8-B9B2-432E-B5A1-439D94909891}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6AE12540-9018-4901-B07B-BA2047531EFA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6B0E98DC-CB52-4227-9A2B-AE0A0B4D73EE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6B2A41A7-FD87-428F-8106-EA7BFD3E181C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6B336275-7AC8-4606-88DA-2AB72369DBCE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6BA37A4D-F9A0-4E9A-879A-90AC8E08C6CA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6BD3568E-E17E-44C6-9946-031829CDB7C8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6BE4F670-1187-4FA8-8F56-CC2F41C478A5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6BE61221-D0DD-44D8-89BB-393CBED9AB19}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6BFB3609-A440-490E-855D-31F75B9F2AB1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6C024D12-65DE-47B8-B5BC-4FB8C0492542}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6C124BD9-B154-410E-AC4B-DF9BCCEAB0B4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6C12CF0A-6DEE-42D5-87A8-B23931238D99}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6C2C37F1-0AB6-43E7-929A-5020B281AA34}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6C472D28-DF63-468A-B82E-BF755736CA55}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6C64FC71-82BF-4C1E-AA3A-6DAA3CED3416}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6C9BC1BA-C23B-4C2A-89C7-683E4D1FAFC9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6CF1CFC0-5465-496C-B34B-A926BA1A0ACF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6D08D583-5450-402F-9CC1-49B19306F2B3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6D2C6BDA-9C4D-4C07-83C7-7105501A87CF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6D2D690A-52DA-42DC-A668-D2444CB5418E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6DE034DC-09EE-4BF2-B711-6F9C0E278FCF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6DFCAB6A-997A-4BCE-8D07-365A3D398CEE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6DFFDB65-C4B9-4C51-A5BA-982A6804E324}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6E2894C9-6F2D-4FCE-B4BD-5E5B170E573C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6E2EB71A-CCB9-4411-8A2A-E1D95B344E53}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6E3220E7-2EE9-493B-B130-FAF8E46AC55F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6E33A01B-BC28-456E-810B-481DBB261C84}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6E787A47-27D6-48A1-87D0-8CC9F7E9E3F2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6E7942CC-7EFB-48DA-8849-AC4E4D87F6AF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6E8A985F-BE9A-4A1E-ABF4-B6E3644358CE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6ED698A6-E8A8-4954-AF99-759675B3BD79}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6EED525A-C1A0-46EC-B32F-3668C3CD1632}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6F77999A-0170-45B0-A725-EFF0E86A5F20}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6FDC2766-0BDC-4230-A4C8-6EB56C3B7E5D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{6FF3D586-A1DD-48C5-AE0C-578C4FBD31CC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{702C342B-F617-4370-A6AF-FB1D65979F81}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7044C820-8358-45FC-83E9-86BA44E7A7E9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{704CAE2A-2610-4241-B2BD-3E5612CABB33}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{707A324C-9237-4971-A3F5-9571641D973C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{70A41F45-AB7D-4120-B369-CDFE1F35EACA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{70A56045-C876-4294-9D24-E3B23CD083A6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{70AC11A5-9220-4AD4-AA0C-4E023841C70A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{70B00BAE-527A-4FED-B284-6BE0B9FF92B2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{70D4967F-5852-4AD6-86CB-64630ACA50CF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{70E43683-A1A5-4ADF-B69D-4A07DA6425B8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{71036EFD-4D55-4043-8466-459FE6E7672C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{71BD264D-8426-4132-A16D-2FA594B91D7A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{71C9342C-6A98-4D5F-A30A-321051A0DD77}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{71C991A9-C9CD-42A1-AC2F-F37250989C16}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{71EFA87F-D38E-475D-BB5D-9CB87E47AA55}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7209EA11-8A91-4E15-B88F-DBA1C44AB777}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7256A04F-C261-497B-91E2-BE249627E36C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{725754EF-B4BA-45CC-A429-9A05CECCF1F2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{731530C3-CD1F-4D9C-81D6-B0BB63C672F5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{733E3901-52F0-40B9-88C5-648B9F69C556}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{73436B18-0B27-4BC4-A924-23535DBE1497}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7344F8F0-A2B5-4ED0-BF88-3C0482D6E307}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7351CB82-6CBD-4FE1-BBAA-431C1205409F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{73821181-21FB-4462-9A4A-74E7CBF5507D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{73C92103-E37E-45BE-AE94-76AEAC307A30}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{73FA2E0D-F81B-4E86-A4FC-09EFB87F52F8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{741C8743-8789-4CC2-ADF1-7D9B9E81CB9B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7428E4D7-CDC0-48B1-B7AA-1D980380F4A6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{743B1389-1C43-47C1-90E1-DEC1FBDD26F2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7455D33C-3ED4-485A-AC49-95649834FDAD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{747D68CB-D458-42E4-8D2F-D500E6183729}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{749A510C-59F6-420B-A155-D9F907A73E01}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{74C04E78-D041-4E2F-B4E4-84FE4A3E29E8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{74C6C252-06FB-4399-8661-374844898BBB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{74D67766-F03A-400E-BBBE-A1526ACD3A41}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{74E7433D-46A8-452C-9590-43BD569B2EF7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7507A85A-873A-44A7-88B3-ACFD65F85C4F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{758F5F10-DA2C-490A-B1F5-72996BA2DCC0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{75DA237C-098F-4D16-B6B4-77758D36FD4D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{75EA1E26-D703-4BD8-8CD7-FE4802B5313C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{75EEDF1B-4D33-4387-AE60-D046B25EF2A6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{76134BDE-5E5C-44AF-A4E5-016C899F3333}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{76986915-DB6D-4004-9BDD-37F5E6925DFE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{76AE5380-CF78-4FDA-98C5-1523F2825B08}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{76F6B89B-D918-461E-91FC-63E2859F0360}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{770387E1-4F76-4A81-933A-FE1A6854ABC5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7725E219-E795-48FF-9B79-E6EACF126EAA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{77424D02-4A5D-417B-B627-1355AFEFD5E6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7749AD56-5A7F-4A5B-95C3-8252521E1F02}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{77771C00-67D1-4306-B2B1-636828847A14}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{778500DD-C34D-46C1-B660-DB6CF586C8B2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{77A22E39-E926-49E7-90ED-CFEF36E743E3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{77D6E81F-7D33-45F3-B59F-318D00D09D7C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{77FB5F58-1A81-4CB0-93FF-01358D286491}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{78308A1A-57EC-49E4-A453-28DEBE0ABDF1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{785A86B1-BE9F-41E6-BF9D-D9CD31E839B3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7871C6E3-7E3C-4AB2-A803-5236E90402CA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{78744B7C-EA38-4CB8-BA80-1F5AF9E793EB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7889B789-8A8C-4F44-91E4-15BA35E4DC6A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{78C533BE-3CAC-4D8F-ADD9-04B36A12EA29}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{78D6DEBC-9828-41F2-AD03-98A0B4FDBFC8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{78EDCE50-2987-4216-8636-2FB64E573059}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{791E3A51-C35C-4786-B457-80878B4298CA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{79361EF7-189F-48D7-A09B-3F14E938E71B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7942C289-9A36-4272-9AF4-3E2A7BB10396}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{795502A3-9985-415E-B2D7-BF42B95513C7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7972D7D7-310E-4249-9A07-B5D76E6A3292}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{79742012-EE53-41B8-BA7C-C9890DCB1247}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{79E882F4-09A7-45F2-9061-3685A74B5ACE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{79F10AB5-EC00-4227-A7FE-224B2D29170D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7A0CC29C-0D08-4BC9-B32E-A2EF96129ECB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7A1FA90E-11BA-4A8E-A44A-654423CB03F2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7A3DBE4E-133A-452A-B25A-94C7D77805B1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7A5D52E4-9198-41DB-AAD7-EE46E8DAE5F2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7A702E8F-2FA2-4D7F-91AE-410C5D220153}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7B5F17DC-8378-41F8-A51F-0B03AF2E9A92}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7B77F049-5DE3-4383-A6D7-8BEC9BCD56EB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7B93A720-5AF9-44A2-B4B1-36E48690A00D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7BA6EDD9-781C-4EBA-8387-76415B917F22}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7C0C158C-9410-440F-8D22-022FB07386AE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7C0C54CB-E828-4FDF-A69D-3CE3C1F2EA0A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7C129BC7-37CC-49D4-AC43-7E84E0E06C5D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7C191D9F-8076-4431-8379-144E3B6196ED}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7C3CF925-D559-45D2-9E13-16CDA9D90532}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7C4D8696-86AA-492D-9A1F-9F2DCD1FCA4A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7C5E9B62-5D56-4B11-9A80-B4B4EDC1B05A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7CB224A3-9950-4691-AAAF-EDC24397675B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7CBC3DBF-3959-4155-8DAF-38754DCCACF6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7CE98ACE-0ABE-4576-9AB0-5A2C53AB1DFF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7CEA272E-6BE3-44F4-915D-453B7E6DDC5F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7D09E80E-2BB0-4E92-9E17-CA0D2C8FCEBB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7D1ED117-B7C7-444D-808C-5A8E84230A36}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7D425FAB-1CC9-45DE-B316-11ACF2C05620}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7D673663-7BEE-4BEE-99B0-CABAB747C098}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7D6BD3F0-F373-4A06-8065-E0E9EB216E83}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7D74E527-45B3-4E50-8224-9CCFA5A7F87E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7E1640BA-B010-46BF-84DB-DD42902DEFC0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7E1830C3-2E47-4268-A7E4-F88C345C094D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7E626AE4-E8AC-4FEE-A2F7-F47717E6050E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7E6E6E46-F8A7-44F2-BB80-490CDD3D7AC5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7E987311-43C5-46DB-A163-117FEC244ABE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7EA8023F-A44D-4A54-95AB-B0428891F4F6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7EA85E98-D9DC-4A3D-ADF4-F2B649E52873}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7EFD3E31-4466-4E09-92E8-AA2A9742871B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7F4F306F-1C2C-46D5-B59E-F578D1AF25C3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7F506FA4-EDF0-43C9-A64C-FA37FC8075CA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{7F82562E-65AF-4D1A-90E8-A31FE49D3C69}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{802E36EB-ED73-4F5F-8EE2-2827FB05A2C2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8033762D-9EC3-41CD-8BFC-E6274B9969EB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{804BC8B5-1628-4AAC-9844-5D536CD774A9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{805C38A3-8FC6-40AE-9033-01A83C8A1846}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{80B6EFBE-DD7E-4A9B-9D09-A910EF14F685}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{80C13F2C-D5A0-42DD-B926-B71BDFCBF87E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{80C9857F-7804-40C1-ADA2-AE6B4E86AE93}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{80DA2BA6-878D-403E-81FD-8F74326BB2E8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8108F960-1C90-4A5A-8D6D-4D3181806EB7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{812432AC-9474-47A4-A6F2-89A198096FEF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8147DC33-769D-4272-AF93-BC86EE36ECFA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{814FDD17-7341-4827-9B28-902837D7062B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8164721C-5537-4D82-A4AE-587803C97F93}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8170BCFA-8A2A-471D-82A1-4AB1CB29B8BF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{81920CE8-D0DD-471E-8E98-2453F2BA9F5E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{81A5CF1E-C863-4C0A-982F-9598B9D6E93B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{82005F6C-174E-4AF1-A6B3-0433D9B42F89}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{821B3CEA-A913-4A28-84B5-3FB06A7B1CF7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{823A7D15-26BF-480A-9CF3-3E561817A685}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{82568561-DF4D-4D7B-B6C5-960E01091C02}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{82875B89-A5F1-4EDB-9E32-7EBAD848B96A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{82C4F494-44DD-4938-82DF-CA1DCDAA3B4B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{82EF8E64-4314-409D-B443-9EDE6B6C778A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83006548-AF4D-46A7-A676-BBA9F58E4D7C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83146B89-4369-47EB-A733-49ADE1A1CCB3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{835210AF-93A5-468A-8157-163151D6E657}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{837D2762-D79E-4A73-A711-69B53F1421E1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{838108A0-D0D9-480A-8076-1F860039606B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8390D13A-B4E6-4F51-8AEC-D927654A1024}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83939F27-EA4D-408D-B3D6-4F5183A6BCD4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83BC3398-4522-4214-B391-2E0A4E07727E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83C1C796-5429-45AB-A118-F0C933C78EC7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83CFF379-7E8F-447D-B50B-5A000BE23FE0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83D42309-F129-4CD2-BA83-88A5275B5472}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83D70BA8-33B3-4E28-8005-64F649E7CAD8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83E223CA-2626-4519-9F35-388FB1F6E7DE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83EB7DD7-D053-488F-92E6-9D01189FA791}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{83F5F4EE-C5D5-4637-8A80-03FC42F51435}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{84474AFA-AAD4-4F40-B20D-05F4D984EBD4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{846A269A-85D9-4E05-8DFB-3997DA7F2985}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{846F745A-5800-4C61-9E4A-765FF2D2A69C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{848EE437-DBE1-46E8-8B40-D925AD9F0607}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{849021E3-8D9C-4400-903C-DA1173F6A107}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{84C6CA5E-A972-4078-8F2D-842196542BAA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{84F99EC0-2D59-4B40-BC1A-781184A2973B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{851366B1-B45F-46FF-92EA-BE66B86B2099}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8525FDDC-EB70-469E-86FF-0856E98E0E7C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{852CFA0D-6072-4DF7-8B17-A8E3544A9988}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{85327133-B9D3-41C4-8366-028CF3C5F511}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{85957668-88F2-40A4-9FDB-081BEDD5F666}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{85BAAAE8-E875-4648-83F5-715090D640E1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{862C2C20-01A7-4EAF-946F-0230471B2DBA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8631493D-8AFF-474B-B302-7919AA725C08}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{86384633-57F1-4E7C-8208-07A71AD41438}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{86950BD5-D99B-4E51-90B7-D96BE289243B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{86B1643F-71F1-4037-87BD-8114590EB39E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{87125592-3EE0-41B3-A8AF-B51F76119D22}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{874C368A-AFED-4BAF-997E-446EDD0FDA19}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8753B145-ECD4-46A1-81AB-643E0D904BE9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8765420D-9FED-4490-A09C-F5D9EAC6EA4A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{87707386-0049-4DB0-8719-3C66FEC125FB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8774ACC5-100D-44E1-B0BB-96CA7505DFB7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{87A136E4-F54D-4A28-B945-348DB13130B4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8806DECC-9BA9-427C-9523-D0233C47202D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{88095D8E-540E-4090-895E-341B89FAA737}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8865D21A-8332-4593-9322-7EE26273CD74}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{88787978-60DA-42B1-B33F-897AF49795E7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{88A45F5B-D6DD-4CA5-ABEE-9BE2AD715472}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{88AC6E99-B5B7-4D0B-AA71-17E7DC897133}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{89051652-974D-4F1D-B8AA-D1CFBF6D7AA3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{89057DAC-963F-4981-89F8-F3AEE26079F0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{891B558F-238B-40BF-B2FA-EB69E69D4EE7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{89267621-5E34-404D-8B61-845F8FE54627}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{896B947D-3E2F-4A7D-812C-4F0BAE893A7D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{897D6DBA-FE51-4628-80CA-DC9982CF0715}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{897F6981-C758-4450-9383-FF8489D5AE74}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{89A4CEDF-8C8F-4686-A2F6-F6809A62C5E8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{89CEE698-60AF-45C9-AE98-A994AC7306A0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8A0D0FFE-594D-4D2D-B0A5-6679963598FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8A20F927-5881-429D-817F-BAAFA290B158}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8A466633-391B-4B58-9AC6-461DD7F549F3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8A4F46E1-D95E-41AE-862C-9C956B8500D3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8A570A3A-CF64-45A7-A0E8-611881ACC72D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8AFD738E-74E7-46A2-A04D-DC8CBAA0441A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8B7FB67D-11E5-4545-9EF3-2805C300DFF8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8B959660-8A72-4CF4-A250-27664EFA576F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8BAFCE84-DE53-406F-93BB-05F57682993A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8BB77B26-7C19-4BB6-8264-3E30DE4C64B0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8BC07FBB-EBDB-4397-847A-AAAA6D1C2AD9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8BC382E9-83C5-4570-A301-87E5D5B94764}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8C082CAC-B5B7-4278-A4FE-94C806F94720}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8C106A8F-A712-45A0-A3FC-DC01E4BE1E07}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8C1AE9E4-401C-4F37-AC62-32A9ADC1D1CD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8C48FC8D-816A-43FB-B107-343D06EE976B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8C77F285-0B0B-4012-A718-850E897FB7D9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8CB92A67-3258-4C5B-B960-D551F090573D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8CC7843B-FE87-437C-B9F9-B1D3AA6DDBA4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8CD3D241-1F51-4258-B66A-CD9462025D0E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8CDDEF73-AC2B-46F9-AAA1-94F0056E8386}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8CF7D6C9-0DDE-4856-8ECC-865FFCA7A3DF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8D37C60C-5E36-407F-8CA8-48442F2CC52D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8D39660B-4CDC-4641-AF4A-BFDAEBD7C375}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8D7EB7CC-7D76-40C3-8C23-4FAED72F69D2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8D90A0D3-132D-4860-9F31-233402B14F93}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8DAF17A5-C697-4FF7-B10E-5023DEC8217D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8DD262A6-549B-45DD-852A-95A752EDE4A0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8DF2798D-6CD8-4D8A-8B45-30AB6FF4F72B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8E349CC9-3276-434C-B0A2-DC573B62C1E8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8E4B6FFF-8615-4D1A-8B1C-ED5526F44EAA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8E656317-7DA0-4213-AEBA-8FA6910ABD02}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8E8AB612-D989-451A-BB7D-19DE17AE61BF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8E9124B6-5D80-4AD8-8F66-2A785DCEDE81}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8EA2A7DB-C4EB-4D9E-868E-E73B121CCD27}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8EBAB3B7-7FE9-42AA-91A1-773F032C961B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8F043242-80B3-4A3F-8374-1EA2D315D5C9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8F255DB4-15D3-4A52-BE91-6A5DD4177414}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8F77D965-2968-4C31-9766-0F125B3662EA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8F8B1597-5AFC-4674-8176-DA59DC247856}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8F90A387-B8BC-49BB-A104-DC0F10D86E7D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8FBA7F75-2B66-42A4-84E3-728FA67F6506}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8FBB180F-54C3-4E5D-B6FE-CFC180633A67}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8FBF2BED-C357-4BF0-AE9B-5181E18D64FA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8FC65A40-463F-4B9D-82AB-F1B5C205068E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{8FF0518A-12EF-4233-87BF-79B467D0060D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{900DFC2B-4418-48A8-BB05-2EC1C1CE1C88}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{900E3744-7285-453C-9054-73F08E6C982E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{90186AC8-2825-4349-921A-8A79DFDB74BA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9029594F-4C8B-4ACC-9047-A2D3AAB11900}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{90E80F78-F4A3-4558-8A0F-5351FF0E6923}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{90F1AB27-010C-4DCD-BB13-DB34E02E265A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9122649C-AE55-4A11-96D8-36C9DB815972}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{913F9E17-9869-4BD0-B618-FC60ECEB979A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{914D0F38-5954-400C-97D8-3F5518A5BC9A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{91922A0B-6033-482B-BA88-0159A029E528}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{91A12C50-DF5F-46C8-84D7-AA61C89211DF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{921CC5D8-E98E-490E-A745-F0CF3AB8DD5A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{927B4F3F-CC7C-4C37-B1B4-58EE91450943}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{92994554-ED8B-4A2B-9B83-62C16933F4BC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{92A6BB17-51EB-4E19-BE4D-DDE54829B8B3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{92B52CF2-0362-4FB6-9068-C327ED98287E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{92B6255D-6F0A-41EA-9DCF-15CC25CCD9FC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{92C2AAE4-728E-4468-B580-E45F50823C72}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{92F90606-E889-45B4-B7F0-547DB93BF105}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{930742E6-746E-4237-906E-B9A5C9834DBF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{935AD13C-9F66-4431-A499-E39EE27B65BA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{935CDA93-A55E-4128-B358-66FD5B2F26DB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9377CF6C-DAAE-48E5-B39B-8630BB12FD86}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{937BDE5A-2CAD-4021-9E5F-8D115BF95827}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9447FF86-26E2-4894-8B7D-A085C1654F46}
         

