Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Amazon Zip

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 05.11.2017, 09:55   #1
Ani73
 
Amazon Zip - Standard

Amazon Zip



Hallo und guten Morgen,

ich habe gerade im total verschlafenen Zustand meine Mails abgefragt. Hatte von Amazon ne Datei drin wegen einer Bestellung und, so blöd wie ich war, den Anhang angeklickt.
Erst kurz drauf habe ich realisiert, dass das ne Zip Datei war.
Hab das Fenster das aufging auch gleich geschlossen.
Bin mir jetzt aber nicht sicher ob ich mir was eingefangen habe.
Ich bin so blöd, hätte nicht gedacht, dass mir das mal passiert. Fazit, nie im verschlafenen Zustand die Mails kontrollieren.

Ich hab auch gleich ein FRST durchlaufen lassen.
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2015 01 (ATTENTION: ====> FRST version is 991 days old and could be outdated)
Ran by Fam. Ade (administrator) on FAMADE-PC on 05-11-2017 09:44:30
Running from C:\Users\Fam. Ade\Desktop
Loaded Profiles: Fam. Ade & Ginua &  (Available profiles: Fam. Ade & Ginua & Shari)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-Agent.exe
(Nico Mak Computing) C:\Program Files\WinZip\WZUpdateNotifier.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
(Nico Mak Computing) C:\Program Files\WinZip\FAHWindow64.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\n360.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_27_0_0_183_ActiveX.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [fssui] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263512 2012-11-30] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2015-01-14] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-11-01] (Dropbox, Inc.)
HKLM-x32\...\RunOnce: [{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}] => C:\ProgramData\Package Cache\{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}\Avira.OE.Setup.Bundle.exe [1288968 2017-11-01] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759384 2013-06-17] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3011152 2015-11-10] (Valve Corporation)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [1690248 2016-12-01] (BlueStack Systems, Inc.)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759384 2013-06-17] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3011152 2015-11-10] (Valve Corporation)
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [1690248 2016-12-01] (BlueStack Systems, Inc.)
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation)
HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\Policies\system: [LogonHoursAction] 2
HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-356143711-355811113-2582273239-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation)
HKU\S-1-5-21-356143711-355811113-2582273239-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-356143711-355811113-2582273239-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\SCANNERMAP\...\Run: [Google Update] => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-05-08] (Google Inc.)
HKU\SCANNERMAP\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation)
HKU\SCANNERMAP\...\Policies\system: [LogonHoursAction] 2
HKU\SCANNERMAP\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Benachrichtigungsdienst.lnk
ShortcutTarget: Update Benachrichtigungsdienst.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\buShell.dll (Symantec Corporation)
GroupPolicyUsers\S-1-5-21-356143711-355811113-2582273239-1008\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-356143711-355811113-2582273239-1007\User: Group Policy restriction detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-356143711-355811113-2582273239-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-356143711-355811113-2582273239-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\SCANNERMAP\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> DefaultScope {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms}
BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\coIEPlg.dll (Symantec Corporation)
BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} ->  No File
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\IPS\IPSBHO.DLL No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} -  No File
Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll No File
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine32\22.11.0.41\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} -  No File
Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\coIEPlg.dll (Symantec Corporation)
Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} -  No File
Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\coIEPlg.dll (Symantec Corporation)
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} 
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=1.6.0_35 -> C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin-x32: @soft-xpansion/npsxpdf -> C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Fam. Ade\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Fam. Ade\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin HKU\SCANNERMAP: @tools.google.com/Google Update;version=3 -> C:\Users\Shari\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\SCANNERMAP: @tools.google.com/Google Update;version=9 -> C:\Users\Shari\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Search Shield Study - C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default\Extensions\@unified-urlbar-shield-study-opt-out-new-users.xpi [2017-10-11]
FF Extension: Safe Browsing Version 4 (temporary add-on) - C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-11]
FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon
FF Extension: Norton Security Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon [2017-10-11]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-02-14]
FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon
FF HKLM-x32\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
StartMenuInternet: Firefox-308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe

Chrome: 
=======
CHR Profile: C:\Users\Fam. Ade\AppData\Local\Google\Chrome\User Data\default
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\Exts\Chrome.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\Exts\Chrome.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-02-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) [File not signed]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1128432 2017-10-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [490968 2017-10-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [490968 2017-10-14] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1525240 2017-10-14] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [407408 2017-10-26] (Avira Operations GmbH & Co. KG)
S3 becldr3Service; C:\Program Files (x86)\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [176128 2011-04-19] () [File not signed]
S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [486936 2016-12-01] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [470552 2016-12-01] (BlueStack Systems, Inc.)
S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [511512 2016-12-01] (BlueStack Systems, Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51016 2017-11-01] (Dropbox, Inc.)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1386496 2016-08-22] (Microsoft Corporation)
S2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [437224 2016-10-27] (Digital Wave Ltd.)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 N360; C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\N360.exe [326144 2017-10-04] (Symantec Corporation)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [180824 2013-06-17] (Sandboxie Holdings, LLC)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-09-18] (soft Xpansion)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2012-10-01] ()
R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [64504 2017-06-17] (Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [194272 2017-09-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [151128 2017-09-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-03-02] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [78600 2017-03-02] (Avira Operations GmbH & Co. KG)
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\BASHDefs\20171101.001\BHDrvx64.sys [1872024 2017-10-11] (Symantec Corporation)
S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-12-01] (BlueStack Systems)
S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-11-08] (Bluestack System Inc. )
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\160B000.029\ccSetx64.sys [187520 2017-10-04] (Symantec Corporation)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [508056 2017-10-18] (Symantec Corporation)
U3 EraserUtilDrv11721; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11721.sys [158360 2017-10-18] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [158336 2017-06-28] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\IPSDefs\20171103.001\IDSvia64.sys [1056920 2017-10-14] (Symantec Corporation)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2012-10-01] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-11-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [198360 2013-06-17] (Sandboxie Holdings, LLC)
R1 SRTSP; C:\Windows\System32\Drivers\N360x64\160B000.029\SRTSP64.SYS [812704 2017-10-04] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\160B000.029\SRTSPX64.SYS [49304 2017-10-04] (Symantec Corporation)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
R0 SymEFASI; C:\Windows\System32\drivers\N360x64\160B000.029\SYMEFASI64.SYS [1868416 2017-10-04] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [102568 2017-07-27] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\160B000.029\Ironx64.SYS [301288 2017-10-04] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\160B000.029\SYMNETS.SYS [566912 2017-10-04] (Symantec Corporation)
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [151184 2016-03-10] (MBB)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 dbx; system32\DRIVERS\dbx.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\SDSDefs\20160713.008\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\SDSDefs\20160713.008\EX64.SYS [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2017-11-05 09:44 - 2017-11-05 09:45 - 00033073 _____ () C:\Users\Fam. Ade\Desktop\FRST.txt
2017-11-04 14:13 - 2017-11-04 14:13 - 00000000 ____D () C:\Windows\System32\Tasks\Remediation
2017-11-02 18:56 - 2017-11-02 18:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-11-01 12:58 - 2017-11-01 12:58 - 00051016 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-11-01 12:58 - 2017-11-01 12:58 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2017-11-01 12:58 - 2017-11-01 12:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2017-11-01 12:58 - 2017-11-01 12:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2017-10-25 11:42 - 2017-10-25 11:42 - 05250048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2017-10-12 12:17 - 2017-10-13 06:30 - 00000000 ____D () C:\Users\TEMP.FamAde-PC.001
2017-10-12 03:05 - 2017-10-12 03:05 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360
2017-10-12 02:59 - 2017-10-12 02:59 - 00003208 _____ () C:\Windows\System32\Tasks\Norton WSC Integration
2017-10-12 02:16 - 2017-10-12 02:16 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-10-11 11:46 - 2017-09-13 16:33 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-10-11 11:46 - 2017-09-13 16:32 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-10-11 11:46 - 2017-09-13 16:32 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-10-11 11:46 - 2017-09-13 16:32 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-10-11 11:46 - 2017-09-13 16:32 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-10-11 11:46 - 2017-09-13 16:31 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:13 - 04001512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-10-11 11:46 - 2017-09-13 16:13 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-10-11 11:46 - 2017-09-13 16:10 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:05 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2017-10-11 11:46 - 2017-09-13 16:00 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-10-11 11:46 - 2017-09-13 16:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-10-11 11:46 - 2017-09-13 16:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-10-11 11:46 - 2017-09-13 16:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-10-11 11:46 - 2017-09-13 15:57 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-10-11 11:46 - 2017-09-13 15:56 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-10-11 11:46 - 2017-09-13 15:53 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-10-11 11:46 - 2017-09-13 15:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-10-11 11:46 - 2017-09-13 15:53 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-10-11 11:46 - 2017-09-13 15:52 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-10-11 11:46 - 2017-09-13 15:52 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-10-11 11:46 - 2017-09-13 15:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-10-11 11:46 - 2017-09-13 15:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-10-11 11:46 - 2017-09-13 15:46 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-10-11 11:46 - 2017-09-13 15:46 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-10-11 11:46 - 2017-09-09 01:45 - 00395984 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-10-11 