Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Datei SpyHunterKiller lässt sich nicht öffnen (https://www.trojaner-board.de/163343-datei-spyhunterkiller-laesst-oeffnen.html)

Nero555 29.01.2015 14:21

Datei SpyHunterKiller lässt sich nicht öffnen
 
Hallo erstmal.
Mir wurde vor einiger Zeit in meinem Browser (Chrome) die Seite: www.Trovi.com angezeigt. Ich habe im Internet nach Lösungen des Problems gesucht und bin auch fündig geworden. Eine Seite empfiehl dass, man SpyHunter 4 runterladen soll, um das Problem zu lösen. Ich habe das Programm gedownloadet und das Problem wurde behoben, jedoch startet sich SpyHunter seit dem bei jedem PC Start direkt, ich habe es versucht zu deinstallieren aber es ging nicht. Daraufhin hab ich mich ein wenig im Internet schlau gemacht. Ich weiß nun dass, SpyHunter ein gefährliches Programm ist, deswegen habe ich SpyHunterKiller runtergeladen (durch einen Link auf dieser Seite) jedoch kann ich die Datei nicht öffnen, wenn ich es versuche erscheint eine Fehlermeldung: "AutoIt error : Unable to open the script file."
Wie kann ich dieses Problem lösen?

cosinus 29.01.2015 14:51

Hallo und :hallo:

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!




Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Nero555 29.01.2015 15:13

FRST Logdateien (2)
 
Code:

2015-01-19 12:08 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\windows\system32\rdrmemptylst.exe
2015-01-19 12:07 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2015-01-19 12:07 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-01-19 12:07 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-01-19 12:07 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-01-19 12:07 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-01-19 12:07 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-01-19 12:07 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-01-19 12:07 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-01-19 12:07 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-01-19 12:07 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-01-19 12:07 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-01-19 12:07 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2015-01-19 12:07 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d11.dll
2015-01-19 12:07 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2015-01-19 12:07 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll
2015-01-19 12:07 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\windows\system32\gameux.dll
2015-01-19 12:07 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wpc.dll
2015-01-19 12:07 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\windows\SysWOW64\gameux.dll
2015-01-19 12:07 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\windows\system32\oflc-nz.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\windows\system32\pegibbfc.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\windows\system32\csrr.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\windows\system32\usk.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\windows\system32\oflc.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-pt.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-fi.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\windows\system32\cero.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\windows\system32\esrb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\windows\system32\fpb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\windows\system32\cob-au.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\windows\system32\grb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\windows\system32\pegi.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\windows\system32\djctq.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\windows\SysWOW64\cero.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\windows\SysWOW64\esrb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\windows\SysWOW64\fpb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\windows\SysWOW64\oflc-nz.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\windows\SysWOW64\pegibbfc.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\windows\SysWOW64\csrr.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\windows\SysWOW64\cob-au.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\windows\SysWOW64\usk.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\windows\SysWOW64\oflc.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\windows\SysWOW64\grb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi-pt.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi-fi.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\windows\SysWOW64\djctq.rs
2015-01-19 12:06 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-01-19 12:06 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-01-19 12:06 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-01-19 12:06 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-01-19 12:06 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-01-19 12:06 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-01-19 12:06 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-01-19 12:06 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-01-19 12:06 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2015-01-19 12:06 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-01-19 12:06 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\windows\SysWOW64\pku2u.dll
2015-01-19 12:06 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-01-19 12:06 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-01-19 12:06 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-01-19 12:06 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-01-19 12:06 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2015-01-19 12:06 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2015-01-19 12:06 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2015-01-19 12:06 - 2014-08-01 12:53 - 01031168 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2015-01-19 12:06 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll
2015-01-19 12:06 - 2014-04-12 03:22 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-01-19 12:06 - 2014-04-12 03:19 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-01-19 12:06 - 2014-04-12 03:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-01-19 12:06 - 2014-04-12 03:19 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-01-19 12:06 - 2014-04-12 03:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-01-19 12:06 - 2014-03-04 10:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-01-19 12:06 - 2014-03-04 10:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-01-19 12:06 - 2014-03-04 10:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-01-19 12:06 - 2014-03-04 10:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-01-19 12:06 - 2014-03-04 09:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-01-19 12:06 - 2014-03-04 09:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-01-19 12:06 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2015-01-19 12:06 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll
2015-01-19 12:06 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-01-19 12:06 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-01-19 12:06 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-01-19 12:06 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2015-01-19 12:06 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\shdocvw.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\windows\system32\netcorehc.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\netevent.dll
2015-01-19 12:06 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2015-01-19 12:06 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\netcorehc.dll
2015-01-19 12:06 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\netevent.dll
2015-01-19 12:06 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2015-01-19 12:05 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-01-19 12:05 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2015-01-19 12:05 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2015-01-19 12:05 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10K.DLL
2015-01-19 12:05 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-01-19 12:05 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-01-19 12:05 - 2014-06-18 03:18 - 00692736 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2015-01-19 12:05 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
2015-01-19 12:05 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2015-01-19 12:05 - 2014-06-06 11:10 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2015-01-19 12:05 - 2014-06-06 10:44 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2015-01-19 12:05 - 2014-04-05 03:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2015-01-19 12:05 - 2014-04-05 03:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2015-01-19 12:05 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2015-01-19 12:05 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2015-01-19 12:05 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-01-19 12:05 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-01-19 12:05 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-01-19 12:05 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-01-19 12:05 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2015-01-19 12:05 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptdlg.dll
2015-01-19 12:05 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2015-01-19 12:05 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2015-01-19 12:05 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2015-01-19 12:05 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wwanprotdim.dll
2015-01-19 12:05 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll
2015-01-19 12:05 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll
2015-01-19 12:05 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore6.dll
2015-01-19 12:05 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc6.dll
2015-01-19 12:05 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\windows\system32\OxpsConverter.exe
2015-01-19 12:05 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\netapi32.dll
2015-01-19 12:05 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\browser.dll
2015-01-19 12:05 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\browcli.dll
2015-01-19 12:05 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\windows\SysWOW64\netapi32.dll
2015-01-19 12:05 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\windows\SysWOW64\browcli.dll
2015-01-19 12:05 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\windows\system32\ntshrui.dll
2015-01-19 12:05 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntshrui.dll
2015-01-19 12:05 - 2011-10-26 06:25 - 01572864 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-01-19 12:05 - 2011-10-26 05:32 - 01328128 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2015-01-19 12:05 - 2011-07-09 03:46 - 00288768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-01-19 12:05 - 2011-05-04 06:25 - 02315776 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 02223616 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00778752 _____ (Microsoft Corporation) C:\windows\system32\mssvp.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00491520 _____ (Microsoft Corporation) C:\windows\system32\mssph.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00288256 _____ (Microsoft Corporation) C:\windows\system32\mssphtb.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00075264 _____ (Microsoft Corporation) C:\windows\system32\msscntrs.dll
2015-01-19 12:05 - 2011-05-04 06:19 - 00591872 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe
2015-01-19 12:05 - 2011-05-04 06:19 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\SearchProtocolHost.exe
2015-01-19 12:05 - 2011-05-04 06:19 - 00113664 _____ (Microsoft Corporation) C:\windows\system32\SearchFilterHost.exe
2015-01-19 12:05 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssvp.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssph.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssphtb.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscntrs.dll
2015-01-19 12:05 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe
2015-01-19 12:05 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchProtocolHost.exe
2015-01-19 12:05 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFilterHost.exe
2015-01-19 12:05 - 2011-04-27 03:40 - 00158208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-01-19 12:05 - 2011-04-27 03:39 - 00128000 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-01-19 12:05 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\poqexec.exe
2015-01-19 12:05 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\poqexec.exe
2015-01-19 12:05 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2015-01-19 12:04 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-01-19 12:04 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-01-19 12:04 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2015-01-19 12:04 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncsi.dll
2015-01-19 12:04 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlaapi.dll
2015-01-19 12:04 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-01-19 12:04 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-01-19 12:04 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2015-01-19 12:04 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2015-01-19 12:04 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-01-19 12:04 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-01-19 12:04 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-01-19 12:04 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-01-19 12:04 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-01-19 12:04 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2015-01-19 12:04 - 2014-05-30 07:45 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-01-19 12:04 - 2014-04-25 03:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2015-01-19 12:04 - 2014-04-25 03:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2015-01-19 12:04 - 2014-03-26 15:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-01-19 12:04 - 2014-03-26 15:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-01-19 12:04 - 2014-03-26 15:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-01-19 12:04 - 2014-03-26 15:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2015-01-19 12:04 - 2014-02-04 03:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2015-01-19 12:04 - 2014-02-04 03:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2015-01-19 12:04 - 2014-02-04 03:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2015-01-19 12:04 - 2014-02-04 03:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2015-01-19 12:04 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2015-01-19 12:04 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2015-01-19 12:04 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2015-01-19 12:04 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2015-01-19 12:04 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2015-01-19 12:04 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-01-19 12:04 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-01-19 12:04 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2015-01-19 12:04 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2015-01-19 12:04 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2015-01-19 12:04 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\SysWOW64\SmartcardCredentialProvider.dll
2015-01-19 12:04 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\credui.dll
2015-01-19 12:04 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2015-01-19 12:04 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2015-01-19 12:04 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2015-01-19 12:04 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2015-01-19 12:04 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-01-19 12:04 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-01-19 12:04 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-01-19 12:04 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2015-01-19 12:04 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-01-19 12:04 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2015-01-19 12:04 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-01-19 12:04 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-01-19 12:04 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-01-19 12:04 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
2015-01-19 12:04 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-01-19 12:04 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-01-19 12:04 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-01-19 12:04 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-01-19 12:04 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-01-19 12:04 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-01-19 12:04 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-01-19 12:04 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-01-19 12:04 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-01-19 12:04 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-01-19 12:04 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-01-19 12:04 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2015-01-19 12:04 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\dpnet.dll
2015-01-19 12:04 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpnet.dll
2015-01-19 12:04 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-01-19 12:04 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\Drivers\RNDISMP.sys
2015-01-19 12:04 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\partmgr.sys
2015-01-19 12:04 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fs_rec.sys
2015-01-19 12:04 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\wmi.dll
2015-01-19 12:04 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmi.dll
2015-01-19 12:04 - 2011-11-17 07:35 - 00395776 _____ (Microsoft Corporation) C:\windows\system32\webio.dll
2015-01-19 12:04 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\windows\SysWOW64\webio.dll
2015-01-19 12:04 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\windows\system32\psisdecd.dll
2015-01-19 12:04 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\psisrndr.ax
2015-01-19 12:04 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\windows\SysWOW64\psisdecd.dll
2015-01-19 12:04 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\windows\SysWOW64\psisrndr.ax
2015-01-19 12:04 - 2011-06-16 06:49 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\xmllite.dll
2015-01-19 12:04 - 2011-06-16 05:33 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\xmllite.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00212992 _____ (Microsoft Corporation) C:\windows\system32\odbctrac.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\odbccp32.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\odbccu32.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\odbccr32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00319488 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbcjt32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbctrac.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00122880 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccp32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccu32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccr32.dll
2015-01-19 12:04 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\umpnpmgr.dll
2015-01-19 12:04 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\windows\SysWOW64\devobj.dll
2015-01-19 12:04 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\windows\SysWOW64\devrtl.dll
2015-01-19 12:04 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cfgmgr32.dll
2015-01-19 12:04 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\windows\SysWOW64\drvinst.exe
2015-01-19 12:04 - 2011-04-29 04:06 - 00467456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2015-01-19 12:04 - 2011-04-29 04:05 - 00410112 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2015-01-19 12:04 - 2011-04-29 04:05 - 00168448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2015-01-19 12:03 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2015-01-19 12:03 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\charmap.exe
2015-01-19 12:03 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2015-01-19 12:03 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2015-01-19 12:03 - 2014-09-25 03:08 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-01-19 12:03 - 2014-09-25 02:40 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2015-01-19 12:03 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2015-01-19 12:03 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2015-01-19 12:03 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2015-01-19 12:03 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2015-01-19 12:03 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2015-01-19 12:03 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-01-19 12:03 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\windows\SysWOW64\synceng.dll
2015-01-19 12:03 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\synceng.dll
2015-01-19 12:03 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\windows\system32\cdosys.dll
2015-01-19 12:03 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\windows\SysWOW64\cdosys.dll
2015-01-19 12:03 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\windows\system32\timedate.cpl
2015-01-19 12:03 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\windows\SysWOW64\timedate.cpl
2015-01-19 12:03 - 2011-02-18 11:51 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\prevhost.exe
2015-01-19 12:03 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\prevhost.exe
2015-01-19 12:02 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-01-19 12:02 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-01-19 12:01 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-01-19 12:01 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2015-01-19 12:01 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-01-19 12:01 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-01-19 12:01 - 2014-01-24 03:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2015-01-19 12:01 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2015-01-19 12:01 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2015-01-19 12:01 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2015-01-19 12:01 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2015-01-19 12:01 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2015-01-19 12:01 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx
2015-01-19 12:01 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2015-01-19 12:01 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2015-01-19 12:01 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2015-01-19 12:01 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2015-01-19 12:01 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2015-01-19 12:01 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe
2015-01-19 12:01 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2015-01-19 12:01 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-01-19 12:01 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2015-01-19 12:01 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2015-01-19 12:01 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\windows\system32\msvcrt.dll
2015-01-19 12:01 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcrt.dll
2015-01-19 12:01 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\windows\system32\EncDec.dll
2015-01-19 12:01 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\EncDec.dll
2015-01-19 12:01 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\windows\system32\oleacc.dll
2015-01-19 12:01 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleacc.dll
2015-01-19 11:50 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-01-19 11:50 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-01-19 11:49 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2015-01-19 11:32 - 2015-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\Virtual Desktop Manager
2015-01-19 11:32 - 2015-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Local\FSP
2015-01-19 11:31 - 2015-01-23 18:06 - 00001003 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-19 11:21 - 2015-01-19 11:21 - 524288000 __RSH () C:\VPART015.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART014.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART013.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART012.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART011.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART010.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART009.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART008.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 00000790 _____ () C:\Users\User\Desktop\Time Stamp.lnk
2015-01-19 11:21 - 2015-01-19 11:21 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Time Stamp
2015-01-19 11:20 - 2015-01-29 15:39 - 00001058 __RSH () C:\windows\system32\VFsRegister
2015-01-19 11:20 - 2015-01-21 12:12 - 00000000 ____D () C:\Program Files\Time Stamp
2015-01-19 11:20 - 2015-01-20 12:00 - 00000000 ____D () C:\ProgramData\Farstone
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART007.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART006.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART005.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART004.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART003.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART002.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART001.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART000.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 00004096 __RSH () C:\RESCUMBR.BIN
2015-01-19 11:20 - 2015-01-19 11:20 - 00000532 __RSH () C:\windows\system32\VFsActitvation
2015-01-19 11:20 - 2011-07-12 09:28 - 00162392 _____ () C:\windows\system32\Drivers\VvBackd5.sys
2015-01-19 11:20 - 2011-04-18 04:12 - 00024664 ____N () C:\windows\system32\Drivers\FarMntIo.sys
2015-01-19 11:20 - 2011-01-04 18:18 - 00066136 ____N () C:\windows\system32\Drivers\HCDisk.sys
2015-01-19 11:19 - 2015-01-19 11:19 - 00000006 _____ () C:\windows\silentOnce.tmp
2015-01-19 11:19 - 2015-01-19 11:19 - 00000000 ____D () C:\ProgramData\Remind
2015-01-19 11:19 - 2015-01-19 11:19 - 00000000 ____D () C:\Program Files (x86)\MSI
2015-01-19 11:16 - 2015-01-19 11:16 - 00000000 ____D () C:\Users\User\AppData\Local\VirtualStore
2015-01-19 11:16 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\windows\system32\rdpcore.dll
2015-01-19 11:16 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpcore.dll
2015-01-19 11:16 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdtcp.sys
2015-01-19 11:09 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-01-19 11:09 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-01-19 11:09 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-01-19 11:09 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-01-19 11:09 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-01-19 11:09 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-01-19 11:09 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-01-19 11:09 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-01-19 11:09 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-01-19 11:06 - 2015-01-21 09:37 - 00058016 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-19 11:06 - 2015-01-19 11:06 - 00000020 ___SH () C:\Users\User\ntuser.ini
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Vorlagen
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Startmenü
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Netzwerkumgebung
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Lokale Einstellungen
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Eigene Dateien
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Druckumgebung
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Documents\Eigene Musik
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Documents\Eigene Bilder
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Local\Verlauf
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Local\Anwendungsdaten
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Anwendungsdaten
2015-01-19 11:06 - 2011-08-11 18:21 - 00000000 ____D () C:\Users\User\AppData\Local\SRS Labs
2015-01-19 11:06 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-19 11:06 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-29 13:44 - 2011-08-11 18:10 - 02012429 _____ () C:\windows\WindowsUpdate.log
2015-01-29 13:40 - 2009-07-14 05:45 - 00016752 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-29 13:40 - 2009-07-14 05:45 - 00016752 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-29 13:34 - 2011-08-11 19:05 - 00772184 _____ () C:\windows\system32\perfh010.dat
2015-01-29 13:34 - 2011-08-11 19:05 - 00159382 _____ () C:\windows\system32\perfc010.dat
2015-01-29 13:34 - 2011-08-11 18:59 - 00779006 _____ () C:\windows\system32\perfh00C.dat
2015-01-29 13:34 - 2011-08-11 18:59 - 00163544 _____ () C:\windows\system32\perfc00C.dat
2015-01-29 13:34 - 2011-08-11 18:52 - 00779960 _____ () C:\windows\system32\perfh00A.dat
2015-01-29 13:34 - 2011-08-11 18:52 - 00173610 _____ () C:\windows\system32\perfc00A.dat
2015-01-29 13:34 - 2011-08-11 18:45 - 00744432 _____ () C:\windows\system32\perfh007.dat
2015-01-29 13:34 - 2011-08-11 18:45 - 00162272 _____ () C:\windows\system32\perfc007.dat
2015-01-29 13:34 - 2009-07-14 05:46 - 00004325 _____ () C:\windows\DtcInstall.log
2015-01-29 13:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\inetsrv
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\inetsrv
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2015-01-29 12:36 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-01-29 12:36 - 2009-07-14 05:51 - 00038985 _____ () C:\windows\setupact.log
2015-01-28 12:46 - 2010-11-21 04:47 - 00278056 _____ () C:\windows\PFRO.log
2015-01-25 16:33 - 2011-08-11 18:24 - 00011580 _____ () C:\windows\DPINST.LOG
2015-01-25 16:33 - 2011-05-17 18:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-23 16:06 - 2011-08-11 18:22 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun
2015-01-22 12:24 - 2009-07-14 03:34 - 00000505 _____ () C:\windows\win.ini
2015-01-22 12:23 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\GroupPolicy
2015-01-21 11:57 - 2009-07-14 06:13 - 04190942 _____ () C:\windows\system32\PerfStringBackup.INI
2015-01-21 11:38 - 2011-08-11 18:21 - 00058016 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-21 11:38 - 2011-08-11 18:21 - 00058016 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-21 11:01 - 2009-07-14 05:45 - 00267816 _____ () C:\windows\system32\FNTCACHE.DAT
2015-01-21 10:24 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\zh-HK
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\zh-HK
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\tr-TR
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-21 09:25 - 2010-11-21 08:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-21 09:25 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-21 09:25 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\Dism
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\AppCompat
2015-01-20 13:51 - 2011-08-11 18:29 - 00000000 ____D () C:\Users\Public\Desktop\User Manual
2015-01-20 12:53 - 2010-01-20 11:34 - 00000000 ____D () C:\Users\User\AppData\Roaming\Adobe
2015-01-19 11:31 - 2011-06-08 03:20 - 00000000 ____D () C:\Utility
2015-01-19 11:21 - 2011-03-21 17:37 - 00000000 ____D () C:\log
2015-01-19 11:19 - 2011-05-17 18:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-01-19 11:05 - 2011-05-16 20:37 - 00000000 __SHD () C:\Recovery
2015-01-19 11:05 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-01-19 11:04 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2015-01-08 09:55 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe

Some content of TEMP:
====================
C:\Users\User\AppData\Local\Temp\9696F194-FBAC-E12D-6210-9B43FAFCA97D.dll
C:\Users\User\AppData\Local\Temp\BackupSetup.exe
C:\Users\User\AppData\Local\Temp\i33FC.tmp.exe
C:\Users\User\AppData\Local\Temp\i3874.tmp.exe
C:\Users\User\AppData\Local\Temp\i9602.tmp.exe
C:\Users\User\AppData\Local\Temp\i9924.tmp.exe
C:\Users\User\AppData\Local\Temp\iBA4.tmp.exe
C:\Users\User\AppData\Local\Temp\iE3FA.tmp.exe
C:\Users\User\AppData\Local\Temp\iE714.tmp.exe
C:\Users\User\AppData\Local\Temp\nst712.exe
C:\Users\User\AppData\Local\Temp\nszF70B.exe
C:\Users\User\AppData\Local\Temp\optprosetup.exe
C:\Users\User\AppData\Local\Temp\setup_472.exe
C:\Users\User\AppData\Local\Temp\vcredist_x64.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-29 14:50

==================== End Of Log ============================

[/CODE]

Nero555 29.01.2015 15:33

FRST Logdateien (1)
 
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by User (administrator) on USER-MSI on 29-01-2015 15:42:42
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files (x86)\PHotkey\AsLdrSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(Intel Corporation) C:\Windows\system32\igfxtray.exe
(Intel Corporation) C:\Windows\system32\hkcmd.exe
(Intel Corporation) C:\Windows\system32\igfxpers.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
() C:\Program Files\Time Stamp\IBP\FsLoader.exe
(FarStone Technology, Inc.) C:\Program Files\Time Stamp\IBP\VBPTask.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
() C:\Program Files (x86)\PHotkey\Atouch64.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\MsOsd.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\system32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\system32\snmp.exe
(Microsoft Corporation) C:\Windows\system32\mqsvc.exe
(Microsoft Corporation) C:\Windows\system32\CISVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exeA
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\dllhost.exe
(Microsoft Corporation) C:\Windows\system32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [6275424 2014-05-13] (Sentelic Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\...\Run: [Gameo] => C:\Users\User\AppData\Roaming\Gameo\gameo.exe "C:\Users\User\AppData\Roaming\Gameo\gameo.dat" mode:minimized
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\...\Run: [GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [856904 2015-01-09] (Google Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2608712115-2613374988-3172207222-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: No Name -> {986c37a1-7b65-476f-80dc-54f80bd4b0d6} ->  No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2608712115-2613374988-3172207222-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\searchplugins\google-avast.xml
FF Extension: firesshnightlightws - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\Extensions\firessh@nightlight.ws [2015-01-29]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-20]

Chrome:
=======
CHR HomePage: Default -> https://www.google.de/
CHR StartupUrls: Default -> "https://twitter.com/", "https://www.youtube.com/feed/subscriptions", "https://www.google.de/"
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-21]
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-21]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-21]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-21]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-21]
CHR Extension: (Adblock Plus) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-01-21]
CHR Extension: (Google-Suche) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-21]
CHR Extension: (Google Tabellen) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-21]
CHR Extension: (AdBlock) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-21]
CHR Extension: (Avast Online Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-01-21]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-21]
CHR Extension: (Google Mail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-21]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-01-20]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-20]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2010-12-10] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-20] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2015-01-20] (Avast Software)
S2 d924d8dc; c:\Program Files (x86)\Optimizer Pro 3.33\OptProMon.dll [1597008 2015-01-21] ()
R2 DriveClone Network Client IBP; C:\Program Files\Time Stamp\IBP\fsloader.exe [126976 2009-08-17] () [File not signed]
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-12-10] ()
S2 iprip; C:\Windows\System32\iprip.dll [35328 2009-07-14] (Microsoft Corporation)
S2 MElGfYhtuP; C:\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe [2733872 2015-01-22] (Time Lapse Solutions)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
S2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 SNMP; C:\Windows\System32\snmp.exe [49664 2010-11-21] (Microsoft Corporation)
R2 SNMP; C:\Windows\SysWOW64\snmp.exe [47616 2010-11-21] (Microsoft Corporation)
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1025920 2015-01-23] (Enigma Software Group USA, LLC.)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-20] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2015-01-20] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-20] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-20] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-20] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-20] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-20] ()
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-01-23] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-01-23] ()
R3 FARMNTIO; c:\windows\system32\drivers\farmntio.sys [24664 2011-04-18] ()
R3 fspad_win764; C:\Windows\System32\DRIVERS\fspad_win764.sys [173408 2014-05-13] (Sentelic Corporation)
S3 fspad_wlh64; C:\Windows\System32\DRIVERS\fspad_wlh64.sys [68608 2010-11-08] (Sentelic Corporation) [File not signed]
R2 HCDisk; C:\Windows\System32\Drivers\HCDisk.sys [66136 2011-01-04] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2014-04-24] (Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [129224 2013-11-29] (Qualcomm Atheros Co., Ltd.)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2010-12-10] (PEGATRON)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [9112792 2014-05-02] (Realtek Semiconductor Corp.)
U4 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2015-01-20] (Avast Software)
R0 VVBackd5; C:\Windows\System32\Drivers\VVBackd5.sys [162392 2011-07-12] ()
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-29 15:42 - 2015-01-29 15:43 - 00017718 _____ () C:\Users\User\Desktop\FRST.txt
2015-01-29 14:58 - 2015-01-29 15:09 - 00028076 _____ () C:\Users\User\Downloads\Addition.txt
2015-01-29 14:57 - 2015-01-29 15:09 - 00127525 _____ () C:\Users\User\Downloads\FRST.txt
2015-01-29 14:56 - 2015-01-29 15:42 - 00000000 ____D () C:\FRST
2015-01-29 14:56 - 2015-01-29 14:56 - 02130432 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2015-01-29 13:34 - 2015-01-29 13:35 - 00041670 _____ () C:\windows\iis7.log
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\SysWOW64\BestPractices
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\system32\msmq
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\system32\BestPractices
2015-01-29 13:31 - 2015-01-29 13:30 - 00000862 _____ () C:\windows\system32\termcap
2015-01-29 13:30 - 2015-01-29 13:31 - 00000000 ____D () C:\inetpub
2015-01-29 13:22 - 2015-01-29 13:22 - 00462888 _____ () C:\Users\User\Downloads\SpyHunterKiller.exe
2015-01-23 21:14 - 2015-01-23 21:14 - 00000000 ____D () C:\windows\pss
2015-01-23 19:14 - 2015-01-23 19:14 - 00003322 _____ () C:\windows\System32\Tasks\SpyHunter4Startup
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 ____D () C:\Users\User\AppData\Roaming\Enigma Software Group
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 ____D () C:\sh4ldr
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 _____ () C:\autoexec.bat
2015-01-23 19:13 - 2015-01-23 19:13 - 00022704 _____ () C:\windows\system32\Drivers\EsgScanner.sys
2015-01-23 19:13 - 2015-01-23 19:13 - 00000000 ____D () C:\Program Files\Enigma Software Group
2015-01-23 18:57 - 2015-01-23 18:57 - 00000247 _____ () C:\windows\system32\2015-01-23-17-57-45.092-aswFe.exe-5340.log
2015-01-23 18:57 - 2015-01-23 18:57 - 00000197 _____ () C:\windows\system32\2015-01-23-17-57-38.027-AvastVBoxSVC.exe-1312.log
2015-01-23 18:47 - 2015-01-25 23:08 - 00000000 ____D () C:\Users\User\AppData\Local\ZombieNews
2015-01-23 17:59 - 2015-01-23 18:47 - 00000000 ____D () C:\AdwCleaner
2015-01-23 17:49 - 2015-01-23 17:49 - 00000197 _____ () C:\windows\system32\2015-01-23-16-49-31.016-AvastVBoxSVC.exe-3784.log
2015-01-23 16:23 - 2015-01-23 16:23 - 00000197 _____ () C:\windows\system32\2015-01-23-15-23-49.010-AvastVBoxSVC.exe-6012.log
2015-01-23 16:08 - 2015-01-23 16:08 - 00000000 ____D () C:\Users\User\AppData\Local\com
2015-01-23 16:06 - 2015-01-23 16:06 - 00000000 ____D () C:\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f
2015-01-23 15:52 - 2015-01-23 15:52 - 00000197 _____ () C:\windows\system32\2015-01-23-14-52-16.032-AvastVBoxSVC.exe-5244.log
2015-01-23 13:21 - 2015-01-23 18:55 - 00001557 _____ () C:\Users\User\Desktop\Chrome.lnk
2015-01-23 13:14 - 2015-01-23 13:14 - 00000197 _____ () C:\windows\system32\2015-01-23-12-14-23.097-AvastVBoxSVC.exe-3880.log
2015-01-23 13:12 - 2015-01-23 13:12 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2015-01-22 18:29 - 2015-01-23 15:58 - 00000000 ____D () C:\Users\User\AppData\Roaming\Apple Computer
2015-01-22 18:29 - 2015-01-22 18:29 - 00001793 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-01-22 18:29 - 2015-01-22 18:29 - 00000000 ____D () C:\Users\User\AppData\Local\Apple Computer
2015-01-22 18:29 - 2015-01-22 18:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-01-22 18:28 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\windows\system32\Drivers\GEARAspiWDM.sys
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\Program Files\iTunes
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-22 18:26 - 2015-01-22 18:26 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-01-22 18:26 - 2015-01-22 18:26 - 00000000 ____D () C:\Program Files\iPod
2015-01-22 18:25 - 2015-01-22 18:25 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\windows\System32\Tasks\Apple
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\Users\User\AppData\Local\Apple
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2015-01-22 18:24 - 2015-01-22 18:26 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-01-22 18:23 - 2015-01-22 18:23 - 00000000 ____D () C:\Program Files\Bonjour
2015-01-22 18:23 - 2015-01-22 18:23 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-01-22 18:21 - 2015-01-22 18:25 - 00000000 ____D () C:\ProgramData\Apple
2015-01-22 18:18 - 2015-01-22 18:20 - 122418480 _____ (Apple Inc.) C:\Users\User\Downloads\iTunes64Setup.exe
2015-01-22 12:40 - 2015-01-22 12:40 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps
2015-01-22 12:36 - 2015-01-22 12:36 - 00000000 ____D () C:\Users\User\AppData\Local\Macromedia
2015-01-22 12:32 - 2015-01-29 13:18 - 00003276 _____ () C:\windows\System32\Tasks\avastBCLRestartS-1-5-21-2608712115-2613374988-3172207222-1001
2015-01-22 12:30 - 2015-01-22 12:31 - 00000000 ____D () C:\Users\User\AppData\Roaming\Mozilla
2015-01-22 12:30 - 2015-01-22 12:31 - 00000000 ____D () C:\Users\User\AppData\Local\Mozilla
2015-01-22 12:29 - 2015-01-22 12:29 - 00000000 ____D () C:\ProgramData\xfIwQZvgdh
2015-01-22 12:24 - 2015-01-22 12:25 - 00000197 _____ () C:\windows\system32\2015-01-22-11-24-48.051-AvastVBoxSVC.exe-3272.log
2015-01-21 23:15 - 2015-01-21 23:15 - 00000197 _____ () C:\windows\system32\2015-01-21-22-15-00.076-AvastVBoxSVC.exe-4408.log
2015-01-21 22:09 - 2015-01-21 22:10 - 00021976 _____ () C:\windows\system32\Drivers\SPPD.sys
2015-01-21 22:05 - 2015-01-21 22:05 - 00000280 _____ () C:\windows\system32\2015-01-21-21-05-13.073-aswFe.exe-6612.log
2015-01-21 22:04 - 2015-01-21 22:04 - 00000000 ____D () C:\Program Files (x86)\ClickCaption_1.10.0.6
2015-01-21 22:01 - 2015-01-21 22:01 - 00000000 ___HD () C:\Users\User\AppData\Roaming\GoldenGate
2015-01-21 22:00 - 2015-01-21 22:00 - 00000170 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2015-01-21 21:47 - 2015-01-21 21:47 - 00000000 ____D () C:\ProgramData\McAfee
2015-01-21 21:18 - 2015-01-21 21:18 - 00000000 ____D () C:\Users\User\AppData\Roaming\Opera Software
2015-01-21 21:18 - 2015-01-21 21:18 - 00000000 ____D () C:\Users\User\AppData\Local\Opera Software
2015-01-21 21:17 - 2015-01-29 12:48 - 00003852 _____ () C:\windows\System32\Tasks\Opera scheduled Autoupdate 1421871456
2015-01-21 21:17 - 2015-01-21 21:17 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-01-21 21:16 - 2015-01-29 12:48 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-01-21 21:03 - 2015-01-21 21:03 - 00000280 _____ () C:\windows\system32\2015-01-21-20-03-26.006-aswFe.exe-3824.log
2015-01-21 20:40 - 2015-01-22 12:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-21 20:39 - 2015-01-29 14:44 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-21 20:39 - 2015-01-29 12:37 - 00001102 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-21 20:39 - 2015-01-21 20:40 - 00000000 ____D () C:\Users\User\AppData\Local\Google
2015-01-21 20:39 - 2015-01-21 20:40 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-21 20:39 - 2015-01-21 20:39 - 00004102 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-01-21 20:39 - 2015-01-21 20:39 - 00003850 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-01-21 20:34 - 2015-01-21 20:38 - 00000000 ____D () C:\Users\User\AppData\Local\Deployment
2015-01-21 20:34 - 2015-01-21 20:34 - 00000000 ____D () C:\Users\User\AppData\Local\Apps\2.0
2015-01-21 20:32 - 2015-01-21 20:32 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.33
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieUserList
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieSiteList
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieBrowserModeList
2015-01-21 20:27 - 2015-01-21 20:27 - 00000197 _____ () C:\windows\system32\2015-01-21-19-27-14.097-AvastVBoxSVC.exe-3556.log
2015-01-21 16:40 - 2015-01-21 16:40 - 00000197 _____ () C:\windows\system32\2015-01-21-15-40-25.087-AvastVBoxSVC.exe-2804.log
2015-01-21 12:12 - 2015-01-21 12:12 - 00000197 _____ () C:\windows\system32\2015-01-21-11-12-09.083-AvastVBoxSVC.exe-3988.log
2015-01-21 11:42 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-01-21 11:42 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-01-21 11:42 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-01-21 11:42 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-01-21 11:42 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-01-21 11:04 - 2015-01-21 11:04 - 00000197 _____ () C:\windows\system32\2015-01-21-10-04-40.059-AvastVBoxSVC.exe-2880.log
2015-01-21 10:35 - 2014-06-27 03:08 - 02777088 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2015-01-21 10:35 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2vdec.dll
2015-01-21 10:33 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2015-01-21 10:33 - 2014-05-08 10:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2015-01-21 10:33 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2015-01-21 10:33 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-01-21 10:33 - 2011-02-25 07:19 - 02871808 _____ (Microsoft Corporation) C:\windows\explorer.exe
2015-01-21 10:33 - 2011-02-25 06:30 - 02616320 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2015-01-21 10:32 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\windows\SysWOW64\d2d1.dll
2015-01-21 10:32 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2015-01-21 10:32 - 2011-03-11 07:41 - 00410496 _____ (Intel Corporation) C:\windows\system32\Drivers\iaStorV.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00166272 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvstor.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00148352 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvraid.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00107904 _____ (Advanced Micro Devices) C:\windows\system32\Drivers\amdsata.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00027008 _____ (Advanced Micro Devices) C:\windows\system32\Drivers\amdxata.sys
2015-01-21 10:32 - 2011-03-11 07:33 - 02565632 _____ (Microsoft Corporation) C:\windows\system32\esent.dll
2015-01-21 10:32 - 2011-03-11 07:30 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\fsutil.exe
2015-01-21 10:32 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\windows\SysWOW64\esent.dll
2015-01-21 10:32 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\fsutil.exe
2015-01-21 10:32 - 2011-03-11 05:37 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2015-01-21 10:31 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDYAK.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDTAT.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU1.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDBASH.DLL
2015-01-21 10:31 - 2014-07-08 23:38 - 00419992 _____ () C:\windows\system32\locale.nls
2015-01-21 10:31 - 2014-07-08 23:30 - 00419992 _____ () C:\windows\SysWOW64\locale.nls
2015-01-21 10:31 - 2014-06-24 04:29 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-01-21 10:31 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2015-01-21 10:31 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2015-01-21 10:31 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\windows\splwow64.exe
2015-01-21 10:27 - 2015-01-21 10:28 - 00000197 _____ () C:\windows\system32\2015-01-21-09-27-50.087-AvastVBoxSVC.exe-2660.log
2015-01-21 10:08 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2015-01-21 10:08 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-21 10:08 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-21 10:08 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2015-01-21 10:07 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2015-01-21 10:07 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2015-01-21 10:07 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-01-21 10:07 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-01-21 10:07 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2015-01-21 10:07 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2015-01-21 10:07 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-01-21 10:07 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2015-01-21 10:07 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2015-01-21 10:07 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-01-21 10:07 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2015-01-21 10:03 - 2015-01-21 11:57 - 04190942 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2015-01-21 09:56 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2015-01-21 09:56 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2015-01-21 09:56 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2015-01-21 09:56 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2015-01-21 09:56 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2015-01-21 09:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-01-21 09:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-01-21 09:35 - 2015-01-21 09:35 - 00000197 _____ () C:\windows\system32\2015-01-21-08-35-45.076-AvastVBoxSVC.exe-2464.log
2015-01-21 09:25 - 2015-01-21 09:25 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-01-21 09:25 - 2015-01-21 09:25 - 00000000 ____D () C:\windows\system32\appraiser
2015-01-21 09:23 - 2015-01-21 09:24 - 00000197 _____ () C:\windows\system32\2015-01-21-08-23-41.005-AvastVBoxSVC.exe-168.log
2015-01-21 09:21 - 2015-01-21 09:21 - 1140010868 _____ () C:\windows\MEMORY.DMP
2015-01-21 09:21 - 2015-01-21 09:21 - 00000000 ____D () C:\windows\Minidump
2015-01-20 21:00 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-01-20 21:00 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-01-20 21:00 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2015-01-20 21:00 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-01-20 20:01 - 2015-01-20 20:01 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-01-20 20:01 - 2015-01-20 20:01 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-01-20 20:01 - 2015-01-20 20:01 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-01-20 20:01 - 2015-01-20 20:01 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat
2015-01-20 20:01 - 2015-01-20 20:01 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2015-01-20 20:01 - 2015-01-20 20:01 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-01-20 20:01 - 2015-01-20 20:01 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-01-20 20:01 - 2015-01-20 20:01 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-01-20 20:01 - 2015-01-20 20:01 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01682432 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01643520 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01247744 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01238528 _____ (Microsoft Corporation) C:\windows\system32\d3d10.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01175552 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01158144 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsPrint.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01080832 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00648192 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00604160 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10level9.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00522752 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsGdiConverter.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00363008 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00333312 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\d3d10core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00293376 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00249856 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10_1core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00245248 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00207872 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecsExt.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00194560 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00187392 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAnimation.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00161792 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10_1.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00010752 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00010752 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00009728 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00009728 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00002560 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00002560 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-01-20 14:53 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-01-20 14:53 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2015-01-20 14:53 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-01-20 14:53 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-01-20 14:53 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-01-20 14:53 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-01-20 14:53 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2015-01-20 14:53 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2015-01-20 14:53 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2015-01-20 14:53 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\windows\system32\WUDFx.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe
2015-01-20 14:51 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\windows\system32\WUDFCoinstaller.dll
2015-01-20 14:51 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys
2015-01-20 14:51 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys
2015-01-20 14:51 - 2012-06-02 15:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-01-20 14:27 - 2015-01-20 14:27 - 00000197 _____ () C:\windows\system32\2015-01-20-13-27-06.064-AvastVBoxSVC.exe-2964.log
2015-01-20 13:56 - 2015-01-20 13:56 - 00000197 _____ () C:\windows\system32\2015-01-20-12-56-28.062-AvastVBoxSVC.exe-4596.log
2015-01-20 13:20 - 2015-01-20 13:20 - 00000247 _____ () C:\windows\system32\2015-01-20-12-20-48.046-aswFe.exe-6056.log
2015-01-20 13:13 - 2015-01-20 13:20 - 00000247 _____ () C:\windows\system32\2015-01-20-12-13-29.071-aswFe.exe-4372.log
2015-01-20 13:13 - 2015-01-20 13:13 - 00000197 _____ () C:\windows\system32\2015-01-20-12-13-23.011-AvastVBoxSVC.exe-4364.log
2015-01-20 13:04 - 2015-01-20 13:04 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVAST Software
2015-01-20 13:00 - 2015-01-20 13:00 - 00000000 ____D () C:\windows\SysWOW64\vbox
2015-01-20 13:00 - 2015-01-20 13:00 - 00000000 ____D () C:\windows\system32\vbox
2015-01-20 12:59 - 2015-01-20 12:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-01-20 12:58 - 2015-01-29 12:39 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2015-01-20 12:58 - 2015-01-21 09:40 - 01050432 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00436624 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00364512 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2015-01-20 12:58 - 2015-01-20 12:58 - 00267632 _____ () C:\windows\system32\Drivers\aswVmm.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00116728 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00083280 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2015-01-20 12:58 - 2015-01-20 12:58 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys
2015-01-20 12:57 - 2015-01-20 12:57 - 00000000 ____D () C:\Program Files\AVAST Software
2015-01-20 12:56 - 2015-01-20 12:57 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-01-20 12:56 - 2015-01-20 12:56 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-01-20 12:56 - 2015-01-20 12:56 - 00002029 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-01-20 12:55 - 2015-01-20 12:55 - 00001080 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\windows\SysWOW64\Adobe
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2015-01-20 12:54 - 2015-01-20 12:54 - 00319912 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2015-01-20 12:54 - 2015-01-20 12:54 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\ProgramData\Sun
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\Program Files\Java
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-20 12:53 - 2015-01-21 22:02 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
2015-01-20 12:53 - 2015-01-20 12:56 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-20 12:53 - 2015-01-20 12:56 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-01-20 12:52 - 2015-01-20 12:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-01-20 12:52 - 2015-01-20 12:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-01-20 12:51 - 2015-01-22 12:32 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-20 12:51 - 2015-01-22 12:32 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\ProgramData\Mozilla
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-20 12:48 - 2015-01-29 15:24 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-01-20 12:48 - 2015-01-25 17:24 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-01-20 12:48 - 2015-01-25 17:24 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-20 12:48 - 2015-01-25 17:24 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-01-20 12:48 - 2015-01-20 12:48 - 00000000 ____D () C:\windows\system32\Macromed
2015-01-19 14:18 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE
2015-01-19 13:38 - 2015-01-20 20:35 - 00041009 _____ () C:\windows\IE11_main.log
2015-01-19 12:14 - 2015-01-19 12:16 - 00000000 ____D () C:\windows\system32\MRT
2015-01-19 12:14 - 2014-12-31 13:12 - 113365784 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-01-19 12:12 - 2015-01-19 12:12 - 00000000 ____D () C:\Users\User\AppData\Local\WindowsUpdate
2015-01-19 12:12 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\windows\system32\icardres.dll
2015-01-19 12:12 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardres.dll
2015-01-19 12:12 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\windows\SysWOW64\TsWpfWrp.exe
2015-01-19 12:12 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
2015-01-19 12:12 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\windows\system32\icardagt.exe
2015-01-19 12:12 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\windows\system32\infocardapi.dll
2015-01-19 12:12 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardagt.exe
2015-01-19 12:12 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\windows\SysWOW64\infocardapi.dll
2015-01-19 12:10 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2015-01-19 12:10 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2015-01-19 12:10 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\windows\SysWOW64\certutil.exe
2015-01-19 12:10 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\certenc.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-01-19 12:09 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-01-19 12:09 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-01-19 12:09 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-01-19 12:08 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2015-01-19 12:08 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2015-01-19 12:08 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2015-01-19 12:08 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2015-01-19 12:08 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2015-01-19 12:08 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2015-01-19 12:08 - 2014-03-04 10:44 - 00722944 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2015-01-19 12:08 - 2014-03-04 10:44 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-01-19 12:08 - 2014-03-04 10:44 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\objsel.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\windows\SysWOW64\adprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\capiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsroam.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredprovider.dll
2015-01-19 12:08 - 2014-03-04 10:16 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll
2015-01-19 12:08 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2015-01-19 12:08 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe
2015-01-19 12:08 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_isv.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_ssp_isv.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_ssp.dll
2015-01-19 12:08 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdrm.dll
2015-01-19 12:08 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_isv.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_ssp.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_ssp_isv.exe
2015-01-19 12:08 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2015-01-19 12:08 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2015-01-19 12:08 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2015-01-19 12:08 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys
2015-01-19 12:08 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\Wdfres.dll
2015-01-19 12:08 - 2012-11-28 23:56 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-01-19 12:08 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\rdpwsx.dll