Alt 22.08.2015, 20:46   #8
mezzomix
 
Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



JRT Part 2
Code:
ATTFilter
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{946A0A80-0BB7-4515-A69B-74C438567914}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{949ECDE4-F4E6-4636-8D7E-F37F39BB87C2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{94ADAD21-1D09-4091-B48E-15EBB8A21153}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{94C59FD4-F4F6-440E-9804-1CFC834F4B89}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{94C73E62-BCA0-4528-806B-664E4F2E9567}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{95181793-B8B2-4F99-85EA-C06FF2E508A7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{956F3176-B7D3-451E-B9A3-70F30C53971F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{958B4967-ABD4-4C56-910B-77AB6CA05B90}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{95943058-12A9-4430-BCCD-045D0493EBBF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{959816EA-0914-4588-8623-B1B8731D3A15}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{959F89E3-E822-4FAD-B3C1-48460E6184C4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{95B53BE0-FB1E-4089-A53B-40C6721A6AF5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{95C90BAC-60A3-4D84-9273-B1D9160F1EBD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{95E56DA1-005B-49E1-932A-E8CBAFC5044B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{95F090D8-5FFF-4599-94B2-9BD3A6CC4352}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{95F730F0-A69D-4ED2-BFF5-FFFB778D44B6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{96414C40-6A23-47F0-87B9-8EBB253818DB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{969BEE96-8FBD-49A9-AF70-8B6EC758EB96}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{96B23DF5-374E-4EB1-8141-4FC605F49CF4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{96CC8523-0AE0-4684-9B14-81252EC733BF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{96E65A75-02C0-4C7E-82FC-AA851EC69614}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9718CD05-634B-4071-85CA-1DA432032570}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9732C7B5-AFB2-4734-9BF1-349346B8AF44}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{974215AC-8CEA-4FDC-8D17-135BF4775062}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{974CF208-7ADE-4E32-9406-028A3D7C6076}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{977925CB-8480-43CA-8FE9-C95785FB6AA3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{977F2AB9-0AF3-4BF8-B6BA-3E11EBBB3C3C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{97E9FD7D-2AC1-45D3-889F-052BA8B3F377}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{97FEFC89-962D-4AC7-ADA3-56048263D2F6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{982ED825-E731-49A1-BB28-BAF311C0ECAA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{985974BF-1F75-475A-836E-F5772A954295}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{985D233A-12B2-42FD-9258-EA12FAD65B43}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{989FF2AD-C16A-416C-8DBF-6534D0345912}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{98BE696B-2FCC-4805-B81F-3A351BFF2494}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{98E7001A-7D17-4339-804A-00747481A3B6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{990212C1-055E-46CC-88FE-61745AB04C86}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{992608BB-0FF1-4E8F-ABAC-BC348DA3CD0A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{996022AC-9D89-45FA-BB8A-8DE0ED537047}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{99D77882-C6A9-4AF4-B1BC-1AB391559C3E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9A1816CB-DBE2-4250-AC9F-8DA5FED71365}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9A1C5092-395C-4AD0-9105-654A1AA05FAD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9A6BFD60-BBE2-4B21-A804-300A877F2149}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9A73B0C1-A5B2-4BC1-B69B-EFA0371F4908}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9A7FF6D3-708C-4059-9EE3-08D42908A298}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9A8393C1-8E2F-4AF0-B264-337EB72A0B35}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9A98C25B-EF50-40FD-AEF7-3122C21513C5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9A9AD8C7-5A45-4DAD-A134-23F982B34E0B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9A9DF8AA-370E-4DD6-AD81-DCB4B16AF6FF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9AC85EE0-D657-4320-AAB6-3FEAD2A548E8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9AFB5409-79DE-43AD-82D9-C8044084AA71}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9AFD32C7-0685-4F02-973E-866906293D3B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B1A9CED-6E0E-4849-BE28-211446993EA6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B24E560-2034-4CC2-8E31-284629993F89}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B2877D3-5E9C-43B5-BBDB-DC2A9E79F6AC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B2ECC10-9C09-4F6F-BD24-ED48EBD914B0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B41508A-E0D9-4B9F-AEA6-D62C42F22098}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B48D0AE-88A9-4CA9-928C-DEACAEE53A47}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B4E6C9E-7ECE-4C7A-9203-09E08DBCEAAD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B52C9C9-BD89-4928-9703-2FCBCA753379}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B5EEC45-7B97-48ED-B2DA-A4AB0DB2AC14}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9B73CF3C-500B-457A-BDBE-1F71D51EEF2C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9BAC2F77-818A-4A1A-A54E-95AC67A20E3D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9BC4F996-B4DB-43C0-B430-789BEF052BD0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9BC6D1A4-3637-42BF-BA24-3734B42FAA4B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9BD42051-9EE7-4626-B6F0-4192E20910A9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9BEC0A8D-3643-4846-B330-F3B30A91D79F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9C4E5FF4-CDB9-48AB-A306-0F9AA99A8C0D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9C5E5B05-2F33-49A3-AD3F-D62FC508FDF3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9C8A298C-29B2-4435-BDF9-6574D25521D1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9CF750DC-B0BB-47EB-BA14-E817598C4375}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9D5C9E39-E9F0-4CCE-A7DD-360B1BA91E58}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9D8EF96B-0AFD-4D76-9D7A-A4B47B0D2653}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9DC55A94-F9BA-46D3-957A-69B1C167BFDD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9E3336FB-B447-46CF-AC87-551C43F785B0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9E3481AC-76F6-45B0-A12F-E92DFC72C14F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9E4CA10B-A1F5-489A-B751-ED5A4889BB2B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9E51ACA8-5B40-48D4-AD5D-74B66B3125D7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9E7E100D-EB5A-4CF2-B9F6-06026AFF9C8C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9EC490AB-C851-4752-8069-143B555D76B6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9EC9907E-B243-4624-A554-DC5D4915AE28}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9EE454C1-30B8-4CE9-A8A8-ECA7FE541011}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9EFC6529-3F42-4601-974C-F5EEBE835919}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9F17DC05-ACF3-48AF-9AC5-895097278F8C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9F1FAB64-4C42-4F7C-BEDE-6825CC3670D4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9F2EB155-79D6-46E6-A52A-BFBA81F1BA52}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9F4E82D0-AB33-4C51-9C95-80B2D60E67EB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9F50EAAE-2649-4D7B-8363-78B534E644E2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9FA96516-AF0A-47DA-95C4-A6CECF46E084}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9FAA8F4A-F035-40F6-99F4-2EB1AAC628FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9FAED7D3-3BA8-493B-BEB7-5F6A22E1CEEF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9FCD65A8-1FA5-48A4-BBE9-ECA329D412DF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{9FF7C07F-A0C4-48EF-A77E-7874C0D61644}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A06D18DA-F8C7-455B-9D02-413E31661A83}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A0900FC1-EADA-4E65-8E87-F146376AD8E1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A0901B6D-0291-4DE3-BE6D-05F4EE4B3AEF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A099EB84-0E05-4662-AFEC-A5441CF38D17}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A0DE4031-D435-4C62-A6D2-FEF2F3B1314D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A1486C8E-2DF5-4C39-8D43-4B890A6ED829}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A1752055-19D8-4C8E-A0DB-14C282504522}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A1753517-0373-4CCE-9878-81515C7E65B2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A1A29733-34F6-4744-8E8D-CE9FC34BEDD0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A1B1566F-9CD8-4555-8448-7070D6AE0821}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A1DF6894-4AC0-45FB-BC1D-BF0727E7F8D7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A1FC693A-AF89-425B-81C9-7467924B9510}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A24D42AA-70D1-4896-BB6D-0E4F998D30A1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A2810B5B-40DF-428A-A867-0D7F655FF640}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A287214D-3370-4FF6-B9E8-4FC760115F95}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A2886446-1B2C-4EEF-B63E-FB543963C470}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A2B3CEFC-9F6C-4743-B14D-20EA5D21E902}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A2CF457A-2C40-4272-AE89-2B65AB350FD4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A2F84DA8-4D49-4DCC-A9D0-0C7C8CD7651F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A317C07D-7795-490C-A227-8DAD94AF8BDA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A370A64E-D385-4326-AF58-F2044785F4E7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A38438F5-334D-47F0-9EA3-3960DC81ADBA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A389E786-BF2D-412A-A8BF-E0DE30AAA89B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A3C3B408-10E2-49B3-86C8-90801F3EAC4B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A3CF7505-C79B-4749-BD34-E4F31ADA2633}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A3E865AD-8FE2-4EF9-BD40-8C6B2A0DEACB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A3F3997A-BAB7-4339-9648-686D38DE5E56}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A3F3E7FC-0170-409E-85F1-9404AA7CEDEB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A3F5DB84-E346-4C96-8917-05A5037626E6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A420B32E-C31A-4139-BA2A-2D07BA198BD6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A42E7790-18E2-4C56-86FF-B800FD0AB349}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A4319D0B-28B8-45FA-9595-FB10CDB58A5B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A44D7971-1881-497A-AAEA-BDAF57C91A73}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A46EB5A5-1B63-4F0A-96EC-785C1F071558}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A482CC62-1228-447C-BF74-39B43F5E5497}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A503FD61-35E3-424D-A165-AF8C86C6D64A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A53F415A-57DF-4521-8EFD-24E19D22093C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A5816DB0-213A-4AF6-B5C6-858FED444446}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A598A4D4-0331-4587-9226-01BCB9E0B15B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A5BD9AAF-8998-4296-B45A-440B7A54D4D4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A5C40B01-E257-4E59-8188-9E86CCC1E531}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A5F97D7B-8DC0-4F06-84A9-021EA70D38E0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A61EA5BF-7E68-4778-9C18-BC916C41D0D7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A676F70F-1347-493D-9A97-9987787C31AC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A6CEE54C-FD51-48E0-907C-7676B0EC7079}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A6D97ECB-585D-43C0-807B-6DBF70C6F58B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A72E2B81-7DBB-47ED-9D6D-5863D9E03F17}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A7761A38-E3C0-439D-BD6E-CBBE62BC2377}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A77AE403-A0BE-4EEA-B826-173FF15E0761}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A77FBC3E-9660-4464-880B-02AE607C8FE7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A797B159-2189-4C34-84AD-BDBCDAFCFAE1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A7B9EE93-0633-4C5E-A45F-9D3E8E93363A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A7EF99E4-AA95-492A-B479-CBF566A93F81}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A81C4665-2346-4724-8F8E-0905006C8F56}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A82A4353-B189-48AA-B779-EF66C1381A3E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A86D362E-AC58-49A0-8F55-DF2622E21EEB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A8E19567-D28A-430A-B903-7B885F620259}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A91099E7-D5D0-4136-A0F1-A9FA05C3C416}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A91CD4B8-133C-4590-8B4E-FF2979FCBB96}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A92EAEC1-5F41-4D6F-8A7B-F4557B459079}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A98C25B6-C938-4347-A39B-4E62AAD9DF24}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A9E390EC-7217-4524-9655-D4C06B9C4364}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{A9F79450-2BF2-49A7-914F-15349844DD29}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AA3673E1-D1E0-49C7-A71D-6DD685CE156F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AA5AD0BF-974A-43D8-A5EE-147DCF25DB6E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AA651721-6E68-45D5-8469-B37FED50FA78}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AAB5DD1A-E943-4CD5-A01A-E97D7E38B44A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AB604A96-8B61-4F2A-BE33-DF10F5AF51E8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AB80E46F-7F3C-4340-95E3-81B4593068B9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AB8B8EA9-BD63-4EF1-B115-1DAEAB0FA254}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ABAF4BA3-6663-44E1-B32A-31DD18CF076C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ABB3780E-3BB4-49C1-BADC-4706404FF5FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AC2A0728-3BDB-40D3-B038-6E044F4A78E3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AC429568-681E-4674-88CA-45D15B61B87E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AC525C3B-DDC1-49AA-B818-D4A561681D20}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AC84F356-0045-4C9F-BA27-54C241F8B81F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AD24F0DA-5156-4860-912B-2A147810C764}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AD2DC381-2052-4153-A4AF-450B3638FE5F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AD306886-5376-4317-B1FF-498660555D00}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AD63238E-9707-4F12-9A1C-C5F3C4E244E5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ADA5C993-142A-478B-A139-E64F69C58ADC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ADDE3828-33E7-4957-AA02-09CE2900D9C9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ADFC17FB-2B98-4D6E-BC9D-F795DA86898D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AE1725AB-D75C-4DDB-9C02-98AA984E6D73}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AE1D0A10-B5C8-42E1-9977-3DC139B322E3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AE572E15-E958-4681-AA28-EC29CB4CC02B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AED62E2E-23CE-426E-9D22-A4775246962B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AEDAD49D-7BDE-4004-A9F2-459300690A50}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AEE3CDC5-B9A5-4062-BC11-A5660081B06A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AF2E8436-6B28-4FD5-A57A-C7002DEC4EA1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AF4E7DE8-3F96-42F6-8680-A1589939FF40}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{AF531142-00CB-4D99-980A-A708D7644A2E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B024BDAE-4270-4063-8186-0118265AA5F7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B03182DD-5538-465C-9E71-DB9F99DCFBF9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B06CB2AD-8332-4B77-BA8A-B8C1BE67EF5E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B0853189-D3E3-4CA2-B840-61B3019392A7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B08E4E93-4D76-4151-A9BA-FC4F335DF566}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B09F3A55-764C-4D5A-9B1B-BFE24C33B083}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B0B9F6D4-F728-4633-9D75-014863583569}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B0BDB41E-D062-4897-9975-F5EBA33BBEE9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B0ED4141-33FE-4C21-AF2F-EFC4C01E34AD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B1127289-C6AE-4A08-885F-520B37ACF665}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B1194AAA-8773-42D3-A1DD-427151024900}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B142BCFB-FF72-4E6C-A734-AD4884B5D770}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B162FE15-478E-4B44-8153-2D47002EBD6B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B1B60BA8-13B5-4705-8E56-6E3BB2A0EDA5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B1C88198-44C1-4E4B-9810-81684E581F41}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B1CB2195-FB64-49ED-99D6-67067A845357}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B1CE91B3-30FE-42B8-9C78-1D41A03D24D5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B1D0CC5E-DB3C-477A-8423-929625592F80}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B20DBD57-6A65-4F56-97CE-B0B66AC5943E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B2434610-E387-4667-96DD-11512FCA5DF9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B2627DD3-4695-477C-A7EE-3BD50EA436B1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B28336BB-5849-4AE7-9C43-B8F05A35B508}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B28E81DB-DCE8-4505-B36C-F5F85B9FFD7F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B2976C40-1ACC-4F8F-BED2-8CCCA03D099B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B29C758B-9C2A-4CE8-ADFA-0987298BF1AB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B2CAF5B9-9DBA-4EDE-A7AE-74D34844CEF6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B2DEE803-D872-4340-A1BA-09DCD091D7A7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B31F8461-EDA6-444F-9682-B452E075B044}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B344AC6F-93F5-4C45-BD7D-606FBE8EC7BB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B345E2BD-50B4-4841-ADDD-B0D3D8E6D5FE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B36B48F6-8D51-48CD-BD01-79923C12B2FF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B36CBE2B-9ECB-40DB-A1D4-19565DB5DA26}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B3AF0A37-61B9-4A14-AC39-D86B3D2B3C07}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B40544AD-70E5-4F24-A374-1CD7240000C1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B42C04AD-4A8A-4E46-9E54-BA78B4299C1E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B42EBB64-722C-47AA-AD44-BC4C91E25F64}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B464B377-B4EE-4E44-8127-2CF49309D734}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B4A7754E-D6A2-44D7-B04D-77A7202E88A5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B4AD8417-DF22-4665-9C39-25EDA3904E1B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B5288AEF-635A-4C53-8E1C-351DD1DD3BBA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B52B8AF7-B87E-4C00-8EF0-10D7A7A0CE54}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B5480380-982A-4E0C-BF7E-A4131F8B638F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B549F598-4D0C-486E-A929-D3F34FF2CE45}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B56FD1E0-5F98-4C9D-BB32-905808B5E6F8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B5725612-F8C8-44D9-8086-E49F85467265}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B5728A51-8A26-41DB-AACC-5A5A505E4713}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B584DC47-1A80-4426-AD4A-45913C2EE836}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B5953CEE-25E2-4EF2-B6C1-FAD7E3633A15}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B5B981CE-7A79-48AB-BF05-5DD381DE1A34}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B5E66AAE-1A4F-4F6E-AED9-B0EC2C460D2A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B62CD398-4740-475F-B94B-4690B0125E9B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B63D08AD-15F3-4C89-8AFD-2D087DCCE5FB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B6485150-5D18-428E-83F5-8D573504B051}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B659C3B2-08E5-4978-A0B2-3F9B51508C19}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B65D6E98-6911-466F-A5F0-5B0E22621779}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B688E28A-EF70-43AA-B142-B91D7C843486}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B68B0682-E9D3-40B5-8F53-1D0E8E8CB870}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B6A55EC8-5BF4-4CF4-B6B4-9932FDFE7E95}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B6BD3946-C552-4B8B-AC33-9350189833E6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B6BE5972-E2A6-4B0D-BDB7-73590593B1ED}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B6E04BA1-E235-4A7F-AB7D-A990D58E34FC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B73D59ED-58C1-43ED-B016-9B79C788A8A8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B77C98A3-12EC-45F7-98CC-55324D5F082D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B7811264-0F76-408E-97BB-3D10BCBDF8EE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B7AE050D-71E1-4CFA-A9DA-BD8F7692A198}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B7C53106-7DCA-4C5A-8AA8-819B40622FC1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B7D1FAB9-E23F-4E98-B13A-DF01C4D24BBE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B805C56A-D7A8-4124-AE30-0D0271D32DD9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B814CA05-281E-407B-A1D3-1012C90D0928}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B814CA6C-356C-4234-8EF2-43EEA97E2D5A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B8527A95-D916-4DF2-8C24-810B17E508BD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B8695FC7-8E37-4D2B-B633-F2E35B79EBAE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B87621A9-5EF0-4563-BDD4-6DD9B9DB2487}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B88B3528-C689-4470-8596-F8C58855E06A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B8A56552-55D1-417F-A6F0-E2F457AF8E2A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B9073756-A870-4CBD-B91F-3C44976FD7A4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B90FBA9E-B962-47DA-AFD8-8C7AFD205C98}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B92D485C-11AC-4A5E-8C72-541F5A3091D0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B935F7EA-B3CA-4784-84E7-80C692BA1AAD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B966414C-3FB6-47FD-8368-D67DEC4EAAF1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B991C3BA-FB09-4AE0-BA46-08294746886D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B9C350F8-4BFC-4EEC-B9D2-C94458F5B6BD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B9C88FC9-AC35-415A-8849-162B7E7AD81F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{B9E1226D-610C-4201-99CE-561A01A4779A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BA29AE6D-F903-48BE-83E3-C36B4FCA3C0F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BA70B33B-4B0E-4581-98CC-328589FB34E6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BA7A91E4-2A76-405B-8C0C-BE9E5C849AF2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BA8B1BFE-F387-4574-830E-EEA1EE169FD1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BAB54620-8998-45ED-9F60-0B55321C6A88}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BB11304B-4F4A-44F5-AB87-5248F5770BFA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BB41C795-A62F-4AE8-A4C8-8F2BDF9740B9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BB6590B9-8624-4C73-8CAD-C7E4B907D71C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BB770EDC-D8DE-478F-B7A7-D5087607A78C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BB79F132-3B8C-47BC-9A9E-351EB63BB42D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BB91886F-CEB6-4D08-A2DB-3719F20E845C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BBCA33DF-F59D-4C27-90CA-DF5D75FBD019}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BC228500-F97E-4148-B125-0B7695D82BE1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BC2F7DC6-7F9C-4C63-91BB-EA0D04B5C8EE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BC2FF28D-44BB-4B02-B766-E25D4FBB9F03}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BC3A6477-E0F5-405C-9E58-6D5C60930C7C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BC3B634A-3BD5-4AC7-89AC-27B1A4431594}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BC73CAFD-EC85-4117-9374-DBA8413E915D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BC7DF84C-9F41-4C83-A572-93844375C404}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BC8DC4C1-D1F5-4B38-9334-F36701E04585}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BC9ECA42-CAA4-4D02-9716-70D3FC62A202}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BCC2395E-F3C1-4A39-BA7E-9EB473CDC13A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BCE192F1-E564-4388-8889-3DF19518FCD5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BCE79031-1642-40A8-AC18-F9BCA19D1057}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BCF831FD-040A-43BD-B0A5-A8345300E626}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BCFEFD30-9E97-41FF-8577-C7803BD652A3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BD092934-7BCB-4B44-B019-432C7E3A3A31}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BD0DCC4F-03DD-4333-8B72-032B3E14697A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BD1C44D5-5664-4E07-80DE-2C8750951249}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BD1CC16E-CF5F-4210-91E9-E05218DAB836}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BD70F1BF-0859-4459-A119-85EF0B3CF51F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BDC83A2D-C6C5-40E3-AF80-58A4FFC16EB1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BDE4E5F5-FD2D-417F-A7D4-E0C9570F9EA8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BDF4821E-96BF-4660-8996-91622706753E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BE1BF063-7D11-48FE-ABDC-0996760AFC9F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BE20D581-6752-42DE-BE0E-4437A1438E56}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BE4FC17C-2D46-40B5-9646-4D7F8ED21CD4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BE7BC00E-C8A3-47B7-B2C6-237976B7C112}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BE86969D-DEEE-41C6-A369-DEC955863E0C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BEF9793D-DD26-42A1-865D-61656F6AC6C8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BF04F357-2227-4A89-83A1-7D588D266E8A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BF07DE89-8127-42BF-85B1-BA01EF1130DC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BF1BBC05-BF39-45DD-91DC-280B6436DD55}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BFC907C6-F637-4EAB-94D2-FB93672B1542}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{BFE6AD4A-7B08-4711-81E0-F571E3C88F9A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C022F541-51BC-471B-BE9F-D3C95B903E21}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C0366CDE-9B6A-4836-A126-B8822CEBFA26}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C048A6FE-A50B-492B-BD20-0D9DD390446C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C07DC29D-7DEC-4E69-8D9F-FFA64B1921EC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C09A1DFE-CBEC-4B9A-93D5-572D08C4C205}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C0A5D9B4-C7AB-4FEE-A5B8-56311F718641}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C0A6BEDE-36D2-448F-A77F-7A0011858DBF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C0B65E64-5769-4A53-97E4-77E201111F8C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C0C733E5-A67F-4DDB-A781-B26E7181331E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C0DAC690-21CA-4F71-8DF3-B4F81C12601A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C0FF8AAE-25F0-493E-9305-0F350A1C9F53}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C101CC75-ECEC-4B27-8BD4-55124C338238}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C1064D2D-94AA-4086-8575-A556671931E7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C10FCF8A-2565-4F6B-93A8-D0CBE4A241DD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C11894A4-6C1E-4845-AA7D-B82989F4968D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C150A870-A8DB-4C51-82D5-63D2E048E4CB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C1714DCF-9F52-4C3D-803F-3F7B7065D595}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C171EE74-6813-403F-9943-4018F6B9A11F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C1804541-5947-437A-A162-FC866BC8BA76}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C18CD945-0527-4B88-80F4-F0AC1B7B5710}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C199CA5A-C21A-4662-9930-E215258EFEB6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C1B64D95-A6B3-4B93-B605-FF3566AF7C12}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C1DE6F59-BE9F-49E3-BC04-8F591794A78A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C1F17395-6EC5-4353-B773-3D31C804339D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C20A1FFF-518D-4A66-90F7-A39677F8F6DF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C2268959-A8F7-4011-A3AC-221E1D4C587E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C23B1D5A-53E6-48F1-A398-35A6A9B34750}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C26D1BAC-F3BE-4EB8-89E2-A7A8A1B340E6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C2987FDB-A6B2-44AF-AE07-D10C43F7FA74}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C2B1ACF0-6268-4735-9A5F-8604FE9DF79A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C2D6A230-2FD8-47C6-B1EF-9980B4873D00}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C31DC47F-6298-46A6-8FE0-C6C11C847876}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C345F920-CC59-419A-9854-CBF8B1562BF2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C362565A-651B-45D6-B05D-358951CAB1ED}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C38EE339-6AAF-4C9C-B775-378E4CFBE666}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C3C654A0-1D88-493B-AF34-94547BF89EF1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C413DF86-4BFA-4130-87E3-ABCF44EBD893}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C4279AF8-84CB-4410-8B7A-802718D69E99}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C4317331-EBBE-4DA0-9C67-FA1E9D466009}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C43A4E8C-A5E2-458E-BE6F-9CECC6C9CD97}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C4A5703D-D4FC-4E7B-9CFB-CDBABC96E536}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C4E613C5-B783-4F1D-A183-8BC1DF332DE0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C4FD454D-EEFC-4864-9469-BEFD4585D915}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C53F2395-A64B-47B8-9E24-AB7F0A99F698}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C5482B92-1A83-494C-9C6F-8E991BA77C98}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C5582320-4D72-491C-8C94-5A19DDB437B6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C56863E8-F671-4DA8-92AF-D175B7F948DE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C57DDE56-A013-4541-9390-ADB3272E21C4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C59BA910-B677-4FD4-A9C8-ED4325F89DFA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C5A280E6-B90B-4604-BA2D-9A50261B874D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C5BED9D4-6F92-4BBC-A785-C79DE5AF55F6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C5DAC092-8D84-4F0A-A766-746B368FB2F9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C5E9B9A1-15C3-4ABB-B9E2-318090E2FA01}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C5F3738B-8C32-4F99-BF1C-D8FAB19659B0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C605E6FB-C111-4722-AB7F-AAEE57913083}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C63B3EEE-1EF4-412A-892D-DCE2D53C60BB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C64DDBD2-BEEE-4839-BAD4-B04090F57890}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C659C291-88B9-4016-8544-3D39450DCC56}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C6989C42-88E2-47F1-AE75-591338BD5C29}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C6D6FB0A-5B39-4446-9988-7B08FB807F8D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C6DA415E-0CC9-40FA-97D0-C56463D16785}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C6DB04C3-1282-4BD0-B62A-8FE392AD86CD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C6DC08EE-47D5-4932-9729-C8DC5DA5019C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C6E53597-2159-4DA8-80CC-23E2B12CA871}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C6ECF0BD-BF06-4DB4-A565-CE36D7DF2E1D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C701FE0F-35C5-4127-A540-10976F87644A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C757017C-CAB7-49C6-83DC-D547BF8DEE8B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C76716AB-5840-4439-B1E1-95A091CCAC50}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