11:46 - 2017-09-09 00:47 - 00347344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-10-11 11:46 - 2017-09-08 16:34 - 01680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-10-11 11:46 - 2017-09-08 16:30 - 02319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 02058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-10-11 11:46 - 2017-09-08 16:14 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-10-11 11:46 - 2017-09-08 16:13 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-10-11 11:46 - 2017-09-08 16:13 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-10-11 11:46 - 2017-09-08 16:10 - 01549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-10-11 11:46 - 2017-09-08 16:10 - 01363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-10-11 11:46 - 2017-09-08 16:10 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-10-11 11:46 - 2017-09-08 16:10 - 00109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-10-11 11:46 - 2017-09-08 16:00 - 03222016 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-10-11 11:46 - 2017-09-08 16:00 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-10-11 11:46 - 2017-09-08 16:00 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-10-11 11:46 - 2017-09-08 15:59 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-10-11 11:46 - 2017-09-08 15:59 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-10-11 11:46 - 2017-09-08 15:20 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-10-11 11:46 - 2017-09-08 15:20 - 00345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-10-11 11:46 - 2017-09-08 15:20 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-10-11 11:46 - 2017-09-07 22:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-10-11 11:46 - 2017-09-07 22:37 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-10-11 11:46 - 2017-09-07 22:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-10-11 11:46 - 2017-09-07 22:18 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-10-11 11:46 - 2017-09-07 22:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-10-11 11:46 - 2017-09-07 22:17 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-10-11 11:46 - 2017-09-07 22:17 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-10-11 11:46 - 2017-09-07 22:15 - 02902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-10-11 11:46 - 2017-09-07 22:08 - 25729536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-10-11 11:46 - 2017-09-07 22:08 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-10-11 11:46 - 2017-09-07 22:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-10-11 11:46 - 2017-09-07 22:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-10-11 11:46 - 2017-09-07 22:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-10-11 11:46 - 2017-09-07 22:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-10-11 11:46 - 2017-09-07 22:01 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-10-11 11:46 - 2017-09-07 22:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-10-11 11:46 - 2017-09-07 21:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-10-11 11:46 - 2017-09-07 21:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-10-11 11:46 - 2017-09-07 21:40 - 05982208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-10-11 11:46 - 2017-09-07 21:39 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-10-11 11:46 - 2017-09-07 21:38 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-10-11 11:46 - 2017-09-07 21:37 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-10-11 11:46 - 2017-09-07 21:33 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-10-11 11:46 - 2017-09-07 21:32 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-10-11 11:46 - 2017-09-07 21:29 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-10-11 11:46 - 2017-09-07 21:27 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-10-11 11:46 - 2017-09-07 21:13 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-10-11 11:46 - 2017-09-07 21:10 - 00807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-10-11 11:46 - 2017-09-07 21:10 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-10-11 11:46 - 2017-09-07 21:08 - 02134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-10-11 11:46 - 2017-09-07 21:08 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-10-11 11:46 - 2017-09-07 20:44 - 15262720 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-10-11 11:46 - 2017-09-07 20:40 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-10-11 11:46 - 2017-09-07 20:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-10-11 11:46 - 2017-09-07 20:27 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-10-11 11:46 - 2017-09-07 20:17 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-10-11 11:46 - 2017-09-07 20:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-10-11 11:46 - 2017-09-07 20:10 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-10-11 11:46 - 2017-09-07 20:10 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-10-11 11:46 - 2017-09-07 20:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-10-11 11:46 - 2017-09-07 20:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-10-11 11:46 - 2017-09-07 20:04 - 20267008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-10-11 11:46 - 2017-09-07 20:03 - 02292736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-10-11 11:46 - 2017-09-07 20:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-10-11 11:46 - 2017-09-07 20:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-10-11 11:46 - 2017-09-07 19:59 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-10-11 11:46 - 2017-09-07 19:58 - 00663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-10-11 11:46 - 2017-09-07 19:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-10-11 11:46 - 2017-09-07 19:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-10-11 11:46 - 2017-09-07 19:49 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-10-11 11:46 - 2017-09-07 19:44 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-10-11 11:46 - 2017-09-07 19:44 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-10-11 11:46 - 2017-09-07 19:43 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-10-11 11:46 - 2017-09-07 19:40 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-10-11 11:46 - 2017-09-07 19:39 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-10-11 11:46 - 2017-09-07 19:37 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-10-11 11:46 - 2017-09-07 19:36 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-10-11 11:46 - 2017-09-07 19:29 - 04547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-10-11 11:46 - 2017-09-07 19:29 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-10-11 11:46 - 2017-09-07 19:26 - 00694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-10-11 11:46 - 2017-09-07 19:25 - 02058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-10-11 11:46 - 2017-09-07 19:25 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-10-11 11:46 - 2017-09-07 19:17 - 13677568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-10-11 11:46 - 2017-09-07 19:01 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-10-11 11:46 - 2017-09-07 18:57 - 01316864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-10-11 11:46 - 2017-09-07 18:57 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-10-11 11:46 - 2017-09-07 16:31 - 02851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2017-10-11 11:46 - 2017-09-07 16:12 - 02755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2017-10-11 11:46 - 2017-09-07 15:55 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-10-11 11:46 - 2017-09-07 15:55 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-10-11 11:46 - 2017-09-07 15:55 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-10-11 11:46 - 2017-08-19 16:28 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-10-11 11:46 - 2017-08-19 16:28 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-10-11 11:46 - 2017-08-19 16:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2017-10-11 11:46 - 2017-08-19 16:10 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2017-10-11 11:46 - 2017-08-19 16:10 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2017-10-11 11:46 - 2017-08-19 16:10 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2017-10-11 11:46 - 2017-08-19 16:08 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2017-10-11 11:46 - 2017-08-19 16:08 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2017-10-11 11:46 - 2017-08-19 15:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2017-10-11 11:46 - 2017-08-19 15:57 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2017-10-11 11:46 - 2017-08-14 18:35 - 01032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-10-11 11:46 - 2017-08-14 18:35 - 00827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-10-11 11:46 - 2017-08-14 18:35 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2017-10-11 11:46 - 2017-08-13 22:45 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2017-10-11 07:41 - 2017-10-11 07:46 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Local\Mozilla
2017-10-11 07:40 - 2017-11-02 08:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2017-10-11 07:40 - 2017-11-02 08:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2017-10-11 07:40 - 2017-10-11 07:40 - 00000936 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-10-11 07:40 - 2017-10-11 07:40 - 00000924 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-10-11 07:37 - 2017-10-11 07:37 - 00245912 _____ (Mozilla) C:\Users\Fam. Ade\Downloads\Firefox Installer.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2017-11-05 09:44 - 2014-04-30 11:01 - 00000000 ____D () C:\FRST
2017-11-05 09:28 - 2017-09-24 11:26 - 00003316 _____ () C:\Windows\System32\Tasks\Avira_Antivirus_Systray
2017-11-05 09:25 - 2014-05-04 19:58 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-11-05 09:22 - 2015-06-02 12:53 - 00001218 _____ () C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-11-05 09:13 - 2012-09-24 16:26 - 01489376 _____ () C:\Windows\WindowsUpdate.log
2017-11-05 09:08 - 2014-05-21 19:03 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA.job
2017-11-05 04:22 - 2015-06-02 12:53 - 00001214 _____ () C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-11-05 04:18 - 2009-07-14 05:45 - 00023344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-11-05 04:18 - 2009-07-14 05:45 - 00023344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-11-04 23:18 - 2016-12-13 08:43 - 00000000 ____D () C:\Program Files (x86)\Bluestacks
2017-11-04 20:08 - 2014-05-21 19:03 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core.job
2017-11-04 12:23 - 2014-10-12 20:18 - 00000000 ____D () C:\Users\Fam. Ade\Documents\Tennis Damen
2017-11-02 18:56 - 2015-06-02 12:53 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2017-11-01 11:34 - 2017-09-24 11:26 - 00003122 _____ () C:\Windows\System32\Tasks\Avira SystrayStartTrigger
2017-11-01 11:34 - 2013-03-06 13:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-11-01 11:33 - 2015-01-21 19:58 - 00000000 ____D () C:\ProgramData\Package Cache
2017-10-30 11:38 - 2015-04-26 14:09 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Local\CrashDumps
2017-10-25 11:43 - 2013-03-06 13:08 - 00004366 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-10-25 11:43 - 2012-09-24 16:42 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-10-25 11:43 - 2012-09-24 16:42 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-10-25 11:43 - 2012-09-24 16:42 - 00000000 ____D () C:\Windows\system32\Macromed
2017-10-25 11:42 - 2012-09-24 16:42 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2017-10-13 06:35 - 2014-05-23 19:19 - 00000000 ____D () C:\Program Files (x86)\Steam
2017-10-13 06:32 - 2013-04-13 14:13 - 00001618 _____ () C:\Windows\Sandboxie.ini
2017-10-13 06:32 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2017-10-13 06:32 - 2009-07-14 05:51 - 00081321 _____ () C:\Windows\setupact.log
2017-10-13 06:31 - 2012-09-24 17:15 - 01196614 _____ () C:\Windows\PFRO.log
2017-10-12 05:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2017-10-12 04:17 - 2015-06-11 02:52 - 00000000 ____D () C:\Program Files\Common Files\AV
2017-10-12 03:05 - 2009-07-14 18:58 - 00703308 _____ () C:\Windows\system32\perfh007.dat
2017-10-12 03:05 - 2009-07-14 18:58 - 00151134 _____ () C:\Windows\system32\perfc007.dat
2017-10-12 03:05 - 2009-07-14 06:13 - 01629508 _____ () C:\Windows\system32\PerfStringBackup.INI
2017-10-12 02:59 - 2015-03-03 14:28 - 00000000 ____D () C:\Windows\system32\Drivers\N360x64
2017-10-12 02:58 - 2016-07-14 02:49 - 00002224 _____ () C:\Users\Public\Desktop\Norton 360.lnk
2017-10-12 02:58 - 2015-08-13 03:06 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
2017-10-12 02:57 - 2009-07-14 05:45 - 00530920 _____ () C:\Windows\system32\FNTCACHE.DAT
2017-10-12 02:32 - 2013-07-25 02:04 - 00000000 ____D () C:\Windows\system32\MRT
2017-10-12 02:16 - 2013-04-06 13:50 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-10-12 02:12 - 2013-09-18 11:19 - 01604370 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2017-10-12 02:04 - 2012-09-25 13:28 - 00000000 ____D () C:\ProgramData\Microsoft Help
2017-10-11 07:41 - 2014-01-08 12:21 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Roaming\Mozilla
2017-10-11 07:08 - 2013-01-21 10:05 - 00000000 ____D () C:\Users\Fam. Ade\Documents\Fußpflege
2017-10-06 19:11 - 2017-09-11 12:28 - 00015194 _____ () C:\Users\Fam. Ade\Documents\Wintertraining17-18.xlsx