cosinus 29.01.2015 15:36

Bitte die Logs in CODE-Tags setzen, das doppelt gepostete Addition.log löschen. Du hast noch bis ca. 16:10 heute Zeit, deinen Beitrag entsprechend zu korrigieren.

Außerdem:

Zukünftig bitte beachten:
Zitat:

Running from C:\Users\User\Downloads
Leider hast du unsere Anleitung nicht richtig befolgt:
Bitte alle Tools direkt auf den Desktop downloaden bzw. dorthin verschieben und vom Desktop starten, da unsere Anleitungen daraufhin ausgelegt sind.
Zudem lassen sich dann am Ende der Bereinigung alle verwendeten Tools sehr einfach entfernen.
Alle Tools bis zum Ende der Bereinigung auf dem Desktop lassen, evtl. benötigen wir manche öfter.

Nero555 29.01.2015 15:55

FRST Addition
 
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2015
Ran by User at 2015-01-29 15:43:37
Running from C:\Users\User\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 16.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.6.156 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.8.1217.36096 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.8.1217.36096 - Alcor Micro Corp.) Hidden
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.36 - Atheros Communications Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1007.2702 - Micro-Star International Co., Ltd.)
Click Caption 1.10.0.6 (HKLM-x32\...\ClickCaption_1.10.0.6) (Version: 1.10.0.6 - ClickCaption) <==== ATTENTION
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.37.50 - Conexant)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Finger Sensing Pad Driver (HKLM\...\{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}) (Version: 8.8.0.9 - Sentelic)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.99 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417071FF}) (Version: 7.0.710 - Oracle)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 35.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0 - Mozilla)
MSI Remind Manager (HKLM-x32\...\{89F17DC5-A776-4DF4-8CD1-FAEF29BCE51A}) (Version: 1.11.0104 - MSI)
MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1801 - Micro-Star International Co., Ltd.)
Opera Stable 27.0.1689.54 (HKLM-x32\...\Opera 27.0.1689.54) (Version: 27.0.1689.54 - Opera Software ASA)
PC Sound (HKLM\...\{F3C66EC8-2F33-452D-9CFF-E8C886B3ECC4}) (Version: 1.11.0200 - SRS Labs, Inc.)
PHotkey (HKLM-x32\...\{24047BE4-329D-46F7-9689-8684C7A1CFBB}) (Version: 1.00.0010 - )
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.20.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.20.0 - Renesas Electronics Corporation) Hidden
SpyHunter 4 (HKLM-x32\...\SpyHunter) (Version: 4.18.9.4384 - Enigma Software Group, LLC)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Time Stamp (HKLM-x32\...\Time Stamp) (Version: 1.0.0.20110711 - Time Stamp Software, Inc.)
USB2.0 UVC 1.3M Webcam (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10275 - Realtek Semiconductor Corp.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{B39AA98E-C966-46C9-ACA2-D2586E300988}) (Version: 2.29.0.3 - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1D7AFB94-A35F-4B66-AFD6-835D0CCE590A} - System32\Tasks\avastBCLRestartS-1-5-21-2608712115-2613374988-3172207222-1001 => Chrome.exe
Task: {5AACC5E5-EBE4-481F-A36C-AB4006FCBA70} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {94942A87-B26C-4606-BBE6-1F7D27FE0F4A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-21] (Google Inc.)
Task: {94C3F196-04F6-461D-B74E-1E026BD544A6} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-01-23] (Enigma Software Group USA, LLC.)
Task: {9D07084A-F4DC-4F63-AB1F-D1A7BBAF9635} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {B6FEBACB-40C4-42D1-9BF2-F5CA91DF8601} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-21] (Google Inc.)
Task: {FAFC338D-5F94-48D0-B2E8-56F884FC5A81} - System32\Tasks\Opera scheduled Autoupdate 1421871456 => C:\Program Files (x86)\Opera\launcher.exe [2015-01-23] (Opera Software)
Task: {FBDED84C-4500-4D63-B3BB-65F540F4B779} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-01-20] (AVAST Software)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-08-11 18:27 - 2010-12-10 20:19 - 00104968 ____R () C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00159752 ____R () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
2011-08-11 18:27 - 2011-07-21 02:51 - 00824328 _____ () C:\Program Files (x86)\PHotkey\PHotkey.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00117256 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00121864 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2011-06-03 11:08 - 2011-04-15 03:16 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00126976 ____N () C:\Program Files\Time Stamp\IBP\fsloader.exe
2011-08-11 18:27 - 2010-12-17 22:04 - 00449032 ____R () C:\Program Files (x86)\PHotkey\ATouch64.exe
2011-08-11 18:27 - 2010-12-27 22:14 - 00776200 ____R () C:\Program Files (x86)\PHotkey\PVDesktop.exe
2011-08-11 18:27 - 2011-04-12 22:32 - 00483336 ____R () C:\Program Files (x86)\PHotkey\PVDAgent.exe
2015-01-20 12:57 - 2015-01-20 12:57 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2015-01-20 12:57 - 2015-01-20 12:57 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2015-01-28 12:48 - 2015-01-28 12:48 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15012800\algo.dll
2015-01-20 12:57 - 2015-01-20 12:57 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2015-01-29 12:41 - 2015-01-29 12:41 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15012900\algo.dll
2011-08-11 18:27 - 2010-12-10 20:19 - 00973432 ____R () C:\Program Files (x86)\PHotkey\acAuth.dll
2011-08-11 18:27 - 2010-12-10 20:19 - 00129544 ____R () C:\Program Files (x86)\PHotkey\GFNEX.dll
2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-20 12:58 - 2015-01-20 12:58 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-01-19 11:20 - 2010-12-07 14:41 - 00151654 ____N () C:\Program Files\Time Stamp\IBP\Snapshot.dll
2015-01-19 11:20 - 2010-03-08 14:53 - 00073779 ____N () C:\Program Files\Time Stamp\IBP\UVFilter.dll
2015-01-19 11:20 - 2010-04-07 11:47 - 00090112 ____N () C:\Program Files\Time Stamp\IBP\VBcfgEx.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00057403 ____N () C:\Program Files\Time Stamp\IBP\DiskMsg.dll
2015-01-19 11:20 - 2011-01-04 10:09 - 00192607 ____N () C:\Program Files\Time Stamp\IBP\vbioctl.dll
2015-01-19 11:20 - 2010-08-30 11:16 - 00102445 ____N () C:\Program Files\Time Stamp\REG\FsAct.dll
2015-01-19 11:20 - 2010-08-29 12:11 - 00131119 ____N () C:\Program Files\Time Stamp\REG\RegKern.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00036864 ____N () C:\Program Files\Time Stamp\IBP\fssti.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00040960 ____N () C:\Program Files\Time Stamp\IBP\multidsk.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libglesv2.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libegl.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\pdf.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 14913352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SRS PC Sound.lnk => C:\windows\pss\SRS PC Sound.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WebBrowserFastPlayer.lnk => C:\windows\pss\WebBrowserFastPlayer.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AmIcoSinglun64 => c:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
MSCONFIG\startupreg: GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: NUSB3MON => "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
MSCONFIG\startupreg: SmartAudio => C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-2608712115-2613374988-3172207222-500 - Administrator - Disabled)
Gast (S-1-5-21-2608712115-2613374988-3172207222-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2608712115-2613374988-3172207222-1002 - Limited - Enabled)
User (S-1-5-21-2608712115-2613374988-3172207222-1001 - Administrator - Enabled) => C:\Users\User

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/29/2015 01:31:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm chrome.exe, Version 39.0.2171.99 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: e78

Startzeit: 01d03bbdbfa9595c

Endzeit: 20

Anwendungspfad: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Berichts-ID: a6d51d85-a7b2-11e4-9377-e069955ae425

Error: (01/29/2015 01:28:05 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\windows\servicing\TrustedInstaller.exe; Beschreibung = Windows Modules Installer; Fehler = 0x80070422).

Error: (01/29/2015 00:49:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Spyhunter4.exe, Version 4.18.9.4384 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 7d0

Startzeit: 01d03bb7e50dcc4a

Endzeit: 10

Anwendungspfad: C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe

Berichts-ID: d9cb65ef-a7ac-11e4-9377-e069955ae425

Error: (01/29/2015 00:38:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/28/2015 09:17:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: launcher.exe_Opera Internet Browser, Version: 26.0.1656.60, Zeitstempel: 0x5490344f
Name des fehlerhaften Moduls: launcher_lib.dll, Version: 0.0.0.0, Zeitstempel: 0x54903446
Ausnahmecode: 0x80000003
Fehleroffset: 0x00014f40
ID des fehlerhaften Prozesses: 0x8c0
Startzeit der fehlerhaften Anwendung: 0xlauncher.exe_Opera Internet Browser0
Pfad der fehlerhaften Anwendung: launcher.exe_Opera Internet Browser1
Pfad des fehlerhaften Moduls: launcher.exe_Opera Internet Browser2
Berichtskennung: launcher.exe_Opera Internet Browser3

Error: (01/28/2015 09:13:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2134811

Error: (01/28/2015 09:13:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2134811

Error: (01/28/2015 09:13:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/28/2015 08:37:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1045

Error: (01/28/2015 08:37:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1045


System errors:
=============
Error: (01/29/2015 01:34:15 PM) (Source: SNMP) (EventID: 1500) (User: )
Description: Beim Zugreifen auf den Registrierungsschlüssel SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration ist ein Fehler aufgetreten.

Error: (01/29/2015 00:40:34 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Type" aufgrund folgenden Fehlers fehlgeschlagen:
%%5

Error: (01/29/2015 00:39:25 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1053AvastVBoxSvc{F319F1B8-7587-4146-AF9C-0D6D77819BF1}

Error: (01/29/2015 00:39:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AvastVBox COM Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (01/29/2015 00:39:24 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst AvastVBox COM Service erreicht.

Error: (01/29/2015 00:38:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MElGfYhtuP" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (01/29/2015 00:38:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MElGfYhtuP erreicht.

Error: (01/28/2015 01:00:29 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Type" aufgrund folgenden Fehlers fehlgeschlagen:
%%5

Error: (01/28/2015 01:00:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MElGfYhtuP" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (01/28/2015 01:00:00 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MElGfYhtuP erreicht.


Microsoft Office Sessions:
=========================
Error: (01/29/2015 01:31:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: chrome.exe39.0.2171.99e7801d03bbdbfa9595c20C:\Program Files (x86)\Google\Chrome\Application\chrome.exea6d51d85-a7b2-11e4-9377-e069955ae425

Error: (01/29/2015 01:28:05 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\windows\servicing\TrustedInstaller.exeWindows Modules Installer0x80070422

Error: (01/29/2015 00:49:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Spyhunter4.exe4.18.9.43847d001d03bb7e50dcc4a10C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exed9cb65ef-a7ac-11e4-9377-e069955ae425

Error: (01/29/2015 00:38:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/28/2015 09:17:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: launcher.exe_Opera Internet Browser26.0.1656.605490344flauncher_lib.dll0.0.0.0549034468000000300014f408c001d03b3780052fe2C:\Program Files (x86)\Opera\launcher.exeC:\Program Files (x86)\Opera\26.0.1656.60\launcher_lib.dllbf6fad93-a72a-11e4-8e77-e069955ae425

Error: (01/28/2015 09:13:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2134811

Error: (01/28/2015 09:13:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2134811

Error: (01/28/2015 09:13:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/28/2015 08:37:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1045

Error: (01/28/2015 08:37:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1045


CodeIntegrity Errors:
===================================
  Date: 2015-01-29 15:42:39.720
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-29 15:42:39.560
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-29 15:42:30.084
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-29 15:42:29.904
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-29 15:35:59.620
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-29 15:35:59.406
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-29 15:34:48.389
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-29 15:34:48.071
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-29 15:33:22.188
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-29 15:33:22.032
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 66%
Total physical RAM: 4008.29 MB
Available physical RAM: 1362.8 MB
Total Pagefile: 8014.76 MB
Available Pagefile: 5057.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:173.39 GB) (Free:101.6 GB) NTFS
Drive d: (Data) (Fixed) (Total:115.6 GB) (Free:104.66 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 5A30F560)
Partition 1: (Not Active) - (Size=9 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=173.4 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=115.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================


cosinus 29.01.2015 16:13

Edit: bitte MBAR ausführen ;)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Nero555 29.01.2015 17:03

mbar Logfile
 
Code:

Malwarebytes Anti-Rootkit BETA 1.08.3.1004
www.malwarebytes.org

Database version:
  main:    v2015.01.29.07
  rootkit: v2015.01.14.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.17501
User :: USER-MSI [administrator]

29.01.2015 16:46:02
mbar-log-2015-01-29 (16-46-02).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 336988
Time elapsed: 12 minute(s), 56 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)


cosinus 30.01.2015 08:46

Adware/Junkware/Toolbars entfernen

(alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!)