C799BDB8-D1AD-4DEA-8E1E-24CD75F95EAE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C7D5023E-88D8-4117-8203-9B3C3722228A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C7EA2685-9A09-461F-A6E1-4EC38A040F39}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C8786F1F-A55B-4495-8AB5-2B84F6E6BC5C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C8D48163-ABC6-43B9-B5C3-D4313A2A3358}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C8EE813F-7256-43EC-986D-5356BB78A583}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C8F8E945-887F-4D1E-9304-B1ECABBEE794}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C90EBEBF-4684-4C94-8789-BE3FA546BA8C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C979F465-4E85-43E4-A686-0B1D09303999}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{C9DEFC2C-2C9B-4AB7-BEA2-2FF33CDCE3E5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CA15B871-35D0-4D23-9E60-694A2352EAC4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CA20371A-45F2-48A2-BB87-285EE4009B35}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CA26C61F-19F9-4828-9038-F96C7DDBDCE4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CA4DD295-74A9-486B-B0AE-29FB7FD72CF9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CA5FAEAD-5EA2-4555-AE6B-88CCF2EADBB2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CA6A6A41-7B79-4FA6-B248-BC432DD5A3CA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CA99A8B3-EEF6-4DEC-B82D-3D8E295349ED}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CAA81487-7EE5-470C-9BEA-18CC0EA11D76}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CAA8CAE3-2C5A-40C1-B014-61533061AC4D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CAB2DA26-D908-4363-B03A-96E5257AC5E6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CAB6C2B2-00BC-4D66-B615-D06C084DA980}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CADE8DA4-748B-49CD-BD36-3E9ABD846714}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CB717A0C-D833-4C23-8A14-EB4F290E58B7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CB7FC9BF-B7C5-4C48-9300-28B71EA7710C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CB8A35F6-7741-4584-9753-32D9365DE81A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CBC79B29-B467-4417-8F51-9F5FFAF18235}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CBD3840C-D36F-46EA-B0B1-B87D949DA701}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CC1B1C46-ACE9-40E8-AEA9-8A4B088D0608}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CC24D100-750B-4BBE-9A3F-10BF0F17C1FD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CC38E9FF-BAE2-4A13-A872-4F7BD431E731}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CC74D8EB-C868-47A0-A651-552018F3F5E4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CC9A7C27-0A91-4D61-B292-EBD9C2B17B35}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CCA61710-9FAA-4C14-97EC-105D39ACED91}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CCBD7EA2-EE9B-483D-B841-83F333EA7D70}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CCD40323-2694-427D-990F-A1996B81C720}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CCF34DFA-E228-4BF8-8348-CB7B2239A6A7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CD0F52CD-2EFD-4608-BB61-E0ACF45AE5B9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CD9B8EAA-2B5C-46A9-9D4C-37FF135B980E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CDBEC8B6-3C8B-4BA2-B504-F559B97FC185}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CDD04C6B-F562-4E64-9484-081766E3A0DB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CDF5B1E4-853D-44FB-B6C3-A74BEF35C566}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CDFC34F3-81EA-41B7-99F5-6E9CA625CC9F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CE372E5F-294D-40D9-AAC6-6296C362985D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CE521D7E-F995-490B-9D9D-EBC7103CC28C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CE65D507-23D4-46C5-920B-B0C7A2791539}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CE709E13-0B14-4756-B7A6-91A96F4654F4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CE791F16-34DE-467F-BAC4-1CD5F234CD44}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CE8D14C5-BD0F-492C-B9EC-3914B243EA3E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CEC6C302-1707-4B48-9721-1E1CFD2104C3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CEDD391B-D964-41DD-A025-5824BF7120EB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CEF507ED-9ACD-44E7-A8D3-8995953BCC27}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CEF8227E-189B-4D5E-8400-A3191BF8B90E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CF1DD428-5C3D-4144-B574-795ACCC16199}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CF38CD99-E735-4151-8B94-5F65D10CAFD4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CF57EBF6-DBEE-4F54-A359-1A3290746E23}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CF59F57E-EAEB-4CCE-8488-D78AAE11DC75}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CF73B7EA-0A74-482C-97F2-0269A30B14D3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CF94492B-5D04-40DF-9654-347F9D841375}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{CF953B0D-EA3F-4583-B457-06E1141F7766}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D0420DE2-7B6E-4794-B552-03E5654F2D7C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D059B8F5-F888-4AB9-B7F7-D007179CEEC7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D06655E2-925D-4502-B7A5-A7805DAAED9B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D0A826CA-7410-4AF1-A1BB-45EEB233A00C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D0AB179E-6889-4114-B687-4CDE1617D24D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D0B2E9A9-9F64-4FE6-A959-AA88A235AFA3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D0C47C28-B1E4-4183-BDEA-D679AEF6FA18}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D1218A09-0E8A-40C6-A469-1A86B27F1E15}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D130111E-0359-459D-992C-B506DB01BD55}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D17C0A9A-8F39-488C-9C25-30D227536ED4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D182A0E3-E109-4581-8DEA-5F7663581C9E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D199CF53-7CCA-48B1-A2AF-D7A20E01A5D9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D1C8F89D-D74D-4B7A-9294-A26AA7270FDA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D1DFE72A-9441-4A5D-B45F-73F9164A50EF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D1ECA8C4-C2E3-42F1-A036-6E2C453D94C2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D22A1A09-3AF5-4DE8-B791-62ABEED572CE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D26543CB-3660-40A4-85FD-0D8147965FB5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D26B3FAA-25A7-4753-A252-C8E266489053}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D28C8077-E0BB-4A4B-B013-883D9F9F7654}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D299EF91-E47C-4192-8C1F-F10B2E8EDDF3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D29F4545-3CF9-45F1-AF6A-45118707320B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D2E6DFC1-769E-4559-9D7E-DE1C63140030}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D3362783-0369-4F55-8F18-D853B13D3464}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D3667AFC-06DE-4295-B0A8-06B67078FD54}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D36C918F-C37F-43F5-AABE-8F79711D5571}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D3842510-E864-4ADE-82C0-3B924C1055CE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D3C24C23-ADB3-46DC-BBE9-5499340A2F87}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D3D37222-7CF1-4834-BBC7-3BCFD829D90E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D3DA01EB-3495-4EF6-8C4B-377D20E40E8D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D3E13421-CD7F-4056-846F-61EB86FD79A7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D422859B-2900-47FB-8670-9EBC7F0139D9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D44126CF-368D-4B55-A980-85C9F73CC9AE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D46D35E5-FB0A-4E68-972B-AA7FAC6AE977}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D4A895FD-F75B-475B-9984-06447C06AD2B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D587D5EA-4D48-45A1-B511-C0CFD17481B1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D594807A-5BBC-4978-85CF-58337362D0ED}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D59C76B9-DC05-4FF1-A8C4-D88195DCA234}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D620A34B-8CCC-4F83-80F7-20A891ED5D21}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D6232F1C-874A-4B04-8CFE-E4A81038675E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D64E5F41-52EA-4F90-BC2E-9CFE55ED8886}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D65D080D-1908-4701-BDF5-C2E4C68ED108}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D69093F1-64C1-499A-BDD7-EDE54E622D18}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D6B8ADAA-902B-4E80-8D30-BE1F7D2D9423}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D72F8BFA-C00D-4C5B-863A-9C43AF2F70F2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D73DF8DD-B770-468C-904F-0552AA2989E2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D818E47C-3418-414E-A8C3-F1A8060A9D6D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D831179B-271F-4657-8351-257E5A18F00D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D8678BBD-BC71-4450-ABDD-24CB2C21762D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D8A725A2-6CDE-48B7-BC7E-A146F5326E89}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D8E0137C-5628-4A90-A2D6-A84F5E2F0644}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D8EF7C83-C307-4773-B99A-1540CB6FAB99}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D910431B-B316-4C99-978B-16DE481D5A70}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D9111FCA-7F54-4558-A2F8-9AF52669627E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D923DD41-5132-43AC-B971-351BC315FC3B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D982DDC4-9F7D-406C-A373-0BD789F0926F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D98C1F82-A4F9-4CAD-8835-60108FD7C86B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{D9A22A25-0A93-4B08-908C-881032B1A716}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DA48376E-5215-46D4-B3FD-D7C5F48E708A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DAC7415A-E411-410D-B24A-1E01AC1A4D04}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DAE0B3C3-654B-4029-945D-2B3CC0CDF475}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DB2EE22C-BB9E-4652-8083-E4F13B11FE4E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DB318DE5-6637-42BA-974C-71C29EC9256F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DB8ABAC3-889E-4977-B0C7-BC890CFB24A5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DBAAD022-F7AF-4751-A580-F6E724C7BF4F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DC2103A2-E15A-405D-8D59-C35CFA0B1648}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DC322E0D-42CB-4075-9D40-00F198B7FD80}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DC3E5B16-BAEE-42C1-AE63-8111183C16A9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DC5190D6-B721-4D05-A230-AE458596E667}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DCEB9142-3599-4A22-AA32-CE02A31E4A25}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DD26D2A5-D554-4B5C-AC17-5B89E041E272}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DD2D1045-F9F7-4EF4-930B-57CEABEBE8F1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DD35133A-58B6-4626-A136-D4C67C1DEE73}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DD8DA38C-7671-48BE-A7A5-471272D5CA7D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DE636CF4-E9ED-4BAE-9FE6-80E3F3D2E1D9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DE743C58-6F1E-4E3B-836C-6763C239EDBF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DE751BAE-A5A8-4EA0-B1CB-A47FC66987B9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DE9924B2-EC07-4571-8C7C-9206AD9C82BD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DECA8CB8-2F8A-4E2E-979D-39184008581E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DEDE8E8A-F4DF-4A23-B813-2D32CD707357}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DF55E706-4DC3-4571-BC04-3CA04EA04125}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DF573804-101F-4D06-8CB7-9B1183A4BCC7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DF9BD535-176A-4FA1-80DD-2F6C242A10AC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DFB1C422-9E07-4C19-BA86-C714076A10CA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{DFE34BDB-2C6D-4EDF-9128-BCBA6BE56672}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E02B2791-4066-4512-9BD5-C071C31223CF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E03788F4-B94C-48B6-9BE4-3AD31A409454}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E03E44BF-0124-487D-9123-495BC2EF9366}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E0BB5D99-52C3-44D8-8FB7-61A4319079A8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E0CA0E4D-9B2F-4967-9537-0F82720C0D7F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E1009A74-7BCF-4210-B861-0C7D8C68F39C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E11D4085-9A77-4624-802A-C21040C80AF7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E13CBC49-BF34-4434-9E92-640864D0FB9B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E14BDC9D-D46F-4672-8CDE-0A4F18BB92BE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E16A09D4-EED0-4177-B554-7D76969E1E03}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E1805EB8-42D8-4087-ABD9-857998E4022F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E18D7096-D6FB-413B-B599-6E381693FA53}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E1C38259-EEFA-4CD3-A5E8-5236060759A4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E1EC778D-246A-4E5A-9063-1D37510592D3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E201609A-76AA-4D37-A6A8-9999C49E0B50}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E20B798B-63AE-4E2A-A813-BD5CDA9C45C5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E2133FE1-E52D-449A-BDE1-D11ADF7A68DA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E231CFFD-A529-4D0B-93D7-2C5A678C0668}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E246235B-1B21-42F3-8BE2-9BAF05FBB0E3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E24C6EA3-83F8-4094-AA20-C4EFEAFB511F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E25ADE58-350A-40A6-B582-F02A5ACDB46B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E28E4CFF-7DE6-4F53-91AA-1D8CB53BE764}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E2AADD0B-83CB-415A-9D8A-EDB47B08748B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E2F45257-4E9D-48B5-8A56-65F5327AE047}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E32EC386-0262-4CED-A119-975E60DCE388}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E36AE006-7159-4C2B-A8C2-4A2D66FB3F89}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E3721D46-E9D2-491B-87F8-0CABE7398613}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E37E4AF5-1D7D-4CC9-90E5-C5D75EDFC15D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E38E1A33-6129-49F4-BA31-264C3F3D94F6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E3907350-A6DF-49AB-8F4E-BA44C548D44A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E395C30D-A481-429C-BE3C-840EDCAAB9C2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E3A3F2DC-0FAF-4C15-8B03-97811A11D299}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E3B40C01-443A-4307-89B8-2B4AEF80ED34}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E3F3BB2C-12CB-4FA2-817B-2FDF75D29A17}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E4048B78-3927-4694-B835-036DECF77D96}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E41694B2-CADE-474B-9581-94AF4D7C468A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E42AE61D-E4BC-4EED-B20B-8CF37966813B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E4697D56-559F-4460-BE03-D85547ED8B5E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E482B725-1AAF-4638-8A36-1362E58FAFC5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E49EDDC8-26B5-4442-BAC5-A24D9FF0E2DB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E4A2D280-2BEA-476D-925C-928F14EC124F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E4A6FFA5-58EB-4211-8046-4655D71E5A8F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E4B533E8-BB27-46DF-8C77-838B22BDD99B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E4C59CF3-0DC7-4C2D-82C8-557D035ABC36}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E4C605AA-E2CB-4BEE-82D5-31FA6C1F43EE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E4D9F866-0F16-4A24-97B9-24E47410ADB1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E5313C71-6253-43E3-B553-59FEE63B7515}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E537FAC3-0C4D-469A-9765-1034BF21AFA8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E555C740-15A9-41BF-B8E1-CAF111E52E45}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E558241F-413D-46DB-B224-FB0B29CAB14D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E593359E-A5F1-4109-A4B7-8443550E5BB6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E5972370-BB46-4D43-8E13-2FFCCA6B8DF2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E5B2BD6F-8185-4220-8532-356CCE418B24}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E5D257DB-830A-42F8-AAE2-C4822FCE86FC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E5EFE94B-3A5A-4766-947C-C99321C3F75A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E5FD4B5B-3FEF-4973-9514-2ABEFAAC6BAC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E604C942-38EB-4139-8128-83D804E24CAD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E61CCFD9-1ECD-4604-A4CE-C79287B3887A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E68A977B-5ACB-412D-AE3D-0429783EB6A5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E6A4022A-552F-4A88-B106-2AB97C4313DC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E6BD05EE-4F56-43F9-B1D4-BE2AA9E42B71}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E6D09EB4-28C0-492F-82A5-4F27F480EB98}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E6E48A71-EF1F-4023-AAC9-BA587D417A67}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E72D44F4-50B8-4B91-8BF5-34F2066A7308}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E7627A22-2FDE-4F52-89A1-06A02743188F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E7ED3FB7-34BC-4440-886A-6402D3A649DB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E8091394-A018-42BA-8A10-5CD905BD1452}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E886A6B9-1B09-4AAB-BA52-E8B3B6BF7C11}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E8B11BAC-6FC1-450D-9864-1541CBD6B6AA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E8B7068A-D9B1-47E3-8FD6-709CA3521915}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E8BAEC8E-0393-4E02-ABE0-122E8535EE47}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E93CA9ED-A7AD-4453-8B7B-732CDEF86CA8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E947CA4A-B05F-403C-8081-F28C41026691}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E9481187-E47B-49A2-91D2-442F9093801F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E9599A64-2A10-449D-AD22-9B8C3DAB30C8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E95F81AD-AC58-4BD6-A466-B58D79C4D283}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E97AF96B-B19A-41C1-87C6-3C61CA127663}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E9895AEB-8AA9-41C7-ABCB-E364534993BC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E99DA664-FE43-452C-9FC5-CC5EF3B4AE91}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E9A0DA88-17EF-441F-A94E-782CAD85E27D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E9A48274-D607-42D8-9B77-D6B71EB7F183}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E9CF969B-064F-43F4-B177-109E88BC5125}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E9E7B355-CC63-430B-B0E5-52DDA407F685}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{E9F6784A-3C88-452B-9293-2FA687BEA9C9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EA4D208C-5F5E-4170-9374-607525FB65B7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EA4F98B6-3AE7-459E-8D93-8E6DE3B56F13}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EA65710A-EBC4-4BA9-9EC6-9879D33E4D49}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EA6C2482-060B-45A9-92D3-0462E6B8DFAE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EA78B8A8-DEC5-41FE-ACE7-537696C07C0A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EA7A0419-7DBB-4F58-9CE8-B55FD2AE88F4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EAAC077E-3E4F-44E3-8528-AE975F150078}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EAB87FE4-752C-4AF4-A26B-A053FCFA0520}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EAC0B43D-7F1C-4298-B1DB-CF62CECEAE08}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EAE523E2-1660-4DBD-BC46-9235C385CE2D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EB1F18C0-82B8-4190-B2B0-B0AC14F2F7FF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EB3FA299-23FD-49DD-9C5D-EEFB291932DB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EB438843-4ED2-4946-98DD-28F6F06CA25A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EB543A9C-38E8-47B5-B89A-D6A61A028D40}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EB842679-2D95-464D-9554-B5DD8A5B1246}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EBA43C91-0515-4119-9326-3B88FA5678DF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EBA9AC92-AF07-48B7-BA4B-D18B5317F4E5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EBD971B0-369E-42AB-B0A2-CACB08B726EB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EBED2124-83BD-4021-B463-C83153AC8D3D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EBF03943-2E3C-4529-B21B-3747A57F7AAB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EBF2BCD5-14D6-43BD-B25A-C04645823CF1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EC520207-4357-49F3-A859-5C9542BA4711}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EC7510F1-D03F-463F-9D50-1212FA08A11A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ECCDEB90-C3EF-4B08-82BB-D7B2844FC4EA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ECFA692F-CC7C-46CA-BF10-2015762C0B39}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ED108372-E5B5-42DA-889F-7838BCF5C9F7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ED275C79-A728-4A53-BC3C-B4E84CEF39C3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ED739887-AB33-4BC1-B8B1-A088E4F83FAA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ED83192E-3FFD-4F53-B1CC-0648E8AC656A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ED8AB9ED-CDFB-431B-9E76-F2EF3F475BAA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{ED8C7757-B1E8-4D0F-BC62-73C71EEE96F9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EDF455C2-8061-4A04-AF4F-44E1E039CA3E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EDFBCE6F-D576-42CF-BBD3-EF24AE01B3B0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EE01C589-655B-4A10-8E50-78739EB1D1EB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EE057E1F-2937-4FF2-9643-F85D4CA542E9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EE5CC003-31FE-4612-816B-C13B4D64D5D0}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EEA3A884-55A2-48D2-9593-1DB575B03476}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EEFD7E75-C1F3-4906-93E7-448FE17DC9FC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EF0E73C9-A26B-4B69-917D-3DB8A3822AAC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EF21C591-3928-4673-B19E-2AB568957CCC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EF57E742-BD02-4819-815C-61CEE44119B8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EF90A547-BDC1-4DCF-9E31-8232B3B07158}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EFA8D99A-3729-4CFD-9A6F-54FF0D872FF6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EFCB342E-4429-4130-9DB5-3AFE90869A1A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EFCFC82C-FFB3-4F62-9FA6-F12A66CAF077}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{EFECE65A-5418-4427-91E1-EA1AFB076B5E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F00F2EDA-6934-403F-B66B-4268AD8B194D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F029A979-EFAB-4AA1-B9EE-829AA629F115}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F05715C5-5AA6-4F1C-B087-705F20DB3539}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F075C4A3-D42D-496C-BEC1-6829AAD7C739}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F08FE8E4-1FFA-4113-AD38-7E049BFFBFC8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F0A775C5-F31F-4B02-A5F0-147E00782BC1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F0E7282A-0289-473B-A20C-73AA633B9B97}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F104F085-95AD-4BD0-9307-3F14EB718D4D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F1171E53-EB8F-4CDF-85F5-819485996EB6}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F149291B-406C-48F6-BD6C-42FA68F060D2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F1635CAF-1FD8-400C-B6FF-6AE04A12BC03}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F17243EB-52D9-4E84-9A7E-0F4B64838CFE}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F178F954-0951-41D7-90BC-2ECBD93259EF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F1BB200B-474F-4188-AAAB-4C2129214723}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F21D4038-F723-4781-B8B3-0A0F588A4C98}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F259EC1B-CC36-4B36-A646-5B868B1D9407}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F27D596F-5BCD-4619-908E-A214059801FA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F27E9C5E-3AB5-42EA-9F34-D3A7BB55C834}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F2C44376-3B29-4A51-8D46-239B89534317}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F2CEEE86-39BE-40D5-8601-76EACBED7778}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F2E47A71-A7EA-48B6-B017-F92C3A2E99C5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F2E4B796-428A-4EF5-AEB5-947C6B4089E9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F3092DB9-BE26-4891-A8B8-04F03293C064}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F31646DD-CD40-4360-AAD9-B96C8F51BA74}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F33069B4-4D81-453C-ACC9-971B092836C8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F362DD25-0089-4D8A-AC64-C46A488A1A0F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F37030D3-1C42-46EE-836D-DEB3D99906D4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F388D5C3-F386-4610-ACDC-5DDDCC0D731D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F3D0C79B-1D47-4938-B63B-E3AD26DCA730}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F4438D6C-070F-469D-81E3-ADC67E20C6FF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F44D5318-AED5-460A-8931-E356504C6D90}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F48FCEF0-0480-4778-821C-8A33D6FDEE2C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F4944DDA-EE74-421E-9603-A1B13D98A2CC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F4D7636E-55C5-40FA-89E8-4A76AC2866B9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F54F2FC8-577B-4CB5-8AC6-03F59D3E933B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F5759958-13F0-40A0-866F-46288029129A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F58B6455-DB9D-479D-8A59-316D1B79D2BF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F5BD12EA-B7BE-4B90-88D1-27123244D997}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F5D5625C-9589-4F50-8C90-6DB2EF5A4E53}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F636A21F-040B-4215-A5C8-463E58B1478B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F6375856-BA9E-4A9E-AF9A-458F37E65372}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F66D67F8-E38F-4EA6-B6B5-A36AFB95E024}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F6E8346F-3350-4352-BA64-C8FC82F5F9A3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F6F2C6B6-070C-4B81-9CA9-A2D80D32F993}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F7028BC8-B754-4E9F-B68C-28DDFEF71BC5}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F72B11B6-2DE7-4E67-9042-4273A87CD7D3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F74E8944-8F83-4D16-88C9-E1B3498A3765}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F7741974-0C03-4BA5-A352-2E5FFDB74248}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F7947407-E550-4C30-A8F0-B467E4370302}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F7A3E61D-FF07-4717-8417-6F2971E8F05E}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F7B81312-5A74-4C0E-AB6F-BDECF36184DC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F7BC4E38-432F-47C3-956E-18C2D56EF5D1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F7E942C3-5E86-466E-A001-E08DB1FFB1DD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F82A4305-2B30-480D-B910-3DEADB5DA842}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F87AAB1A-54DB-4C64-8566-7AF584346549}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F885FFA4-CDA8-431F-9A98-83211982C69B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F90555AF-8162-49DA-875C-3391E0383041}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F973487B-00C4-4561-9AE2-B98AD78AF574}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F9A986CB-C93E-41AD-81A2-0B8BEBAB345A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F9AA5E1A-0137-4FE8-AE91-D14ABE48065F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F9E1C659-D2D8-4172-B58A-1D0EE913036D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{F9E86932-99E4-43A2-B980-66FF1F049AA7}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FA0A9031-66FA-45C8-AD09-DC6BD279043B}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FA263BFA-7620-4CA0-996E-23EBA1D71002}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FA2BC93D-1655-42DD-B592-177DF1360264}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FA5CD7F8-5575-4B45-8219-69BC8EC5B4C2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FA717FBA-FB2F-44DD-81E3-5A9B99F744A1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FA72A09F-E3D3-4E6B-8B01-2D3D53BCF5AC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FAC541E4-97D9-4C98-9AA4-A50315AE2AAF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FACC16C9-E7D1-42D9-84AB-59D1C0CB181F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FAD1E7A7-301D-4859-8AA6-6119F502C82A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FAD6E27C-AE60-4AE9-839A-AC91C01C85FA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FB1FBD3E-B8AB-4595-90D5-17BF0FCA9657}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FB2EB96B-267F-4BAD-88DC-D19EF0E06482}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FB878F7F-5D4C-4A4F-ACEE-5B96C3C4ACEB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FB89E92E-13C0-4F63-8A1E-BE16D732D9D8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FB8C4BC4-550A-45EE-BD28-CD41435AC686}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FBA2F40C-48DF-4A00-9C02-58D38A80F69D}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FBFF56CA-7A04-44AB-8C8A-6D57F5BB31DF}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FBFFEA4A-0656-41FA-82B5-26B88809B80C}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FC2F31D4-49A0-4E62-9216-1A37341BD795}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FC7A8D7E-AF5D-4D8F-9D23-139055B0C259}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FC95D89A-1F2C-4EDC-9AA2-8F4755822C17}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FD187BDC-3C72-447C-825C-81C5475735B9}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FD1B19EE-0898-48D5-823F-83CBCBB13DEB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FD38152B-93A4-4DD8-9C18-08FC5AB6FDC2}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FD4AB6AF-0C48-48B6-8C10-DBA41FCB2BE3}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FD4B0296-EBE3-498C-A39D-7DDBFBA64F5A}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FD5C5656-4DF0-4149-A099-674DCBA18A55}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FD8AEB85-54A1-4F56-B497-93A632CF29F4}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FD93A0C2-ED30-4355-9523-D8125A411CCC}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FDB77EA7-E030-439C-85E2-890674F22363}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FDBAFACB-E862-4595-9256-1426058E6674}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FDD650AD-6EA3-4088-89DD-A4046F73BD93}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FE73C688-8232-492A-8223-F368F5F1B644}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FE7B4AF7-C1F6-483F-8201-89FD7CF213FD}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FE87BFE3-20F6-49C3-80CF-DAB690E523CB}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FEBFB3B1-847D-4E19-8A48-C52496A96B41}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FEC11C7C-C430-40EB-BD07-DF5E9F62BEDA}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FF1DF4DA-7332-43C0-A4A4-7CE7AEFA37F1}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FF206FE5-B1DB-4173-831E-83A3D0205094}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FF48D0B2-D9A5-44C1-A801-AA487E71D93F}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FF847376-9400-4A31-A7B1-E54C439420D8}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FFC6EE20-7D73-4994-ADA1-3F7932AB2F17}
Successfully deleted: [Empty Folder] C:\Users\Lore *******\Appdata\Local\{FFDE6512-A5A9-48B0-B756-F9A452DEF3A7}
Successfully deleted: [Folder] C:\Users\Lore *******\AppData\Roaming\reviversoft



~~~ FireFox

Successfully deleted the following from C:\Users\Lore *******\AppData\Roaming\mozilla\firefox\profiles\fcmf6clf.default\prefs.js

user_pref(avira.safe_search.search_was_active, false);
user_pref(extensions.unitedinternet.email.runonceNewUsersShown, true);
Emptied folder: C:\Users\Lore *******\AppData\Roaming\mozilla\firefox\profiles\fcmf6clf.default\minidumps [1370 files]