==================== Files in the root of some directories =======

2013-01-03 14:56 - 2013-01-03 17:16 - 0000029 _____ () C:\Users\Fam. Ade\AppData\Roaming\default.rss
2013-01-03 17:15 - 2013-01-03 17:15 - 0000000 _____ () C:\Users\Fam. Ade\AppData\Roaming\downloads.m3u
2013-09-23 19:56 - 2013-09-23 19:56 - 0000059 _____ () C:\Users\Fam. Ade\AppData\Roaming\WB.CFG
2013-09-23 19:56 - 2013-09-23 19:56 - 0000005 _____ () C:\Users\Fam. Ade\AppData\Roaming\WBPU-TTL.DAT
2016-12-13 08:51 - 2017-03-22 12:36 - 0000552 _____ () C:\Users\Fam. Ade\AppData\Local\TroubleshooterConfig.json
2014-07-03 14:24 - 2014-07-03 14:24 - 0000057 _____ () C:\ProgramData\Ament.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2017-10-30 00:14

==================== End Of Log ============================
         
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2015 01
Ran by Fam. Ade at 2017-11-05 09:46:18
Running from C:\Users\Fam. Ade\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F}
AV: Norton 360 Online (Enabled - Up to date) {30744133-1E94-7B35-F4A3-82A5AEF1CBAA}
AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton 360 Online (Enabled - Up to date) {8B15A0D7-38AE-74BB-CE13-B9D7D5768117}
FW: Norton 360 Online (Enabled) {084FC016-54FB-7A6D-DFFC-2B9050228CD1}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version:  - )
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated)
Adobe Digital Editions 2.0 (HKLM-x32\...\Adobe Digital Editions 2.0) (Version: 2.0 - Adobe Systems Incorporated)
Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.183 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{53A19094-2C04-A9B9-7309-3E92152D4845}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
Any Video Converter 3.5.8 (HKLM-x32\...\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG)
Avira (HKLM-x32\...\{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}) (Version: 1.2.98.37213 - Avira Operations GmbH & Co. KG)
Avira (HKLM-x32\...\{f5da837f-e932-4f55-995c-7e97c5cbebdd}) (Version: 1.2.98.29730 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.2.98.37213 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.32.12 - Avira Operations GmbH & Co. KG)
BCL easyConverter 3.0 Licensing Module (BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 Loader SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 Module (Loader, BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 Module (RTF, BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 RTF SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden
Benutzerhandbuch ESDX5000_CX4900 (HKLM-x32\...\Benutzerhandbuch ESDX5000_CX4900) (Version:  - )
BlueStacks App Player (HKLM-x32\...\BlueStacks) (Version: 2.5.78.7302 - BlueStack Systems, Inc.)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6521 - CDBurnerXP)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DC Universe Online (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\SOE-DC Universe Online) (Version: 1.0.3.183 - Sony Online Entertainment)
DC Universe Online (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SOE-DC Universe Online) (Version: 1.0.3.183 - Sony Online Entertainment)
DC Universe Online Live (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\SOE-DC Universe Online Live PSG) (Version:  - Sony Online Entertainment)
DC Universe Online Live (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SOE-DC Universe Online Live PSG) (Version:  - Sony Online Entertainment)
DC Universe Online PSG (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\soe-DC Universe Online PSG) (Version: 1.0.3.183 - Sony Online Entertainment)
DC Universe Online PSG (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\soe-DC Universe Online PSG) (Version: 1.0.3.183 - Sony Online Entertainment)
DEUTSCHLAND SPIELT GAME CENTER (HKLM-x32\...\DSGPlayer) (Version: 1.0.0.46 - INTENIUM GmbH)
Die Siedler 7 (HKLM-x32\...\{63860309-DA8A-4BAE-9EAE-CE1D6D79340C}) (Version: 1.12.1396 - Ubisoft)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.22 - DivX, LLC)
DMG Extractor (HKLM-x32\...\DMGExtractor) (Version: 1.1.1.1 - Reincubate Ltd)
doPDF 7.3 printer (HKLM\...\doPDF 7 printer_is1) (Version:  - Softland)
Dropbox (HKLM-x32\...\Dropbox) (Version: 38.4.27 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - )
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{6C5F8503-55D2-4398-858C-362B7A7AF51C}) (Version: 2.1.31.0 - MAGIX AG)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Free Easy Burner V 5.1 (HKLM-x32\...\Free Easy Burner_is1) (Version: 5.1.0.0 - Koyote soft)
Free MP4 Video Converter (HKLM-x32\...\Free MP4 Video Converter_is1) (Version: 5.0.102.1027 - Digital Wave Ltd)
Freemium Free PDF Perfect (HKLM-x32\...\{88265079-D6F4-4292-86BE-D2053E80BFE4}) (Version: 1.0 - Freemium)
GameMaker-Studio 1.2 (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\GameMaker-Studio12) (Version:  - YoYo Games Ltd.)
GameMaker-Studio 1.2 (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\GameMaker-Studio12) (Version:  - YoYo Games Ltd.)
Goat Simulator (HKLM-x32\...\Steam App 265930) (Version:  - Coffee Stain Studios)
Google Chrome (HKU\SCANNERMAP\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
Green City: Die Stadt deiner Träume (HKLM-x32\...\Green City: Die Stadt deiner Träume) (Version: 1.0.0.0 - INTENIUM GmbH)
HP Officejet 6700 Basic Device Software (HKLM\...\{A1CFA587-90D4-4DE6-B200-68CC0F92252F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HPDiagnosticCoreDll (HKLM-x32\...\{9262B08F-E183-4FED-A2BD-23FF1A84EB79}) (Version: 1.0.15.0 - Hewlett Packard)
Image Converter (HKLM-x32\...\Image Converter Image Converter) (Version: 1.0.0 - Image Converter)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
James Cameron's AVATAR(tm): DAS SPIEL (HKLM-x32\...\{7E19B002-4CA3-4C9F-BA92-91D101B97219}) (Version: 1.02.00 - Ubisoft)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Lawn & Order: Die Gartenprofis (HKLM-x32\...\Lawn & Order: Die Gartenprofis) (Version: 1.0.0.0 - INTENIUM GmbH)
Magic Life (HKLM-x32\...\Magic Life) (Version: 1.0.0.0 - INTENIUM GmbH)
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{5900B465-32E8-48DA-AC09-21B8363F7A41}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video deluxe 2013 (HKLM-x32\...\MAGIX_{8C73E551-5AFA-42EE-B76E-64821590BCD3}) (Version: 12.0.0.32 - MAGIX AG)
MAGIX Video deluxe 2013 (Version: 12.0.0.32 - MAGIX AG) Hidden
Malkreuz (x32 Version: 1.00.0000 - Medienwerkstatt Mühlacker Verlagsgesellschaft mbH) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mein CEWE FOTOBUCH (HKLM-x32\...\Mein CEWE FOTOBUCH) (Version: 5.1.6 - CEWE Stiftung u Co. KGaA)
Microsoft .NET Framework 4.7 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Moai: Erschaffe deinen Traum (HKLM-x32\...\Moai: Erschaffe deinen Traum) (Version: 1.0.0.0 - INTENIUM GmbH)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 56.0.2 (x64 de) (HKLM\...\Mozilla Firefox 56.0.2 (x64 de)) (Version: 56.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Nero 12 (HKLM-x32\...\{95E152CF-0EB5-4BFA-B6EE-8FC7F9601BA5}) (Version: 12.0.02900 - Nero AG)
Norton 360 Online (HKLM-x32\...\N360) (Version: 22.11.0.41 - Symantec Corporation)
PDF2Word Converter Version 1.0.8 (Build 164, 7-PDF) (HKLM-x32\...\PDF2Word Converter (7-PDF)_is1) (Version: PDF2Word Converter - Version 1.0.8 (Build 164) - 7-PDF, Germany - Thorsten Hodes)
PIF DESIGNER (HKLM-x32\...\{B90450DF-E781-46FD-B1F1-0C86DA40E443}) (Version:  - )
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version:  - )
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15013.18 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.3.15013.18 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
Sandboxie 4.02 (64-bit) (HKLM\...\Sandboxie) (Version: 4.02 - Sandboxie Holdings, LLC)
Search-Results Toolbar (HKLM-x32\...\koyotesofttoolbarnew) (Version: 1.0.0.12 - APN LLC) <==== ATTENTION
Stadt der Narren (HKLM-x32\...\Stadt der Narren) (Version: 1.0.0.0 - INTENIUM GmbH)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Taxpool-Buchhalter Mini 6.24 (HKLM-x32\...\Taxpool-Buchhalter Mini) (Version: 6.24 - psynetic® Software)
TomTom MyDrive Connect 4.1.4.3089 (HKLM-x32\...\MyDriveConnect) (Version: 4.1.4.3089 - TomTom)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
VLC media player 2.0.5 (HKLM-x32\...\VLC media player) (Version: 2.0.5 - VideoLAN)
Vokabeltrainer für Windows Version 1.51 (HKLM-x32\...\Vokabeltrainer für Windows_is1) (Version:  - diginvent)
Welcome App (Start-up experience) (x32 Version: 12.0.15000 - Nero AG) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip 20.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EF}) (Version: 20.0.11659 - WinZip Computing, S.L. )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

19-10-2017 08:15:47 Geplanter Prüfpunkt
26-10-2017 23:00:01 Geplanter Prüfpunkt
03-11-2017 00:00:03 Geplanter Prüfpunkt

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2014-05-02 10:11 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0A4539CC-5316-4A61-A8D8-4293850F15AB} - \ProtectedSearch\Protected Search No Task File <==== ATTENTION
Task: {38B020D1-357C-46F5-BE86-B4F07C855C6A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-25] (Adobe Systems Incorporated)
Task: {3DD9AF00-814A-442E-BFB1-DC652AFA045E} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton 360 Online\Upgrade.exe [2017-10-04] (Symantec Corporation)
Task: {4F387278-2353-45BD-9D8A-4FF1C5E179E9} - System32\Tasks\HP AR Program Upload - 2def856e98fd42c0af2ab35d45102a3a0e33f155164447319ccbababe29426c0 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {5549F126-D485-4FEC-9719-9A267731B31F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-08] (Google Inc.)
Task: {707B181D-A35C-47F7-A039-9AE8C7AE9045} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-08] (Google Inc.)
Task: {718F6CAB-BBCC-4B69-83C6-7C640482C103} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => C:\Windows\system32\compattelrunner.exe [2017-05-03] (Microsoft Corporation)
Task: {76C4BED5-8938-498E-8B9C-DF91AC9CC146} - System32\Tasks\Norton 360\Norton 360 Online Error Processor => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\SymErr.exe [2017-10-04] (Symantec Corporation)
Task: {78298D72-8D94-4D21-8547-B8E7F33AE507} - \Browser Updater\Browser Updater No Task File <==== ATTENTION
Task: {81F538A1-8928-4F07-AADA-B1F413A22C5B} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {829625F8-5F95-4644-AF85-07F67B1BA23B} - System32\Tasks\{616C99AF-BEAA-4FB4-B382-A2B20D86BF98} => pcalua.exe -a "C:\Users\Fam. Ade\Downloads\epson30027eu.exe" -d "C:\Users\Fam. Ade\Desktop"
Task: {86915168-38FE-4D52-8A11-943B62A978C1} - System32\Tasks\HP AR Program Upload - 6b89bd66a6e048649e04dc31f8a1706355a107ddc5e946ea96303cd76419b11a => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {A8F4716A-C403-4172-8143-1C37E871A9A1} - System32\Tasks\HP AR Program Upload - b5c01ba5ad9742f4a0f74f1e55da5e26a18df2df1c71450ba082ef8703b8a046 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {AC41F180-9E7F-4FF9-A73E-8679FD382213} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\WSCStub.exe [2017-10-04] (Symantec Corporation)
Task: {ACB42A5E-DD1D-4A78-A33D-B8D97BF29E44} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {B04ADAFE-C2D3-4B5E-92E6-282F4E5D2466} - System32\Tasks\Avira SystrayStartTrigger => Avira.SystrayStartTrigger.exe
Task: {CD4E143F-DF5F-425A-AD44-2B5FB4A8B8F7} - System32\Tasks\HP AR Program Upload - e330d555d2874ebabc0a30c862a2da613d4700ba94ea4d58b3ea0a32d8279410 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {DA6FBD2A-306D-4AFB-B613-EC241A16AAC3} - System32\Tasks\HP AR Program Upload - 1d8f182b717540109e3b0ba996d8e3a5ddca8dc77dbe40168d810be1d221880c => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {DB4BFC02-368F-42E8-A891-583B1A4B7666} - System32\Tasks\Norton 360\Norton 360 Online Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\22.11.0.41\SymErr.exe [2017-10-04] (Symantec Corporation)
Task: {E74A986E-6F94-49FE-A756-29239914FF0B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {E788F862-969C-49EA-8C62-4A862DF892BF} - System32\Tasks\{96513A81-C24F-4D2B-B615-9465B77B3F3E} => pcalua.exe -a "C:\Program Files (x86)\Common Files\Freemium\Uninstall\{88265079-D6F4-4292-86BE-D2053E80BFE4}.exe" -c /X{88265079-D6F4-4292-86BE-D2053E80BFE4}
Task: {EC16D64F-AB1A-4596-9D67-D3175F7EF657} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-11-16] (Microsoft Corporation)
Task: {ED78580D-DCE2-4EE7-8B0C-05F674DE4621} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {F08F917F-B88F-40C8-B27B-0AA46D8F0B91} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {FA8C6F5A-DDF6-4572-9A22-F2B113B8607A} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2017-10-14] (Avira Operations GmbH & Co. KG)
Task: {FB495BFB-94A9-45B1-B537-46D21553FE01} - System32\Tasks\{F05BE82B-0D12-4C43-9B39-6F8C0F9D86D0} => pcalua.exe -a "C:\Users\Fam. Ade\Desktop\Setup.exe" -d "C:\Users\Fam. Ade\Desktop"
Task: {FB98B0F5-C9FE-4ACA-8476-9DFC13597F8C} - System32\Tasks\{1409713F-E48C-431F-96D2-68F676C4E085} => pcalua.exe -a "C:\Users\Fam. Ade\Downloads\mmskasse.exe" -d "C:\Users\Fam. Ade\Downloads"
Task: {FFE725A4-F749-49E7-AFF3-25B7A3B47FC2} - System32\Tasks\HP AR Program Upload - 7dca521ae57b484ea823d2e9c7cbe31f29d3c42b6c9e458097c61fd4bf5ad836 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core.job => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA.job => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2013-09-18 11:23 - 2010-06-17 19:56 - 00087040 _____ () C:\Windows\System32\redmonnt.dll
2012-11-30 03:06 - 2012-11-30 03:06 - 01263512 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2012-12-19 15:32 - 2012-12-19 15:32 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2012-11-30 03:07 - 2012-11-30 03:07 - 00100248 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2009-02-26 12:46 - 2009-02-26 12:46 - 00064344 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll
2011-06-22 10:46 - 2011-06-22 10:46 - 00434016 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll
2015-11-11 03:41 - 2015-11-11 03:41 - 00756376 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SecureAssist => ""="service"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-356143711-355811113-2582273239-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Fam. Ade\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Fam. Ade\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\s-1-5-21-356143711-355811113-2582273239-1007\Control Panel\Desktop\\Wallpaper -> C:\Users\Ginua\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-356143711-355811113-2582273239-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Ginua\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\SCANNERMAP\Control Panel\Desktop\\Wallpaper -> C:\Users\Shari\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-356143711-355811113-2582273239-500 - Administrator - Disabled)
Fam. Ade (S-1-5-21-356143711-355811113-2582273239-1001 - Administrator - Enabled) => C:\Users\Fam. Ade
Gast (S-1-5-21-356143711-355811113-2582273239-501 - Limited - Disabled)
Ginua (S-1-5-21-356143711-355811113-2582273239-1007 - Limited - Enabled) => C:\Users\Ginua
HomeGroupUser$ (S-1-5-21-356143711-355811113-2582273239-1002 - Limited - Enabled)
Shari (S-1-5-21-356143711-355811113-2582273239-1008 - Limited - Enabled) => C:\Users\Shari

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/05/2017 09:42:35 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/05/2017 04:10:06 AM) (Source: SideBySide) (EventID: 9) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Das Stammelement der Manifestdatei muss assembliert sein.

Error: (11/05/2017 04:09:57 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/05/2017 04:09:47 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1".
Die abhängige Assemblierung "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/04/2017 04:28:58 AM) (Source: SideBySide) (EventID: 9) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Das Stammelement der Manifestdatei muss assembliert sein.