1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Nero555 30.01.2015 13:15

AdwClenaer Bericht
 
Code:

# AdwCleaner v4.109 - Bericht erstellt am 30/01/2015 um 12:31:38
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-01-26.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : User - USER-MSI
# Gestartet von : C:\Users\User\Desktop\AdwCleaner_4.109.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Users\User\AppData\Local\ZombieNews
Datei Gelöscht : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{986C37A1-7B65-476F-80DC-54F80BD4B0D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyHunter
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Mozilla Firefox v35.0 (x86 de)


-\\ Google Chrome v39.0.2171.99


-\\ Opera v27.0.1689.54


*************************

AdwCleaner[R0].txt - [29715 octets] - [23/01/2015 18:00:16]
AdwCleaner[R1].txt - [2228 octets] - [23/01/2015 18:13:58]
AdwCleaner[R2].txt - [2288 octets] - [23/01/2015 18:17:15]
AdwCleaner[R3].txt - [1221 octets] - [23/01/2015 18:24:46]
AdwCleaner[R4].txt - [1342 octets] - [23/01/2015 18:33:05]
AdwCleaner[R5].txt - [2588 octets] - [23/01/2015 18:37:37]
AdwCleaner[R6].txt - [1626 octets] - [23/01/2015 18:45:57]
AdwCleaner[R7].txt - [325 octets] - [30/01/2015 12:22:41]
AdwCleaner[R8].txt - [2397 octets] - [30/01/2015 12:28:12]
AdwCleaner[S0].txt - [27757 octets] - [23/01/2015 18:04:32]
AdwCleaner[S1].txt - [2349 octets] - [23/01/2015 18:18:55]
AdwCleaner[S2].txt - [1283 octets] - [23/01/2015 18:26:40]
AdwCleaner[S3].txt - [2649 octets] - [23/01/2015 18:39:09]
AdwCleaner[S4].txt - [2318 octets] - [30/01/2015 12:31:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [2378 octets] ##########

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Home Premium x64
Ran by User on 30.01.2015 at 12:39:45,98
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.01.2015 at 12:51:08,08
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by User (administrator) on USER-MSI on 30-01-2015 13:06:57
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
() C:\Program Files (x86)\PHotkey\AsLdrSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\system32\igfxtray.exe
(Intel Corporation) C:\Windows\system32\hkcmd.exe
(Intel Corporation) C:\Windows\system32\igfxpers.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\system32\CISVC.EXE
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
() C:\Program Files\Time Stamp\IBP\FsLoader.exe
(FarStone Technology, Inc.) C:\Program Files\Time Stamp\IBP\VBPTask.exe
(Microsoft Corporation) C:\Windows\system32\mqsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corporation) C:\Windows\system32\TCPSVCS.EXE
(Microsoft Corporation) C:\Windows\system32\snmp.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\PHotkey\Atouch64.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\MsOsd.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\system32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [6275424 2014-05-13] (Sentelic Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\...\Run: [Gameo] => C:\Users\User\AppData\Roaming\Gameo\gameo.exe "C:\Users\User\AppData\Roaming\Gameo\gameo.dat" mode:minimized
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\...\Run: [GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [856904 2015-01-09] (Google Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2608712115-2613374988-3172207222-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2608712115-2613374988-3172207222-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.111 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\searchplugins\google-avast.xml
FF Extension: firesshnightlightws - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\Extensions\firessh@nightlight.ws [2015-01-29]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-20]

Chrome:
=======
CHR HomePage: Default -> https://www.google.de/
CHR StartupUrls: Default -> "https://twitter.com/", "https://www.youtube.com/feed/subscriptions", "https://www.google.de/"
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-21]
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-21]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-21]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-21]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-21]
CHR Extension: (Adblock Plus) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-01-21]
CHR Extension: (Google-Suche) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-21]
CHR Extension: (Google Tabellen) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-21]
CHR Extension: (AdBlock) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-21]
CHR Extension: (Avast Online Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-01-21]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-21]
CHR Extension: (Google Mail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-20]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2010-12-10] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-20] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2015-01-20] (Avast Software)
S2 d924d8dc; c:\Program Files (x86)\Optimizer Pro 3.33\OptProMon.dll [1597008 2015-01-21] ()
R2 DriveClone Network Client IBP; C:\Program Files\Time Stamp\IBP\fsloader.exe [126976 2009-08-17] () [File not signed]
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-12-10] ()
U2 iprip; C:\Windows\System32\iprip.dll [35328 2009-07-14] (Microsoft Corporation)
S2 MElGfYhtuP; C:\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe [2733872 2015-01-22] (Time Lapse Solutions)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 SNMP; C:\Windows\System32\snmp.exe [49664 2010-11-21] (Microsoft Corporation)
R2 SNMP; C:\Windows\SysWOW64\snmp.exe [47616 2010-11-21] (Microsoft Corporation)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1025920 2015-01-23] (Enigma Software Group USA, LLC.)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-20] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2015-01-20] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-20] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-20] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-20] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-20] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-20] ()
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-01-23] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-01-23] ()
R3 FARMNTIO; c:\windows\system32\drivers\farmntio.sys [24664 2011-04-18] ()
R3 fspad_win764; C:\Windows\System32\DRIVERS\fspad_win764.sys [173408 2014-05-13] (Sentelic Corporation)
S3 fspad_wlh64; C:\Windows\System32\DRIVERS\fspad_wlh64.sys [68608 2010-11-08] (Sentelic Corporation) [File not signed]
R2 HCDisk; C:\Windows\System32\Drivers\HCDisk.sys [66136 2011-01-04] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2014-04-24] (Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [129224 2013-11-29] (Qualcomm Atheros Co., Ltd.)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2010-12-10] (PEGATRON)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [9112792 2014-05-02] (Realtek Semiconductor Corp.)
R3 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2015-01-20] (Avast Software)
R0 VVBackd5; C:\Windows\System32\Drivers\VVBackd5.sys [162392 2011-07-12] ()
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-30 12:58 - 2015-01-30 12:58 - 00000000 ___DC () C:\Users\User\AppData\Local\MigWiz
2015-01-30 12:51 - 2015-01-30 12:51 - 00000758 _____ () C:\Users\User\Desktop\JRT.txt
2015-01-30 12:38 - 2015-01-30 12:38 - 01707939 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2015-01-30 12:21 - 2015-01-30 12:21 - 02194432 _____ () C:\Users\User\Desktop\AdwCleaner_4.109.exe
2015-01-29 23:18 - 2015-01-29 23:36 - 00000000 ____D () C:\Users\User\Downloads\SSF2DemoV0_9b1978 (1)
2015-01-29 21:46 - 2015-01-29 21:57 - 191153583 _____ () C:\Users\User\Downloads\SSF2DemoV0_9b1978 (1).zip
2015-01-29 21:46 - 2015-01-29 21:46 - 00000000 ____D () C:\Users\User\data
2015-01-29 16:17 - 2015-01-29 17:00 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-29 16:17 - 2015-01-29 16:31 - 00136408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-29 16:17 - 2015-01-29 16:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-29 16:15 - 2015-01-29 17:01 - 00000000 ____D () C:\Users\User\Desktop\mbar
2015-01-29 16:15 - 2015-01-29 16:29 - 00097496 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-01-29 16:14 - 2015-01-29 16:15 - 16466552 _____ (Malwarebytes Corp.) C:\Users\User\Desktop\mbar-1.08.3.1004.exe
2015-01-29 15:42 - 2015-01-30 13:06 - 00017512 _____ () C:\Users\User\Desktop\FRST.txt
2015-01-29 14:58 - 2015-01-29 15:09 - 00028076 _____ () C:\Users\User\Downloads\Addition.txt
2015-01-29 14:57 - 2015-01-29 15:09 - 00127525 _____ () C:\Users\User\Downloads\FRST.txt
2015-01-29 14:56 - 2015-01-30 13:06 - 00000000 ____D () C:\FRST
2015-01-29 14:56 - 2015-01-29 14:56 - 02130432 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2015-01-29 13:34 - 2015-01-29 13:35 - 00041670 _____ () C:\windows\iis7.log
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\SysWOW64\BestPractices
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\system32\msmq
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\system32\BestPractices
2015-01-29 13:31 - 2015-01-29 13:30 - 00000862 _____ () C:\windows\system32\termcap
2015-01-29 13:30 - 2015-01-29 13:31 - 00000000 ____D () C:\inetpub
2015-01-29 13:22 - 2015-01-29 13:22 - 00462888 _____ () C:\Users\User\Downloads\SpyHunterKiller.exe
2015-01-23 21:14 - 2015-01-23 21:14 - 00000000 ____D () C:\windows\pss
2015-01-23 19:14 - 2015-01-23 19:14 - 00003322 _____ () C:\windows\System32\Tasks\SpyHunter4Startup
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 ____D () C:\Users\User\AppData\Roaming\Enigma Software Group
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 ____D () C:\sh4ldr
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 _____ () C:\autoexec.bat
2015-01-23 19:13 - 2015-01-23 19:13 - 00022704 _____ () C:\windows\system32\Drivers\EsgScanner.sys
2015-01-23 19:13 - 2015-01-23 19:13 - 00000000 ____D () C:\Program Files\Enigma Software Group
2015-01-23 18:57 - 2015-01-23 18:57 - 00000247 _____ () C:\windows\system32\2015-01-23-17-57-45.092-aswFe.exe-5340.log
2015-01-23 18:57 - 2015-01-23 18:57 - 00000197 _____ () C:\windows\system32\2015-01-23-17-57-38.027-AvastVBoxSVC.exe-1312.log
2015-01-23 17:59 - 2015-01-30 12:56 - 00000000 ____D () C:\AdwCleaner
2015-01-23 17:49 - 2015-01-23 17:49 - 00000197 _____ () C:\windows\system32\2015-01-23-16-49-31.016-AvastVBoxSVC.exe-3784.log
2015-01-23 16:23 - 2015-01-23 16:23 - 00000197 _____ () C:\windows\system32\2015-01-23-15-23-49.010-AvastVBoxSVC.exe-6012.log
2015-01-23 16:08 - 2015-01-23 16:08 - 00000000 ____D () C:\Users\User\AppData\Local\com
2015-01-23 16:06 - 2015-01-23 16:06 - 00000000 ____D () C:\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f
2015-01-23 15:52 - 2015-01-23 15:52 - 00000197 _____ () C:\windows\system32\2015-01-23-14-52-16.032-AvastVBoxSVC.exe-5244.log
2015-01-23 13:21 - 2015-01-23 18:55 - 00001557 _____ () C:\Users\User\Desktop\Chrome.lnk
2015-01-23 13:14 - 2015-01-23 13:14 - 00000197 _____ () C:\windows\system32\2015-01-23-12-14-23.097-AvastVBoxSVC.exe-3880.log
2015-01-23 13:12 - 2015-01-23 13:12 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2015-01-22 18:29 - 2015-01-23 15:58 - 00000000 ____D () C:\Users\User\AppData\Roaming\Apple Computer
2015-01-22 18:29 - 2015-01-22 18:29 - 00001793 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-01-22 18:29 - 2015-01-22 18:29 - 00000000 ____D () C:\Users\User\AppData\Local\Apple Computer
2015-01-22 18:29 - 2015-01-22 18:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-01-22 18:28 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\windows\system32\Drivers\GEARAspiWDM.sys
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\Program Files\iTunes
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-22 18:26 - 2015-01-22 18:26 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-01-22 18:26 - 2015-01-22 18:26 - 00000000 ____D () C:\Program Files\iPod
2015-01-22 18:25 - 2015-01-22 18:25 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\windows\System32\Tasks\Apple
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\Users\User\AppData\Local\Apple
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2015-01-22 18:24 - 2015-01-22 18:26 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-01-22 18:23 - 2015-01-22 18:23 - 00000000 ____D () C:\Program Files\Bonjour
2015-01-22 18:23 - 2015-01-22 18:23 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-01-22 18:21 - 2015-01-22 18:25 - 00000000 ____D () C:\ProgramData\Apple
2015-01-22 18:18 - 2015-01-22 18:20 - 122418480 _____ (Apple Inc.) C:\Users\User\Downloads\iTunes64Setup.exe
2015-01-22 12:40 - 2015-01-22 12:40 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps
2015-01-22 12:36 - 2015-01-22 12:36 - 00000000 ____D () C:\Users\User\AppData\Local\Macromedia
2015-01-22 12:32 - 2015-01-29 13:18 - 00003276 _____ () C:\windows\System32\Tasks\avastBCLRestartS-1-5-21-2608712115-2613374988-3172207222-1001
2015-01-22 12:30 - 2015-01-22 12:31 - 00000000 ____D () C:\Users\User\AppData\Roaming\Mozilla
2015-01-22 12:30 - 2015-01-22 12:31 - 00000000 ____D () C:\Users\User\AppData\Local\Mozilla
2015-01-22 12:29 - 2015-01-22 12:29 - 00000000 ____D () C:\ProgramData\xfIwQZvgdh
2015-01-22 12:24 - 2015-01-22 12:25 - 00000197 _____ () C:\windows\system32\2015-01-22-11-24-48.051-AvastVBoxSVC.exe-3272.log
2015-01-21 23:15 - 2015-01-21 23:15 - 00000197 _____ () C:\windows\system32\2015-01-21-22-15-00.076-AvastVBoxSVC.exe-4408.log
2015-01-21 22:09 - 2015-01-21 22:10 - 00021976 _____ () C:\windows\system32\Drivers\SPPD.sys
2015-01-21 22:05 - 2015-01-21 22:05 - 00000280 _____ () C:\windows\system32\2015-01-21-21-05-13.073-aswFe.exe-6612.log
2015-01-21 22:04 - 2015-01-21 22:04 - 00000000 ____D () C:\Program Files (x86)\ClickCaption_1.10.0.6
2015-01-21 22:01 - 2015-01-21 22:01 - 00000000 ___HD () C:\Users\User\AppData\Roaming\GoldenGate
2015-01-21 22:00 - 2015-01-21 22:00 - 00000170 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2015-01-21 21:47 - 2015-01-21 21:47 - 00000000 ____D () C:\ProgramData\McAfee
2015-01-21 21:18 - 2015-01-21 21:18 - 00000000 ____D () C:\Users\User\AppData\Roaming\Opera Software
2015-01-21 21:18 - 2015-01-21 21:18 - 00000000 ____D () C:\Users\User\AppData\Local\Opera Software
2015-01-21 21:17 - 2015-01-29 12:48 - 00003852 _____ () C:\windows\System32\Tasks\Opera scheduled Autoupdate 1421871456
2015-01-21 21:17 - 2015-01-21 21:17 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-01-21 21:16 - 2015-01-29 12:48 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-01-21 21:03 - 2015-01-21 21:03 - 00000280 _____ () C:\windows\system32\2015-01-21-20-03-26.006-aswFe.exe-3824.log
2015-01-21 20:40 - 2015-01-22 12:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-21 20:39 - 2015-01-30 12:44 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-21 20:39 - 2015-01-30 12:34 - 00001102 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-21 20:39 - 2015-01-21 20:40 - 00000000 ____D () C:\Users\User\AppData\Local\Google
2015-01-21 20:39 - 2015-01-21 20:40 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-21 20:39 - 2015-01-21 20:39 - 00004102 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-01-21 20:39 - 2015-01-21 20:39 - 00003850 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-01-21 20:34 - 2015-01-21 20:38 - 00000000 ____D () C:\Users\User\AppData\Local\Deployment
2015-01-21 20:34 - 2015-01-21 20:34 - 00000000 ____D () C:\Users\User\AppData\Local\Apps\2.0
2015-01-21 20:32 - 2015-01-21 20:32 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.33
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieUserList
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieSiteList
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieBrowserModeList
2015-01-21 20:27 - 2015-01-21 20:27 - 00000197 _____ () C:\windows\system32\2015-01-21-19-27-14.097-AvastVBoxSVC.exe-3556.log
2015-01-21 16:40 - 2015-01-21 16:40 - 00000197 _____ () C:\windows\system32\2015-01-21-15-40-25.087-AvastVBoxSVC.exe-2804.log
2015-01-21 12:12 - 2015-01-21 12:12 - 00000197 _____ () C:\windows\system32\2015-01-21-11-12-09.083-AvastVBoxSVC.exe-3988.log
2015-01-21 11:42 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-01-21 11:42 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-01-21 11:42 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-01-21 11:42 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-01-21 11:42 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-01-21 11:04 - 2015-01-21 11:04 - 00000197 _____ () C:\windows\system32\2015-01-21-10-04-40.059-AvastVBoxSVC.exe-2880.log
2015-01-21 10:35 - 2014-06-27 03:08 - 02777088 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2015-01-21 10:35 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2vdec.dll
2015-01-21 10:33 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2015-01-21 10:33 - 2014-05-08 10:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2015-01-21 10:33 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2015-01-21 10:33 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-01-21 10:33 - 2011-02-25 07:19 - 02871808 _____ (Microsoft Corporation) C:\windows\explorer.exe
2015-01-21 10:33 - 2011-02-25 06:30 - 02616320 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2015-01-21 10:32 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\windows\SysWOW64\d2d1.dll
2015-01-21 10:32 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2015-01-21 10:32 - 2011-03-11 07:41 - 00410496 _____ (Intel Corporation) C:\windows\system32\Drivers\iaStorV.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00166272 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvstor.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00148352 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvraid.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00107904 _____ (Advanced Micro Devices) C:\windows\system32\Drivers\amdsata.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00027008 _____ (Advanced Micro Devices) C:\windows\system32\Drivers\amdxata.sys
2015-01-21 10:32 - 2011-03-11 07:33 - 02565632 _____ (Microsoft Corporation) C:\windows\system32\esent.dll
2015-01-21 10:32 - 2011-03-11 07:30 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\fsutil.exe
2015-01-21 10:32 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\windows\SysWOW64\esent.dll
2015-01-21 10:32 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\fsutil.exe
2015-01-21 10:32 - 2011-03-11 05:37 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2015-01-21 10:31 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDYAK.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDTAT.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU1.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDBASH.DLL
2015-01-21 10:31 - 2014-07-08 23:38 - 00419992 _____ () C:\windows\system32\locale.nls
2015-01-21 10:31 - 2014-07-08 23:30 - 00419992 _____ () C:\windows\SysWOW64\locale.nls
2015-01-21 10:31 - 2014-06-24 04:29 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-01-21 10:31 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2015-01-21 10:31 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2015-01-21 10:31 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\windows\splwow64.exe
2015-01-21 10:27 - 2015-01-21 10:28 - 00000197 _____ () C:\windows\system32\2015-01-21-09-27-50.087-AvastVBoxSVC.exe-2660.log
2015-01-21 10:08 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2015-01-21 10:08 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-21 10:08 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-21 10:08 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2015-01-21 10:07 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2015-01-21 10:07 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2015-01-21 10:07 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-01-21 10:07 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-01-21 10:07 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2015-01-21 10:07 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2015-01-21 10:07 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-01-21 10:07 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2015-01-21 10:07 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2015-01-21 10:07 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-01-21 10:07 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2015-01-21 10:03 - 2015-01-21 11:57 - 04190942 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2015-01-21 09:56 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2015-01-21 09:56 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2015-01-21 09:56 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2015-01-21 09:56 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2015-01-21 09:56 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2015-01-21 09:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-01-21 09:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-01-21 09:35 - 2015-01-21 09:35 - 00000197 _____ () C:\windows\system32\2015-01-21-08-35-45.076-AvastVBoxSVC.exe-2464.log
2015-01-21 09:25 - 2015-01-21 09:25 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-01-21 09:25 - 2015-01-21 09:25 - 00000000 ____D () C:\windows\system32\appraiser
2015-01-21 09:23 - 2015-01-21 09:24 - 00000197 _____ () C:\windows\system32\2015-01-21-08-23-41.005-AvastVBoxSVC.exe-168.log
2015-01-21 09:21 - 2015-01-21 09:21 - 1140010868 _____ () C:\windows\MEMORY.DMP
2015-01-21 09:21 - 2015-01-21 09:21 - 00000000 ____D () C:\windows\Minidump
2015-01-20 21:00 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-01-20 21:00 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-01-20 21:00 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2015-01-20 21:00 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-01-20 20:01 - 2015-01-20 20:01 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-01-20 20:01 - 2015-01-20 20:01 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-01-20 20:01 - 2015-01-20 20:01 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-01-20 20:01 - 2015-01-20 20:01 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat
2015-01-20 20:01 - 2015-01-20 20:01 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2015-01-20 20:01 - 2015-01-20 20:01 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-01-20 20:01 - 2015-01-20 20:01 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-01-20 20:01 - 2015-01-20 20:01 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-01-20 20:01 - 2015-01-20 20:01 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01682432 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01643520 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01247744 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01238528 _____ (Microsoft Corporation) C:\windows\system32\d3d10.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01175552 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01158144 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsPrint.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01080832 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00648192 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00604160 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10level9.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00522752 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsGdiConverter.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00363008 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00333312 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\d3d10core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00293376 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00249856 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10_1core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00245248 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00207872 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecsExt.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00194560 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00187392 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAnimation.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00161792 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10_1.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00010752 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00010752 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00009728 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00009728 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00002560 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00002560 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-01-20 14:53 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-01-20 14:53 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2015-01-20 14:53 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-01-20 14:53 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-01-20 14:53 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-01-20 14:53 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-01-20 14:53 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2015-01-20 14:53 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2015-01-20 14:53 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2015-01-20 14:53 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\windows\system32\WUDFx.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe
2015-01-20 14:51 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\windows\system32\WUDFCoinstaller.dll
2015-01-20 14:51 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys
2015-01-20 14:51 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys
2015-01-20 14:51 - 2012-06-02 15:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-01-20 14:27 - 2015-01-20 14:27 - 00000197 _____ () C:\windows\system32\2015-01-20-13-27-06.064-AvastVBoxSVC.exe-2964.log
2015-01-20 13:56 - 2015-01-20 13:56 - 00000197 _____ () C:\windows\system32\2015-01-20-12-56-28.062-AvastVBoxSVC.exe-4596.log
2015-01-20 13:20 - 2015-01-20 13:20 - 00000247 _____ () C:\windows\system32\2015-01-20-12-20-48.046-aswFe.exe-6056.log
2015-01-20 13:13 - 2015-01-20 13:20 - 00000247 _____ () C:\windows\system32\2015-01-20-12-13-29.071-aswFe.exe-4372.log
2015-01-20 13:13 - 2015-01-20 13:13 - 00000197 _____ () C:\windows\system32\2015-01-20-12-13-23.011-AvastVBoxSVC.exe-4364.log
2015-01-20 13:04 - 2015-01-20 13:04 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVAST Software
2015-01-20 13:00 - 2015-01-20 13:00 - 00000000 ____D () C:\windows\SysWOW64\vbox
2015-01-20 13:00 - 2015-01-20 13:00 - 00000000 ____D () C:\windows\system32\vbox
2015-01-20 12:59 - 2015-01-20 12:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-01-20 12:58 - 2015-01-29 12:39 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2015-01-20 12:58 - 2015-01-21 09:40 - 01050432 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00436624 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00364512 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2015-01-20 12:58 - 2015-01-20 12:58 - 00267632 _____ () C:\windows\system32\Drivers\aswVmm.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00116728 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00083280 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2015-01-20 12:58 - 2015-01-20 12:58 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys
2015-01-20 12:57 - 2015-01-20 12:57 - 00000000 ____D () C:\Program Files\AVAST Software
2015-01-20 12:56 - 2015-01-20 12:57 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-01-20 12:56 - 2015-01-20 12:56 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-01-20 12:56 - 2015-01-20 12:56 - 00002029 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-01-20 12:55 - 2015-01-20 12:55 - 00001080 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\windows\SysWOW64\Adobe
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2015-01-20 12:54 - 2015-01-20 12:54 - 00319912 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2015-01-20 12:54 - 2015-01-20 12:54 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\ProgramData\Sun
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\Program Files\Java
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-20 12:53 - 2015-01-21 22:02 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
2015-01-20 12:53 - 2015-01-20 12:56 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-20 12:53 - 2015-01-20 12:56 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-01-20 12:52 - 2015-01-20 12:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-01-20 12:52 - 2015-01-20 12:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-01-20 12:51 - 2015-01-22 12:32 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-20 12:51 - 2015-01-22 12:32 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\ProgramData\Mozilla
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-20 12:48 - 2015-01-30 12:24 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-01-20 12:48 - 2015-01-25 17:24 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-01-20 12:48 - 2015-01-25 17:24 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-20 12:48 - 2015-01-25 17:24 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-01-20 12:48 - 2015-01-20 12:48 - 00000000 ____D () C:\windows\system32\Macromed
2015-01-19 14:18 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE
2015-01-19 13:38 - 2015-01-20 20:35 - 00041009 _____ () C:\windows\IE11_main.log
2015-01-19 12:14 - 2015-01-19 12:16 - 00000000 ____D () C:\windows\system32\MRT
2015-01-19 12:14 - 2014-12-31 13:12 - 113365784 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-01-19 12:12 - 2015-01-19 12:12 - 00000000 ____D () C:\Users\User\AppData\Local\WindowsUpdate
2015-01-19 12:12 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\windows\system32\icardres.dll
2015-01-19 12:12 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardres.dll
2015-01-19 12:12 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\windows\SysWOW64\TsWpfWrp.exe
2015-01-19 12:12 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
2015-01-19 12:12 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\windows\system32\icardagt.exe
2015-01-19 12:12 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\windows\system32\infocardapi.dll
2015-01-19 12:12 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardagt.exe
2015-01-19 12:12 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\windows\SysWOW64\infocardapi.dll
2015-01-19 12:10 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2015-01-19 12:10 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2015-01-19 12:10 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\windows\SysWOW64\certutil.exe
2015-01-19 12:10 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\certenc.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-01-19 12:09 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-01-19 12:09 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-01-19 12:09 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-01-19 12:08 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2015-01-19 12:08 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2015-01-19 12:08 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2015-01-19 12:08 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2015-01-19 12:08 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2015-01-19 12:08 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2015-01-19 12:08 - 2014-03-04 10:44 - 00722944 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2015-01-19 12:08 - 2014-03-04 10:44 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-01-19 12:08 - 2014-03-04 10:44 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\objsel.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\windows\SysWOW64\adprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\capiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsroam.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredprovider.dll
2015-01-19 12:08 - 2014-03-04 10:16 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll
2015-01-19 12:08 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2015-01-19 12:08 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe
2015-01-19 12:08 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_isv.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_ssp_isv.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_ssp.dll
2015-01-19 12:08 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdrm.dll
2015-01-19 12:08 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_isv.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_ssp.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_ssp_isv.exe
2015-01-19 12:08 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2015-01-19 12:08 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2015-01-19 12:08 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2015-01-19 12:08 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys
2015-01-19 12:08 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\Wdfres.dll
2015-01-19 12:08 - 2012-11-28 23:56 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-01-19 12:08 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\rdpwsx.dll
2015-01-19 12:08 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\windows\system32\rdrmemptylst.exe
2015-01-19 12:07 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2015-01-19 12:07 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-01-19 12:07 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-01-19 12:07 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-01-19 12:07 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-01-19 12:07 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-01-19 12:07 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-01-19 12:07 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-01-19 12:07 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-01-19 12:07 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-01-19 12:07 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-01-19 12:07 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2015-01-19 12:07 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d11.dll
2015-01-19 12:07 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2015-01-19 12:07 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll
2015-01-19 12:07 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\windows\system32\gameux.dll
2015-01-19 12:07 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wpc.dll
2015-01-19 12:07 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\windows\SysWOW64\gameux.dll
2015-01-19 12:07 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\windows\system32\oflc-nz.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\windows\system32\pegibbfc.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\windows\system32\csrr.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\windows\system32\usk.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\windows\system32\oflc.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-pt.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-fi.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\windows\system32\cero.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\windows\system32\esrb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\windows\system32\fpb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\windows\system32\cob-au.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\windows\system32\grb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\windows\system32\pegi.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\windows\system32\djctq.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\windows\SysWOW64\cero.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\windows\SysWOW64\esrb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\windows\SysWOW64\fpb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\windows\SysWOW64\oflc-nz.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\windows\SysWOW64\pegibbfc.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\windows\SysWOW64\csrr.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\windows\SysWOW64\cob-au.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\windows\SysWOW64\usk.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\windows\SysWOW64\oflc.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\windows\SysWOW64\grb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi-pt.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi-fi.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\windows\SysWOW64\djctq.rs
2015-01-19 12:06 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-01-19 12:06 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-01-19 12:06 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-01-19 12:06 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-01-19 12:06 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-01-19 12:06 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-01-19 12:06 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-01-19 12:06 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-01-19 12:06 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2015-01-19 12:06 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-01-19 12:06 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\windows\SysWOW64\pku2u.dll
2015-01-19 12:06 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-01-19 12:06 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-01-19 12:06 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-01-19 12:06 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-01-19 12:06 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2015-01-19 12:06 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2015-01-19 12:06 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2015-01-19 12:06 - 2014-08-01 12:53 - 01031168 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2015-01-19 12:06 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll
2015-01-19 12:06 - 2014-04-12 03:22 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-01-19 12:06 - 2014-04-12 03:19 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-01-19 12:06 - 2014-04-12 03:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-01-19 12:06 - 2014-04-12 03:19 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-01-19 12:06 - 2014-04-12 03:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-01-19 12:06 - 2014-03-04 10:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-01-19 12:06 - 2014-03-04 10:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-01-19 12:06 - 2014-03-04 10:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-01-19 12:06 - 2014-03-04 10:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-01-19 12:06 - 2014-03-04 09:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-01-19 12:06 - 2014-03-04 09:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-01-19 12:06 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2015-01-19 12:06 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll
2015-01-19 12:06 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-01-19 12:06 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-01-19 12:06 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-01-19 12:06 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2015-01-19 12:06 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\shdocvw.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\windows\system32\netcorehc.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\netevent.dll
2015-01-19 12:06 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2015-01-19 12:06 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\netcorehc.dll
2015-01-19 12:06 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\netevent.dll
2015-01-19 12:06 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2015-01-19 12:05 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-01-19 12:05 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2015-01-19 12:05 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2015-01-19 12:05 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10K.DLL
2015-01-19 12:05 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-01-19 12:05 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-01-19 12:05 - 2014-06-18 03:18 - 00692736 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2015-01-19 12:05 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
2015-01-19 12:05 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2015-01-19 12:05 - 2014-06-06 11:10 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2015-01-19 12:05 - 2014-06-06 10:44 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2015-01-19 12:05 - 2014-04-05 03:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2015-01-19 12:05 - 2014-04-05 03:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2015-01-19 12:05 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2015-01-19 12:05 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2015-01-19 12:05 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-01-19 12:05 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-01-19 12:05 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-01-19 12:05 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-01-19 12:05 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2015-01-19 12:05 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptdlg.dll
2015-01-19 12:05 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2015-01-19 12:05 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2015-01-19 12:05 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2015-01-19 12:05 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wwanprotdim.dll
2015-01-19 12:05 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll
2015-01-19 12:05 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll
2015-01-19 12:05 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore6.dll
2015-01-19 12:05 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc6.dll
2015-01-19 12:05 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\windows\system32\OxpsConverter.exe
2015-01-19 12:05 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\netapi32.dll
2015-01-19 12:05 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\browser.dll
2015-01-19 12:05 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\browcli.dll
2015-01-19 12:05 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\windows\SysWOW64\netapi32.dll
2015-01-19 12:05 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\windows\SysWOW64\browcli.dll
2015-01-19 12:05 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\windows\system32\ntshrui.dll
2015-01-19 12:05 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntshrui.dll
2015-01-19 12:05 - 2011-10-26 06:25 - 01572864 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-01-19 12:05 - 2011-10-26 05:32 - 01328128 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2015-01-19 12:05 - 2011-07-09 03:46 - 00288768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-01-19 12:05 - 2011-05-04 06:25 - 02315776 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 02223616 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00778752 _____ (Microsoft Corporation) C:\windows\system32\mssvp.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00491520 _____ (Microsoft Corporation) C:\windows\system32\mssph.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00288256 _____ (Microsoft Corporation) C:\windows\system32\mssphtb.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00075264 _____ (Microsoft Corporation) C:\windows\system32\msscntrs.dll
2015-01-19 12:05 - 2011-05-04 06:19 - 00591872 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe
2015-01-19 12:05 - 2011-05-04 06:19 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\SearchProtocolHost.exe
2015-01-19 12:05 - 2011-05-04 06:19 - 00113664 _____ (Microsoft Corporation) C:\windows\system32\SearchFilterHost.exe
2015-01-19 12:05 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssvp.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssph.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssphtb.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscntrs.dll
2015-01-19 12:05 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe
2015-01-19 12:05 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchProtocolHost.exe
2015-01-19 12:05 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFilterHost.exe
2015-01-19 12:05 - 2011-04-27 03:40 - 00158208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-01-19 12:05 - 2011-04-27 03:39 - 00128000 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-01-19 12:05 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\poqexec.exe
2015-01-19 12:05 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\poqexec.exe
2015-01-19 12:05 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2015-01-19 12:04 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-01-19 12:04 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-01-19 12:04 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2015-01-19 12:04 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncsi.dll
2015-01-19 12:04 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlaapi.dll
2015-01-19 12:04 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-01-19 12:04 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-01-19 12:04 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2015-01-19 12:04 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2015-01-19 12:04 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-01-19 12:04 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-01-19 12:04 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-01-19 12:04 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-01-19 12:04 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-01-19 12:04 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2015-01-19 12:04 - 2014-05-30 07:45 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-01-19 12:04 - 2014-04-25 03:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2015-01-19 12:04 - 2014-04-25 03:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2015-01-19 12:04 - 2014-03-26 15:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-01-19 12:04 - 2014-03-26 15:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-01-19 12:04 - 2014-03-26 15:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-01-19 12:04 - 2014-03-26 15:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2015-01-19 12:04 - 2014-02-04 03:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2015-01-19 12:04 - 2014-02-04 03:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2015-01-19 12:04 - 2014-02-04 03:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2015-01-19 12:04 - 2014-02-04 03:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2015-01-19 12:04 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll


Nero555 30.01.2015 13:19

FRST Editor Logfile (2)
 
Code:

2015-01-19 12:04 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2015-01-19 12:04 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2015-01-19 12:04 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2015-01-19 12:04 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2015-01-19 12:04 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-01-19 12:04 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-01-19 12:04 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2015-01-19 12:04 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2015-01-19 12:04 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2015-01-19 12:04 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\SysWOW64\SmartcardCredentialProvider.dll
2015-01-19 12:04 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\credui.dll
2015-01-19 12:04 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2015-01-19 12:04 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2015-01-19 12:04 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2015-01-19 12:04 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2015-01-19 12:04 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-01-19 12:04 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-01-19 12:04 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-01-19 12:04 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2015-01-19 12:04 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-01-19 12:04 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2015-01-19 12:04 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-01-19 12:04 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-01-19 12:04 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-01-19 12:04 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
2015-01-19 12:04 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-01-19 12:04 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-01-19 12:04 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-01-19 12:04 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-01-19 12:04 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-01-19 12:04 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-01-19 12:04 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-01-19 12:04 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-01-19 12:04 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-01-19 12:04 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-01-19 12:04 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-01-19 12:04 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2015-01-19 12:04 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\dpnet.dll
2015-01-19 12:04 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpnet.dll
2015-01-19 12:04 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-01-19 12:04 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\Drivers\RNDISMP.sys
2015-01-19 12:04 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\partmgr.sys
2015-01-19 12:04 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fs_rec.sys
2015-01-19 12:04 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\wmi.dll
2015-01-19 12:04 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmi.dll
2015-01-19 12:04 - 2011-11-17 07:35 - 00395776 _____ (Microsoft Corporation) C:\windows\system32\webio.dll
2015-01-19 12:04 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\windows\SysWOW64\webio.dll
2015-01-19 12:04 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\windows\system32\psisdecd.dll
2015-01-19 12:04 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\psisrndr.ax
2015-01-19 12:04 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\windows\SysWOW64\psisdecd.dll
2015-01-19 12:04 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\windows\SysWOW64\psisrndr.ax
2015-01-19 12:04 - 2011-06-16 06:49 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\xmllite.dll
2015-01-19 12:04 - 2011-06-16 05:33 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\xmllite.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00212992 _____ (Microsoft Corporation) C:\windows\system32\odbctrac.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\odbccp32.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\odbccu32.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\odbccr32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00319488 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbcjt32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbctrac.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00122880 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccp32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccu32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccr32.dll
2015-01-19 12:04 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\umpnpmgr.dll
2015-01-19 12:04 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\windows\SysWOW64\devobj.dll
2015-01-19 12:04 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\windows\SysWOW64\devrtl.dll
2015-01-19 12:04 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cfgmgr32.dll
2015-01-19 12:04 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\windows\SysWOW64\drvinst.exe
2015-01-19 12:04 - 2011-04-29 04:06 - 00467456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2015-01-19 12:04 - 2011-04-29 04:05 - 00410112 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2015-01-19 12:04 - 2011-04-29 04:05 - 00168448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2015-01-19 12:03 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2015-01-19 12:03 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\charmap.exe
2015-01-19 12:03 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2015-01-19 12:03 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2015-01-19 12:03 - 2014-09-25 03:08 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-01-19 12:03 - 2014-09-25 02:40 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2015-01-19 12:03 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2015-01-19 12:03 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2015-01-19 12:03 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2015-01-19 12:03 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2015-01-19 12:03 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2015-01-19 12:03 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-01-19 12:03 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\windows\SysWOW64\synceng.dll
2015-01-19 12:03 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\synceng.dll
2015-01-19 12:03 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\windows\system32\cdosys.dll
2015-01-19 12:03 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\windows\SysWOW64\cdosys.dll
2015-01-19 12:03 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\windows\system32\timedate.cpl
2015-01-19 12:03 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\windows\SysWOW64\timedate.cpl
2015-01-19 12:03 - 2011-02-18 11:51 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\prevhost.exe
2015-01-19 12:03 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\prevhost.exe
2015-01-19 12:02 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-01-19 12:02 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-01-19 12:01 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-01-19 12:01 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2015-01-19 12:01 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-01-19 12:01 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-01-19 12:01 - 2014-01-24 03:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2015-01-19 12:01 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2015-01-19 12:01 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2015-01-19 12:01 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2015-01-19 12:01 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2015-01-19 12:01 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2015-01-19 12:01 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx
2015-01-19 12:01 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2015-01-19 12:01 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2015-01-19 12:01 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2015-01-19 12:01 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2015-01-19 12:01 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2015-01-19 12:01 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe
2015-01-19 12:01 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2015-01-19 12:01 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-01-19 12:01 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2015-01-19 12:01 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2015-01-19 12:01 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\windows\system32\msvcrt.dll
2015-01-19 12:01 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcrt.dll
2015-01-19 12:01 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\windows\system32\EncDec.dll
2015-01-19 12:01 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\EncDec.dll
2015-01-19 12:01 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\windows\system32\oleacc.dll
2015-01-19 12:01 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleacc.dll
2015-01-19 11:50 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-01-19 11:50 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-01-19 11:49 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2015-01-19 11:32 - 2015-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\Virtual Desktop Manager
2015-01-19 11:32 - 2015-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Local\FSP
2015-01-19 11:31 - 2015-01-23 18:06 - 00001003 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-19 11:21 - 2015-01-19 11:21 - 524288000 __RSH () C:\VPART015.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART014.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART013.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART012.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART011.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART010.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART009.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART008.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 00000790 _____ () C:\Users\User\Desktop\Time Stamp.lnk
2015-01-19 11:21 - 2015-01-19 11:21 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Time Stamp
2015-01-19 11:20 - 2015-01-30 12:57 - 00001058 __RSH () C:\windows\system32\VFsRegister
2015-01-19 11:20 - 2015-01-21 12:12 - 00000000 ____D () C:\Program Files\Time Stamp
2015-01-19 11:20 - 2015-01-20 12:00 - 00000000 ____D () C:\ProgramData\Farstone
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART007.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART006.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART005.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART004.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART003.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART002.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART001.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART000.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 00004096 __RSH () C:\RESCUMBR.BIN
2015-01-19 11:20 - 2015-01-19 11:20 - 00000532 __RSH () C:\windows\system32\VFsActitvation
2015-01-19 11:20 - 2011-07-12 09:28 - 00162392 _____ () C:\windows\system32\Drivers\VvBackd5.sys
2015-01-19 11:20 - 2011-04-18 04:12 - 00024664 ____N () C:\windows\system32\Drivers\FarMntIo.sys
2015-01-19 11:20 - 2011-01-04 18:18 - 00066136 ____N () C:\windows\system32\Drivers\HCDisk.sys
2015-01-19 11:19 - 2015-01-19 11:19 - 00000006 _____ () C:\windows\silentOnce.tmp
2015-01-19 11:19 - 2015-01-19 11:19 - 00000000 ____D () C:\ProgramData\Remind
2015-01-19 11:19 - 2015-01-19 11:19 - 00000000 ____D () C:\Program Files (x86)\MSI
2015-01-19 11:16 - 2015-01-19 11:16 - 00000000 ____D () C:\Users\User\AppData\Local\VirtualStore
2015-01-19 11:16 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\windows\system32\rdpcore.dll
2015-01-19 11:16 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpcore.dll
2015-01-19 11:16 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdtcp.sys
2015-01-19 11:09 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-01-19 11:09 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-01-19 11:09 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-01-19 11:09 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-01-19 11:09 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-01-19 11:09 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-01-19 11:09 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-01-19 11:09 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-01-19 11:09 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-01-19 11:06 - 2015-01-21 09:37 - 00058016 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-19 11:06 - 2015-01-19 11:06 - 00000020 ___SH () C:\Users\User\ntuser.ini
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Vorlagen
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Startmenü
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Netzwerkumgebung
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Lokale Einstellungen
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Eigene Dateien
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Druckumgebung
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Documents\Eigene Musik
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Documents\Eigene Bilder
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Local\Verlauf
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Local\Anwendungsdaten
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Anwendungsdaten
2015-01-19 11:06 - 2011-08-11 18:21 - 00000000 ____D () C:\Users\User\AppData\Local\SRS Labs
2015-01-19 11:06 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-19 11:06 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-30 13:06 - 2011-08-11 18:10 - 01058861 _____ () C:\windows\WindowsUpdate.log
2015-01-30 12:44 - 2009-07-14 05:45 - 00016752 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-30 12:44 - 2009-07-14 05:45 - 00016752 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-30 12:35 - 2009-07-14 05:46 - 00004591 _____ () C:\windows\DtcInstall.log
2015-01-30 12:33 - 2010-11-21 04:47 - 00278366 _____ () C:\windows\PFRO.log
2015-01-30 12:33 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-01-30 12:33 - 2009-07-14 05:51 - 00039097 _____ () C:\windows\setupact.log
2015-01-29 13:34 - 2011-08-11 19:05 - 00772184 _____ () C:\windows\system32\perfh010.dat
2015-01-29 13:34 - 2011-08-11 19:05 - 00159382 _____ () C:\windows\system32\perfc010.dat
2015-01-29 13:34 - 2011-08-11 18:59 - 00779006 _____ () C:\windows\system32\perfh00C.dat
2015-01-29 13:34 - 2011-08-11 18:59 - 00163544 _____ () C:\windows\system32\perfc00C.dat
2015-01-29 13:34 - 2011-08-11 18:52 - 00779960 _____ () C:\windows\system32\perfh00A.dat
2015-01-29 13:34 - 2011-08-11 18:52 - 00173610 _____ () C:\windows\system32\perfc00A.dat
2015-01-29 13:34 - 2011-08-11 18:45 - 00744432 _____ () C:\windows\system32\perfh007.dat
2015-01-29 13:34 - 2011-08-11 18:45 - 00162272 _____ () C:\windows\system32\perfc007.dat
2015-01-29 13:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\inetsrv
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\inetsrv
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2015-01-25 16:33 - 2011-08-11 18:24 - 00011580 _____ () C:\windows\DPINST.LOG
2015-01-25 16:33 - 2011-05-17 18:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-23 16:06 - 2011-08-11 18:22 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun
2015-01-22 12:24 - 2009-07-14 03:34 - 00000505 _____ () C:\windows\win.ini
2015-01-22 12:23 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\GroupPolicy
2015-01-21 11:57 - 2009-07-14 06:13 - 04190942 _____ () C:\windows\system32\PerfStringBackup.INI
2015-01-21 11:38 - 2011-08-11 18:21 - 00058016 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-21 11:38 - 2011-08-11 18:21 - 00058016 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-21 11:01 - 2009-07-14 05:45 - 00267816 _____ () C:\windows\system32\FNTCACHE.DAT
2015-01-21 10:24 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\zh-HK
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\zh-HK
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\tr-TR
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-21 09:25 - 2010-11-21 08:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-21 09:25 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-21 09:25 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\Dism
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\AppCompat
2015-01-20 13:51 - 2011-08-11 18:29 - 00000000 ____D () C:\Users\Public\Desktop\User Manual
2015-01-20 12:53 - 2010-01-20 11:34 - 00000000 ____D () C:\Users\User\AppData\Roaming\Adobe
2015-01-19 11:31 - 2011-06-08 03:20 - 00000000 ____D () C:\Utility
2015-01-19 11:21 - 2011-03-21 17:37 - 00000000 ____D () C:\log
2015-01-19 11:19 - 2011-05-17 18:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-01-19 11:05 - 2011-05-16 20:37 - 00000000 __SHD () C:\Recovery
2015-01-19 11:05 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-01-19 11:04 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2015-01-08 09:55 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe

Some content of TEMP:
====================
C:\Users\User\AppData\Local\Temp\9696F194-FBAC-E12D-6210-9B43FAFCA97D.dll
C:\Users\User\AppData\Local\Temp\BackupSetup.exe
C:\Users\User\AppData\Local\Temp\i33FC.tmp.exe
C:\Users\User\AppData\Local\Temp\i3874.tmp.exe
C:\Users\User\AppData\Local\Temp\i9602.tmp.exe
C:\Users\User\AppData\Local\Temp\i9924.tmp.exe
C:\Users\User\AppData\Local\Temp\iBA4.tmp.exe
C:\Users\User\AppData\Local\Temp\iE3FA.tmp.exe
C:\Users\User\AppData\Local\Temp\iE714.tmp.exe
C:\Users\User\AppData\Local\Temp\nst712.exe
C:\Users\User\AppData\Local\Temp\nszF70B.exe
C:\Users\User\AppData\Local\Temp\optprosetup.exe
C:\Users\User\AppData\Local\Temp\Quarantine.exe
C:\Users\User\AppData\Local\Temp\setup_472.exe
C:\Users\User\AppData\Local\Temp\sqlite3.dll
C:\Users\User\AppData\Local\Temp\vcredist_x64.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-29 14:50

==================== End Of Log ============================

Die FRST Addition Logfile wird nicht angezeigt.

Es erscheint die Meldung:

Farbar Recovery Scan Tool

Scan completed. The "FRST.txt" is saved in the same location FRST tool is run

Wo finde ich diese Logdatei?

cosinus 30.01.2015 13:51

Bitte auch ne neue Addition.txt erstellen, dazu FRST starten und einen Haken setzen bei Addition.txt, dann auf Scan klicken.

http://saved.im/mtg0mjy4yjlu/2014-04...ryscantool.png

Nero555 30.01.2015 14:33

FRST Addition
 
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2015
Ran by User at 2015-01-30 14:31:31
Running from C:\Users\User\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 16.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.6.156 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.8.1217.36096 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.8.1217.36096 - Alcor Micro Corp.) Hidden
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.36 - Atheros Communications Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1007.2702 - Micro-Star International Co., Ltd.)
Click Caption 1.10.0.6 (HKLM-x32\...\ClickCaption_1.10.0.6) (Version: 1.10.0.6 - ClickCaption) <==== ATTENTION
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.37.50 - Conexant)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Finger Sensing Pad Driver (HKLM\...\{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}) (Version: 8.8.0.9 - Sentelic)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.99 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417071FF}) (Version: 7.0.710 - Oracle)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 35.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0 - Mozilla)
MSI Remind Manager (HKLM-x32\...\{89F17DC5-A776-4DF4-8CD1-FAEF29BCE51A}) (Version: 1.11.0104 - MSI)
MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1801 - Micro-Star International Co., Ltd.)
Opera Stable 27.0.1689.54 (HKLM-x32\...\Opera 27.0.1689.54) (Version: 27.0.1689.54 - Opera Software ASA)
PC Sound (HKLM\...\{F3C66EC8-2F33-452D-9CFF-E8C886B3ECC4}) (Version: 1.11.0200 - SRS Labs, Inc.)
PHotkey (HKLM-x32\...\{24047BE4-329D-46F7-9689-8684C7A1CFBB}) (Version: 1.00.0010 - )
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.20.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.20.0 - Renesas Electronics Corporation) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Time Stamp (HKLM-x32\...\Time Stamp) (Version: 1.0.0.20110711 - Time Stamp Software, Inc.)
USB2.0 UVC 1.3M Webcam (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10275 - Realtek Semiconductor Corp.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{B39AA98E-C966-46C9-ACA2-D2586E300988}) (Version: 2.29.0.3 - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1D7AFB94-A35F-4B66-AFD6-835D0CCE590A} - System32\Tasks\avastBCLRestartS-1-5-21-2608712115-2613374988-3172207222-1001 => Chrome.exe
Task: {5AACC5E5-EBE4-481F-A36C-AB4006FCBA70} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {94942A87-B26C-4606-BBE6-1F7D27FE0F4A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-21] (Google Inc.)
Task: {94C3F196-04F6-461D-B74E-1E026BD544A6} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-01-23] (Enigma Software Group USA, LLC.)
Task: {9D07084A-F4DC-4F63-AB1F-D1A7BBAF9635} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {B6FEBACB-40C4-42D1-9BF2-F5CA91DF8601} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-21] (Google Inc.)
Task: {FAFC338D-5F94-48D0-B2E8-56F884FC5A81} - System32\Tasks\Opera scheduled Autoupdate 1421871456 => C:\Program Files (x86)\Opera\launcher.exe [2015-01-23] (Opera Software)
Task: {FBDED84C-4500-4D63-B3BB-65F540F4B779} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-01-20] (AVAST Software)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-08-11 18:27 - 2010-12-10 20:19 - 00104968 ____R () C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00159752 ____R () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
2011-08-11 18:27 - 2011-07-21 02:51 - 00824328 _____ () C:\Program Files (x86)\PHotkey\PHotkey.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00117256 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00121864 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2011-06-03 11:08 - 2011-04-15 03:16 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00126976 ____N () C:\Program Files\Time Stamp\IBP\fsloader.exe
2011-08-11 18:27 - 2010-12-17 22:04 - 00449032 ____R () C:\Program Files (x86)\PHotkey\ATouch64.exe
2011-08-11 18:27 - 2010-12-27 22:14 - 00776200 ____R () C:\Program Files (x86)\PHotkey\PVDesktop.exe
2011-08-11 18:27 - 2011-04-12 22:32 - 00483336 ____R () C:\Program Files (x86)\PHotkey\PVDAgent.exe
2015-01-20 12:57 - 2015-01-20 12:57 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2015-01-20 12:57 - 2015-01-20 12:57 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2015-01-29 21:25 - 2015-01-29 21:25 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15012901\algo.dll
2015-01-20 12:57 - 2015-01-20 12:57 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2011-08-11 18:27 - 2010-12-10 20:19 - 00973432 ____R () C:\Program Files (x86)\PHotkey\acAuth.dll
2011-08-11 18:27 - 2010-12-10 20:19 - 00129544 ____R () C:\Program Files (x86)\PHotkey\GFNEX.dll
2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-20 12:58 - 2015-01-20 12:58 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-01-19 11:20 - 2010-12-07 14:41 - 00151654 ____N () C:\Program Files\Time Stamp\IBP\Snapshot.dll
2015-01-19 11:20 - 2010-03-08 14:53 - 00073779 ____N () C:\Program Files\Time Stamp\IBP\UVFilter.dll
2015-01-19 11:20 - 2010-04-07 11:47 - 00090112 ____N () C:\Program Files\Time Stamp\IBP\VBcfgEx.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00057403 ____N () C:\Program Files\Time Stamp\IBP\DiskMsg.dll
2015-01-19 11:20 - 2011-01-04 10:09 - 00192607 ____N () C:\Program Files\Time Stamp\IBP\vbioctl.dll
2015-01-19 11:20 - 2010-08-30 11:16 - 00102445 ____N () C:\Program Files\Time Stamp\REG\FsAct.dll
2015-01-19 11:20 - 2010-08-29 12:11 - 00131119 ____N () C:\Program Files\Time Stamp\REG\RegKern.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00036864 ____N () C:\Program Files\Time Stamp\IBP\fssti.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00040960 ____N () C:\Program Files\Time Stamp\IBP\multidsk.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libglesv2.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libegl.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\pdf.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SRS PC Sound.lnk => C:\windows\pss\SRS PC Sound.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WebBrowserFastPlayer.lnk => C:\windows\pss\WebBrowserFastPlayer.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AmIcoSinglun64 => c:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
MSCONFIG\startupreg: GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: NUSB3MON => "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
MSCONFIG\startupreg: SmartAudio => C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-2608712115-2613374988-3172207222-500 - Administrator - Disabled)
Gast (S-1-5-21-2608712115-2613374988-3172207222-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2608712115-2613374988-3172207222-1002 - Limited - Enabled)
User (S-1-5-21-2608712115-2613374988-3172207222-1001 - Administrator - Enabled) => C:\Users\User

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/30/2015 00:57:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm AdwCleaner_4.109.exe, Version 4.1.0.9 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: de4

Startzeit: 01d03c83861fab14

Endzeit: 0

Anwendungspfad: C:\Users\User\Desktop\AdwCleaner_4.109.exe

Berichts-ID:


System errors:
=============
Error: (01/30/2015 01:25:38 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Microsoft Office Sessions:
=========================
Error: (01/30/2015 00:57:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: AdwCleaner_4.109.exe4.1.0.9de401d03c83861fab140C:\Users\User\Desktop\AdwCleaner_4.109.exe


CodeIntegrity Errors:
===================================
  Date: 2015-01-30 14:27:02.619
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 14:27:02.364
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 14:26:06.606
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 14:26:06.273
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 14:13:43.898
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 14:13:43.645
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 13:50:32.855
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 13:50:32.602
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 13:46:31.408
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 13:46:31.237
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 51%
Total physical RAM: 4008.29 MB
Available physical RAM: 1935.48 MB
Total Pagefile: 8014.76 MB
Available Pagefile: 5482.57 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:173.39 GB) (Free:100.97 GB) NTFS
Drive d: (Data) (Fixed) (Total:115.6 GB) (Free:104.66 GB) NTFS

==================== MBR & Partition Table ==================

==================== End Of Log ============================


cosinus 30.01.2015 14:36

Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    Click Caption 1.10.0.6

  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 


Nero555 30.01.2015 14:52

SpyHunterKiller funktioniert trotzdem nicht.
 
Ich habe alle Schritte erfolgreich ausgeführt. Ich habe daraufhin versucht SpyHunterKiller zu öffnen jedoch lässt es sich trotzdem nicht öffnen, der selbe Fehler wie am Anfang.

cosinus 30.01.2015 15:05

Vergiss den spyhunterkiller

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Task: {94C3F196-04F6-461D-B74E-1E026BD544A6} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-01-23] (Enigma Software Group USA, LLC.)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1025920 2015-01-23] (Enigma Software Group USA, LLC.)
C:\Program Files\Enigma Software Group
C:\windows\System32\Tasks\SpyHunter4Startup
C:\Users\User\AppData\Roaming\Enigma Software Group
C:\windows\system32\Drivers\EsgScanner.sys
C:\Program Files\Enigma Software Group
C:\Users\User\AppData\Local\Temp\9696F194-FBAC-E12D-6210-9B43FAFCA97D.dll
C:\Users\User\AppData\Local\Temp\BackupSetup.exe
C:\Users\User\AppData\Local\Temp\i33FC.tmp.exe
C:\Users\User\AppData\Local\Temp\i3874.tmp.exe
C:\Users\User\AppData\Local\Temp\i9602.tmp.exe
C:\Users\User\AppData\Local\Temp\i9924.tmp.exe
C:\Users\User\AppData\Local\Temp\iBA4.tmp.exe
C:\Users\User\AppData\Local\Temp\iE3FA.tmp.exe
C:\Users\User\AppData\Local\Temp\iE714.tmp.exe
C:\Users\User\AppData\Local\Temp\nst712.exe
C:\Users\User\AppData\Local\Temp\nszF70B.exe
C:\Users\User\AppData\Local\Temp\optprosetup.exe
C:\Users\User\AppData\Local\Temp\Quarantine.exe
C:\Users\User\AppData\Local\Temp\setup_472.exe
C:\Users\User\AppData\Local\Temp\sqlite3.dll
C:\Users\User\AppData\Local\Temp\vcredist_x64.exe
EmptyTemp:
Hosts:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Nero555 30.01.2015 15:22

FRST Fixlist
 
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015
Ran by User at 2015-01-30 15:10:34 Run:1
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Task: {94C3F196-04F6-461D-B74E-1E026BD544A6} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-01-23] (Enigma Software Group USA, LLC.)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1025920 2015-01-23] (Enigma Software Group USA, LLC.)
C:\Program Files\Enigma Software Group
C:\windows\System32\Tasks\SpyHunter4Startup
C:\Users\User\AppData\Roaming\Enigma Software Group
C:\windows\system32\Drivers\EsgScanner.sys
C:\Program Files\Enigma Software Group
C:\Users\User\AppData\Local\Temp\9696F194-FBAC-E12D-6210-9B43FAFCA97D.dll
C:\Users\User\AppData\Local\Temp\BackupSetup.exe
C:\Users\User\AppData\Local\Temp\i33FC.tmp.exe
C:\Users\User\AppData\Local\Temp\i3874.tmp.exe
C:\Users\User\AppData\Local\Temp\i9602.tmp.exe
C:\Users\User\AppData\Local\Temp\i9924.tmp.exe
C:\Users\User\AppData\Local\Temp\iBA4.tmp.exe
C:\Users\User\AppData\Local\Temp\iE3FA.tmp.exe
C:\Users\User\AppData\Local\Temp\iE714.tmp.exe
C:\Users\User\AppData\Local\Temp\nst712.exe
C:\Users\User\AppData\Local\Temp\nszF70B.exe
C:\Users\User\AppData\Local\Temp\optprosetup.exe
C:\Users\User\AppData\Local\Temp\Quarantine.exe
C:\Users\User\AppData\Local\Temp\setup_472.exe
C:\Users\User\AppData\Local\Temp\sqlite3.dll
C:\Users\User\AppData\Local\Temp\vcredist_x64.exe
EmptyTemp:
Hosts:
       

*****************

C:\windows\system32\GroupPolicy\Machine => Moved successfully.
C:\windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{94C3F196-04F6-461D-B74E-1E026BD544A6}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94C3F196-04F6-461D-B74E-1E026BD544A6}" => Key deleted successfully.
C:\Windows\System32\Tasks\SpyHunter4Startup => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpyHunter4Startup" => Key deleted successfully.
SpyHunter 4 Service => Service stopped successfully.
SpyHunter 4 Service => Service deleted successfully.

"C:\Program Files\Enigma Software Group" directory move:

C:\Program Files\Enigma Software Group\SpyHunter\Brazilian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Common.dll => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\cos.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Czech.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Danish.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Defman.dll => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Dutch.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\English.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\EsgScanner.inf => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\EsgScanner.sys => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\ExecutionGuard.dll => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Finnish.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\French.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\gas.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\German.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\gil.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Italian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Japanese.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\license.txt => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Lithuanian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\native.exe => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Norwegian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Portuguese.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\purl.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Russian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\safeol.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\scanlog.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\ShScanner.dll => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Spanish.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.com => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\supportlog.txt => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Swedish.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\unkcache.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\mon\autoexec.bat.bk => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\mon\hosts.bk => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\mon\system.ini.bk => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\mon\win.ini.bk => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150123_191427.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150124_113331.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150124_194723.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150125_133945.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150126_133635.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150127_130036.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150128_125032.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150128_130131.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150129_123945.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150130_121624.log => Moved successfully.
Could not move "C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150130_123611.log" => Scheduled to move on reboot.
C:\Program Files\Enigma Software Group\SpyHunter\defs\cmp_2015012902.def => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Data\dns.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Data\proxy.dat => Moved successfully.
Could not move "C:\Program Files\Enigma Software Group" directory. => Scheduled to move on reboot.

"C:\windows\System32\Tasks\SpyHunter4Startup" => File/Directory not found.
C:\Users\User\AppData\Roaming\Enigma Software Group => Moved successfully.
C:\windows\system32\Drivers\EsgScanner.sys => Moved successfully.