~~~ Chrome


[C:\Users\Lore *******\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Lore *******\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Lore *******\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Lore *******\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.08.2015 at 20:33:57,83
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         

Alt 22.08.2015, 21:41   #9
mezzomix
 
Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



FRST
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:20-08-2015
durchgeführt von Lore ******* (Administrator) auf NB******* (22-08-2015 20:36:26)
Gestartet von C:\Users\Lore *******\Desktop
Geladene Profile: Lore ******* (Verfügbare Profile: Lore *******)
Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Hewlett-Packard Development Company, L.P) C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-04-05] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2011-02-09] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-07-21] (Hewlett-Packard Company)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [489472 2011-02-09] (IDT, Inc.)
HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [3488640 2012-03-14] (Hewlett-Packard Company)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\...\Run: [File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11268096 2010-05-06] (Hewlett-Packard)
HKLM-x32\...\Run: [AppleSyncNotifier] => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [334240 2012-09-12] (Hewlett-Packard Company)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66936 2015-08-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [782008 2015-07-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [HP Connection Manager.exe] => [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [Syncables] => C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe [530736 2010-05-18] (Hewlett-Packard)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2015-03-18] (Microsoft Corporation)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [BingSvc] => C:\Users\Lore *******\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-12-04]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 4.0 HD Edition.lnk [2011-02-11]
ShortcutTarget: PHOTOfunSTUDIO 4.0 HD Edition.lnk -> C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe (Panasonic Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/4
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=de-AT&Src=MSE&Tid=00033BB0&OHP=http%3A%2F%2Fg.uk.msn.com%2FHPCOM%2F4&OSP=
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3921111220-2900040076-1547133076-1003 -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3921111220-2900040076-1547133076-1003 -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
BHO: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2011-05-02] (DigitalPersona, Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: File Sanitizer for HP ProtectTools -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2010-05-06] (Hewlett-Packard)
BHO-x32: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2011-05-02] (DigitalPersona, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-05-08] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-08] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{F4FF26DF-9FE9-4F91-A720-687E53208FA1}: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Bing 
FF NetworkProxy: "autoconfig_url", "https://guard-safe.net/a2tunnel.js"
FF NetworkProxy: "no_proxies_on", "*.local"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-13] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-13] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\system32\Adobe\Director\np32dsw.dll [Keine Datei]
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-08] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Extension: Avira Browser Safety - C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\Extensions\abs@avira.com [2015-08-20]
FF Extension: GMX MailCheck - C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\Extensions\mailcheck@gmx.net [2015-08-19]
FF Extension: Kein Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-19]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-08-19]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2011-12-09]