Error: (11/04/2017 04:28:49 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/04/2017 04:28:38 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1".
Die abhängige Assemblierung "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/03/2017 04:32:21 AM) (Source: SideBySide) (EventID: 9) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Das Stammelement der Manifestdatei muss assembliert sein.

Error: (11/03/2017 04:32:12 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/03/2017 04:32:02 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1".
Die abhängige Assemblierung "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".


System errors:
=============
Error: (10/29/2017 09:44:21 AM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung empfangen: 20.

Error: (10/13/2017 06:34:30 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (10/13/2017 06:33:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Live Family Safety Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (10/13/2017 06:33:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Live Family Safety Service erreicht.

Error: (10/13/2017 06:33:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Digital Wave Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (10/13/2017 06:33:02 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Digital Wave Update Service erreicht.

Error: (10/12/2017 00:17:05 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1096) (User: FamAde-PC)
Description: Fehler bei der Verarbeitung der Gruppenrichtlinie. Es wurde versucht, registrierungsbasierte Richtlinieneinstellungen für das Gruppenrichtlinienobjekt "LocalGPO" zu lesen. Die Gruppenrichtlinieneinstellungen dürfen nicht erzwungen werden, bis dieses Ereignis behoben ist. Weitere Informationen über den Dateinamen und -pfad, der den Fehler verursacht hat, können den Ereignisdetails entnommen werden.

Error: (10/12/2017 02:59:17 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (10/12/2017 02:50:25 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.

Error: (10/06/2017 07:27:20 AM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung empfangen: 20.


Microsoft Office Sessions:
=========================
Error: (10/30/2017 11:40:40 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6776.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 91167 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (09/21/2017 07:28:21 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6776.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 65740 seconds with 480 seconds of active time.  This session ended with a crash.

Error: (08/14/2017 02:35:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6774.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 113 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (02/25/2017 01:38:24 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6762.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 350330 seconds with 600 seconds of active time.  This session ended with a crash.

Error: (01/05/2017 00:14:09 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6762.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 173666 seconds with 1740 seconds of active time.  This session ended with a crash.

Error: (12/13/2016 00:16:07 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6759.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2708 seconds with 540 seconds of active time.  This session ended with a crash.

Error: (11/04/2016 01:28:16 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6755.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1512 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (10/04/2016 05:51:15 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6755.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 41009 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (09/30/2016 10:38:24 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6755.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 73493 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (09/10/2016 02:42:57 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6750.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 273 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2014-05-02 11:10:37.809
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-05-02 11:10:37.310
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info =========================== 

Processor: AMD Athlon(tm) II X4 620 Processor
Percentage of memory in use: 63%
Total physical RAM: 4094.16 MB
Available physical RAM: 1487.49 MB
Total Pagefile: 8186.51 MB
Available Pagefile: 4522.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:288.71 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: EF017F90)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
Ich sag schon mal danke für Eure Hilfe.

LG
Ani

Alt 05.11.2017, 11:51   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Amazon Zip - Standard

Amazon Zip



Bitte Avira deinstallieren. Wir deinstallieren dann am besten auch gleich weiteren unnötigen oder veralteten Krempel.

Avira empfehlen wir schon seit Jahren aus mehreren Gründen nicht mehr. Ein Grund ist ne rel. hohe Fehlalarmquote, der zweite Hauptgrund ist, dass die immer noch mit ASK zusammenarbeiten (Avira Suchfunktion geht über ASK). Auch andere Freewareanbieter wie AVG, Avast oder Panda sprangen auf diesen Zug auf; so was ist bei Sicherheitssoftware einfach inakzeptabel. Vgl. Antivirensoftware: Schutz Für Ihre Dateien, Aber Auf Kosten Ihrer Privatsphäre? | Emsisoft Blog



Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:


    7-Zip 9.20

    Adobe Acrobat Reader DC - Deutsch

    Adobe Digital Editions 2.0

    Ashampoo Burning Studio FREE v.1.14.5

    Avira

    Avira Antivirus

    DivX-Setup

    Java 7 Update 51

    Nero 12

    Norton 360 Online

    VLC media player 2.0.5

    WinZip 20.0


  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 





Gib Bescheid wenn Avira weg ist; wenn wir hier durch sind, kannst du auf einen anderen Virenscanner umsteigen, Infos folgen dann im Abschlussposting. Bitte JETZT nix mehr ohne Absprache installieren!
__________________

__________________

Alt 05.11.2017, 13:42   #3
Ani73
 
Amazon Zip - Standard

Amazon Zip



so hab jetzt alle Programme mit Revo gelöscht. Hoffe auch alles richtig gemacht zu haben.

Avira ist auch weg.
Den Norton den ich drauf hatte, ist von der Telekom.

Grüße
Ani
__________________

Alt 05.11.2017, 13:58   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Amazon Zip - Standard

Amazon Zip



Ich brauche neue FRST-Logs . Haken setzen bei addition.txt dann auf Untersuchen klicken.

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 05.11.2017, 18:30   #5
Ani73
 
Amazon Zip - Standard

Amazon Zip



Hier die neuen FRST


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2015 01 (ATTENTION: ====> FRST version is 991 days old and could be outdated)
Ran by Fam. Ade (administrator) on FAMADE-PC on 05-11-2017 17:15:19
Running from C:\Users\Fam. Ade\Desktop
Loaded Profiles: Fam. Ade & Ginua (Available profiles: Fam. Ade & Ginua & Shari)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-Agent.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_27_0_0_183_ActiveX.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [fssui] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263512 2012-11-30] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2015-01-14] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-11-01] (Dropbox, Inc.)
HKLM-x32\...\RunOnce: [{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}] => C:\ProgramData\Package Cache\{bd94e862-c44b-4f68-98ca-b35ddf9dbbfc}\Avira.OE.Setup.Bundle.exe [1288968 2017-11-01] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759384 2013-06-17] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3011152 2015-11-10] (Valve Corporation)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [1690248 2016-12-01] (BlueStack Systems, Inc.)
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\RunOnce: [JavaInstallRetry] => RUNONCE=1 SPONSORS=0
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759384 2013-06-17] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3011152 2015-11-10] (Valve Corporation)
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [1690248 2016-12-01] (BlueStack Systems, Inc.)
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation)
HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\Policies\system: [LogonHoursAction] 2
HKU\s-1-5-21-356143711-355811113-2582273239-1007\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\SCANNERMAP\...\Run: [Google Update] => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-05-08] (Google Inc.)
HKU\SCANNERMAP\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [892416 2012-09-12] (Microsoft Corporation)
HKU\SCANNERMAP\...\Policies\system: [LogonHoursAction] 2
HKU\SCANNERMAP\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll (Dropbox, Inc.)
GroupPolicyUsers\S-1-5-21-356143711-355811113-2582273239-1008\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-356143711-355811113-2582273239-1007\User: Group Policy restriction detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-356143711-355811113-2582273239-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-356143711-355811113-2582273239-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\SCANNERMAP\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> DefaultScope {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {4E70BA39-0667-4718-AAC1-B91BC7DCB15C} URL = https://www.google.com/search?q={searchTerms}
BHO: No Name -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} ->  No File
BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} ->  No File
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: No Name -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} ->  No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} -  No File
Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} -  No File
Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} -  No File
Toolbar: HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} 
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=1.6.0_35 -> C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @soft-xpansion/npsxpdf -> C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Fam. Ade\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Fam. Ade\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin HKU\SCANNERMAP: @tools.google.com/Google Update;version=3 -> C:\Users\Shari\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\SCANNERMAP: @tools.google.com/Google Update;version=9 -> C:\Users\Shari\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Search Shield Study - C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default\Extensions\@unified-urlbar-shield-study-opt-out-new-users.xpi [2017-10-11]
FF Extension: Safe Browsing Version 4 (temporary add-on) - C:\Users\Fam. Ade\AppData\Roaming\Mozilla\Firefox\Profiles\eubjp8nl.default\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-11]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-02-14]
FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF HKLM-x32\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
StartMenuInternet: Firefox-308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe

Chrome: 
=======
CHR Profile: C:\Users\Fam. Ade\AppData\Local\Google\Chrome\User Data\default
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-02-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) [File not signed]
S3 becldr3Service; C:\Program Files (x86)\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [176128 2011-04-19] () [File not signed]
S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [486936 2016-12-01] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [470552 2016-12-01] (BlueStack Systems, Inc.)
S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [511512 2016-12-01] (BlueStack Systems, Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51016 2017-11-01] (Dropbox, Inc.)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1386496 2016-08-22] (Microsoft Corporation)
S2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [437224 2016-10-27] (Digital Wave Ltd.)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [180824 2013-06-17] (Sandboxie Holdings, LLC)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-09-18] (soft Xpansion)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 Avira.ServiceHost; "C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2012-10-01] ()
R4 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-03-02] (Avira Operations GmbH & Co. KG)
S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-12-01] (BlueStack Systems)
S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-11-08] (Bluestack System Inc. )
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2012-10-01] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-11-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [198360 2013-06-17] (Sandboxie Holdings, LLC)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [151184 2016-03-10] (MBB)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
R4 ccSet_N360; \SystemRoot\system32\drivers\N360x64\160B000.029\ccSetx64.sys [X]
S3 dbx; system32\DRIVERS\dbx.sys [X]
R4 IDSVia64; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\IPSDefs\20171103.001\IDSvia64.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\SDSDefs\20160713.008\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.2.15\Definitions\SDSDefs\20160713.008\EX64.SYS [X]
R4 SRTSPX; \SystemRoot\system32\drivers\N360x64\160B000.029\SRTSPX64.SYS [X]
R4 SymEFASI; system32\drivers\N360x64\160B000.029\SYMEFASI64.SYS [X]
R4 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2017-11-05 12:50 - 2017-11-05 12:50 - 00001034 _____ () C:\Users\Public\Desktop\Revo Uninstaller.lnk
2017-11-05 12:50 - 2017-11-05 12:50 - 00000000 ____D () C:\Program Files\VS Revo Group
2017-11-05 09:46 - 2017-11-05 09:48 - 00041679 _____ () C:\Users\Fam. Ade\Desktop\Addition.txt
2017-11-05 09:44 - 2017-11-05 17:15 - 00025572 _____ () C:\Users\Fam. Ade\Desktop\FRST.txt
2017-11-04 14:13 - 2017-11-05 13:30 - 00000000 ____D () C:\Windows\System32\Tasks\Remediation
2017-11-02 18:56 - 2017-11-02 18:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-11-01 12:58 - 2017-11-01 12:58 - 00051016 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-11-01 12:58 - 2017-11-01 12:58 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2017-11-01 12:58 - 2017-11-01 12:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2017-11-01 12:58 - 2017-11-01 12:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2017-10-25 11:42 - 2017-10-25 11:42 - 05250048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2017-10-12 12:17 - 2017-10-13 06:30 - 00000000 ____D () C:\Users\TEMP.FamAde-PC.001
2017-10-12 02:16 - 2017-10-12 02:16 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-10-11 11:46 - 2017-09-13 16:33 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-10-11 11:46 - 2017-09-13 16:32 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-10-11 11:46 - 2017-09-13 16:32 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-10-11 11:46 - 2017-09-13 16:32 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-10-11 11:46 - 2017-09-13 16:32 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-10-11 11:46 - 2017-09-13 16:31 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-10-11 11:46 - 2017-09-13 16:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:13 - 04001512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-10-11 11:46 - 2017-09-13 16:13 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-10-11 11:46 - 2017-09-13 16:10 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-10-11 11:46 - 2017-09-13 16:09 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 16:05 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2017-10-11 11:46 - 2017-09-13 16:00 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-10-11 11:46 - 2017-09-13 16:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-10-11 11:46 - 2017-09-13 16:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-10-11 11:46 - 2017-09-13 16:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-10-11 11:46 - 2017-09-13 15:57 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-10-11 11:46 - 2017-09-13 15:56 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-10-11 11:46 - 2017-09-13 15:53 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-10-11 11:46 - 2017-09-13 15:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-10-11 11:46 - 2017-09-13 15:53 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-10-11 11:46 - 2017-09-13 15:52 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-10-11 11:46 - 2017-09-13 15:52 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-10-11 11:46 - 2017-09-13 15:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-10-11 11:46 - 2017-09-13 15:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-10-11 11:46 - 2017-09-13 15:46 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-10-11 11:46 - 2017-09-13 15:46 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-10-11 11:46 - 2017-09-13 15:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-10-11 11:46 - 2017-09-09 01:45 - 00395984 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-10-11 11:46 - 2017-09-09 00:47 - 00347344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-10-11 11:46 - 2017-09-08 16:34 - 01680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-10-11 11:46 - 2017-09-08 16:30 - 02319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 02058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-10-11 11:46 - 2017-09-08 16:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-10-11 11:46 - 2017-09-08 16:14 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-10-11 11:46 - 2017-09-08 16:13 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-10-11 11:46 - 2017-09-08 16:13 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-10-11 11:46 - 2017-09-08 16:10 - 01549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-10-11 11:46 - 2017-09-08 16:10 - 01363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-10-11 11:46 - 2017-09-08 16:10 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-10-11 11:46 - 2017-09-08 16:10 - 00109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-10-11 11:46 - 2017-09-08 16:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-10-11 11:46 - 2017-09-08 16:00 - 03222016 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-10-11 11:46 - 2017-09-08 16:00 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-10-11 11:46 - 2017-09-08 16:00 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-10-11 11:46 - 2017-09-08 15:59 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-10-11 11:46 - 2017-09-08 15:59 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-10-11 11:46 - 2017-09-08 15:20 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-10-11 11:46 - 2017-09-08 15:20 - 00345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-10-11 11:46 - 2017-09-08 15:20 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-10-11 11:46 - 2017-09-07 22:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-10-11 11:46 - 2017-09-07 22:37 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-10-11 11:46 - 2017-09-07 22:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-10-11 11:46 - 2017-09-07 22:18 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-10-11 11:46 - 2017-09-07 22:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-10-11 11:46 - 2017-09-07 22:17 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-10-11 11:46 - 2017-09-07 22:17 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-10-11 11:46 - 2017-09-07 22:15 - 02902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-10-11 11:46 - 2017-09-07 22:08 - 25729536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-10-11 11:46 - 2017-09-07 22:08 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-10-11 11:46 - 2017-09-07 22:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-10-11 11:46 - 2017-09-07 22:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-10-11 11:46 - 2017-09-07 22:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-10-11 11:46 - 2017-09-07 22:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-10-11 11:46 - 2017-09-07 22:01 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-10-11 11:46 - 2017-09-07 22:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-10-11 11:46 - 2017-09-07 21:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-10-11 11:46 - 2017-09-07 21:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-10-11 11:46 - 2017-09-07 21:40 - 05982208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-10-11 11:46 - 2017-09-07 21:39 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-10-11 11:46 - 2017-09-07 21:38 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-10-11 11:46 - 2017-09-07 21:37 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-10-11 11:46 - 2017-09-07 21:33 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-10-11 11:46 - 2017-09-07 21:32 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-10-11 11:46 - 2017-09-07 21:29 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-10-11 11:46 - 2017-09-07 21:27 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-10-11 11:46 - 2017-09-07 21:13 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-10-11 11:46 - 2017-09-07 21:10 - 00807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-10-11 11:46 - 2017-09-07 21:10 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-10-11 11:46 - 2017-09-07 21:08 - 02134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-10-11 11:46 - 2017-09-07 21:08 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-10-11 11:46 - 2017-09-07 20:44 - 15262720 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-10-11 11:46 - 2017-09-07 20:40 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-10-11 11:46 - 2017-09-07 20:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-10-11 11:46 - 2017-09-07 20:27 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-10-11 11:46 - 2017-09-07 20:17 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-10-11 11:46 - 2017-09-07 20:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-10-11 11:46 - 2017-09-07 20:10 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-10-11 11:46 - 2017-09-07 20:10 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-10-11 11:46 - 2017-09-07 20:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-10-11 11:46 - 2017-09-07 20:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-10-11 11:46 - 2017-09-07 20:04 - 20267008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-10-11 11:46 - 2017-09-07 20:03 - 02292736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-10-11 11:46 - 2017-09-07 20:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-10-11 11:46 - 2017-09-07 20:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-10-11 11:46 - 2017-09-07 19:59 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-10-11 11:46 - 2017-09-07 19:58 - 00663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-10-11 11:46 - 2017-09-07 19:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-10-11 11:46 - 2017-09-07 19:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-10-11 11:46 - 2017-09-07 19:49 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-10-11 11:46 - 2017-09-07 19:44 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-10-11 11:46 - 2017-09-07 19:44 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-10-11 11:46 - 2017-09-07 19:43 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-10-11 11:46 - 2017-09-07 19:40 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-10-11 11:46 - 2017-09-07 19:39 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-10-11 11:46 - 2017-09-07 19:37 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-10-11 11:46 - 2017-09-07 19:36 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-10-11 11:46 - 2017-09-07 19:29 - 04547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-10-11 11:46 - 2017-09-07 19:29 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-10-11 11:46 - 2017-09-07 19:26 - 00694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-10-11 11:46 - 2017-09-07 19:25 - 02058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-10-11 11:46 - 2017-09-07 19:25 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-10-11 11:46 - 2017-09-07 19:17 - 13677568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-10-11 11:46 - 2017-09-07 19:01 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-10-11 11:46 - 2017-09-07 18:57 - 01316864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-10-11 11:46 - 2017-09-07 18:57 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-10-11 11:46 - 2017-09-07 16:31 - 02851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2017-10-11 11:46 - 2017-09-07 16:12 - 02755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2017-10-11 11:46 - 2017-09-07 15:55 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-10-11 11:46 - 2017-09-07 15:55 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-10-11 11:46 - 2017-09-07 15:55 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-10-11 11:46 - 2017-08-19 16:28 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-10-11 11:46 - 2017-08-19 16:28 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-10-11 11:46 - 2017-08-19 16:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2017-10-11 11:46 - 2017-08-19 16:10 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2017-10-11 11:46 - 2017-08-19 16:10 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2017-10-11 11:46 - 2017-08-19 16:10 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2017-10-11 11:46 - 2017-08-19 16:08 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2017-10-11 11:46 - 2017-08-19 16:08 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2017-10-11 11:46 - 2017-08-19 15:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2017-10-11 11:46 - 2017-08-19 15:57 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2017-10-11 11:46 - 2017-08-14 18:35 - 01032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-10-11 11:46 - 2017-08-14 18:35 - 00827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-10-11 11:46 - 2017-08-14 18:35 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2017-10-11 11:46 - 2017-08-13 22:45 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2017-10-11 07:41 - 2017-10-11 07:46 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Local\Mozilla
2017-10-11 07:40 - 2017-11-02 08:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2017-10-11 07:40 - 2017-11-02 08:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2017-10-11 07:40 - 2017-10-11 07:40 - 00000936 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-10-11 07:40 - 2017-10-11 07:40 - 00000924 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-10-11 07:37 - 2017-10-11 07:37 - 00245912 _____ (Mozilla) C:\Users\Fam. Ade\Downloads\Firefox Installer.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2017-11-05 17:15 - 2014-04-30 11:01 - 00000000 ____D () C:\FRST
2017-11-05 17:08 - 2014-05-21 19:03 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA.job
2017-11-05 16:22 - 2015-06-02 12:53 - 00001218 _____ () C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-11-05 13:38 - 2014-05-23 19:19 - 00000000 ____D () C:\Program Files (x86)\Steam
2017-11-05 13:31 - 2015-03-03 14:28 - 00000000 ____D () C:\ProgramData\Norton
2017-11-05 13:30 - 2015-03-03 14:28 - 00000000 ____D () C:\Program Files (x86)\Norton 360
2017-11-05 13:13 - 2014-03-22 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-11-05 13:08 - 2013-02-14 21:13 - 00000000 ____D () C:\ProgramData\DivX
2017-11-05 13:07 - 2013-03-06 13:07 - 00000000 ____D () C:\Program Files (x86)\Avira
2017-11-05 12:58 - 2013-06-06 13:06 - 00000000 ____D () C:\Users\Fam. Ade\Documents\My Digital Editions
2017-11-05 09:25 - 2014-05-04 19:58 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-11-05 09:13 - 2012-09-24 16:26 - 01489376 _____ () C:\Windows\WindowsUpdate.log
2017-11-05 04:22 - 2015-06-02 12:53 - 00001214 _____ () C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-11-05 04:18 - 2009-07-14 05:45 - 00023344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-11-05 04:18 - 2009-07-14 05:45 - 00023344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-11-04 23:18 - 2016-12-13 08:43 - 00000000 ____D () C:\Program Files (x86)\Bluestacks
2017-11-04 20:08 - 2014-05-21 19:03 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core.job
2017-11-04 12:23 - 2014-10-12 20:18 - 00000000 ____D () C:\Users\Fam. Ade\Documents\Tennis Damen
2017-11-02 18:56 - 2015-06-02 12:53 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2017-11-01 11:34 - 2017-09-24 11:26 - 00003122 _____ () C:\Windows\System32\Tasks\Avira SystrayStartTrigger
2017-11-01 11:33 - 2015-01-21 19:58 - 00000000 ____D () C:\ProgramData\Package Cache
2017-10-30 11:38 - 2015-04-26 14:09 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Local\CrashDumps
2017-10-25 11:43 - 2013-03-06 13:08 - 00004366 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-10-25 11:43 - 2012-09-24 16:42 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-10-25 11:43 - 2012-09-24 16:42 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-10-25 11:43 - 2012-09-24 16:42 - 00000000 ____D () C:\Windows\system32\Macromed
2017-10-25 11:42 - 2012-09-24 16:42 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2017-10-13 06:32 - 2013-04-13 14:13 - 00001618 _____ () C:\Windows\Sandboxie.ini
2017-10-13 06:32 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2017-10-13 06:32 - 2009-07-14 05:51 - 00081321 _____ () C:\Windows\setupact.log
2017-10-13 06:31 - 2012-09-24 17:15 - 01196614 _____ () C:\Windows\PFRO.log
2017-10-12 05:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2017-10-12 04:17 - 2015-06-11 02:52 - 00000000 ____D () C:\Program Files\Common Files\AV
2017-10-12 03:05 - 2009-07-14 18:58 - 00703308 _____ () C:\Windows\system32\perfh007.dat
2017-10-12 03:05 - 2009-07-14 18:58 - 00151134 _____ () C:\Windows\system32\perfc007.dat
2017-10-12 03:05 - 2009-07-14 06:13 - 01629508 _____ () C:\Windows\system32\PerfStringBackup.INI
2017-10-12 02:59 - 2015-03-03 14:28 - 00000000 ____D () C:\Windows\system32\Drivers\N360x64
2017-10-12 02:57 - 2009-07-14 05:45 - 00530920 _____ () C:\Windows\system32\FNTCACHE.DAT
2017-10-12 02:32 - 2013-07-25 02:04 - 00000000 ____D () C:\Windows\system32\MRT
2017-10-12 02:16 - 2013-04-06 13:50 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-10-12 02:12 - 2013-09-18 11:19 - 01604370 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2017-10-12 02:04 - 2012-09-25 13:28 - 00000000 ____D () C:\ProgramData\Microsoft Help
2017-10-11 07:41 - 2014-01-08 12:21 - 00000000 ____D () C:\Users\Fam. Ade\AppData\Roaming\Mozilla
2017-10-11 07:08 - 2013-01-21 10:05 - 00000000 ____D () C:\Users\Fam. Ade\Documents\Fußpflege
2017-10-06 19:11 - 2017-09-11 12:28 - 00015194 _____ () C:\Users\Fam. Ade\Documents\Wintertraining17-18.xlsx

==================== Files in the root of some directories =======

2013-01-03 14:56 - 2013-01-03 17:16 - 0000029 _____ () C:\Users\Fam. Ade\AppData\Roaming\default.rss
2013-01-03 17:15 - 2013-01-03 17:15 - 0000000 _____ () C:\Users\Fam. Ade\AppData\Roaming\downloads.m3u
2013-09-23 19:56 - 2013-09-23 19:56 - 0000059 _____ () C:\Users\Fam. Ade\AppData\Roaming\WB.CFG
2013-09-23 19:56 - 2013-09-23 19:56 - 0000005 _____ () C:\Users\Fam. Ade\AppData\Roaming\WBPU-TTL.DAT
2016-12-13 08:51 - 2017-03-22 12:36 - 0000552 _____ () C:\Users\Fam. Ade\AppData\Local\TroubleshooterConfig.json
2014-07-03 14:24 - 2014-07-03 14:24 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Fam. Ade\AppData\Local\Temp\SEVINST64x86.EXE
C:\Users\Fam. Ade\AppData\Local\Temp\VSUSetup.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2017-10-30 00:14