"C:\Program Files\Enigma Software Group" directory move:

Could not move "C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150130_123611.log" => Scheduled to move on reboot.
Could not move "C:\Program Files\Enigma Software Group" directory. => Scheduled to move on reboot.

C:\Users\User\AppData\Local\Temp\9696F194-FBAC-E12D-6210-9B43FAFCA97D.dll => Moved successfully.
C:\Users\User\AppData\Local\Temp\BackupSetup.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\i33FC.tmp.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\i3874.tmp.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\i9602.tmp.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\i9924.tmp.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\iBA4.tmp.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\iE3FA.tmp.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\iE714.tmp.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\nst712.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\nszF70B.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\optprosetup.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\setup_472.exe => Moved successfully.
C:\Users\User\AppData\Local\Temp\sqlite3.dll => Moved successfully.
C:\Users\User\AppData\Local\Temp\vcredist_x64.exe => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 2.6 GB temporary data.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-01-30 15:18:09)<=

C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150130_123611.log => Is moved successfully.
C:\Program Files\Enigma Software Group => Is moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150130_123611.log => Is moved successfully.
C:\Program Files\Enigma Software Group => Is moved successfully.

==== End of Fixlog 15:18:09 ====


cosinus 30.01.2015 15:27

Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken

http://saved.im/mtg0mjy4yjlu/2014-04...ryscantool.png

Nero555 30.01.2015 15:58

FRST Editor Logfile (1)
 
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by User (administrator) on USER-MSI on 30-01-2015 15:51:14
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files (x86)\PHotkey\AsLdrSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(Intel Corporation) C:\Windows\system32\igfxtray.exe
(Intel Corporation) C:\Windows\system32\hkcmd.exe
(Intel Corporation) C:\Windows\system32\igfxpers.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\system32\CISVC.EXE
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
() C:\Program Files\Time Stamp\IBP\FsLoader.exe
(FarStone Technology, Inc.) C:\Program Files\Time Stamp\IBP\VBPTask.exe
(Microsoft Corporation) C:\Windows\system32\mqsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corporation) C:\Windows\system32\TCPSVCS.EXE
(Microsoft Corporation) C:\Windows\system32\snmp.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Time Lapse Solutions) C:\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\PHotkey\Atouch64.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\MsOsd.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\system32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [6275424 2014-05-13] (Sentelic Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\...\Run: [Gameo] => C:\Users\User\AppData\Roaming\Gameo\gameo.exe "C:\Users\User\AppData\Roaming\Gameo\gameo.dat" mode:minimized
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\...\Run: [GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [856904 2015-01-09] (Google Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2608712115-2613374988-3172207222-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2608712115-2613374988-3172207222-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.111 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\searchplugins\google-avast.xml
FF Extension: firesshnightlightws - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\Extensions\firessh@nightlight.ws [2015-01-29]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-20]

Chrome:
=======
CHR HomePage: Default -> https://www.google.de/
CHR StartupUrls: Default -> "https://twitter.com/", "https://www.youtube.com/feed/subscriptions", "https://www.google.de/"
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-21]
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-21]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-21]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-21]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-21]
CHR Extension: (Adblock Plus) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-01-21]
CHR Extension: (Google-Suche) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-21]
CHR Extension: (Google Tabellen) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-21]
CHR Extension: (AdBlock) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-21]
CHR Extension: (Avast Online Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-01-21]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-21]
CHR Extension: (Google Mail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-20]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2010-12-10] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-20] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2015-01-20] (Avast Software)
S2 d924d8dc; c:\Program Files (x86)\Optimizer Pro 3.33\OptProMon.dll [1597008 2015-01-21] ()
R2 DriveClone Network Client IBP; C:\Program Files\Time Stamp\IBP\fsloader.exe [126976 2009-08-17] () [File not signed]
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-12-10] ()
U2 iprip; C:\Windows\System32\iprip.dll [35328 2009-07-14] (Microsoft Corporation)
R2 MElGfYhtuP; C:\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe [2733872 2015-01-22] (Time Lapse Solutions)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 SNMP; C:\Windows\System32\snmp.exe [49664 2010-11-21] (Microsoft Corporation)
R2 SNMP; C:\Windows\SysWOW64\snmp.exe [47616 2010-11-21] (Microsoft Corporation)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-20] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2015-01-20] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-20] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-20] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-20] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-20] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-20] ()
R3 FARMNTIO; c:\windows\system32\drivers\farmntio.sys [24664 2011-04-18] ()
R3 fspad_win764; C:\Windows\System32\DRIVERS\fspad_win764.sys [173408 2014-05-13] (Sentelic Corporation)
S3 fspad_wlh64; C:\Windows\System32\DRIVERS\fspad_wlh64.sys [68608 2010-11-08] (Sentelic Corporation) [File not signed]
R2 HCDisk; C:\Windows\System32\Drivers\HCDisk.sys [66136 2011-01-04] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2014-04-24] (Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [129224 2013-11-29] (Qualcomm Atheros Co., Ltd.)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2010-12-10] (PEGATRON)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [9112792 2014-05-02] (Realtek Semiconductor Corp.)
R3 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2015-01-20] (Avast Software)
R0 VVBackd5; C:\Windows\System32\Drivers\VVBackd5.sys [162392 2011-07-12] ()
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X]
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-30 15:50 - 2015-01-30 15:50 - 00024386 _____ () C:\Users\User\Desktop\Addition.txt
2015-01-30 15:48 - 2015-01-30 15:51 - 00016720 _____ () C:\Users\User\Desktop\FRST.txt
2015-01-30 15:26 - 2015-01-30 15:26 - 00002126 _____ () C:\Users\Public\Desktop\speed browser.lnk
2015-01-30 15:26 - 2015-01-30 15:26 - 00000000 ____D () C:\Users\User\AppData\Local\speed browser
2015-01-30 15:26 - 2015-01-30 15:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\speed browser
2015-01-30 15:23 - 2015-01-30 15:26 - 00000000 ____D () C:\Program Files (x86)\speed browser
2015-01-30 15:22 - 2015-01-30 15:22 - 01498256 _____ () C:\ProgramData\Setup.exe
2015-01-30 15:21 - 2015-01-30 15:21 - 00000000 ____D () C:\ProgramData\Browser
2015-01-30 15:19 - 2015-01-30 15:21 - 00000000 ____D () C:\Users\User\AppData\Local\ZombieNews
2015-01-30 15:09 - 2015-01-30 15:09 - 00000000 ____D () C:\Users\User\Documents\Neuer Ordner
2015-01-30 15:07 - 2015-01-30 15:09 - 00001796 _____ () C:\Users\User\Documents\Fixlist.txt
2015-01-30 14:43 - 2015-01-30 14:43 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\User\Downloads\revosetup95.exe
2015-01-30 14:43 - 2015-01-30 14:43 - 00001278 _____ () C:\Users\User\Desktop\Revo Uninstaller.lnk
2015-01-30 14:43 - 2015-01-30 14:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-01-30 12:58 - 2015-01-30 12:58 - 00000000 ___DC () C:\Users\User\AppData\Local\MigWiz
2015-01-30 12:51 - 2015-01-30 12:51 - 00000758 _____ () C:\Users\User\Desktop\JRT.txt
2015-01-30 12:38 - 2015-01-30 12:38 - 01707939 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2015-01-30 12:21 - 2015-01-30 12:21 - 02194432 _____ () C:\Users\User\Desktop\AdwCleaner_4.109.exe
2015-01-29 23:18 - 2015-01-29 23:36 - 00000000 ____D () C:\Users\User\Downloads\SSF2DemoV0_9b1978 (1)
2015-01-29 21:46 - 2015-01-29 21:57 - 191153583 _____ () C:\Users\User\Downloads\SSF2DemoV0_9b1978 (1).zip
2015-01-29 21:46 - 2015-01-29 21:46 - 00000000 ____D () C:\Users\User\data
2015-01-29 16:17 - 2015-01-29 17:00 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-29 16:17 - 2015-01-29 16:31 - 00136408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-29 16:17 - 2015-01-29 16:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-29 16:15 - 2015-01-29 17:01 - 00000000 ____D () C:\Users\User\Desktop\mbar
2015-01-29 16:15 - 2015-01-29 16:29 - 00097496 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-01-29 16:14 - 2015-01-29 16:15 - 16466552 _____ (Malwarebytes Corp.) C:\Users\User\Desktop\mbar-1.08.3.1004.exe
2015-01-29 14:56 - 2015-01-30 15:51 - 00000000 ____D () C:\FRST
2015-01-29 14:56 - 2015-01-29 14:56 - 02130432 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2015-01-29 13:34 - 2015-01-29 13:35 - 00041670 _____ () C:\windows\iis7.log
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\SysWOW64\BestPractices
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\system32\msmq
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\system32\BestPractices
2015-01-29 13:31 - 2015-01-29 13:30 - 00000862 _____ () C:\windows\system32\termcap
2015-01-29 13:30 - 2015-01-29 13:31 - 00000000 ____D () C:\inetpub
2015-01-29 13:22 - 2015-01-29 13:22 - 00462888 _____ () C:\Users\User\Downloads\SpyHunterKiller.exe
2015-01-23 21:14 - 2015-01-23 21:14 - 00000000 ____D () C:\windows\pss
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 ____D () C:\sh4ldr
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 _____ () C:\autoexec.bat
2015-01-23 18:57 - 2015-01-23 18:57 - 00000247 _____ () C:\windows\system32\2015-01-23-17-57-45.092-aswFe.exe-5340.log
2015-01-23 18:57 - 2015-01-23 18:57 - 00000197 _____ () C:\windows\system32\2015-01-23-17-57-38.027-AvastVBoxSVC.exe-1312.log
2015-01-23 17:59 - 2015-01-30 12:56 - 00000000 ____D () C:\AdwCleaner
2015-01-23 17:49 - 2015-01-23 17:49 - 00000197 _____ () C:\windows\system32\2015-01-23-16-49-31.016-AvastVBoxSVC.exe-3784.log
2015-01-23 16:23 - 2015-01-23 16:23 - 00000197 _____ () C:\windows\system32\2015-01-23-15-23-49.010-AvastVBoxSVC.exe-6012.log
2015-01-23 16:08 - 2015-01-23 16:08 - 00000000 ____D () C:\Users\User\AppData\Local\com
2015-01-23 16:06 - 2015-01-23 16:06 - 00000000 ____D () C:\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f
2015-01-23 15:52 - 2015-01-23 15:52 - 00000197 _____ () C:\windows\system32\2015-01-23-14-52-16.032-AvastVBoxSVC.exe-5244.log
2015-01-23 13:21 - 2015-01-23 18:55 - 00001557 _____ () C:\Users\User\Desktop\Chrome.lnk
2015-01-23 13:14 - 2015-01-23 13:14 - 00000197 _____ () C:\windows\system32\2015-01-23-12-14-23.097-AvastVBoxSVC.exe-3880.log
2015-01-23 13:12 - 2015-01-30 15:16 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-22 18:29 - 2015-01-23 15:58 - 00000000 ____D () C:\Users\User\AppData\Roaming\Apple Computer
2015-01-22 18:29 - 2015-01-22 18:29 - 00001793 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-01-22 18:29 - 2015-01-22 18:29 - 00000000 ____D () C:\Users\User\AppData\Local\Apple Computer
2015-01-22 18:29 - 2015-01-22 18:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-01-22 18:28 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\windows\system32\Drivers\GEARAspiWDM.sys
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\Program Files\iTunes
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-22 18:26 - 2015-01-22 18:26 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-01-22 18:26 - 2015-01-22 18:26 - 00000000 ____D () C:\Program Files\iPod
2015-01-22 18:25 - 2015-01-22 18:25 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\windows\System32\Tasks\Apple
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\Users\User\AppData\Local\Apple
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2015-01-22 18:24 - 2015-01-22 18:26 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-01-22 18:23 - 2015-01-22 18:23 - 00000000 ____D () C:\Program Files\Bonjour
2015-01-22 18:23 - 2015-01-22 18:23 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-01-22 18:21 - 2015-01-22 18:25 - 00000000 ____D () C:\ProgramData\Apple
2015-01-22 18:18 - 2015-01-22 18:20 - 122418480 _____ (Apple Inc.) C:\Users\User\Downloads\iTunes64Setup.exe
2015-01-22 12:40 - 2015-01-22 12:40 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps
2015-01-22 12:36 - 2015-01-22 12:36 - 00000000 ____D () C:\Users\User\AppData\Local\Macromedia
2015-01-22 12:32 - 2015-01-29 13:18 - 00003276 _____ () C:\windows\System32\Tasks\avastBCLRestartS-1-5-21-2608712115-2613374988-3172207222-1001
2015-01-22 12:30 - 2015-01-22 12:31 - 00000000 ____D () C:\Users\User\AppData\Roaming\Mozilla
2015-01-22 12:30 - 2015-01-22 12:31 - 00000000 ____D () C:\Users\User\AppData\Local\Mozilla
2015-01-22 12:29 - 2015-01-22 12:29 - 00000000 ____D () C:\ProgramData\xfIwQZvgdh
2015-01-22 12:24 - 2015-01-22 12:25 - 00000197 _____ () C:\windows\system32\2015-01-22-11-24-48.051-AvastVBoxSVC.exe-3272.log
2015-01-21 23:15 - 2015-01-21 23:15 - 00000197 _____ () C:\windows\system32\2015-01-21-22-15-00.076-AvastVBoxSVC.exe-4408.log
2015-01-21 22:09 - 2015-01-21 22:10 - 00021976 _____ () C:\windows\system32\Drivers\SPPD.sys
2015-01-21 22:05 - 2015-01-21 22:05 - 00000280 _____ () C:\windows\system32\2015-01-21-21-05-13.073-aswFe.exe-6612.log
2015-01-21 22:01 - 2015-01-21 22:01 - 00000000 ___HD () C:\Users\User\AppData\Roaming\GoldenGate
2015-01-21 22:00 - 2015-01-21 22:00 - 00000170 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2015-01-21 21:47 - 2015-01-21 21:47 - 00000000 ____D () C:\ProgramData\McAfee
2015-01-21 21:18 - 2015-01-21 21:18 - 00000000 ____D () C:\Users\User\AppData\Roaming\Opera Software
2015-01-21 21:18 - 2015-01-21 21:18 - 00000000 ____D () C:\Users\User\AppData\Local\Opera Software
2015-01-21 21:17 - 2015-01-29 12:48 - 00003852 _____ () C:\windows\System32\Tasks\Opera scheduled Autoupdate 1421871456
2015-01-21 21:17 - 2015-01-21 21:17 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-01-21 21:16 - 2015-01-29 12:48 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-01-21 21:03 - 2015-01-21 21:03 - 00000280 _____ () C:\windows\system32\2015-01-21-20-03-26.006-aswFe.exe-3824.log
2015-01-21 20:40 - 2015-01-22 12:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-21 20:39 - 2015-01-30 15:45 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-21 20:39 - 2015-01-30 15:28 - 00001102 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-21 20:39 - 2015-01-21 20:40 - 00000000 ____D () C:\Users\User\AppData\Local\Google
2015-01-21 20:39 - 2015-01-21 20:40 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-21 20:39 - 2015-01-21 20:39 - 00004102 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-01-21 20:39 - 2015-01-21 20:39 - 00003850 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-01-21 20:34 - 2015-01-21 20:38 - 00000000 ____D () C:\Users\User\AppData\Local\Deployment
2015-01-21 20:34 - 2015-01-21 20:34 - 00000000 ____D () C:\Users\User\AppData\Local\Apps\2.0
2015-01-21 20:32 - 2015-01-21 20:32 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.33
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieUserList
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieSiteList
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieBrowserModeList
2015-01-21 20:27 - 2015-01-21 20:27 - 00000197 _____ () C:\windows\system32\2015-01-21-19-27-14.097-AvastVBoxSVC.exe-3556.log
2015-01-21 16:40 - 2015-01-21 16:40 - 00000197 _____ () C:\windows\system32\2015-01-21-15-40-25.087-AvastVBoxSVC.exe-2804.log
2015-01-21 12:12 - 2015-01-21 12:12 - 00000197 _____ () C:\windows\system32\2015-01-21-11-12-09.083-AvastVBoxSVC.exe-3988.log
2015-01-21 11:42 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-01-21 11:42 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-01-21 11:42 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-01-21 11:42 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-01-21 11:42 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-01-21 11:04 - 2015-01-21 11:04 - 00000197 _____ () C:\windows\system32\2015-01-21-10-04-40.059-AvastVBoxSVC.exe-2880.log
2015-01-21 10:35 - 2014-06-27 03:08 - 02777088 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2015-01-21 10:35 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2vdec.dll
2015-01-21 10:33 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2015-01-21 10:33 - 2014-05-08 10:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2015-01-21 10:33 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2015-01-21 10:33 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-01-21 10:33 - 2011-02-25 07:19 - 02871808 _____ (Microsoft Corporation) C:\windows\explorer.exe
2015-01-21 10:33 - 2011-02-25 06:30 - 02616320 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2015-01-21 10:32 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\windows\SysWOW64\d2d1.dll
2015-01-21 10:32 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2015-01-21 10:32 - 2011-03-11 07:41 - 00410496 _____ (Intel Corporation) C:\windows\system32\Drivers\iaStorV.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00166272 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvstor.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00148352 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvraid.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00107904 _____ (Advanced Micro Devices) C:\windows\system32\Drivers\amdsata.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00027008 _____ (Advanced Micro Devices) C:\windows\system32\Drivers\amdxata.sys
2015-01-21 10:32 - 2011-03-11 07:33 - 02565632 _____ (Microsoft Corporation) C:\windows\system32\esent.dll
2015-01-21 10:32 - 2011-03-11 07:30 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\fsutil.exe
2015-01-21 10:32 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\windows\SysWOW64\esent.dll
2015-01-21 10:32 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\fsutil.exe
2015-01-21 10:32 - 2011-03-11 05:37 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2015-01-21 10:31 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDYAK.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDTAT.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU1.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDBASH.DLL
2015-01-21 10:31 - 2014-07-08 23:38 - 00419992 _____ () C:\windows\system32\locale.nls
2015-01-21 10:31 - 2014-07-08 23:30 - 00419992 _____ () C:\windows\SysWOW64\locale.nls
2015-01-21 10:31 - 2014-06-24 04:29 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-01-21 10:31 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2015-01-21 10:31 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2015-01-21 10:31 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\windows\splwow64.exe
2015-01-21 10:27 - 2015-01-21 10:28 - 00000197 _____ () C:\windows\system32\2015-01-21-09-27-50.087-AvastVBoxSVC.exe-2660.log
2015-01-21 10:08 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2015-01-21 10:08 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-21 10:08 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-21 10:08 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2015-01-21 10:07 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2015-01-21 10:07 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2015-01-21 10:07 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-01-21 10:07 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-01-21 10:07 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2015-01-21 10:07 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2015-01-21 10:07 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-01-21 10:07 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2015-01-21 10:07 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2015-01-21 10:07 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-01-21 10:07 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2015-01-21 10:03 - 2015-01-21 11:57 - 04190942 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2015-01-21 09:56 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2015-01-21 09:56 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2015-01-21 09:56 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2015-01-21 09:56 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2015-01-21 09:56 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2015-01-21 09:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-01-21 09:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-01-21 09:35 - 2015-01-21 09:35 - 00000197 _____ () C:\windows\system32\2015-01-21-08-35-45.076-AvastVBoxSVC.exe-2464.log
2015-01-21 09:25 - 2015-01-21 09:25 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-01-21 09:25 - 2015-01-21 09:25 - 00000000 ____D () C:\windows\system32\appraiser
2015-01-21 09:23 - 2015-01-21 09:24 - 00000197 _____ () C:\windows\system32\2015-01-21-08-23-41.005-AvastVBoxSVC.exe-168.log
2015-01-21 09:21 - 2015-01-21 09:21 - 1140010868 _____ () C:\windows\MEMORY.DMP
2015-01-21 09:21 - 2015-01-21 09:21 - 00000000 ____D () C:\windows\Minidump
2015-01-20 21:00 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-01-20 21:00 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-01-20 21:00 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2015-01-20 21:00 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-01-20 20:01 - 2015-01-20 20:01 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-01-20 20:01 - 2015-01-20 20:01 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-01-20 20:01 - 2015-01-20 20:01 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-01-20 20:01 - 2015-01-20 20:01 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat
2015-01-20 20:01 - 2015-01-20 20:01 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2015-01-20 20:01 - 2015-01-20 20:01 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-01-20 20:01 - 2015-01-20 20:01 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-01-20 20:01 - 2015-01-20 20:01 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-01-20 20:01 - 2015-01-20 20:01 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01682432 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01643520 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01247744 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01238528 _____ (Microsoft Corporation) C:\windows\system32\d3d10.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01175552 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01158144 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsPrint.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01080832 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00648192 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00604160 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10level9.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00522752 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsGdiConverter.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00363008 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00333312 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\d3d10core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00293376 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00249856 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10_1core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00245248 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00207872 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecsExt.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00194560 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00187392 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAnimation.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00161792 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10_1.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00010752 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00010752 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00009728 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00009728 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00002560 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00002560 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-01-20 14:53 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-01-20 14:53 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2015-01-20 14:53 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-01-20 14:53 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-01-20 14:53 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-01-20 14:53 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-01-20 14:53 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2015-01-20 14:53 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2015-01-20 14:53 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2015-01-20 14:53 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\windows\system32\WUDFx.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe
2015-01-20 14:51 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\windows\system32\WUDFCoinstaller.dll
2015-01-20 14:51 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys
2015-01-20 14:51 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys
2015-01-20 14:51 - 2012-06-02 15:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-01-20 14:27 - 2015-01-20 14:27 - 00000197 _____ () C:\windows\system32\2015-01-20-13-27-06.064-AvastVBoxSVC.exe-2964.log
2015-01-20 13:56 - 2015-01-20 13:56 - 00000197 _____ () C:\windows\system32\2015-01-20-12-56-28.062-AvastVBoxSVC.exe-4596.log
2015-01-20 13:20 - 2015-01-20 13:20 - 00000247 _____ () C:\windows\system32\2015-01-20-12-20-48.046-aswFe.exe-6056.log
2015-01-20 13:13 - 2015-01-20 13:20 - 00000247 _____ () C:\windows\system32\2015-01-20-12-13-29.071-aswFe.exe-4372.log
2015-01-20 13:13 - 2015-01-20 13:13 - 00000197 _____ () C:\windows\system32\2015-01-20-12-13-23.011-AvastVBoxSVC.exe-4364.log
2015-01-20 13:04 - 2015-01-20 13:04 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVAST Software
2015-01-20 13:00 - 2015-01-20 13:00 - 00000000 ____D () C:\windows\SysWOW64\vbox
2015-01-20 13:00 - 2015-01-20 13:00 - 00000000 ____D () C:\windows\system32\vbox
2015-01-20 12:59 - 2015-01-20 12:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-01-20 12:58 - 2015-01-29 12:39 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2015-01-20 12:58 - 2015-01-21 09:40 - 01050432 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00436624 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00364512 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2015-01-20 12:58 - 2015-01-20 12:58 - 00267632 _____ () C:\windows\system32\Drivers\aswVmm.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00116728 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00083280 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2015-01-20 12:58 - 2015-01-20 12:58 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys
2015-01-20 12:57 - 2015-01-20 12:57 - 00000000 ____D () C:\Program Files\AVAST Software
2015-01-20 12:56 - 2015-01-20 12:57 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-01-20 12:56 - 2015-01-20 12:56 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-01-20 12:56 - 2015-01-20 12:56 - 00002029 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-01-20 12:55 - 2015-01-20 12:55 - 00001080 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\windows\SysWOW64\Adobe
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2015-01-20 12:54 - 2015-01-20 12:54 - 00319912 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2015-01-20 12:54 - 2015-01-20 12:54 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\ProgramData\Sun
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\Program Files\Java
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-20 12:53 - 2015-01-21 22:02 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
2015-01-20 12:53 - 2015-01-20 12:56 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-20 12:53 - 2015-01-20 12:56 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-01-20 12:52 - 2015-01-20 12:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-01-20 12:52 - 2015-01-20 12:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-01-20 12:51 - 2015-01-22 12:32 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-20 12:51 - 2015-01-22 12:32 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\ProgramData\Mozilla
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-20 12:48 - 2015-01-30 15:24 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-01-20 12:48 - 2015-01-25 17:24 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-01-20 12:48 - 2015-01-25 17:24 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-20 12:48 - 2015-01-25 17:24 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-01-20 12:48 - 2015-01-20 12:48 - 00000000 ____D () C:\windows\system32\Macromed
2015-01-19 14:18 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE
2015-01-19 13:38 - 2015-01-20 20:35 - 00041009 _____ () C:\windows\IE11_main.log
2015-01-19 12:14 - 2015-01-19 12:16 - 00000000 ____D () C:\windows\system32\MRT
2015-01-19 12:14 - 2014-12-31 13:12 - 113365784 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-01-19 12:12 - 2015-01-19 12:12 - 00000000 ____D () C:\Users\User\AppData\Local\WindowsUpdate
2015-01-19 12:12 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\windows\system32\icardres.dll
2015-01-19 12:12 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardres.dll
2015-01-19 12:12 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\windows\SysWOW64\TsWpfWrp.exe
2015-01-19 12:12 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
2015-01-19 12:12 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\windows\system32\icardagt.exe
2015-01-19 12:12 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\windows\system32\infocardapi.dll
2015-01-19 12:12 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardagt.exe
2015-01-19 12:12 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\windows\SysWOW64\infocardapi.dll
2015-01-19 12:10 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2015-01-19 12:10 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2015-01-19 12:10 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\windows\SysWOW64\certutil.exe
2015-01-19 12:10 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\certenc.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-01-19 12:09 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-01-19 12:09 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-01-19 12:09 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-01-19 12:08 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2015-01-19 12:08 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2015-01-19 12:08 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2015-01-19 12:08 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2015-01-19 12:08 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2015-01-19 12:08 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2015-01-19 12:08 - 2014-03-04 10:44 - 00722944 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2015-01-19 12:08 - 2014-03-04 10:44 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-01-19 12:08 - 2014-03-04 10:44 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\objsel.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\windows\SysWOW64\adprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\capiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsroam.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredprovider.dll
2015-01-19 12:08 - 2014-03-04 10:16 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll
2015-01-19 12:08 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2015-01-19 12:08 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe
2015-01-19 12:08 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_isv.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_ssp_isv.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_ssp.dll
2015-01-19 12:08 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdrm.dll
2015-01-19 12:08 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_isv.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_ssp.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_ssp_isv.exe
2015-01-19 12:08 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2015-01-19 12:08 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2015-01-19 12:08 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2015-01-19 12:08 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys
2015-01-19 12:08 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\Wdfres.dll
2015-01-19 12:08 - 2012-11-28 23:56 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-01-19 12:08 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\rdpwsx.dll
2015-01-19 12:08 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\windows\system32\rdrmemptylst.exe
2015-01-19 12:07 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2015-01-19 12:07 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-01-19 12:07 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-01-19 12:07 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-01-19 12:07 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-01-19 12:07 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-01-19 12:07 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-01-19 12:07 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-01-19 12:07 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-01-19 12:07 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-01-19 12:07 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-01-19 12:07 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2015-01-19 12:07 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d11.dll
2015-01-19 12:07 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2015-01-19 12:07 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll
2015-01-19 12:07 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\windows\system32\gameux.dll
2015-01-19 12:07 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wpc.dll
2015-01-19 12:07 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\windows\SysWOW64\gameux.dll
2015-01-19 12:07 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\windows\system32\oflc-nz.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\windows\system32\pegibbfc.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\windows\system32\csrr.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\windows\system32\usk.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\windows\system32\oflc.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-pt.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-fi.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\windows\system32\cero.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\windows\system32\esrb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\windows\system32\fpb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\windows\system32\cob-au.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\windows\system32\grb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\windows\system32\pegi.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\windows\system32\djctq.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\windows\SysWOW64\cero.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\windows\SysWOW64\esrb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\windows\SysWOW64\fpb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\windows\SysWOW64\oflc-nz.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\windows\SysWOW64\pegibbfc.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\windows\SysWOW64\csrr.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\windows\SysWOW64\cob-au.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\windows\SysWOW64\usk.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\windows\SysWOW64\oflc.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\windows\SysWOW64\grb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi-pt.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi-fi.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\windows\SysWOW64\djctq.rs
2015-01-19 12:06 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-01-19 12:06 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-01-19 12:06 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-01-19 12:06 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-01-19 12:06 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-01-19 12:06 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-01-19 12:06 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-01-19 12:06 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-01-19 12:06 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2015-01-19 12:06 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-01-19 12:06 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\windows\SysWOW64\pku2u.dll
2015-01-19 12:06 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-01-19 12:06 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-01-19 12:06 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-01-19 12:06 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-01-19 12:06 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2015-01-19 12:06 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2015-01-19 12:06 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2015-01-19 12:06 - 2014-08-01 12:53 - 01031168 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2015-01-19 12:06 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll
2015-01-19 12:06 - 2014-04-12 03:22 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-01-19 12:06 - 2014-04-12 03:19 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-01-19 12:06 - 2014-04-12 03:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-01-19 12:06 - 2014-04-12 03:19 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-01-19 12:06 - 2014-04-12 03:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-01-19 12:06 - 2014-03-04 10:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-01-19 12:06 - 2014-03-04 10:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-01-19 12:06 - 2014-03-04 10:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-01-19 12:06 - 2014-03-04 10:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-01-19 12:06 - 2014-03-04 09:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-01-19 12:06 - 2014-03-04 09:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-01-19 12:06 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2015-01-19 12:06 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll
2015-01-19 12:06 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-01-19 12:06 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-01-19 12:06 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-01-19 12:06 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2015-01-19 12:06 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\shdocvw.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\windows\system32\netcorehc.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\netevent.dll
2015-01-19 12:06 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2015-01-19 12:06 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\netcorehc.dll
2015-01-19 12:06 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\netevent.dll
2015-01-19 12:06 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2015-01-19 12:05 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-01-19 12:05 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2015-01-19 12:05 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2015-01-19 12:05 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10K.DLL
2015-01-19 12:05 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-01-19 12:05 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-01-19 12:05 - 2014-06-18 03:18 - 00692736 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2015-01-19 12:05 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
2015-01-19 12:05 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2015-01-19 12:05 - 2014-06-06 11:10 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2015-01-19 12:05 - 2014-06-06 10:44 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2015-01-19 12:05 - 2014-04-05 03:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2015-01-19 12:05 - 2014-04-05 03:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2015-01-19 12:05 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2015-01-19 12:05 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2015-01-19 12:05 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-01-19 12:05 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-01-19 12:05 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-01-19 12:05 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-01-19 12:05 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2015-01-19 12:05 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptdlg.dll
2015-01-19 12:05 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2015-01-19 12:05 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2015-01-19 12:05 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2015-01-19 12:05 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wwanprotdim.dll
2015-01-19 12:05 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll
2015-01-19 12:05 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll
2015-01-19 12:05 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore6.dll
2015-01-19 12:05 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc6.dll
2015-01-19 12:05 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\windows\system32\OxpsConverter.exe
2015-01-19 12:05 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\netapi32.dll
2015-01-19 12:05 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\browser.dll
2015-01-19 12:05 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\browcli.dll
2015-01-19 12:05 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\windows\SysWOW64\netapi32.dll
2015-01-19 12:05 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\windows\SysWOW64\browcli.dll
2015-01-19 12:05 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\windows\system32\ntshrui.dll
2015-01-19 12:05 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntshrui.dll
2015-01-19 12:05 - 2011-10-26 06:25 - 01572864 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-01-19 12:05 - 2011-10-26 05:32 - 01328128 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2015-01-19 12:05 - 2011-07-09 03:46 - 00288768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-01-19 12:05 - 2011-05-04 06:25 - 02315776 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 02223616 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00778752 _____ (Microsoft Corporation) C:\windows\system32\mssvp.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00491520 _____ (Microsoft Corporation) C:\windows\system32\mssph.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00288256 _____ (Microsoft Corporation) C:\windows\system32\mssphtb.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00075264 _____ (Microsoft Corporation) C:\windows\system32\msscntrs.dll
2015-01-19 12:05 - 2011-05-04 06:19 - 00591872 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe
2015-01-19 12:05 - 2011-05-04 06:19 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\SearchProtocolHost.exe
2015-01-19 12:05 - 2011-05-04 06:19 - 00113664 _____ (Microsoft Corporation) C:\windows\system32\SearchFilterHost.exe
2015-01-19 12:05 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssvp.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssph.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssphtb.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscntrs.dll
2015-01-19 12:05 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe
2015-01-19 12:05 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchProtocolHost.exe
2015-01-19 12:05 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFilterHost.exe
2015-01-19 12:05 - 2011-04-27 03:40 - 00158208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-01-19 12:05 - 2011-04-27 03:39 - 00128000 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-01-19 12:05 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\poqexec.exe
2015-01-19 12:05 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\poqexec.exe
2015-01-19 12:05 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2015-01-19 12:04 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-01-19 12:04 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-01-19 12:04 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2015-01-19 12:04 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncsi.dll
2015-01-19 12:04 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlaapi.dll
2015-01-19 12:04 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-01-19 12:04 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-01-19 12:04 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2015-01-19 12:04 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2015-01-19 12:04 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-01-19 12:04 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-01-19 12:04 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-01-19 12:04 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-01-19 12:04 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-01-19 12:04 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2015-01-19 12:04 - 2014-05-30 07:45 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-01-19 12:04 - 2014-04-25 03:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2015-01-19 12:04 - 2014-04-25 03:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2015-01-19 12:04 - 2014-03-26 15:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-01-19 12:04 - 2014-03-26 15:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-01-19 12:04 - 2014-03-26 15:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-01-19 12:04 - 2014-03-26 15:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2015-01-19 12:04 - 2014-02-04 03:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2015-01-19 12:04 - 2014-02-04 03:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2015-01-19 12:04 - 2014-02-04 03:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2015-01-19 12:04 - 2014-02-04 03:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2015-01-19 12:04 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2015-01-19 12:04 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2015-01-19 12:04 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2015-01-19 12:04 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2015-01-19 12:04 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2015-01-19 12:04 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-01-19 12:04 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-01-19 12:04 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2015-01-19 12:04 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2015-01-19 12:04 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2015-01-19 12:04 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\SysWOW64\SmartcardCredentialProvider.dll
2015-01-19 12:04 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\credui.dll
2015-01-19 12:04 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2015-01-19 12:04 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2015-01-19 12:04 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2015-01-19 12:04 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2015-01-19 12:04 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-01-19 12:04 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-01-19 12:04 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-01-19 12:04 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2015-01-19 12:04 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-01-19 12:04 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2015-01-19 12:04 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-01-19 12:04 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-01-19 12:04 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-01-19 12:04 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
2015-01-19 12:04 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-01-19 12:04 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-01-19 12:04 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-01-19 12:04 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-01-19 12:04 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-01-19 12:04 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-01-19 12:04 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-01-19 12:04 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-01-19 12:04 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-01-19 12:04 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-01-19 12:04 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-01-19 12:04 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2015-01-19 12:04 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\dpnet.dll
2015-01-19 12:04 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpnet.dll
2015-01-19 12:04 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-01-19 12:04 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\Drivers\RNDISMP.sys
2015-01-19 12:04 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\partmgr.sys
2015-01-19 12:04 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fs_rec.sys
2015-01-19 12:04 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\wmi.dll
2015-01-19 12:04 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmi.dll
2015-01-19 12:04 - 2011-11-17 07:35 - 00395776 _____ (Microsoft Corporation) C:\windows\system32\webio.dll
2015-01-19 12:04 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\windows\SysWOW64\webio.dll
2015-01-19 12:04 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\windows\system32\psisdecd.dll
2015-01-19 12:04 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\psisrndr.ax
2015-01-19 12:04 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\windows\SysWOW64\psisdecd.dll
2015-01-19 12:04 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\windows\SysWOW64\psisrndr.ax
2015-01-19 12:04 - 2011-06-16 06:49 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\xmllite.dll
2015-01-19 12:04 - 2011-06-16 05:33 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\xmllite.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00212992 _____ (Microsoft Corporation) C:\windows\system32\odbctrac.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\odbccp32.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\odbccu32.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\odbccr32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00319488 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbcjt32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbctrac.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00122880 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccp32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccu32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccr32.dll