Chrome: 
=======
CHR Profile: C:\Users\Lore *******\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [887128 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [461672 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [461672 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [227592 2015-08-03] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S3 DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [704512 2010-02-02] (McAfee, Inc.) [Datei ist nicht signiert]
S2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462160 2010-07-16] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [362040 2010-04-28] (Hewlett-Packard Ltd)
R2 HP ProtectTools Service; C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [32768 2010-10-19] (Hewlett-Packard Development Company, L.P) [Datei ist nicht signiert]
S2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [90112 2010-06-14] (Hewlett-Packard Company) [Datei ist nicht signiert]
S2 HpFkCryptService; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [281192 2010-02-02] (McAfee, Inc.)
S2 HPFSService; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [298496 2010-05-06] (Hewlett-Packard) [Datei ist nicht signiert]
S2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-09-12] (Hewlett-Packard Company)
S2 KMService; C:\windows\SysWOW64\srvany.exe [8192 2014-03-31] () [Datei ist nicht signiert]
S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S2 QDLService2kHP; C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe [1687360 2011-04-29] (QUALCOMM, Inc.)
S2 SMManager; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\SMManager.exe [84808 2010-09-17] (Smith Micro Software, Inc.)
S2 StatusAgent4; C:\windows\SysWOW64\SAgent4.exe [131072 2006-12-20] (SEIKO EPSON CORPORATION) [Datei ist nicht signiert]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R5 ACPI; C:\Windows\System32\drivers\ACPI.sys [334208 2010-11-20] (Microsoft Corporation)
R5 amdxata; C:\Windows\System32\drivers\amdxata.sys [27008 2011-03-11] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162528 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [141416 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 cdrbsdrv; C:\Windows\System32\Drivers\cdrbsdrv.sys [39208 2006-08-25] (B.H.A Corporation)
R5 CLFS; C:\Windows\System32\CLFS.sys [367552 2015-03-04] (Microsoft Corporation)
R5 CNG; C:\Windows\System32\Drivers\cng.sys [459336 2015-01-31] (Microsoft Corporation)
R5 Compbatt; C:\Windows\System32\DRIVERS\compbatt.sys [21584 2009-07-14] (Microsoft Corporation)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [40760 2010-03-09] (Hewlett-Packard Development Company L.P.)
R5 Disk; C:\Windows\System32\DRIVERS\disk.sys [73280 2009-07-14] (Microsoft Corporation)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.)
R5 FileInfo; C:\Windows\System32\drivers\fileinfo.sys [70224 2009-07-14] (Microsoft Corporation)
R5 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [289664 2010-11-20] (Microsoft Corporation)
U5 Fs_Rec; C:\Windows\System32\Drivers\Fs_Rec.sys [23408 2012-03-01] (Microsoft Corporation)
R5 fvevol; C:\Windows\System32\DRIVERS\fvevol.sys [223752 2013-01-24] (Microsoft Corporation)
R5 hpdskflt; C:\Windows\System32\DRIVERS\hpdskflt.sys [30008 2011-05-13] (Hewlett-Packard Company)
R5 hwpolicy; C:\Windows\System32\drivers\hwpolicy.sys [14720 2010-11-20] (Microsoft Corporation)
R5 iaStor; C:\Windows\System32\DRIVERS\iaStor.sys [409624 2010-04-05] (Intel Corporation)
R5 KSecDD; C:\Windows\System32\Drivers\ksecdd.sys [95680 2015-07-23] (Microsoft Corporation)
R5 KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [155584 2015-07-23] (Microsoft Corporation)
R1 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [109272 2015-06-18] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-22] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R5 mountmgr; C:\Windows\System32\drivers\mountmgr.sys [94656 2015-07-15] (Microsoft Corporation)
R5 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R5 msisadrv; C:\Windows\System32\drivers\msisadrv.sys [15424 2009-07-14] (Microsoft Corporation)
R5 Mup; C:\Windows\System32\Drivers\mup.sys [60496 2009-07-14] (Microsoft Corporation)
R5 NDIS; C:\Windows\System32\drivers\ndis.sys [950128 2012-08-22] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R5 partmgr; C:\Windows\System32\drivers\partmgr.sys [75120 2012-03-17] (Microsoft Corporation)
R5 pci; C:\Windows\System32\drivers\pci.sys [184704 2010-11-20] (Microsoft Corporation)
R5 pcw; C:\Windows\System32\drivers\pcw.sys [50768 2009-07-14] (Microsoft Corporation)
R5 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [55856 2010-03-19] (Sonic Solutions)
R3 qcfilterhp2k; C:\Windows\System32\DRIVERS\qcfilterhp2k.sys [6400 2011-04-29] (QUALCOMM Incorporated)
R3 qcombushp; C:\Windows\System32\DRIVERS\qcombushp.sys [160328 2011-04-29] (MCCI)
R3 qcusbnethp2k; C:\Windows\System32\DRIVERS\qcusbnethp2k.sys [444416 2011-04-29] (QUALCOMM Incorporated)
R3 qcusbserhp2k; C:\Windows\System32\DRIVERS\qcusbserhp2k.sys [230784 2011-04-29] (QUALCOMM Incorporated)
R5 rdyboost; C:\Windows\System32\drivers\rdyboost.sys [213888 2010-11-20] (Microsoft Corporation)
R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [58184 2010-02-02] (McAfee, Inc.)
R1 RsvLock; C:\Windows\SysWow64\Drivers\RsvLock.sys [40088 2010-02-02] (McAfee, Inc.)
R5 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [56648 2010-02-02] ()
R5 SafeBoot; C:\Windows\SysWow64\Drivers\SafeBoot.sys [110520 2010-02-02] (McAfee, Inc.)
R5 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2009-06-04] (McAfee, Inc.)
R5 SbAlg; C:\Windows\SysWow64\Drivers\SbAlg.sys [51800 2010-02-02] (McAfee, Inc.)
R5 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15688 2010-02-02] (McAfee, Inc.)
R5 SbFsLock; C:\Windows\SysWow64\Drivers\SbFsLock.sys [13256 2010-02-02] (McAfee, Inc.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1803904 2010-04-27] ()
R5 spldr; C:\Windows\System32\Drivers\spldr.sys [19008 2009-07-14] (Microsoft Corporation)
R5 storflt; C:\Windows\System32\drivers\vmstorfl.sys [46464 2010-11-20] (Microsoft Corporation)
R5 Tcpip; C:\Windows\System32\drivers\tcpip.sys [1903552 2014-04-05] (Microsoft Corporation)
R5 vdrvroot; C:\Windows\System32\drivers\vdrvroot.sys [36432 2009-07-14] (Microsoft Corporation)
R5 vmbus; C:\Windows\System32\drivers\vmbus.sys [199552 2010-11-20] (Microsoft Corporation)
R5 volmgr; C:\Windows\System32\drivers\volmgr.sys [71552 2010-11-20] (Microsoft Corporation)
R5 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [363392 2010-11-20] (Microsoft Corporation)
R5 volsnap; C:\Windows\System32\drivers\volsnap.sys [296320 2011-02-25] (Microsoft Corporation)
R5 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [785624 2013-06-26] (Microsoft Corporation)
S3 ARCVCAM; system32\DRIVERS\ArcSoftVCapture.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CpqDfw; system32\drivers\CpqDfw.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-22 20:33 - 2015-08-22 20:33 - 00198005 _____ C:\Users\Lore *******\Desktop\JRT.txt
2015-08-22 20:26 - 2015-08-22 18:37 - 01798576 _____ (Malwarebytes Corporation) C:\Users\Lore *******\Desktop\JRT.exe
2015-08-21 23:24 - 2015-08-21 23:24 - 00035959 _____ C:\ComboFix.txt
2015-08-21 22:55 - 2011-06-26 08:45 - 00256000 _____ C:\windows\PEV.exe
2015-08-21 22:55 - 2010-11-07 19:20 - 00208896 _____ C:\windows\MBR.exe
2015-08-21 22:55 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe
2015-08-21 22:53 - 2015-08-21 23:24 - 00000000 ____D C:\Qoobox
2015-08-21 22:52 - 2015-08-21 23:21 - 00000000 ____D C:\windows\erdnt
2015-08-21 22:45 - 2015-08-21 21:38 - 05635234 ____R (Swearware) C:\Users\Lore *******\Desktop\ComboFix.exe
2015-08-21 12:55 - 2015-08-21 13:35 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-08-21 12:51 - 2015-08-21 13:34 - 00000000 ____D C:\Users\Lore *******\Desktop\mbar
2015-08-21 12:50 - 2015-08-21 11:45 - 16563304 _____ (Malwarebytes Corp.) C:\Users\Lore *******\Desktop\mbar-1.09.2.1008.exe
2015-08-20 20:33 - 2015-08-20 20:33 - 00032886 _____ C:\Users\Lore *******\Desktop\Gmer.log
2015-08-20 20:15 - 2015-08-20 10:41 - 01585664 _____ C:\Users\Lore *******\Desktop\adwcleaner_5.002.exe
2015-08-20 20:14 - 2015-08-20 20:14 - 00001206 _____ C:\Users\Lore *******\Desktop\Malwarebytes.txt
2015-08-20 19:29 - 2015-08-20 19:31 - 00042039 _____ C:\Users\Lore *******\Desktop\Addition.txt
2015-08-20 19:25 - 2015-08-22 20:36 - 00026843 _____ C:\Users\Lore *******\Desktop\FRST.txt
2015-08-20 19:00 - 2015-08-20 19:01 - 00000480 _____ C:\Users\Lore *******\Desktop\defogger_disable.log
2015-08-20 19:00 - 2015-08-20 19:00 - 00000000 _____ C:\Users\Lore *******\defogger_reenable
2015-08-20 18:59 - 2015-08-20 17:58 - 00380416 _____ C:\Users\Lore *******\Desktop\Gmer-19357.exe
2015-08-20 18:59 - 2015-08-20 17:58 - 00050477 _____ C:\Users\Lore *******\Desktop\Defogger.exe
2015-08-20 18:50 - 2015-08-22 20:36 - 00000000 ____D C:\FRST
2015-08-20 18:49 - 2015-08-20 17:45 - 02173952 _____ (Farbar) C:\Users\Lore *******\Desktop\FRST64.exe
2015-08-20 18:33 - 2015-08-20 18:33 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\Avira
2015-08-20 18:23 - 2015-08-11 03:20 - 25191936 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-08-20 18:23 - 2015-08-11 03:14 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-08-20 18:23 - 2015-08-11 02:33 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-08-20 18:23 - 2015-08-11 02:20 - 19871232 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-08-20 18:21 - 2015-08-20 18:21 - 00003432 _____ C:\windows\System32\Tasks\Avira Browser Safety Updater Task
2015-08-20 18:16 - 2015-07-15 08:37 - 00162528 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00141416 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00044088 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2015-08-20 18:13 - 2015-08-20 18:13 - 00001210 _____ C:\Users\Public\Desktop\Avira Launcher.lnk
2015-08-20 18:12 - 2015-08-20 18:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-08-20 18:11 - 2015-08-20 18:12 - 00000000 ____D C:\ProgramData\Package Cache
2015-08-20 17:46 - 2015-08-20 17:47 - 00005939 _____ C:\Users\Lore *******\Desktop\AdwCleaner[C1].txt
2015-08-20 17:44 - 2015-08-22 20:18 - 00000000 ____D C:\AdwCleaner
2015-08-20 17:44 - 2015-08-20 17:46 - 00005604 _____ C:\AdwCleaner[S1].txt
2015-08-20 17:38 - 2015-07-23 02:06 - 05568960 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-08-20 17:38 - 2015-07-23 02:06 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-08-20 17:38 - 2015-07-23 02:06 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-08-20 17:38 - 2015-07-23 02:03 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01390592 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-08-20 17:38 - 2015-07-23 02:02 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-08-20 17:38 - 2015-07-23 02:02 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-08-20 17:38 - 2015-07-23 02:01 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-08-20 17:38 - 2015-07-23 02:01 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-08-20 17:38 - 2015-07-23 02:01 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-08-20 17:38 - 2015-07-23 01:58 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-08-20 17:38 - 2015-07-23 01:57 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:51 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-08-20 17:38 - 2015-07-22 19:57 - 03989952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-08-20 17:38 - 2015-07-22 19:57 - 03934656 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-08-20 17:38 - 2015-07-22 19:54 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00641536 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00635392 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-08-20 17:38 - 2015-07-22 19:52 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-08-20 17:38 - 2015-07-22 19:52 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-08-20 17:38 - 2015-07-22 19:47 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-08-20 17:38 - 2015-07-22 19:46 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:48 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2015-08-20 17:38 - 2015-07-22 18:45 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-08-20 17:38 - 2015-07-22 18:44 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-08-20 17:38 - 2015-07-22 18:44 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-08-20 17:38 - 2015-07-22 18:34 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-08-20 17:38 - 2015-07-22 18:34 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-08-20 17:38 - 2015-07-22 18:31 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-20 17:37 - 2015-07-15 05:17 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-08-20 17:37 - 2015-07-15 04:54 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2015-08-20 17:37 - 2015-07-09 19:58 - 01632256 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2015-08-20 17:37 - 2015-07-09 19:58 - 00082944 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll
2015-08-20 17:37 - 2015-07-09 19:42 - 01372160 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2015-08-20 17:37 - 2015-07-09 19:42 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll
2015-08-20 17:33 - 2015-06-25 12:06 - 00115136 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-08-20 17:33 - 2015-06-25 12:01 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-08-20 17:33 - 2015-06-25 12:01 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-08-20 17:33 - 2015-06-25 11:44 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-08-20 11:42 - 2015-08-22 20:20 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-08-20 11:42 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-08-20 11:42 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-08-20 11:42 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-08-19 18:00 - 2015-08-20 16:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-13 11:03 - 2015-07-30 15:13 - 00124624 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 11:03 - 2015-07-30 15:13 - 00103120 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 10:19 - 2015-07-28 22:09 - 00017344 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-08-13 10:19 - 2015-07-28 22:05 - 01116672 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00774656 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00743424 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00437760 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-08-13 10:19 - 2015-07-28 21:55 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-08-13 10:19 - 2015-07-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-08-13 10:18 - 2015-07-15 20:15 - 00094656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-08-13 10:18 - 2015-07-15 20:10 - 01743360 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2015-08-13 10:18 - 2015-07-15 20:10 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-08-13 10:17 - 2015-07-21 02:39 - 00389840 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-08-13 10:17 - 2015-07-21 02:12 - 00342736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-08-13 10:17 - 2015-07-16 22:54 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-08-13 10:17 - 2015-07-16 22:36 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-08-13 10:17 - 2015-07-16 22:35 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-08-13 10:17 - 2015-07-16 22:26 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-08-13 10:17 - 2015-07-16 22:21 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-08-13 10:17 - 2015-07-16 22:12 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-08-13 10:17 - 2015-07-16 22:00 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 10:17 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-08-13 10:17 - 2015-07-16 21:51 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-08-13 10:17 - 2015-07-16 21:50 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-08-13 10:17 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-08-13 10:17 - 2015-07-16 21:43 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-08-13 10:17 - 2015-07-16 21:43 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-08-13 10:17 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-08-13 10:17 - 2015-07-16 21:39 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-08-13 10:17 - 2015-07-16 21:38 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-08-13 10:17 - 2015-07-16 21:35 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-08-13 10:17 - 2015-07-16 21:24 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-13 10:17 - 2015-07-16 21:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-08-13 10:17 - 2015-07-16 21:17 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-08-13 10:17 - 2015-07-16 21:06 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-08-13 10:17 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-08-13 10:17 - 2015-07-16 21:01 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-08-13 10:17 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-08-13 10:17 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-08-13 10:17 - 2015-07-15 05:19 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\basesrv.dll
2015-08-13 10:16 - 2015-07-16 22:37 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-08-13 10:16 - 2015-07-16 22:36 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-08-13 10:16 - 2015-07-16 22:36 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-08-13 10:16 - 2015-07-16 22:35 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-08-13 10:16 - 2015-07-16 22:27 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-08-13 10:16 - 2015-07-16 22:26 - 05923328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-08-13 10:16 - 2015-07-16 22:23 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-08-13 10:16 - 2015-07-16 22:08 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-08-13 10:16 - 2015-07-16 21:55 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-08-13 10:16 - 2015-07-16 21:54 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-08-13 10:16 - 2015-07-16 21:51 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-08-13 10:16 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-08-13 10:16 - 2015-07-16 21:49 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-08-13 10:16 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-08-13 10:16 - 2015-07-16 21:36 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-08-13 10:16 - 2015-07-16 21:34 - 14451200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-08-13 10:16 - 2015-07-16 21:33 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-08-13 10:16 - 2015-07-16 21:32 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-08-13 10:16 - 2015-07-16 21:29 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-08-13 10:16 - 2015-07-16 21:20 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-08-13 10:16 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-08-13 10:16 - 2015-07-16 21:12 - 02427904 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-08-13 10:16 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-08-13 10:16 - 2015-07-16 21:05 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-08-13 10:16 - 2015-07-16 20:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-08-13 10:16 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 01648128 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 01180160 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 01251328 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-08-13 10:15 - 2015-07-30 19:55 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-08-13 10:15 - 2015-07-30 18:56 - 03208192 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-08-13 10:15 - 2015-07-30 18:52 - 00372736 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-08-13 10:15 - 2015-07-30 18:49 - 00299520 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 03154944 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 02606080 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-08-13 10:15 - 2015-07-20 20:12 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-08-13 10:15 - 2015-07-20 20:12 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00173056 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00093184 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-08-13 10:15 - 2015-07-20 19:56 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-08-13 10:15 - 2015-07-15 05:19 - 02004992 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-08-13 10:15 - 2015-07-15 05:19 - 01887232 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-08-13 10:15 - 2015-07-15 05:14 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-08-13 10:15 - 2015-07-15 05:13 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-08-13 10:15 - 2015-07-15 04:55 - 01390592 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-08-13 10:15 - 2015-07-15 04:55 - 01241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-08-13 10:15 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2015-08-13 10:15 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-08-13 10:15 - 2015-07-10 19:51 - 14177280 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-08-13 10:15 - 2015-07-10 19:34 - 12875776 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-08-13 10:15 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\notepad.exe
2015-08-13 10:15 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\notepad.exe
2015-08-13 10:15 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
2015-08-13 10:15 - 2015-07-01 22:49 - 00260096 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-08-13 10:15 - 2015-07-01 22:48 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-08-13 10:15 - 2015-07-01 22:30 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-08-13 10:15 - 2015-07-01 22:30 - 00082432 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-08-13 10:15 - 2015-05-09 20:26 - 00493504 _____ (Microsoft Corporation) C:\windows\system32\mcupdate_GenuineIntel.dll
2015-07-31 21:53 - 2015-07-31 21:53 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-07-31 21:53 - 2015-07-31 21:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-07-31 21:52 - 2015-07-31 21:53 - 00000000 ____D C:\Program Files\iTunes
2015-07-31 21:52 - 2015-07-31 21:52 - 00000000 ____D C:\Program Files\iPod
2015-07-31 21:52 - 2015-07-31 21:52 - 00000000 ____D C:\Program Files (x86)\iTunes

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-22 20:32 - 2011-05-15 18:12 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-22 20:30 - 2009-07-14 06:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-22 20:30 - 2009-07-14 06:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-22 20:29 - 2010-09-07 23:49 - 00000000 ____D C:\ProgramData\HPQLOG
2015-08-22 20:27 - 2011-01-11 14:33 - 01216313 _____ C:\windows\WindowsUpdate.log
2015-08-22 20:23 - 2011-02-11 11:25 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\Skype
2015-08-22 20:20 - 2011-05-15 18:12 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-22 20:19 - 2014-12-04 10:45 - 00007184 _____ C:\windows\setupact.log
2015-08-22 20:19 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-08-22 20:16 - 2013-12-15 14:50 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-08-22 20:01 - 2011-05-15 18:19 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-22 19:18 - 2011-02-11 15:00 - 00003214 _____ C:\windows\System32\Tasks\HPCeeScheduleForNB*******$
2015-08-22 19:18 - 2011-02-11 15:00 - 00000338 _____ C:\windows\Tasks\HPCeeScheduleForNB*******$.job
2015-08-21 23:15 - 2009-07-14 04:34 - 00000215 _____ C:\windows\system.ini
2015-08-21 23:12 - 2010-09-08 00:27 - 05463296 _____ C:\windows\PFRO.log
2015-08-21 22:44 - 2015-06-12 22:52 - 00000348 _____ C:\windows\Tasks\HPCeeScheduleForLore *******.job
2015-08-21 20:33 - 2011-02-11 12:46 - 00000000 ____D C:\Users\Lore *******\Documents\Eigene Dateien
2015-08-21 19:51 - 2015-06-12 22:52 - 00003210 _____ C:\windows\System32\Tasks\HPCeeScheduleForLore *******
2015-08-21 19:50 - 2011-02-10 14:32 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2015-08-21 19:44 - 2013-09-21 13:49 - 00000000 ____D C:\Users\Lore *******\Documents\Outlook-Dateien
2015-08-20 21:36 - 2011-02-07 18:42 - 00000000 ____D C:\windows\rescache
2015-08-20 19:00 - 2011-02-07 10:48 - 00000000 ____D C:\Users\Lore *******
2015-08-20 18:21 - 2013-09-21 14:57 - 00000000 ____D C:\Program Files (x86)\Avira
2015-08-20 18:16 - 2013-09-21 14:57 - 00000000 ____D C:\ProgramData\Avira
2015-08-20 17:57 - 2010-09-07 23:55 - 00702028 _____ C:\windows\system32\perfh007.dat
2015-08-20 17:57 - 2010-09-07 23:55 - 00150638 _____ C:\windows\system32\perfc007.dat
2015-08-20 17:57 - 2009-07-14 07:13 - 01622300 _____ C:\windows\system32\PerfStringBackup.INI
2015-08-20 16:24 - 2013-04-30 19:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-20 16:24 - 2009-07-14 05:20 - 00000000 ____D C:\windows\L2Schemas
2015-08-20 16:22 - 2011-02-09 16:31 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\SoftGrid Client
2015-08-20 12:14 - 2011-04-20 07:36 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-08-20 12:14 - 2011-04-20 07:36 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-08-20 12:14 - 2011-02-07 10:59 - 00001425 _____ C:\Users\Lore *******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-17 08:34 - 2011-02-11 11:25 - 00000000 ____D C:\ProgramData\Skype
2015-08-13 17:10 - 2011-02-07 10:59 - 00000000 ___RD C:\Users\Lore *******\Virtual Machines
2015-08-13 17:08 - 2009-07-14 06:45 - 00413936 _____ C:\windows\system32\FNTCACHE.DAT
2015-08-13 17:05 - 2015-04-15 22:59 - 00000000 ____D C:\windows\system32\appraiser
2015-08-13 17:05 - 2014-05-06 16:01 - 00000000 ___SD C:\windows\system32\CompatTel
2015-08-13 11:03 - 2013-03-14 09:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-13 11:02 - 2013-03-14 09:02 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-13 11:02 - 2013-03-14 09:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-13 11:00 - 2011-02-13 09:25 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 10:54 - 2009-07-14 04:34 - 00000478 _____ C:\windows\win.ini
2015-08-13 10:53 - 2013-07-24 00:50 - 00000000 ____D C:\windows\system32\MRT
2015-08-13 10:47 - 2011-02-07 18:45 - 132483416 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-08-13 10:16 - 2013-12-15 14:50 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-08-13 10:16 - 2012-04-13 18:28 - 00778440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-08-13 10:16 - 2011-06-17 15:47 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-31 21:52 - 2011-02-11 12:02 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-07-31 17:26 - 2011-02-13 09:25 - 00000000 ____D C:\Users\Lore *******\AppData\Local\Microsoft Help
2015-07-25 11:00 - 2015-04-04 22:56 - 00000000 ___SD C:\windows\system32\GWX

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-03-30 18:19 - 2015-07-19 06:43 - 0000121 _____ () C:\Users\Lore *******\AppData\Roaming\default.rss
2011-04-15 22:57 - 2011-06-03 09:07 - 0001854 _____ () C:\Users\Lore *******\AppData\Roaming\GhostObjGAFix.xml
2013-09-21 14:33 - 2013-09-21 14:33 - 0022216 _____ () C:\Users\Lore *******\AppData\Roaming\Kommagetrennte Werte (DOS).ADR
2013-09-21 14:21 - 2013-09-21 16:35 - 0022405 _____ () C:\Users\Lore *******\AppData\Roaming\Kommagetrennte Werte (Windows).ADR

Einige Dateien in TEMP:
====================
C:\Users\Lore *******\AppData\Local\Temp\avgnt.exe
C:\Users\Lore *******\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-08-22 19:18

==================== Ende von Ergebnis ============================
         
Was ich in meinem Eingangspost vergessen habe zu erwähnen. Ich hab nach den ersten Scans noch einen 2. User angelegt und in keinem der 3 Browser das Problem.