==================== End Of Log ============================
         
--- --- ---



Code:
ATTFilter
Additional
FRST Logfile:
Code:
ATTFilter
scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2015 01
Ran by Fam. Ade at 2017-11-05 17:16:41
Running from C:\Users\Fam. Ade\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.183 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{53A19094-2C04-A9B9-7309-3E92152D4845}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
Any Video Converter 3.5.8 (HKLM-x32\...\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
BCL easyConverter 3.0 Licensing Module (BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 Loader SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 Module (Loader, BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 Module (RTF, BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 RTF SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden
BCL easyConverter 3.0 SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden
Benutzerhandbuch ESDX5000_CX4900 (HKLM-x32\...\Benutzerhandbuch ESDX5000_CX4900) (Version:  - )
BlueStacks App Player (HKLM-x32\...\BlueStacks) (Version: 2.5.78.7302 - BlueStack Systems, Inc.)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6521 - CDBurnerXP)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DC Universe Online (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\SOE-DC Universe Online) (Version: 1.0.3.183 - Sony Online Entertainment)
DC Universe Online (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SOE-DC Universe Online) (Version: 1.0.3.183 - Sony Online Entertainment)
DC Universe Online Live (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\SOE-DC Universe Online Live PSG) (Version:  - Sony Online Entertainment)
DC Universe Online Live (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SOE-DC Universe Online Live PSG) (Version:  - Sony Online Entertainment)
DC Universe Online PSG (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\soe-DC Universe Online PSG) (Version: 1.0.3.183 - Sony Online Entertainment)
DC Universe Online PSG (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\soe-DC Universe Online PSG) (Version: 1.0.3.183 - Sony Online Entertainment)
DEUTSCHLAND SPIELT GAME CENTER (HKLM-x32\...\DSGPlayer) (Version: 1.0.0.46 - INTENIUM GmbH)
Die Siedler 7 (HKLM-x32\...\{63860309-DA8A-4BAE-9EAE-CE1D6D79340C}) (Version: 1.12.1396 - Ubisoft)
DMG Extractor (HKLM-x32\...\DMGExtractor) (Version: 1.1.1.1 - Reincubate Ltd)
doPDF 7.3 printer (HKLM\...\doPDF 7 printer_is1) (Version:  - Softland)
Dropbox (HKLM-x32\...\Dropbox) (Version: 38.4.27 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - )
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{6C5F8503-55D2-4398-858C-362B7A7AF51C}) (Version: 2.1.31.0 - MAGIX AG)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Free Easy Burner V 5.1 (HKLM-x32\...\Free Easy Burner_is1) (Version: 5.1.0.0 - Koyote soft)
Free MP4 Video Converter (HKLM-x32\...\Free MP4 Video Converter_is1) (Version: 5.0.102.1027 - Digital Wave Ltd)
Freemium Free PDF Perfect (HKLM-x32\...\{88265079-D6F4-4292-86BE-D2053E80BFE4}) (Version: 1.0 - Freemium)
GameMaker-Studio 1.2 (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\GameMaker-Studio12) (Version:  - YoYo Games Ltd.)
GameMaker-Studio 1.2 (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\GameMaker-Studio12) (Version:  - YoYo Games Ltd.)
Goat Simulator (HKLM-x32\...\Steam App 265930) (Version:  - Coffee Stain Studios)
Google Chrome (HKU\SCANNERMAP\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
Green City: Die Stadt deiner Träume (HKLM-x32\...\Green City: Die Stadt deiner Träume) (Version: 1.0.0.0 - INTENIUM GmbH)
HP Officejet 6700 Basic Device Software (HKLM\...\{A1CFA587-90D4-4DE6-B200-68CC0F92252F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HPDiagnosticCoreDll (HKLM-x32\...\{9262B08F-E183-4FED-A2BD-23FF1A84EB79}) (Version: 1.0.15.0 - Hewlett Packard)
Image Converter (HKLM-x32\...\Image Converter Image Converter) (Version: 1.0.0 - Image Converter)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
James Cameron's AVATAR(tm): DAS SPIEL (HKLM-x32\...\{7E19B002-4CA3-4C9F-BA92-91D101B97219}) (Version: 1.02.00 - Ubisoft)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Lawn & Order: Die Gartenprofis (HKLM-x32\...\Lawn & Order: Die Gartenprofis) (Version: 1.0.0.0 - INTENIUM GmbH)
Magic Life (HKLM-x32\...\Magic Life) (Version: 1.0.0.0 - INTENIUM GmbH)
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{5900B465-32E8-48DA-AC09-21B8363F7A41}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video deluxe 2013 (HKLM-x32\...\MAGIX_{8C73E551-5AFA-42EE-B76E-64821590BCD3}) (Version: 12.0.0.32 - MAGIX AG)
MAGIX Video deluxe 2013 (Version: 12.0.0.32 - MAGIX AG) Hidden
Malkreuz (x32 Version: 1.00.0000 - Medienwerkstatt Mühlacker Verlagsgesellschaft mbH) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mein CEWE FOTOBUCH (HKLM-x32\...\Mein CEWE FOTOBUCH) (Version: 5.1.6 - CEWE Stiftung u Co. KGaA)
Microsoft .NET Framework 4.7 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-356143711-355811113-2582273239-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Moai: Erschaffe deinen Traum (HKLM-x32\...\Moai: Erschaffe deinen Traum) (Version: 1.0.0.0 - INTENIUM GmbH)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 56.0.2 (x64 de) (HKLM\...\Mozilla Firefox 56.0.2 (x64 de)) (Version: 56.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
PDF2Word Converter Version 1.0.8 (Build 164, 7-PDF) (HKLM-x32\...\PDF2Word Converter (7-PDF)_is1) (Version: PDF2Word Converter - Version 1.0.8 (Build 164) - 7-PDF, Germany - Thorsten Hodes)
PIF DESIGNER (HKLM-x32\...\{B90450DF-E781-46FD-B1F1-0C86DA40E443}) (Version:  - )
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version:  - )
Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15013.18 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.3.15013.18 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
Sandboxie 4.02 (64-bit) (HKLM\...\Sandboxie) (Version: 4.02 - Sandboxie Holdings, LLC)
Search-Results Toolbar (HKLM-x32\...\koyotesofttoolbarnew) (Version: 1.0.0.12 - APN LLC) <==== ATTENTION
Stadt der Narren (HKLM-x32\...\Stadt der Narren) (Version: 1.0.0.0 - INTENIUM GmbH)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Taxpool-Buchhalter Mini 6.24 (HKLM-x32\...\Taxpool-Buchhalter Mini) (Version: 6.24 - psynetic® Software)
TomTom MyDrive Connect 4.1.4.3089 (HKLM-x32\...\MyDriveConnect) (Version: 4.1.4.3089 - TomTom)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
Vokabeltrainer für Windows Version 1.51 (HKLM-x32\...\Vokabeltrainer für Windows_is1) (Version:  - diginvent)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-356143711-355811113-2582273239-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Fam. Ade\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

26-10-2017 23:00:01 Geplanter Prüfpunkt
03-11-2017 00:00:03 Geplanter Prüfpunkt
05-11-2017 12:51:36 Revo Uninstaller's restore point - Adobe Acrobat Reader DC - Deutsch
05-11-2017 12:52:52 Revo Uninstaller's restore point - 7-Zip 9.20
05-11-2017 12:53:55 Revo Uninstaller's restore point - 7-Zip 9.20
05-11-2017 12:54:58 Revo Uninstaller's restore point - Adobe Acrobat Reader DC - Deutsch
05-11-2017 12:57:56 Revo Uninstaller's restore point - Adobe Digital Editions 2.0
05-11-2017 12:58:55 Revo Uninstaller's restore point - Ashampoo Burning Studio FREE v.1.14.5
05-11-2017 13:00:34 Revo Uninstaller's restore point - Avira
05-11-2017 13:01:49 Revo Uninstaller's restore point - Avira Antivirus
05-11-2017 13:05:58 Revo Uninstaller's restore point - Avira
05-11-2017 13:08:03 Revo Uninstaller's restore point - DivX-Setup
05-11-2017 13:09:20 Revo Uninstaller's restore point - Java 7 Update 51
05-11-2017 13:09:50 Removed Java 7 Update 51
05-11-2017 13:14:03 Revo Uninstaller's restore point - Nero 12
05-11-2017 13:26:49 Revo Uninstaller's restore point - Norton 360 Online
05-11-2017 13:32:40 Revo Uninstaller's restore point - VLC media player 2.0.5
05-11-2017 13:34:37 Revo Uninstaller's restore point - WinZip 20.0
05-11-2017 13:35:20 WinZip 20.0 wird entfernt
05-11-2017 13:37:47 Revo Uninstaller's restore point - Goat Simulator

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2014-05-02 10:11 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0A4539CC-5316-4A61-A8D8-4293850F15AB} - \ProtectedSearch\Protected Search No Task File <==== ATTENTION
Task: {38B020D1-357C-46F5-BE86-B4F07C855C6A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-25] (Adobe Systems Incorporated)
Task: {4F387278-2353-45BD-9D8A-4FF1C5E179E9} - System32\Tasks\HP AR Program Upload - 2def856e98fd42c0af2ab35d45102a3a0e33f155164447319ccbababe29426c0 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {5549F126-D485-4FEC-9719-9A267731B31F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-08] (Google Inc.)
Task: {707B181D-A35C-47F7-A039-9AE8C7AE9045} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-08] (Google Inc.)
Task: {718F6CAB-BBCC-4B69-83C6-7C640482C103} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => C:\Windows\system32\compattelrunner.exe [2017-05-03] (Microsoft Corporation)
Task: {78298D72-8D94-4D21-8547-B8E7F33AE507} - \Browser Updater\Browser Updater No Task File <==== ATTENTION
Task: {81F538A1-8928-4F07-AADA-B1F413A22C5B} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {829625F8-5F95-4644-AF85-07F67B1BA23B} - System32\Tasks\{616C99AF-BEAA-4FB4-B382-A2B20D86BF98} => pcalua.exe -a "C:\Users\Fam. Ade\Downloads\epson30027eu.exe" -d "C:\Users\Fam. Ade\Desktop"
Task: {86915168-38FE-4D52-8A11-943B62A978C1} - System32\Tasks\HP AR Program Upload - 6b89bd66a6e048649e04dc31f8a1706355a107ddc5e946ea96303cd76419b11a => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {A8F4716A-C403-4172-8143-1C37E871A9A1} - System32\Tasks\HP AR Program Upload - b5c01ba5ad9742f4a0f74f1e55da5e26a18df2df1c71450ba082ef8703b8a046 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {B04ADAFE-C2D3-4B5E-92E6-282F4E5D2466} - System32\Tasks\Avira SystrayStartTrigger => Avira.SystrayStartTrigger.exe
Task: {CD4E143F-DF5F-425A-AD44-2B5FB4A8B8F7} - System32\Tasks\HP AR Program Upload - e330d555d2874ebabc0a30c862a2da613d4700ba94ea4d58b3ea0a32d8279410 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {DA6FBD2A-306D-4AFB-B613-EC241A16AAC3} - System32\Tasks\HP AR Program Upload - 1d8f182b717540109e3b0ba996d8e3a5ddca8dc77dbe40168d810be1d221880c => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {E74A986E-6F94-49FE-A756-29239914FF0B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {E788F862-969C-49EA-8C62-4A862DF892BF} - System32\Tasks\{96513A81-C24F-4D2B-B615-9465B77B3F3E} => pcalua.exe -a "C:\Program Files (x86)\Common Files\Freemium\Uninstall\{88265079-D6F4-4292-86BE-D2053E80BFE4}.exe" -c /X{88265079-D6F4-4292-86BE-D2053E80BFE4}
Task: {EC16D64F-AB1A-4596-9D67-D3175F7EF657} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-11-16] (Microsoft Corporation)
Task: {ED78580D-DCE2-4EE7-8B0C-05F674DE4621} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {F08F917F-B88F-40C8-B27B-0AA46D8F0B91} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {FB495BFB-94A9-45B1-B537-46D21553FE01} - System32\Tasks\{F05BE82B-0D12-4C43-9B39-6F8C0F9D86D0} => pcalua.exe -a "C:\Users\Fam. Ade\Desktop\Setup.exe" -d "C:\Users\Fam. Ade\Desktop"
Task: {FB98B0F5-C9FE-4ACA-8476-9DFC13597F8C} - System32\Tasks\{1409713F-E48C-431F-96D2-68F676C4E085} => pcalua.exe -a "C:\Users\Fam. Ade\Downloads\mmskasse.exe" -d "C:\Users\Fam. Ade\Downloads"
Task: {FFE725A4-F749-49E7-AFF3-25B7A3B47FC2} - System32\Tasks\HP AR Program Upload - 7dca521ae57b484ea823d2e9c7cbe31f29d3c42b6c9e458097c61fd4bf5ad836 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008Core.job => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-356143711-355811113-2582273239-1008UA.job => C:\Users\Shari\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2013-09-18 11:23 - 2010-06-17 19:56 - 00087040 _____ () C:\Windows\System32\redmonnt.dll
2012-11-30 03:06 - 2012-11-30 03:06 - 01263512 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2012-12-19 15:32 - 2012-12-19 15:32 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2012-11-30 03:07 - 2012-11-30 03:07 - 00100248 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2009-02-26 12:46 - 2009-02-26 12:46 - 00064344 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll
2011-06-22 10:46 - 2011-06-22 10:46 - 00434016 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll
2015-11-11 03:41 - 2015-11-11 03:41 - 00756376 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SecureAssist => ""="service"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-356143711-355811113-2582273239-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Fam. Ade\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-356143711-355811113-2582273239-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Fam. Ade\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\s-1-5-21-356143711-355811113-2582273239-1007\Control Panel\Desktop\\Wallpaper -> C:\Users\Ginua\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\SCANNERMAP\Control Panel\Desktop\\Wallpaper -> C:\Users\Shari\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-356143711-355811113-2582273239-500 - Administrator - Disabled)
Fam. Ade (S-1-5-21-356143711-355811113-2582273239-1001 - Administrator - Enabled) => C:\Users\Fam. Ade
Gast (S-1-5-21-356143711-355811113-2582273239-501 - Limited - Disabled)
Ginua (S-1-5-21-356143711-355811113-2582273239-1007 - Limited - Enabled) => C:\Users\Ginua
HomeGroupUser$ (S-1-5-21-356143711-355811113-2582273239-1002 - Limited - Enabled)
Shari (S-1-5-21-356143711-355811113-2582273239-1008 - Limited - Enabled) => C:\Users\Shari