Alt 23.08.2015, 08:42   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 23.08.2015, 15:41   #11
mezzomix
 
Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



ESET:
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=8f30cd022202084ca0c5f459b533cd34
# end=init
# utc_time=2015-08-23 09:38:56
# local_time=2015-08-23 11:38:56 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 25406
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=8f30cd022202084ca0c5f459b533cd34
# end=updated
# utc_time=2015-08-23 09:41:59
# local_time=2015-08-23 11:41:59 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=8f30cd022202084ca0c5f459b533cd34
# engine=25406
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2015-08-23 11:56:31
# local_time=2015-08-23 01:56:31 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 8810623 63314985 0 0
# scanned=263624
# found=22
# cleaned=22
# scan_time=8071
sh=CF6185A9EDFBA0217C9D36D25CA9F6ADCC9F6BC8 ft=1 fh=f90d49fcbe154eac vn="Win32/Toolbar.Conduit potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir"
sh=621E3AD116A9636951F6EF3875A66184F98927EC ft=1 fh=a6891e3482fc6efd vn="a variant of Win64/Systweak.A potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\windows\Sysnative\roboot64.exe.vir"
sh=C3736F57F49699D10022E8A5F68D96971282925F ft=0 fh=0000000000000000 vn="JS/Spy.Banker.BW trojan (deleted - quarantined)" ac=C fn="C:\Users\Lore *******\AppData\Local\Mozilla\Firefox\Profiles\fcmf6clf.default\cache2\entries\33F3D2A9D5D8377223998C122F8308CD1E78E810"
sh=CEFEA38F6021A0C1521F4EEE29211203FF14996A ft=0 fh=0000000000000000 vn="JS/Spy.Banker.BW trojan (deleted - quarantined)" ac=C fn="C:\Users\Lore *******\AppData\Local\Mozilla\Firefox\Profiles\fcmf6clf.default\cache2\entries\621C2ACC923DBB52E1A911D3C967F14F3BFA0A5A"
sh=EB8ECF51CD3F7E6E91F675679C67F137DE4831A4 ft=0 fh=0000000000000000 vn="JS/Spy.Banker.BW trojan (deleted - quarantined)" ac=C fn="C:\Users\Lore *******\AppData\Local\Mozilla\Firefox\Profiles\fcmf6clf.default\cache2\entries\803BB4C008D723B5EBD1D7D4CB0FF1F6C348FD07"
sh=E61CD6656285CD757B187515414097BA7E5BC570 ft=0 fh=0000000000000000 vn="JS/Spy.Banker.BW trojan (deleted - quarantined)" ac=C fn="C:\Users\Lore *******\AppData\Local\Mozilla\Firefox\Profiles\fcmf6clf.default\cache2\entries\AECEC5E9F506F9CB613BC7E9CE3591AB511D77BE"
sh=9AC46A5A335712F4A885A21FE8A2341CC400A046 ft=0 fh=0000000000000000 vn="JS/Spy.Banker.BW trojan (deleted - quarantined)" ac=C fn="C:\Users\Lore *******\AppData\Local\Mozilla\Firefox\Profiles\fcmf6clf.default\cache2\entries\B81C1D92D3A1DF6612EFACF053DB42FEBF668DFA"
sh=A6012A7A7C46B09C70F640A6B5AD2FD817947EEE ft=1 fh=b0e4701566bbdda9 vn="a variant of Win32/Toolbar.Babylon.H potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Lore *******\Downloads\Babylon10_setup.exe"
sh=F7260CE69E39008609AC6570C2013A39315C46F5 ft=1 fh=c8129b0266621a88 vn="Win32/Toolbar.Conduit potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Lore *******\Downloads\FreeYouTubeToMP3Converter_3.12.1.320.exe"
sh=6B5177D673F30B2F03A5F3B328B03E2BD3690BE7 ft=0 fh=0000000000000000 vn="Win32/HackKMS.A potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Lore *******\Downloads\OnlineFestplatte_1438232(1).tgz"
sh=6B5177D673F30B2F03A5F3B328B03E2BD3690BE7 ft=0 fh=0000000000000000 vn="Win32/HackKMS.A potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Lore *******\Downloads\OnlineFestplatte_1438232.tgz"
sh=BC4F7C0968F8C31895C475977D7C1B34AAC2EA8C ft=1 fh=5b3ac980435a168c vn="a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application (cleaned by deleting - quarantined)" ac=C fn="C:\Windows\Installer\MSIC60F.tmp"
sh=E81C4FC11483E678F98C0D626F9CEDA317E44946 ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-AVIRA-V7BDBHUF7N.7z"
sh=BC3251B2A2511FA232CCB62C82CD63DFE9D8450F ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-AVIRA-V7[10].7z"
sh=E44D062204C9698F5C95651F2E424D37A31F5B15 ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-AVIRA-V7[2].7z"
sh=A9B44B47329DFDC56F86EDA59429593DF39B5A54 ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-AVIRA-V7[3].7z"
sh=43E3A09433924E0BDDE371565879FF58E5F39FC4 ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-AVIRA-V7[7].7z"
sh=6AF5EEAA3E0DE2AB0B510417C4C79285B3FB1869 ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-AVIRA-V7[8].7z"
sh=73B5514E7773F2A36FD231F803547F90D061D3EA ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-AVIRA-V7[9].7z"
sh=6325ACF1DB55192D8E3B4F4EB505F373B81411E3 ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-ORJ-SPE[1].7z"
sh=A3E80A4342F81EE9BA0353A947674AD70EC29AB5 ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-ORJ-SPE[2].7z"
sh=1EFF205D7D0D82BAF841A98C176D700114E13FE6 ft=1 fh=b22528247c19a550 vn="a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application (cleaned by deleting - quarantined)" ac=C fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5\ApnIC[1].0"
         
SecurityCheck
Code:
ATTFilter
 Results of screen317's Security Check version 1.008  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Avira Antivirus                 
Microsoft Security Essentials   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Java 8 Update 45  
 Java version 32-bit out of Date! 
 Adobe Flash Player 18.0.0.232  
 Adobe Reader XI  
 Mozilla Firefox (40.0) 
 Google Chrome (44.0.2403.155) 
 Google Chrome (44.0.2403.157) 
````````Process Check: objlist.exe by Laurent````````  
 Microsoft Security Essentials MSMpEng.exe 
 Microsoft Security Essentials msseces.exe 
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Avira Antivir avgnt.exe 
 Avira Antivir avguard.exe 
 Avira Antivirus sched.exe  
 Avira Antivirus avshadow.exe  
 Malwarebytes Anti-Malware mbamscheduler.exe   
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
FRST:

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:23-08-2015
durchgeführt von Lore ******* (ACHTUNG: der angemeldete Benutzer ist kein Administrator) auf NB******* (23-08-2015 14:09:35)
Gestartet von C:\Users\Lore *******\Desktop
Geladene Profile: Lore ******* (Verfügbare Profile: Lore ******* & Kartoffelmann)
Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

konnte nicht auf den Prozess zugreifen -> smss.exe
konnte nicht auf den Prozess zugreifen -> csrss.exe
konnte nicht auf den Prozess zugreifen -> wininit.exe
konnte nicht auf den Prozess zugreifen -> csrss.exe
konnte nicht auf den Prozess zugreifen -> services.exe
konnte nicht auf den Prozess zugreifen -> lsass.exe
konnte nicht auf den Prozess zugreifen -> lsm.exe
konnte nicht auf den Prozess zugreifen -> winlogon.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> HPFSService.exe
konnte nicht auf den Prozess zugreifen -> HpFkCrypt.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> MsMpEng.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> stacsv64.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> hpservice.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> wlanext.exe
konnte nicht auf den Prozess zugreifen -> conhost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> spoolsv.exe
konnte nicht auf den Prozess zugreifen -> DpHostW.exe
konnte nicht auf den Prozess zugreifen -> sched.exe
konnte nicht auf den Prozess zugreifen -> armsvc.exe
konnte nicht auf den Prozess zugreifen -> AESTSr64.exe
konnte nicht auf den Prozess zugreifen -> avguard.exe
konnte nicht auf den Prozess zugreifen -> AppleMobileDeviceService.exe
konnte nicht auf den Prozess zugreifen -> bgsvcgen.exe
konnte nicht auf den Prozess zugreifen -> mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
konnte nicht auf den Prozess zugreifen -> btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\jre\bin\javaw.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
konnte nicht auf den Prozess zugreifen -> SkypeC2CAutoUpdateSvc.exe
konnte nicht auf den Prozess zugreifen -> SkypeC2CPNRSvc.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> E_S40STB.EXE
konnte nicht auf den Prozess zugreifen -> E_S40RPB.EXE
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> PTChangeFilterService.exe
konnte nicht auf den Prozess zugreifen -> HPDayStarterService.exe
konnte nicht auf den Prozess zugreifen -> HPDrvMntSvc.exe
konnte nicht auf den Prozess zugreifen -> HPHotkeyMonitor.exe
konnte nicht auf den Prozess zugreifen -> LMS.exe
konnte nicht auf den Prozess zugreifen -> mbamscheduler.exe
konnte nicht auf den Prozess zugreifen -> mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
konnte nicht auf den Prozess zugreifen -> NBService.exe
konnte nicht auf den Prozess zugreifen -> QDLService2kHP.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
konnte nicht auf den Prozess zugreifen -> sftvsa.exe
konnte nicht auf den Prozess zugreifen -> SAgent4.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> TeamViewer_Service.exe
konnte nicht auf den Prozess zugreifen -> WLIDSVC.EXE
konnte nicht auf den Prozess zugreifen -> WLIDSVCM.EXE
konnte nicht auf den Prozess zugreifen -> sftlist.exe
konnte nicht auf den Prozess zugreifen -> avshadow.exe
konnte nicht auf den Prozess zugreifen -> SMManager.exe
konnte nicht auf den Prozess zugreifen -> Avira.ServiceHost.exe
konnte nicht auf den Prozess zugreifen -> unsecapp.exe
konnte nicht auf den Prozess zugreifen -> WmiPrvSE.exe
konnte nicht auf den Prozess zugreifen -> WmiPrvSE.exe
konnte nicht auf den Prozess zugreifen -> CVHSVC.EXE
konnte nicht auf den Prozess zugreifen -> IAANTmon.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSyncMAPI.exe
konnte nicht auf den Prozess zugreifen -> SearchIndexer.exe
konnte nicht auf den Prozess zugreifen -> hpqwmiex.exe
konnte nicht auf den Prozess zugreifen -> iPodService.exe
konnte nicht auf den Prozess zugreifen -> SbHpAuthenticatorService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Panasonic Corporation) C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
konnte nicht auf den Prozess zugreifen -> WUDFHost.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
konnte nicht auf den Prozess zugreifen -> wmpnetwk.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
konnte nicht auf den Prozess zugreifen -> HPPA_Service.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
(Portrait Displays, Inc) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSDKHelperx64.exe
konnte nicht auf den Prozess zugreifen -> PresentationFontCache.exe
konnte nicht auf den Prozess zugreifen -> dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
konnte nicht auf den Prozess zugreifen -> HPSA_Service.exe
konnte nicht auf den Prozess zugreifen -> HPWA_Service.exe
konnte nicht auf den Prozess zugreifen -> UNS.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> WUDFHost.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> SearchProtocolHost.exe
konnte nicht auf den Prozess zugreifen -> SearchFilterHost.exe
() C:\Users\Lore *******\Desktop\FRST64.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-04-05] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2011-02-09] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-07-21] (Hewlett-Packard Company)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [489472 2011-02-09] (IDT, Inc.)
HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [3488640 2012-03-14] (Hewlett-Packard Company)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\...\Run: [File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11268096 2010-05-06] (Hewlett-Packard)
HKLM-x32\...\Run: [AppleSyncNotifier] => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [334240 2012-09-12] (Hewlett-Packard Company)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66936 2015-08-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [782008 2015-07-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [HP Connection Manager.exe] => [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [Syncables] => C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe [530736 2010-05-18] (Hewlett-Packard)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2015-03-18] (Microsoft Corporation)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [BingSvc] => C:\Users\Lore *******\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-12-04]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 4.0 HD Edition.lnk [2011-02-11]
ShortcutTarget: PHOTOfunSTUDIO 4.0 HD Edition.lnk -> C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe (Panasonic Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/4
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=de-AT&Src=MSE&Tid=00033BB0&OHP=http%3A%2F%2Fg.uk.msn.com%2FHPCOM%2F4&OSP=
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3921111220-2900040076-1547133076-1003 -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3921111220-2900040076-1547133076-1003 -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
BHO: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2011-05-02] (DigitalPersona, Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: File Sanitizer for HP ProtectTools -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2010-05-06] (Hewlett-Packard)
BHO-x32: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2011-05-02] (DigitalPersona, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-05-08] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-08] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{F4FF26DF-9FE9-4F91-A720-687E53208FA1}: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Bing 
FF NetworkProxy: "autoconfig_url", "https://guard-safe.net/a2tunnel.js"
FF NetworkProxy: "no_proxies_on", "*.local"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-13] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-13] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\system32\Adobe\Director\np32dsw.dll [Keine Datei]
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-08] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Extension: Avira Browser Safety - C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\Extensions\abs@avira.com [2015-08-20]
FF Extension: GMX MailCheck - C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\fcmf6clf.default\Extensions\mailcheck@gmx.net [2015-08-19]
FF Extension: Kein Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-19]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-08-19]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2011-12-09]

Chrome: 
=======
CHR Profile: C:\Users\Lore *******\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [887128 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [461672 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [461672 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [227592 2015-08-03] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R3 DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [704512 2010-02-02] (McAfee, Inc.) [Datei ist nicht signiert]
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462160 2010-07-16] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [362040 2010-04-28] (Hewlett-Packard Ltd)
R2 HP ProtectTools Service; C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [32768 2010-10-19] (Hewlett-Packard Development Company, L.P) [Datei ist nicht signiert]
R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [90112 2010-06-14] (Hewlett-Packard Company) [Datei ist nicht signiert]
R2 HpFkCryptService; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [281192 2010-02-02] (McAfee, Inc.)
R2 HPFSService; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [298496 2010-05-06] (Hewlett-Packard) [Datei ist nicht signiert]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-09-12] (Hewlett-Packard Company)
S2 KMService; C:\windows\SysWOW64\srvany.exe [8192 2014-03-31] () [Datei ist nicht signiert]
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 QDLService2kHP; C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe [1687360 2011-04-29] (QUALCOMM, Inc.)
R2 SMManager; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\SMManager.exe [84808 2010-09-17] (Smith Micro Software, Inc.)
R2 StatusAgent4; C:\windows\SysWOW64\SAgent4.exe [131072 2006-12-20] (SEIKO EPSON CORPORATION) [Datei ist nicht signiert]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162528 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [141416 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 cdrbsdrv; C:\Windows\System32\Drivers\cdrbsdrv.sys [39208 2006-08-25] (B.H.A Corporation)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [40760 2010-03-09] (Hewlett-Packard Development Company L.P.)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.)
R1 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [109272 2015-06-18] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-23] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R3 qcfilterhp2k; C:\Windows\System32\DRIVERS\qcfilterhp2k.sys [6400 2011-04-29] (QUALCOMM Incorporated)
R3 qcombushp; C:\Windows\System32\DRIVERS\qcombushp.sys [160328 2011-04-29] (MCCI)
R3 qcusbnethp2k; C:\Windows\System32\DRIVERS\qcusbnethp2k.sys [444416 2011-04-29] (QUALCOMM Incorporated)
R3 qcusbserhp2k; C:\Windows\System32\DRIVERS\qcusbserhp2k.sys [230784 2011-04-29] (QUALCOMM Incorporated)
R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [58184 2010-02-02] (McAfee, Inc.)
R1 RsvLock; C:\Windows\SysWow64\Drivers\RsvLock.sys [40088 2010-02-02] (McAfee, Inc.)
R0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [56648 2010-02-02] ()
R0 SafeBoot; C:\Windows\SysWow64\Drivers\SafeBoot.sys [110520 2010-02-02] (McAfee, Inc.)
R0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2009-06-04] (McAfee, Inc.)
R0 SbAlg; C:\Windows\SysWow64\Drivers\SbAlg.sys [51800 2010-02-02] (McAfee, Inc.)
R0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15688 2010-02-02] (McAfee, Inc.)
R0 SbFsLock; C:\Windows\SysWow64\Drivers\SbFsLock.sys [13256 2010-02-02] (McAfee, Inc.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1803904 2010-04-27] ()
S3 ARCVCAM; system32\DRIVERS\ArcSoftVCapture.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CpqDfw; system32\drivers\CpqDfw.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-23 14:09 - 2015-08-23 14:09 - 00000000 ____D C:\Users\Lore *******\Desktop\FRST-OlderVersion
2015-08-23 14:01 - 2015-08-23 10:37 - 00852704 _____ C:\Users\Lore *******\Desktop\SecurityCheck.exe
2015-08-22 21:37 - 2015-08-22 21:38 - 00000000 ____D C:\Users\Kartoffelmann
2015-08-22 20:33 - 2015-08-22 20:33 - 00198005 _____ C:\Users\Lore *******\Desktop\JRT.txt
2015-08-22 20:26 - 2015-08-22 18:37 - 01798576 _____ (Malwarebytes Corporation) C:\Users\Lore *******\Desktop\JRT.exe
2015-08-21 23:24 - 2015-08-21 23:24 - 00035959 _____ C:\ComboFix.txt
2015-08-21 22:55 - 2011-06-26 08:45 - 00256000 _____ C:\windows\PEV.exe
2015-08-21 22:55 - 2010-11-07 19:20 - 00208896 _____ C:\windows\MBR.exe
2015-08-21 22:55 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe
2015-08-21 22:53 - 2015-08-21 23:24 - 00000000 ____D C:\Qoobox
2015-08-21 22:52 - 2015-08-21 23:21 - 00000000 ____D C:\windows\erdnt
2015-08-21 22:45 - 2015-08-21 21:38 - 05635234 ____R (Swearware) C:\Users\Lore *******\Desktop\ComboFix.exe
2015-08-21 12:55 - 2015-08-21 13:35 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-08-21 12:51 - 2015-08-21 13:34 - 00000000 ____D C:\Users\Lore *******\Desktop\mbar
2015-08-21 12:50 - 2015-08-21 11:45 - 16563304 _____ (Malwarebytes Corp.) C:\Users\Lore *******\Desktop\mbar-1.09.2.1008.exe
2015-08-20 20:33 - 2015-08-20 20:33 - 00032886 _____ C:\Users\Lore *******\Desktop\Gmer.log
2015-08-20 20:15 - 2015-08-20 10:41 - 01585664 _____ C:\Users\Lore *******\Desktop\adwcleaner_5.002.exe
2015-08-20 20:14 - 2015-08-20 20:14 - 00001206 _____ C:\Users\Lore *******\Desktop\Malwarebytes.txt
2015-08-20 19:29 - 2015-08-20 19:31 - 00042039 _____ C:\Users\Lore *******\Desktop\Addition.txt
2015-08-20 19:25 - 2015-08-23 14:09 - 00030144 _____ C:\Users\Lore *******\Desktop\FRST.txt
2015-08-20 19:00 - 2015-08-20 19:01 - 00000480 _____ C:\Users\Lore *******\Desktop\defogger_disable.log
2015-08-20 19:00 - 2015-08-20 19:00 - 00000000 _____ C:\Users\Lore *******\defogger_reenable
2015-08-20 18:59 - 2015-08-20 17:58 - 00380416 _____ C:\Users\Lore *******\Desktop\Gmer-19357.exe
2015-08-20 18:59 - 2015-08-20 17:58 - 00050477 _____ C:\Users\Lore *******\Desktop\Defogger.exe
2015-08-20 18:50 - 2015-08-23 14:09 - 00000000 ____D C:\FRST
2015-08-20 18:49 - 2015-08-23 14:09 - 02173440 _____ C:\Users\Lore *******\Desktop\FRST64.exe
2015-08-20 18:33 - 2015-08-20 18:33 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\Avira
2015-08-20 18:23 - 2015-08-11 03:20 - 25191936 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-08-20 18:23 - 2015-08-11 03:14 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-08-20 18:23 - 2015-08-11 02:33 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-08-20 18:23 - 2015-08-11 02:20 - 19871232 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-08-20 18:16 - 2015-07-15 08:37 - 00162528 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00141416 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00044088 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2015-08-20 18:13 - 2015-08-20 18:13 - 00001210 _____ C:\Users\Public\Desktop\Avira Launcher.lnk
2015-08-20 18:12 - 2015-08-20 18:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-08-20 18:11 - 2015-08-20 18:12 - 00000000 ____D C:\ProgramData\Package Cache
2015-08-20 17:46 - 2015-08-20 17:47 - 00005939 _____ C:\Users\Lore *******\Desktop\AdwCleaner[C1].txt
2015-08-20 17:44 - 2015-08-22 20:18 - 00000000 ____D C:\AdwCleaner
2015-08-20 17:44 - 2015-08-20 17:46 - 00005604 _____ C:\AdwCleaner[S1].txt
2015-08-20 17:38 - 2015-07-23 02:06 - 05568960 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-08-20 17:38 - 2015-07-23 02:06 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-08-20 17:38 - 2015-07-23 02:06 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-08-20 17:38 - 2015-07-23 02:03 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01390592 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-08-20 17:38 - 2015-07-23 02:02 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-08-20 17:38 - 2015-07-23 02:02 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-08-20 17:38 - 2015-07-23 02:01 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-08-20 17:38 - 2015-07-23 02:01 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-08-20 17:38 - 2015-07-23 02:01 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-08-20 17:38 - 2015-07-23 01:58 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-08-20 17:38 - 2015-07-23 01:57 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:51 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-08-20 17:38 - 2015-07-22 19:57 - 03989952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-08-20 17:38 - 2015-07-22 19:57 - 03934656 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-08-20 17:38 - 2015-07-22 19:54 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00641536 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00635392 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-08-20 17:38 - 2015-07-22 19:52 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-08-20 17:38 - 2015-07-22 19:52 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-08-20 17:38 - 2015-07-22 19:47 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-08-20 17:38 - 2015-07-22 19:46 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:48 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2015-08-20 17:38 - 2015-07-22 18:45 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-08-20 17:38 - 2015-07-22 18:44 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-08-20 17:38 - 2015-07-22 18:44 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-08-20 17:38 - 2015-07-22 18:34 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-08-20 17:38 - 2015-07-22 18:34 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-08-20 17:38 - 2015-07-22 18:31 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-20 17:37 - 2015-07-15 05:17 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-08-20 17:37 - 2015-07-15 04:54 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2015-08-20 17:37 - 2015-07-09 19:58 - 01632256 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2015-08-20 17:37 - 2015-07-09 19:58 - 00082944 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll
2015-08-20 17:37 - 2015-07-09 19:42 - 01372160 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2015-08-20 17:37 - 2015-07-09 19:42 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll
2015-08-20 17:33 - 2015-06-25 12:06 - 00115136 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-08-20 17:33 - 2015-06-25 12:01 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-08-20 17:33 - 2015-06-25 12:01 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-08-20 17:33 - 2015-06-25 11:44 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-08-20 11:42 - 2015-08-23 11:51 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-08-20 11:42 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-08-20 11:42 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-08-20 11:42 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-08-19 18:00 - 2015-08-20 16:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-13 11:03 - 2015-07-30 15:13 - 00124624 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 11:03 - 2015-07-30 15:13 - 00103120 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 10:19 - 2015-07-28 22:09 - 00017344 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-08-13 10:19 - 2015-07-28 22:05 - 01116672 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00774656 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00743424 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00437760 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-08-13 10:19 - 2015-07-28 21:55 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-08-13 10:19 - 2015-07-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-08-13 10:18 - 2015-07-15 20:15 - 00094656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-08-13 10:18 - 2015-07-15 20:10 - 01743360 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2015-08-13 10:18 - 2015-07-15 20:10 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-08-13 10:17 - 2015-07-21 02:39 - 00389840 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-08-13 10:17 - 2015-07-21 02:12 - 00342736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-08-13 10:17 - 2015-07-16 22:54 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-08-13 10:17 - 2015-07-16 22:36 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-08-13 10:17 - 2015-07-16 22:35 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-08-13 10:17 - 2015-07-16 22:26 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-08-13 10:17 - 2015-07-16 22:21 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-08-13 10:17 - 2015-07-16 22:12 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-08-13 10:17 - 2015-07-16 22:00 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 10:17 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-08-13 10:17 - 2015-07-16 21:51 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-08-13 10:17 - 2015-07-16 21:50 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-08-13 10:17 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-08-13 10:17 - 2015-07-16 21:43 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-08-13 10:17 - 2015-07-16 21:43 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-08-13 10:17 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-08-13 10:17 - 2015-07-16 21:39 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-08-13 10:17 - 2015-07-16 21:38 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-08-13 10:17 - 2015-07-16 21:35 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-08-13 10:17 - 2015-07-16 21:24 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-13 10:17 - 2015-07-16 21:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-08-13 10:17 - 2015-07-16 21:17 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-08-13 10:17 - 2015-07-16 21:06 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-08-13 10:17 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-08-13 10:17 - 2015-07-16 21:01 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-08-13 10:17 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-08-13 10:17 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-08-13 10:17 - 2015-07-15 05:19 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\basesrv.dll
2015-08-13 10:16 - 2015-07-16 22:37 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-08-13 10:16 - 2015-07-16 22:36 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-08-13 10:16 - 2015-07-16 22:36 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-08-13 10:16 - 2015-07-16 22:35 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-08-13 10:16 - 2015-07-16 22:27 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-08-13 10:16 - 2015-07-16 22:26 - 05923328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-08-13 10:16 - 2015-07-16 22:23 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-08-13 10:16 - 2015-07-16 22:08 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-08-13 10:16 - 2015-07-16 21:55 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-08-13 10:16 - 2015-07-16 21:54 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-08-13 10:16 - 2015-07-16 21:51 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-08-13 10:16 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-08-13 10:16 - 2015-07-16 21:49 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-08-13 10:16 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-08-13 10:16 - 2015-07-16 21:36 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-08-13 10:16 - 2015-07-16 21:34 - 14451200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-08-13 10:16 - 2015-07-16 21:33 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-08-13 10:16 - 2015-07-16 21:32 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-08-13 10:16 - 2015-07-16 21:29 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-08-13 10:16 - 2015-07-16 21:20 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-08-13 10:16 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-08-13 10:16 - 2015-07-16 21:12 - 02427904 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-08-13 10:16 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-08-13 10:16 - 2015-07-16 21:05 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-08-13 10:16 - 2015-07-16 20:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-08-13 10:16 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 01648128 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 01180160 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 01251328 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-08-13 10:15 - 2015-07-30 19:55 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-08-13 10:15 - 2015-07-30 18:56 - 03208192 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-08-13 10:15 - 2015-07-30 18:52 - 00372736 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-08-13 10:15 - 2015-07-30 18:49 - 00299520 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 03154944 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 02606080 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-08-13 10:15 - 2015-07-20 20:12 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-08-13 10:15 - 2015-07-20 20:12 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00173056 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00093184 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-08-13 10:15 - 2015-07-20 19:56 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-08-13 10:15 - 2015-07-15 05:19 - 02004992 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-08-13 10:15 - 2015-07-15 05:19 - 01887232 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-08-13 10:15 - 2015-07-15 05:14 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-08-13 10:15 - 2015-07-15 05:13 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-08-13 10:15 - 2015-07-15 04:55 - 01390592 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-08-13 10:15 - 2015-07-15 04:55 - 01241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-08-13 10:15 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2015-08-13 10:15 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-08-13 10:15 - 2015-07-10 19:51 - 14177280 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-08-13 10:15 - 2015-07-10 19:34 - 12875776 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-08-13 10:15 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\notepad.exe
2015-08-13 10:15 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\notepad.exe
2015-08-13 10:15 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
2015-08-13 10:15 - 2015-07-01 22:49 - 00260096 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-08-13 10:15 - 2015-07-01 22:48 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-08-13 10:15 - 2015-07-01 22:30 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-08-13 10:15 - 2015-07-01 22:30 - 00082432 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-08-13 10:15 - 2015-05-09 20:26 - 00493504 _____ (Microsoft Corporation) C:\windows\system32\mcupdate_GenuineIntel.dll
2015-07-31 21:53 - 2015-07-31 21:53 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-07-31 21:53 - 2015-07-31 21:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-07-31 21:52 - 2015-07-31 21:53 - 00000000 ____D C:\Program Files\iTunes
2015-07-31 21:52 - 2015-07-31 21:52 - 00000000 ____D C:\Program Files\iPod
2015-07-31 21:52 - 2015-07-31 21:52 - 00000000 ____D C:\Program Files (x86)\iTunes

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-23 14:09 - 2011-02-11 11:25 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\Skype
2015-08-23 13:32 - 2011-05-15 18:12 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-23 13:16 - 2013-12-15 14:50 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-08-23 12:43 - 2011-01-11 14:33 - 01234461 _____ C:\windows\WindowsUpdate.log
2015-08-23 12:25 - 2009-07-14 06:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-23 12:25 - 2009-07-14 06:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-23 11:32 - 2010-09-07 23:49 - 00000000 ____D C:\ProgramData\HPQLOG
2015-08-23 11:31 - 2014-12-04 10:45 - 00007296 _____ C:\windows\setupact.log
2015-08-23 11:31 - 2011-05-15 18:12 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-23 11:31 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-08-22 20:01 - 2011-05-15 18:19 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-22 19:18 - 2011-02-11 15:00 - 00000338 _____ C:\windows\Tasks\HPCeeScheduleForNB*******$.job
2015-08-21 23:15 - 2009-07-14 04:34 - 00000215 _____ C:\windows\system.ini
2015-08-21 23:12 - 2010-09-08 00:27 - 05463296 _____ C:\windows\PFRO.log
2015-08-21 22:44 - 2015-06-12 22:52 - 00000348 _____ C:\windows\Tasks\HPCeeScheduleForLore *******.job
2015-08-21 20:33 - 2011-02-11 12:46 - 00000000 ____D C:\Users\Lore *******\Documents\Eigene Dateien
2015-08-21 19:50 - 2011-02-10 14:32 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2015-08-21 19:44 - 2013-09-21 13:49 - 00000000 ____D C:\Users\Lore *******\Documents\Outlook-Dateien
2015-08-20 21:36 - 2011-02-07 18:42 - 00000000 ____D C:\windows\rescache
2015-08-20 19:00 - 2011-02-07 10:48 - 00000000 ____D C:\Users\Lore *******
2015-08-20 18:21 - 2013-09-21 14:57 - 00000000 ____D C:\Program Files (x86)\Avira
2015-08-20 18:16 - 2013-09-21 14:57 - 00000000 ____D C:\ProgramData\Avira
2015-08-20 17:57 - 2010-09-07 23:55 - 00702028 _____ C:\windows\system32\perfh007.dat
2015-08-20 17:57 - 2010-09-07 23:55 - 00150638 _____ C:\windows\system32\perfc007.dat
2015-08-20 17:57 - 2009-07-14 07:13 - 01622300 _____ C:\windows\system32\PerfStringBackup.INI
2015-08-20 16:24 - 2013-04-30 19:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-20 16:24 - 2009-07-14 05:20 - 00000000 ____D C:\windows\L2Schemas
2015-08-20 16:22 - 2011-02-09 16:31 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\SoftGrid Client
2015-08-20 12:14 - 2011-04-20 07:36 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-08-20 12:14 - 2011-04-20 07:36 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-08-20 12:14 - 2011-02-07 10:59 - 00001425 _____ C:\Users\Lore *******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-17 08:34 - 2011-02-11 11:25 - 00000000 ____D C:\ProgramData\Skype
2015-08-13 17:10 - 2011-02-07 10:59 - 00000000 ___RD C:\Users\Lore *******\Virtual Machines
2015-08-13 17:08 - 2009-07-14 06:45 - 00413936 _____ C:\windows\system32\FNTCACHE.DAT
2015-08-13 17:05 - 2015-04-15 22:59 - 00000000 ____D C:\windows\system32\appraiser
2015-08-13 17:05 - 2014-05-06 16:01 - 00000000 ___SD C:\windows\system32\CompatTel
2015-08-13 11:03 - 2013-03-14 09:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-13 11:02 - 2013-03-14 09:02 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-13 11:02 - 2013-03-14 09:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-13 11:00 - 2011-02-13 09:25 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 10:54 - 2009-07-14 04:34 - 00000478 _____ C:\windows\win.ini
2015-08-13 10:53 - 2013-07-24 00:50 - 00000000 ____D C:\windows\system32\MRT
2015-08-13 10:47 - 2011-02-07 18:45 - 132483416 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-08-13 10:16 - 2012-04-13 18:28 - 00778440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-08-13 10:16 - 2011-06-17 15:47 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-31 21:52 - 2011-02-11 12:02 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-07-31 17:26 - 2011-02-13 09:25 - 00000000 ____D C:\Users\Lore *******\AppData\Local\Microsoft Help
2015-07-25 11:00 - 2015-04-04 22:56 - 00000000 ___SD C:\windows\system32\GWX

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-03-30 18:19 - 2015-07-19 06:43 - 0000121 _____ () C:\Users\Lore *******\AppData\Roaming\default.rss
2011-04-15 22:57 - 2011-06-03 09:07 - 0001854 _____ () C:\Users\Lore *******\AppData\Roaming\GhostObjGAFix.xml