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/05/2017 01:37:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary Symantec Network Security WFP Driver.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/05/2017 01:37:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary Symantec Iron Driver.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/05/2017 01:37:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary EraserUtilRebootDrv.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/05/2017 01:37:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary Symantec Eraser Control driver.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/05/2017 01:35:29 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary Symantec Network Security WFP Driver.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/05/2017 01:35:29 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary Symantec Iron Driver.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/05/2017 01:35:29 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary EraserUtilRebootDrv.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/05/2017 01:35:29 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary Symantec Eraser Control driver.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/05/2017 01:34:38 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary Symantec Network Security WFP Driver.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/05/2017 01:34:38 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary Symantec Iron Driver.

System Error:
Das System kann die angegebene Datei nicht finden.
.


System errors:
=============
Error: (11/05/2017 01:07:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (10/29/2017 09:44:21 AM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung empfangen: 20.

Error: (10/13/2017 06:34:30 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (10/13/2017 06:33:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Live Family Safety Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (10/13/2017 06:33:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Live Family Safety Service erreicht.

Error: (10/13/2017 06:33:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Digital Wave Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (10/13/2017 06:33:02 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Digital Wave Update Service erreicht.

Error: (10/12/2017 00:17:05 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1096) (User: FamAde-PC)
Description: Fehler bei der Verarbeitung der Gruppenrichtlinie. Es wurde versucht, registrierungsbasierte Richtlinieneinstellungen für das Gruppenrichtlinienobjekt "LocalGPO" zu lesen. Die Gruppenrichtlinieneinstellungen dürfen nicht erzwungen werden, bis dieses Ereignis behoben ist. Weitere Informationen über den Dateinamen und -pfad, der den Fehler verursacht hat, können den Ereignisdetails entnommen werden.

Error: (10/12/2017 02:59:17 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (10/12/2017 02:50:25 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.


Microsoft Office Sessions:
=========================
Error: (10/30/2017 11:40:40 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6776.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 91167 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (09/21/2017 07:28:21 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6776.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 65740 seconds with 480 seconds of active time.  This session ended with a crash.

Error: (08/14/2017 02:35:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6774.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 113 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (02/25/2017 01:38:24 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6762.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 350330 seconds with 600 seconds of active time.  This session ended with a crash.

Error: (01/05/2017 00:14:09 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6762.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 173666 seconds with 1740 seconds of active time.  This session ended with a crash.

Error: (12/13/2016 00:16:07 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6759.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2708 seconds with 540 seconds of active time.  This session ended with a crash.

Error: (11/04/2016 01:28:16 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6755.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1512 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (10/04/2016 05:51:15 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6755.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 41009 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (09/30/2016 10:38:24 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6755.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 73493 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (09/10/2016 02:42:57 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6750.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 273 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
         
--- --- --- Date: 2014-05-02 11:10:37.809 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-05-02 11:10:37.310 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: AMD Athlon(tm) II X4 620 Processor Percentage of memory in use: 60% Total physical RAM: 4094.16 MB Available physical RAM: 1624.09 MB Total Pagefile: 8186.51 MB Available Pagefile: 5458.7 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:292.86 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: EF017F90) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ==================== End Of Log ============================

Grüße
Ani


Alt 05.11.2017, 18:45   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Amazon Zip - Standard

Amazon Zip



gut gut


Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers



Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________
--> Amazon Zip

Alt 06.11.2017, 17:49   #7
Ani73
 
Amazon Zip - Standard

Amazon Zip



Hallo Cosinus,

also es gab keine Funde.

Ich finde auch keine Datei als Logfile.
Ich weiß nicht mehr wo ich noch suchen soll.

Grüße
Ani

lies mir jetzt doch keine Ruhe, diese Log Datei zu finden. Und siehe da über Malware habe ich dann noch den Pfad gefunden wo ich die Datei finden kann.

Code:
ATTFilter
<?xml version="1.0" encoding="UTF-16"?>

-<mbam-log>


-<header>

<date>2017/11/06 14:07:13 +0100</date>

<logfile>mbam-log-2017-11-06 (14-07-03).xml</logfile>

<isadmin>yes</isadmin>

</header>


-<engine>

<version>2.2.0.1024</version>

<malware-database>v2017.11.06.06</malware-database>

<rootkit-database>v2017.10.14.01</rootkit-database>

<license>free</license>

<file-protection>disabled</file-protection>

<web-protection>disabled</web-protection>

<self-protection>disabled</self-protection>

</engine>


-<system>

<hostname>FAMADE-PC</hostname>

<ip>192.168.2.111</ip>

<osversion>Windows 7 Service Pack 1</osversion>

<arch>x64</arch>

<username>Fam. Ade</username>

<filesys>NTFS</filesys>

</system>


-<summary>

<type>threat</type>

<result>completed</result>

<objects>409550</objects>

<time>2652</time>

<processes>0</processes>

<modules>0</modules>

<keys>0</keys>

<values>0</values>

<datas>0</datas>

<folders>0</folders>

<files>0</files>

<sectors>0</sectors>

</summary>


-<options>

<memory>enabled</memory>

<startup>enabled</startup>

<filesystem>enabled</filesystem>

<archives>enabled</archives>

<rootkits>enabled</rootkits>

<deeprootkit>disabled</deeprootkit>

<heuristics>enabled</heuristics>

<pup>enabled</pup>

<pum>enabled</pum>

</options>

<items> </items>

</mbam-log>
         
Grüße
Ani

Alt 07.11.2017, 09:24   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Amazon Zip - Icon22

Amazon Zip



Ist das denn so schwierig die paar Zeilen Anleitung mal richtig zu lesen??

Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.
__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 07.11.2017, 16:26   #9
Ani73
 
Amazon Zip - Standard

Amazon Zip



Hallo Cosinus,

nein es ist nicht schwierig zu lesen, aber etwas zu finden, was nicht da ist.....
Ich habe das schon gepostete Logfile unter:
ProgramData/Malwarebytes..../logs/protection gefunden.
Nur da finde ich Dateien.
Diese heißen allerdings:
mbam-log-2017-11-06 (14-07-03)
Code:
ATTFilter
<?xml version="1.0" encoding="UTF-16"?>

-<mbam-log>


-<header>

<date>2017/11/06 14:07:13 +0100</date>

<logfile>mbam-log-2017-11-06 (14-07-03).xml</logfile>

<isadmin>yes</isadmin>

</header>


-<engine>

<version>2.2.0.1024</version>

<malware-database>v2017.11.06.06</malware-database>

<rootkit-database>v2017.10.14.01</rootkit-database>

<license>free</license>

<file-protection>disabled</file-protection>

<web-protection>disabled</web-protection>

<self-protection>disabled</self-protection>

</engine>


-<system>

<hostname>FAMADE-PC</hostname>

<ip>192.168.2.111</ip>

<osversion>Windows 7 Service Pack 1</osversion>

<arch>x64</arch>

<username>Fam. Ade</username>

<filesys>NTFS</filesys>

</system>


-<summary>

<type>threat</type>

<result>completed</result>

<objects>409550</objects>

<time>2652</time>

<processes>0</processes>

<modules>0</modules>

<keys>0</keys>

<values>0</values>

<datas>0</datas>

<folders>0</folders>

<files>0</files>

<sectors>0</sectors>

</summary>


-<options>

<memory>enabled</memory>

<startup>enabled</startup>

<filesystem>enabled</filesystem>

<archives>enabled</archives>

<rootkits>enabled</rootkits>

<deeprootkit>disabled</deeprootkit>

<heuristics>enabled</heuristics>

<pup>enabled</pup>

<pum>enabled</pum>

</options>

<items> </items>

</mbam-log>
         

und
protection-log-2017-11-06

Code:
ATTFilter
<?xml version="1.0" encoding="UTF-8"?>

-<logs>

<record toVersion="2017.11.6.1" name="IP Database" last_modified_tag="58860638-df58-41a5-823a-241b21a1b1f3" fromVersion="2017.11.3.2" systemname="FAMADE-PC" username="SYSTEM" type="Update" source="Manual" datetime="2017-11-06T12:26:10.934810+01:00" LoggingEventType="1" severity="debug"/>

<record toVersion="2017.11.6.5" name="Malware Database" last_modified_tag="982e017f-7413-47b5-aff0-efe7c16b2215" fromVersion="2017.11.5.2" systemname="FAMADE-PC" username="SYSTEM" type="Update" source="Manual" datetime="2017-11-06T12:26:15.068817+01:00" LoggingEventType="1" severity="debug"/>

<record toVersion="2017.11.6.1" name="Domain Database" last_modified_tag="a3f190e3-2c93-4dab-827a-e33682cd0f5d" fromVersion="2017.11.3.8" systemname="FAMADE-PC" username="SYSTEM" type="Update" source="Manual" datetime="2017-11-06T12:26:15.427618+01:00" LoggingEventType="1" severity="debug"/>

<record last_modified_tag="bcb56403-d990-48f2-9dac-66fc9939ee5a" systemname="FAMADE-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2017-11-06T12:26:52.689428+01:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="1" malwaredetections="0" duration="3721" starttime="2017-11-05T09:25:01+01:00" scantype="threat"/>

<record last_modified_tag="bcd93e0a-c445-42f3-a8b8-8a1dfb79ab21" systemname="FAMADE-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2017-11-06T13:12:42.397022+01:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="0" malwaredetections="0" duration="2745" starttime="2017-11-06T12:26:57+01:00" scantype="threat"/>

<record last_modified_tag="355175b1-4d1f-425a-9714-e53375c7bd5c" systemname="FAMADE-PC" username="SYSTEM" type="Error" source="Protection" datetime="2017-11-06T13:58:37.404704+01:00" LoggingEventType="4" severity="debug" message="IsLicensed" code="13"/>

<record last_modified_tag="614a8b04-4426-4776-a205-1fe10cd07eb1" systemname="FAMADE-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-11-06T13:58:37.435905+01:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopping"/>

<record last_modified_tag="e2ce1be1-c4f3-42bd-beee-a483df8051a1" systemname="FAMADE-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-11-06T13:58:37.435905+01:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopped"/>

<record toVersion="2017.11.6.6" name="Malware Database" last_modified_tag="ce087538-d41e-47e2-8117-df935e2d04b3" fromVersion="2017.11.6.5" systemname="FAMADE-PC" username="SYSTEM" type="Update" source="Manual" datetime="2017-11-06T14:07:12.510043+01:00" LoggingEventType="1" severity="debug"/>

<record last_modified_tag="7e042852-9354-4e35-81ab-4cb94631bc43" systemname="FAMADE-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2017-11-06T14:51:26.480271+01:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="0" malwaredetections="0" duration="2652" starttime="2017-11-06T14:07:13+01:00" scantype="threat"/>

</logs>
         
Einen separaten Ordner der evtl. erstellt wurde habe ich nicht gefunden. Es tut mir leid.