2013-09-21 14:33 - 2013-09-21 14:33 - 0022216 _____ () C:\Users\Lore *******\AppData\Roaming\Kommagetrennte Werte (DOS).ADR
2013-09-21 14:21 - 2013-09-21 16:35 - 0022405 _____ () C:\Users\Lore *******\AppData\Roaming\Kommagetrennte Werte (Windows).ADR

Einige Dateien in TEMP:
====================
C:\Users\Lore *******\AppData\Local\Temp\avgnt.exe
C:\Users\Lore *******\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


ACHTUNG: ==> Auf den BCD konnte nicht zugegriffen werden. Der Benutzer ist kein Administrator.

==================== Ende von Ergebnis ============================
         
Leider ist im Hauptuser das Problem immer noch vorhanden nachdem Eset einiges gefunden hat

Nach einem Zurücksetzen aller Browser ist auch das ewige pop-up weg. Und ich hoff der Rest den meine Mutter drauf hatte jetzt auch.

Alt 24.08.2015, 08:14   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



FRST bitte nochmal, da fehlten Adminrechte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 24.08.2015, 12:30   #13
mezzomix
 
Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



Sorry

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:23-08-2015
durchgeführt von Lore ******* (Administrator) auf NB******* (24-08-2015 12:24:50)
Gestartet von C:\Users\Lore *******\Desktop
Geladene Profile: Lore ******* (Verfügbare Profile: Lore *******)
Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\jre\bin\javaw.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(B.H.A Corporation) C:\Windows\SysWOW64\bgsvcgen.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Hewlett-Packard Development Company, L.P) C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\HPHotkeyMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSyncMAPI.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(SEIKO EPSON CORPORATION) C:\Windows\SysWOW64\SAgent4.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Smith Micro Software, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\SMManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Panasonic Corporation) C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Portrait Displays, Inc) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSDKHelperx64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-04-05] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2011-02-09] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-07-21] (Hewlett-Packard Company)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [489472 2011-02-09] (IDT, Inc.)
HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [3488640 2012-03-14] (Hewlett-Packard Company)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\...\Run: [File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11268096 2010-05-06] (Hewlett-Packard)
HKLM-x32\...\Run: [AppleSyncNotifier] => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [334240 2012-09-12] (Hewlett-Packard Company)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66936 2015-08-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [782008 2015-07-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [HP Connection Manager.exe] => [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [Syncables] => C:\Program Files (x86)\Hewlett-Packard\HP QuickSync\QuickSync.exe [530736 2010-05-18] (Hewlett-Packard)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2015-03-18] (Microsoft Corporation)
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\...\Run: [BingSvc] => C:\Users\Lore *******\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-12-04]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 4.0 HD Edition.lnk [2011-02-11]
ShortcutTarget: PHOTOfunSTUDIO 4.0 HD Edition.lnk -> C:\Program Files (x86)\Panasonic\PHOTOfunSTUDIO 4.0 HD\AutoStartupService.exe (Panasonic Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/4
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=de-AT&Src=MSE&Tid=00033BB0&OHP=http%3A%2F%2Fg.uk.msn.com%2FHPCOM%2F4&OSP=
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\S-1-5-21-3921111220-2900040076-1547133076-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3921111220-2900040076-1547133076-1003 -> DefaultScope {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3921111220-2900040076-1547133076-1003 -> {1693D839-D6BE-4450-935F-791493B6851C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
BHO: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2011-05-02] (DigitalPersona, Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: File Sanitizer for HP ProtectTools -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2010-05-06] (Hewlett-Packard)
BHO-x32: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2011-05-02] (DigitalPersona, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-05-08] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-08] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{F4FF26DF-9FE9-4F91-A720-687E53208FA1}: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\Lore *******\AppData\Roaming\Mozilla\Firefox\Profiles\ogv9zrns.default-1440333370442
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-13] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-13] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\system32\Adobe\Director\np32dsw.dll [Keine Datei]
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-08] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Extension: Kein Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-24]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-08-24]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2011-12-09]

Chrome: 
=======
CHR Profile: C:\Users\Lore *******\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avira Browser Safety) - C:\Users\Lore *******\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-08-23]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Lore *******\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Lore *******\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-23]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [887128 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [461672 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [461672 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [227592 2015-08-03] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R3 DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [704512 2010-02-02] (McAfee, Inc.) [Datei ist nicht signiert]
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462160 2010-07-16] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [362040 2010-04-28] (Hewlett-Packard Ltd)
R2 HP ProtectTools Service; C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [32768 2010-10-19] (Hewlett-Packard Development Company, L.P) [Datei ist nicht signiert]
R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [90112 2010-06-14] (Hewlett-Packard Company) [Datei ist nicht signiert]
R2 HpFkCryptService; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [281192 2010-02-02] (McAfee, Inc.)
R2 HPFSService; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [298496 2010-05-06] (Hewlett-Packard) [Datei ist nicht signiert]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-09-12] (Hewlett-Packard Company)
S2 KMService; C:\windows\SysWOW64\srvany.exe [8192 2014-03-31] () [Datei ist nicht signiert]
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 QDLService2kHP; C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kHP.exe [1687360 2011-04-29] (QUALCOMM, Inc.)
R2 SMManager; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\SMManager.exe [84808 2010-09-17] (Smith Micro Software, Inc.)
R2 StatusAgent4; C:\windows\SysWOW64\SAgent4.exe [131072 2006-12-20] (SEIKO EPSON CORPORATION) [Datei ist nicht signiert]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162528 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [141416 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 cdrbsdrv; C:\Windows\System32\Drivers\cdrbsdrv.sys [39208 2006-08-25] (B.H.A Corporation)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [40760 2010-03-09] (Hewlett-Packard Development Company L.P.)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.)
R1 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [109272 2015-06-18] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-24] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R3 qcfilterhp2k; C:\Windows\System32\DRIVERS\qcfilterhp2k.sys [6400 2011-04-29] (QUALCOMM Incorporated)
R3 qcombushp; C:\Windows\System32\DRIVERS\qcombushp.sys [160328 2011-04-29] (MCCI)
R3 qcusbnethp2k; C:\Windows\System32\DRIVERS\qcusbnethp2k.sys [444416 2011-04-29] (QUALCOMM Incorporated)
R3 qcusbserhp2k; C:\Windows\System32\DRIVERS\qcusbserhp2k.sys [230784 2011-04-29] (QUALCOMM Incorporated)
R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [58184 2010-02-02] (McAfee, Inc.)
R1 RsvLock; C:\Windows\SysWow64\Drivers\RsvLock.sys [40088 2010-02-02] (McAfee, Inc.)
R0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [56648 2010-02-02] ()
R0 SafeBoot; C:\Windows\SysWow64\Drivers\SafeBoot.sys [110520 2010-02-02] (McAfee, Inc.)
R0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2009-06-04] (McAfee, Inc.)
R0 SbAlg; C:\Windows\SysWow64\Drivers\SbAlg.sys [51800 2010-02-02] (McAfee, Inc.)
R0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15688 2010-02-02] (McAfee, Inc.)
R0 SbFsLock; C:\Windows\SysWow64\Drivers\SbFsLock.sys [13256 2010-02-02] (McAfee, Inc.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1803904 2010-04-27] ()
S3 ARCVCAM; system32\DRIVERS\ArcSoftVCapture.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CpqDfw; system32\drivers\CpqDfw.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-24 12:24 - 2015-08-24 12:24 - 00028945 _____ C:\Users\Lore *******\Desktop\FRST.txt
2015-08-24 12:23 - 2015-08-24 12:23 - 02173952 _____ (Farbar) C:\Users\Lore *******\Desktop\FRST64.exe
2015-08-24 09:36 - 2015-08-24 12:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-21 23:24 - 2015-08-21 23:24 - 00035959 _____ C:\ComboFix.txt
2015-08-21 22:55 - 2011-06-26 08:45 - 00256000 _____ C:\windows\PEV.exe
2015-08-21 22:55 - 2010-11-07 19:20 - 00208896 _____ C:\windows\MBR.exe
2015-08-21 22:55 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe
2015-08-21 22:55 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe
2015-08-21 22:53 - 2015-08-21 23:24 - 00000000 ____D C:\Qoobox
2015-08-21 22:52 - 2015-08-21 23:21 - 00000000 ____D C:\windows\erdnt
2015-08-21 12:55 - 2015-08-21 13:35 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-08-20 19:00 - 2015-08-20 19:00 - 00000000 _____ C:\Users\Lore *******\defogger_reenable
2015-08-20 18:50 - 2015-08-24 12:24 - 00000000 ____D C:\FRST
2015-08-20 18:33 - 2015-08-20 18:33 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\Avira
2015-08-20 18:23 - 2015-08-11 03:20 - 25191936 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-08-20 18:23 - 2015-08-11 03:14 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-08-20 18:23 - 2015-08-11 02:33 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-08-20 18:23 - 2015-08-11 02:20 - 19871232 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-08-20 18:21 - 2015-08-20 18:21 - 00003432 _____ C:\windows\System32\Tasks\Avira Browser Safety Updater Task
2015-08-20 18:16 - 2015-07-15 08:37 - 00162528 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00141416 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00044088 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2015-08-20 18:16 - 2015-07-15 08:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2015-08-20 18:12 - 2015-08-20 18:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-08-20 18:11 - 2015-08-20 18:12 - 00000000 ____D C:\ProgramData\Package Cache
2015-08-20 17:44 - 2015-08-22 20:18 - 00000000 ____D C:\AdwCleaner
2015-08-20 17:44 - 2015-08-20 17:46 - 00005604 _____ C:\AdwCleaner[S1].txt
2015-08-20 17:38 - 2015-07-23 02:06 - 05568960 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-08-20 17:38 - 2015-07-23 02:06 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-08-20 17:38 - 2015-07-23 02:06 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-08-20 17:38 - 2015-07-23 02:03 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-08-20 17:38 - 2015-07-23 02:03 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01390592 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-08-20 17:38 - 2015-07-23 02:02 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-08-20 17:38 - 2015-07-23 02:02 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-08-20 17:38 - 2015-07-23 02:02 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-08-20 17:38 - 2015-07-23 02:01 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-08-20 17:38 - 2015-07-23 02:01 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-08-20 17:38 - 2015-07-23 02:01 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-08-20 17:38 - 2015-07-23 01:58 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-08-20 17:38 - 2015-07-23 01:57 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:52 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-20 17:38 - 2015-07-23 01:51 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-08-20 17:38 - 2015-07-22 19:57 - 03989952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-08-20 17:38 - 2015-07-22 19:57 - 03934656 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-08-20 17:38 - 2015-07-22 19:54 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00641536 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00635392 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-08-20 17:38 - 2015-07-22 19:53 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-08-20 17:38 - 2015-07-22 19:52 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-08-20 17:38 - 2015-07-22 19:52 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-08-20 17:38 - 2015-07-22 19:52 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-08-20 17:38 - 2015-07-22 19:47 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-08-20 17:38 - 2015-07-22 19:46 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 19:42 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:48 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2015-08-20 17:38 - 2015-07-22 18:45 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-08-20 17:38 - 2015-07-22 18:44 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-08-20 17:38 - 2015-07-22 18:44 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-08-20 17:38 - 2015-07-22 18:34 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-08-20 17:38 - 2015-07-22 18:34 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-08-20 17:38 - 2015-07-22 18:31 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-20 17:38 - 2015-07-22 18:31 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-20 17:37 - 2015-07-15 05:17 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-08-20 17:37 - 2015-07-15 04:54 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2015-08-20 17:37 - 2015-07-09 19:58 - 01632256 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2015-08-20 17:37 - 2015-07-09 19:58 - 00082944 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll
2015-08-20 17:37 - 2015-07-09 19:42 - 01372160 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2015-08-20 17:37 - 2015-07-09 19:42 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll
2015-08-20 17:33 - 2015-06-25 12:06 - 00115136 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-08-20 17:33 - 2015-06-25 12:01 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-08-20 17:33 - 2015-06-25 12:01 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-08-20 17:33 - 2015-06-25 11:44 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-08-20 11:42 - 2015-08-24 11:15 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-20 11:42 - 2015-08-20 11:42 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-08-20 11:42 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-08-20 11:42 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-08-20 11:42 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-08-13 11:03 - 2015-07-30 15:13 - 00124624 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 11:03 - 2015-07-30 15:13 - 00103120 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 10:19 - 2015-07-28 22:09 - 00017344 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-08-13 10:19 - 2015-07-28 22:05 - 01116672 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00774656 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00743424 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00437760 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-08-13 10:19 - 2015-07-28 22:05 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-08-13 10:19 - 2015-07-28 21:55 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-08-13 10:19 - 2015-07-16 21:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-08-13 10:19 - 2015-07-16 21:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-08-13 10:19 - 2015-07-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-08-13 10:18 - 2015-07-15 20:15 - 00094656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-08-13 10:18 - 2015-07-15 20:10 - 01743360 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2015-08-13 10:18 - 2015-07-15 20:10 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-08-13 10:17 - 2015-07-21 02:39 - 00389840 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-08-13 10:17 - 2015-07-21 02:12 - 00342736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-08-13 10:17 - 2015-07-16 22:54 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-08-13 10:17 - 2015-07-16 22:36 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-08-13 10:17 - 2015-07-16 22:35 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-08-13 10:17 - 2015-07-16 22:26 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-08-13 10:17 - 2015-07-16 22:21 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-08-13 10:17 - 2015-07-16 22:12 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-08-13 10:17 - 2015-07-16 22:00 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 10:17 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-08-13 10:17 - 2015-07-16 21:51 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-08-13 10:17 - 2015-07-16 21:50 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-08-13 10:17 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-08-13 10:17 - 2015-07-16 21:43 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-08-13 10:17 - 2015-07-16 21:43 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-08-13 10:17 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-08-13 10:17 - 2015-07-16 21:39 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-08-13 10:17 - 2015-07-16 21:38 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-08-13 10:17 - 2015-07-16 21:35 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-08-13 10:17 - 2015-07-16 21:24 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-13 10:17 - 2015-07-16 21:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-08-13 10:17 - 2015-07-16 21:17 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-08-13 10:17 - 2015-07-16 21:06 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-08-13 10:17 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-08-13 10:17 - 2015-07-16 21:01 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-08-13 10:17 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-08-13 10:17 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-08-13 10:17 - 2015-07-15 05:19 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\basesrv.dll
2015-08-13 10:16 - 2015-07-16 22:37 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-08-13 10:16 - 2015-07-16 22:36 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-08-13 10:16 - 2015-07-16 22:36 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-08-13 10:16 - 2015-07-16 22:35 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-08-13 10:16 - 2015-07-16 22:27 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-08-13 10:16 - 2015-07-16 22:26 - 05923328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-08-13 10:16 - 2015-07-16 22:23 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-08-13 10:16 - 2015-07-16 22:21 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-08-13 10:16 - 2015-07-16 22:08 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-08-13 10:16 - 2015-07-16 21:55 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-08-13 10:16 - 2015-07-16 21:54 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-08-13 10:16 - 2015-07-16 21:51 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-08-13 10:16 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-08-13 10:16 - 2015-07-16 21:49 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-08-13 10:16 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-08-13 10:16 - 2015-07-16 21:36 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-08-13 10:16 - 2015-07-16 21:34 - 14451200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-08-13 10:16 - 2015-07-16 21:33 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-08-13 10:16 - 2015-07-16 21:32 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-08-13 10:16 - 2015-07-16 21:29 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-08-13 10:16 - 2015-07-16 21:20 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-08-13 10:16 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-08-13 10:16 - 2015-07-16 21:12 - 02427904 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-08-13 10:16 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-08-13 10:16 - 2015-07-16 21:05 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-08-13 10:16 - 2015-07-16 20:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-08-13 10:16 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 01648128 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 01180160 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-08-13 10:15 - 2015-07-30 20:06 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 01251328 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-08-13 10:15 - 2015-07-30 19:57 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-08-13 10:15 - 2015-07-30 19:55 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-08-13 10:15 - 2015-07-30 18:56 - 03208192 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-08-13 10:15 - 2015-07-30 18:52 - 00372736 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-08-13 10:15 - 2015-07-30 18:49 - 00299520 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 03154944 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 02606080 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-08-13 10:15 - 2015-07-20 20:12 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-08-13 10:15 - 2015-07-20 20:12 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-08-13 10:15 - 2015-07-20 20:12 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00173056 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00093184 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-08-13 10:15 - 2015-07-20 19:56 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-08-13 10:15 - 2015-07-20 19:56 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-08-13 10:15 - 2015-07-15 05:19 - 02004992 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-08-13 10:15 - 2015-07-15 05:19 - 01887232 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-08-13 10:15 - 2015-07-15 05:14 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-08-13 10:15 - 2015-07-15 05:13 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-08-13 10:15 - 2015-07-15 04:55 - 01390592 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-08-13 10:15 - 2015-07-15 04:55 - 01241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-08-13 10:15 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2015-08-13 10:15 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-08-13 10:15 - 2015-07-10 19:51 - 14177280 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-08-13 10:15 - 2015-07-10 19:34 - 12875776 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-08-13 10:15 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\notepad.exe
2015-08-13 10:15 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\notepad.exe
2015-08-13 10:15 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
2015-08-13 10:15 - 2015-07-01 22:49 - 00260096 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-08-13 10:15 - 2015-07-01 22:48 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-08-13 10:15 - 2015-07-01 22:30 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-08-13 10:15 - 2015-07-01 22:30 - 00082432 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-08-13 10:15 - 2015-05-09 20:26 - 00493504 _____ (Microsoft Corporation) C:\windows\system32\mcupdate_GenuineIntel.dll
2015-07-31 21:53 - 2015-07-31 21:53 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-07-31 21:53 - 2015-07-31 21:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-07-31 21:52 - 2015-07-31 21:53 - 00000000 ____D C:\Program Files\iTunes
2015-07-31 21:52 - 2015-07-31 21:52 - 00000000 ____D C:\Program Files\iPod
2015-07-31 21:52 - 2015-07-31 21:52 - 00000000 ____D C:\Program Files (x86)\iTunes

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-24 12:21 - 2013-04-30 19:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-24 12:16 - 2013-12-15 14:50 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-08-24 12:15 - 2013-09-21 13:49 - 00000000 ____D C:\Users\Lore *******\Documents\Outlook-Dateien
2015-08-24 12:15 - 2011-02-11 11:25 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\Skype
2015-08-24 11:32 - 2011-05-15 18:12 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-24 11:31 - 2009-07-14 06:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-24 11:31 - 2009-07-14 06:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-24 09:32 - 2011-01-11 14:33 - 01322057 _____ C:\windows\WindowsUpdate.log
2015-08-24 09:17 - 2010-09-07 23:49 - 00000000 ____D C:\ProgramData\HPQLOG
2015-08-24 09:14 - 2014-12-04 10:45 - 00007464 _____ C:\windows\setupact.log
2015-08-24 09:14 - 2011-05-15 18:12 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-24 09:14 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-08-23 14:31 - 2014-12-04 11:29 - 00000000 __SHD C:\Users\Lore *******\AppData\Local\EmieBrowserModeList
2015-08-23 14:31 - 2014-04-14 17:20 - 00000000 __SHD C:\Users\Lore *******\AppData\Local\EmieUserList
2015-08-23 14:31 - 2014-04-14 17:20 - 00000000 __SHD C:\Users\Lore *******\AppData\Local\EmieSiteList
2015-08-23 14:17 - 2010-09-08 00:27 - 05464130 _____ C:\windows\PFRO.log
2015-08-22 20:01 - 2011-05-15 18:19 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-22 19:18 - 2011-02-11 15:00 - 00003214 _____ C:\windows\System32\Tasks\HPCeeScheduleForNB*******$
2015-08-22 19:18 - 2011-02-11 15:00 - 00000338 _____ C:\windows\Tasks\HPCeeScheduleForNB*******$.job
2015-08-21 23:15 - 2009-07-14 04:34 - 00000215 _____ C:\windows\system.ini
2015-08-21 22:44 - 2015-06-12 22:52 - 00000348 _____ C:\windows\Tasks\HPCeeScheduleForLore *******.job
2015-08-21 20:33 - 2011-02-11 12:46 - 00000000 ____D C:\Users\Lore *******\Documents\Eigene Dateien
2015-08-21 19:51 - 2015-06-12 22:52 - 00003210 _____ C:\windows\System32\Tasks\HPCeeScheduleForLore *******
2015-08-21 19:50 - 2011-02-10 14:32 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2015-08-20 21:36 - 2011-02-07 18:42 - 00000000 ____D C:\windows\rescache
2015-08-20 19:00 - 2011-02-07 10:48 - 00000000 ____D C:\Users\Lore *******
2015-08-20 18:21 - 2013-09-21 14:57 - 00000000 ____D C:\Program Files (x86)\Avira
2015-08-20 18:16 - 2013-09-21 14:57 - 00000000 ____D C:\ProgramData\Avira
2015-08-20 17:57 - 2010-09-07 23:55 - 00702028 _____ C:\windows\system32\perfh007.dat
2015-08-20 17:57 - 2010-09-07 23:55 - 00150638 _____ C:\windows\system32\perfc007.dat
2015-08-20 17:57 - 2009-07-14 07:13 - 01622300 _____ C:\windows\system32\PerfStringBackup.INI
2015-08-20 16:24 - 2009-07-14 05:20 - 00000000 ____D C:\windows\L2Schemas
2015-08-20 16:22 - 2011-02-09 16:31 - 00000000 ____D C:\Users\Lore *******\AppData\Roaming\SoftGrid Client
2015-08-20 12:14 - 2011-04-20 07:36 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-08-20 12:14 - 2011-04-20 07:36 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-08-20 12:14 - 2011-02-07 10:59 - 00001425 _____ C:\Users\Lore *******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-17 08:34 - 2011-02-11 11:25 - 00000000 ____D C:\ProgramData\Skype
2015-08-13 17:10 - 2011-02-07 10:59 - 00000000 ___RD C:\Users\Lore *******\Virtual Machines
2015-08-13 17:08 - 2009-07-14 06:45 - 00413936 _____ C:\windows\system32\FNTCACHE.DAT
2015-08-13 17:05 - 2015-04-15 22:59 - 00000000 ____D C:\windows\system32\appraiser
2015-08-13 17:05 - 2014-05-06 16:01 - 00000000 ___SD C:\windows\system32\CompatTel
2015-08-13 11:03 - 2013-03-14 09:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-13 11:02 - 2013-03-14 09:02 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-13 11:02 - 2013-03-14 09:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-13 11:00 - 2011-02-13 09:25 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 10:54 - 2009-07-14 04:34 - 00000478 _____ C:\windows\win.ini
2015-08-13 10:53 - 2013-07-24 00:50 - 00000000 ____D C:\windows\system32\MRT
2015-08-13 10:47 - 2011-02-07 18:45 - 132483416 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-08-13 10:16 - 2013-12-15 14:50 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-08-13 10:16 - 2012-04-13 18:28 - 00778440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-08-13 10:16 - 2011-06-17 15:47 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-31 21:52 - 2011-02-11 12:02 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-07-31 17:26 - 2011-02-13 09:25 - 00000000 ____D C:\Users\Lore *******\AppData\Local\Microsoft Help
2015-07-25 11:00 - 2015-04-04 22:56 - 00000000 ___SD C:\windows\system32\GWX

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-03-30 18:19 - 2015-07-19 06:43 - 0000121 _____ () C:\Users\Lore *******\AppData\Roaming\default.rss
2011-04-15 22:57 - 2011-06-03 09:07 - 0001854 _____ () C:\Users\Lore *******\AppData\Roaming\GhostObjGAFix.xml
2013-09-21 14:33 - 2013-09-21 14:33 - 0022216 _____ () C:\Users\Lore *******\AppData\Roaming\Kommagetrennte Werte (DOS).ADR
2013-09-21 14:21 - 2013-09-21 16:35 - 0022405 _____ () C:\Users\Lore *******\AppData\Roaming\Kommagetrennte Werte (Windows).ADR

Einige Dateien in TEMP:
====================
C:\Users\Lore *******\AppData\Local\Temp\avgnt.exe
C:\Users\Lore *******\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-08-22 19:18

==================== Ende von Ergebnis ============================
         

Alt 25.08.2015, 06:38   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Browser Hijack - Standard

Windows 7 - Browser Hijack



Was besteht jetzt aktuell noch an Problemen?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Windows 7 - Browser Hijack
autostart, avira, browser, explorer, firefox, gmer, google, hijack, internet, internet explorer, laptop, log, logfile, malwarebytes, microsoft, mozilla, newtab, opera, registry, server, software, system, temp, updates, windows, windows updates



Ähnliche Themen: Windows 7 - Browser Hijack


  1. Hijack Browser Proxy
    Log-Analyse und Auswertung - 02.02.2015 (13)
  2. Browser Hijack
    Plagegeister aller Art und deren Bekämpfung - 10.12.2014 (46)
  3. VLC.de Browser Hijack
    Plagegeister aller Art und deren Bekämpfung - 12.10.2014 (3)
  4. Windows 7:wprotectmanager, Browser-Hijack?
    Log-Analyse und Auswertung - 15.06.2014 (10)
  5. Browser Hijack?
    Plagegeister aller Art und deren Bekämpfung - 19.01.2014 (9)
  6. Browser hijack blueseek
    Plagegeister aller Art und deren Bekämpfung - 27.12.2013 (4)
  7. u-search browser hijack
    Plagegeister aller Art und deren Bekämpfung - 02.02.2013 (3)
  8. Browser Hijack, Windows 7
    Log-Analyse und Auswertung - 05.10.2012 (37)
  9. Browser Hijack - Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 11.03.2011 (30)
  10. 10 TAN eingeben und IE7 Browser-Hijack
    Log-Analyse und Auswertung - 26.04.2010 (31)
  11. Browser Hijack?
    Log-Analyse und Auswertung - 18.01.2010 (1)
  12. Trojaner Browser Hijack
    Plagegeister aller Art und deren Bekämpfung - 10.05.2009 (3)
  13. Google-Browser-Hijack
    Log-Analyse und Auswertung - 18.02.2009 (1)
  14. Browser Hijack
    Log-Analyse und Auswertung - 07.01.2005 (2)
  15. warscheinlich browser hijack
    Log-Analyse und Auswertung - 24.09.2004 (4)
  16. Hartnäckiger Browser Hijack
    Log-Analyse und Auswertung - 12.09.2004 (10)
  17. Possible Browser Hijack attemp
    Plagegeister aller Art und deren Bekämpfung - 17.05.2004 (18)

Zum Thema Windows 7 - Browser Hijack - Meine Mutter hat mir heute ihren Laptop übergeben mit den Worten "Schmuddelbilder". Einmal alle 3 Browser (IE, Firefox, Chrome) aufgemacht und schon habe ich folgendes gesehen: Was habe ich bereits - Windows 7 - Browser Hijack...
Archiv
Du betrachtest: Windows 7 - Browser Hijack auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.