Grüße
Ani

Alt 07.11.2017, 16:32   #10
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Amazon Zip - Icon32

Amazon Zip



__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 07.11.2017, 17:24   #11
Ani73
 
Amazon Zip - Standard

Amazon Zip



Hallo Cosinus,

ich habe nun das Malware B. das ich drauf hatte runtergeschmissen mit Revo und nochmal neu installiert.
Dann, tatsächlich, erstellte es mir das Logfile das du benötigst.

Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.10.3.1001
www.malwarebytes.org

Database version:
  main:    v2017.11.07.06
  rootkit: v2017.10.14.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18816
Fam. Ade :: FAMADE-PC [administrator]

07.11.2017 16:33:05
mbar-log-2017-11-07 (16-33-05).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 409887
Time elapsed: 37 minute(s), 28 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         
Das hatte ich vorher nicht in dem Ordner drin.

Grüße
Ani

Alt 07.11.2017, 22:07   #12
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Amazon Zip - Standard

Amazon Zip



Schön, aber was vorher gefunden wurde weiß nun niemand mehr
__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 07.11.2017, 22:16   #13
Ani73
 
Amazon Zip - Standard

Amazon Zip



oh jeh, da hab ich jetzt aber echt Scheisse gebaut


allerdings hat er bei dem Durchlauf gestern auch nichts gefunden

Alt 07.11.2017, 22:33   #14
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Amazon Zip - Standard

Amazon Zip



schwein gehabt

Adware/Junkware/Toolbars entfernen

Alte Versionen von adwCleaner vorher löschen, danach neu runterladen auf den Desktop!
Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren!




adwCleaner v7.x

Downloade Dir bitte AdwCleaner auf Deinen Desktop (Bebilderte Anleitung).
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Werkzeuge > Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • Tracing Schlüssel
    • Prefetch Dateien
    • Proxy
    • Winsock
    • IE Richtlinien
    • Chrome Richtlinien
  • Bestätige die Auswahl mit Ok.
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist. Am Ende des Suchlaufs öffnet sich automatisch eine Logdatei. Schließe diese.
  • Klicke nun auf Löschen (auch dann wenn AdwCleaner sagt, dass nichts gefunden wurde) und bestätige auftretende Hinweise mit Ok.
  • Klicke am Ende der Bereinigung auf Jetzt neu starten. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).
__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 08.11.2017, 08:05   #15
Ani73
 
Amazon Zip - Standard

Amazon Zip



anbei das Logfile vom Adware Cleaner

Code:
ATTFilter
# AdwCleaner 7.0.4.0 - Logfile created on Wed Nov 08 06:51:01 2017
# Updated on 2017/27/10 by Malwarebytes 
# Running on Windows 7 Home Premium (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

Deleted: C:\Windows\System32\config\systemprofile\AppData\LocalLow\AVG Secure Search
Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AVG Secure Search


***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted: Browser Updater\Browser Updater
Deleted: Browser Updater


***** [ Registry ] *****

Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cloudfront.net
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d10lpsik1i8c69.cloudfront.net
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d16fk4ms6rqz1v.cloudfront.net
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d1733r3id7jrw5.cloudfront.net
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d22j4fzzszoii2.cloudfront.net
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ism.de
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\wtb-tennis.de
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.ism.de
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.wtb-tennis.de
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{97AE1DAA-7852-42DD-BA5E-1B553C951158}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{F362D347-1A0E-47C6-9636-763D41D00053}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{AB34B361-22F6-44F2-863D-DF296443DFD8}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{62460538-69BC-44FB-B14A-6AE9B1B5B5F6}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{17F8F466-53C4-42D2-B894-68B3EE270E23}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{3F3AA3CF-3A04-4447-AF4D-A2BDCDA48E20}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{79F04CF4-4BDB-47CE-AC81-A984C113C365}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{6E8C525B-5752-4A4C-9A22-7F5D692B6F01}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{5230E5A4-CE74-4FAB-A3F4-01170669CEFC}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{21931936-6C91-43DA-9181-07F863DF15A1}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3038A20B9089EC34D8F74220191FAB30
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION|BackgroundHost64.exe
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD|BackgroundHost64.exe
Deleted: [Key] - HKLM\SOFTWARE\Classes\MIME\Database\Content Type\application\x-vnd.bdliveupdate.oneclickctrl.9
Deleted: [Key] - HKLM\SOFTWARE\Classes\MIME\Database\Content Type\application\x-vnd.bdliveupdate.update3webcontrol.3
Deleted: [Value] - HKLM\SOFTWARE\Classes\.torrent|iLivid.torrent_backup
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\game-maker.de.softonic.com
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\kabu-kassenbuch.de.softonic.com
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{078FA2D5-DE68-416E-BA7F-894A4A4EAB6C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{0AD8FD27-9029-43A1-B9D5-C54FF18C3DD7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{1D7BEA54-B699-4A4D-83D7-D10875B8D7FD}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{45C2D25B-0816-419A-B74B-CD4D7024FB71}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{3C8BE759-0A8F-4C0D-8CAD-0E5898EAE6AF}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{4E695B8D-101C-4F95-B5C7-A7D9D2E975EF}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{2203FA35-9590-4CBA-8AFF-CC53930B7F5C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{9566B021-2079-4C32-8F1F-A26911954C8B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{FFC65EC8-C373-4E11-9882-905817219E16}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{6BD95127-7C32-4C10-ACF0-1C4687629C85}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{75CF0360-C187-4E6E-AB01-6FA65F3DA6CB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{C8B204C2-D508-4B71-9CC5-AED5E1302A86}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{C3FD9F92-09FA-493C-8C1F-2A3D7DD55DDD}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{F340A9AB-C377-4855-A106-0DAC2893A1A8}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{558F32DF-FA22-4656-B0D2-64DD9EB41F8F}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{54AFDC23-353C-4789-84F5-9C955AD44AC5}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{BBA36C2E-EC79-494A-988D-19398D9222A2}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{39FB51B1-8784-4BD5-A411-F1B7A5DB4D67}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{EC5A8488-566B-442C-9E5E-259031985B7A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{41AC4A66-D0C5-4646-BFAE-1041584C43DE}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{74009D24-8B75-4783-9E69-4566B239FB30}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{349385B4-83FC-4BE1-9DBF-DC0195C65DB4}
Deleted: [Key] - HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\UniblueDriverScanner
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{E9EFC215-5D07-4CC7-80FB-BC1EF2BF58D0}
Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application
Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{41435ED1-CD00-4950-905D-61BDDA585000}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{9D076A92-97E7-4946-8FE3-AE0DA86075C8}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{0C11527F-0008-4F12-9C1A-20B89DBCD8B1}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{E9386C9C-C4C5-4DE0-9836-0539D72EF6A7}
Deleted: [Value] - HKCU\Software\Classes\.torrent|iLivid.torrent_backup
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{E05B5B97-4986-4DA4-B9F4-AAE4E7E9D57F}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{FCDC5AB0-703B-4565-9AD4-3CF7C9FE54B9}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{5230E5A4-CE74-4FAB-A3F4-01170669CEFC}
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{21931936-6C91-43DA-9181-07F863DF15A1}
Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing|bProtectShowTabsWelcome
Deleted: [Key] - HKLM\SOFTWARE\Classes\Applications\iLividSetup-r343-n-bi.exe


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Prefetch files deleted
::Proxy settings cleared
::IE policies deleted
::Chrome policies deleted
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[C4].txt - [36378 B] - [2016/1/14 8:1:11]
C:/AdwCleaner/AdwCleaner[S0].txt - [1577 B] - [2014/1/8 11:34:35]
C:/AdwCleaner/AdwCleaner[S1].txt - [15576 B] - [2014/4/27 9:28:41]
C:/AdwCleaner/AdwCleaner[S2].txt - [1435 B] - [2014/5/4 20:10:11]
C:/AdwCleaner/AdwCleaner[S4].txt - [10075 B] - [2017/11/8 5:16:30]
C:/AdwCleaner/AdwCleaner[S5].txt - [10143 B] - [2017/11/8 6:46:14]
C:/AdwCleaner/AdwCleaner[S6].txt - [34815 B] - [2016/1/14 7:55:47]


########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt ##########
         

Antwort

Themen zu Amazon Zip
adware, antivir, antivirus, avdevprot.sys, avira, browser, combofix, einstellungen, excel, fehler, flash player, google, helper, home, mozilla, registry, scan, security, services.exe, software, svchost.exe, symantec, system, usb, warnung, windows



Ähnliche Themen: Amazon Zip


  1. Android-Trojaner auf Amazon.de
    Nachrichten - 04.03.2016 (0)
  2. Fremdzugriff auf E-Mail, Amazon etc.
    Log-Analyse und Auswertung - 28.10.2015 (13)
  3. Amazon-Icon, GIGA-Android-Startseite und Amazon.de.Url nach Download einer Datei(jedoch keine erkennbarne Probleme)
    Log-Analyse und Auswertung - 13.08.2014 (11)
  4. Amazon Spam von "info@amazon.de"
    Plagegeister aller Art und deren Bekämpfung - 01.07.2014 (14)
  5. Amazon Pishing Email
    Plagegeister aller Art und deren Bekämpfung - 06.01.2014 (3)
  6. amazon.de Spam: Ihre Amazon.de Bestellung vom 05.11.13
    Diskussionsforum - 12.11.2013 (2)
  7. Amazon Toolbar entfernen
    Anleitungen, FAQs & Links - 30.10.2013 (2)
  8. Amazon-Konto geknackt
    Log-Analyse und Auswertung - 17.10.2013 (19)
  9. Falsche E-Mail von Amazon.de
    Plagegeister aller Art und deren Bekämpfung - 31.08.2013 (7)
  10. Manipulierte Weiterleitung (Amazon) immer auf http://www.amazon.de/?cmd=redxme
    Plagegeister aller Art und deren Bekämpfung - 30.06.2013 (5)
  11. Amazon startet Single Sign-On "Login with Amazon"
    Nachrichten - 30.05.2013 (0)
  12. Amazon - Keylogger
    Alles rund um Windows - 06.04.2013 (1)
  13. Bei Amazon bestelllt - TROJANER !
    Mülltonne - 06.04.2013 (1)
  14. Schwerwiegende Sicherheitslücke bei Amazon
    Nachrichten - 18.01.2013 (0)
  15. PishingEmail von Amazon
    Plagegeister aller Art und deren Bekämpfung - 27.12.2012 (1)
  16. Fehler bei Amazon
    Überwachung, Datenschutz und Spam - 04.08.2012 (10)
  17. free6.se & Amazon
    Log-Analyse und Auswertung - 16.11.2004 (4)

Zum Thema Amazon Zip - Hallo und guten Morgen, ich habe gerade im total verschlafenen Zustand meine Mails abgefragt. Hatte von Amazon ne Datei drin wegen einer Bestellung und, so blöd wie ich war, den - Amazon Zip...
Archiv
Du betrachtest: Amazon Zip auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.