Nero555 30.01.2015 16:00

FRST Editor Logfile (2)
 
Code:

2015-01-19 12:04 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\umpnpmgr.dll
2015-01-19 12:04 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\windows\SysWOW64\devobj.dll
2015-01-19 12:04 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\windows\SysWOW64\devrtl.dll
2015-01-19 12:04 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cfgmgr32.dll
2015-01-19 12:04 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\windows\SysWOW64\drvinst.exe
2015-01-19 12:04 - 2011-04-29 04:06 - 00467456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2015-01-19 12:04 - 2011-04-29 04:05 - 00410112 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2015-01-19 12:04 - 2011-04-29 04:05 - 00168448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2015-01-19 12:03 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2015-01-19 12:03 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\charmap.exe
2015-01-19 12:03 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2015-01-19 12:03 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2015-01-19 12:03 - 2014-09-25 03:08 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-01-19 12:03 - 2014-09-25 02:40 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2015-01-19 12:03 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2015-01-19 12:03 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2015-01-19 12:03 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2015-01-19 12:03 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2015-01-19 12:03 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2015-01-19 12:03 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-01-19 12:03 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\windows\SysWOW64\synceng.dll
2015-01-19 12:03 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\synceng.dll
2015-01-19 12:03 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\windows\system32\cdosys.dll
2015-01-19 12:03 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\windows\SysWOW64\cdosys.dll
2015-01-19 12:03 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\windows\system32\timedate.cpl
2015-01-19 12:03 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\windows\SysWOW64\timedate.cpl
2015-01-19 12:03 - 2011-02-18 11:51 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\prevhost.exe
2015-01-19 12:03 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\prevhost.exe
2015-01-19 12:02 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-01-19 12:02 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-01-19 12:01 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-01-19 12:01 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2015-01-19 12:01 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-01-19 12:01 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-01-19 12:01 - 2014-01-24 03:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2015-01-19 12:01 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2015-01-19 12:01 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2015-01-19 12:01 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2015-01-19 12:01 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2015-01-19 12:01 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2015-01-19 12:01 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx
2015-01-19 12:01 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2015-01-19 12:01 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2015-01-19 12:01 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2015-01-19 12:01 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2015-01-19 12:01 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2015-01-19 12:01 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe
2015-01-19 12:01 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2015-01-19 12:01 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-01-19 12:01 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2015-01-19 12:01 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2015-01-19 12:01 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\windows\system32\msvcrt.dll
2015-01-19 12:01 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcrt.dll
2015-01-19 12:01 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\windows\system32\EncDec.dll
2015-01-19 12:01 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\EncDec.dll
2015-01-19 12:01 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\windows\system32\oleacc.dll
2015-01-19 12:01 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleacc.dll
2015-01-19 11:50 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-01-19 11:50 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-01-19 11:49 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2015-01-19 11:32 - 2015-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\Virtual Desktop Manager
2015-01-19 11:32 - 2015-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Local\FSP
2015-01-19 11:31 - 2015-01-23 18:06 - 00001003 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-19 11:21 - 2015-01-19 11:21 - 524288000 __RSH () C:\VPART015.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART014.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART013.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART012.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART011.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART010.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART009.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART008.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 00000790 _____ () C:\Users\User\Desktop\Time Stamp.lnk
2015-01-19 11:21 - 2015-01-19 11:21 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Time Stamp
2015-01-19 11:20 - 2015-01-30 15:42 - 00001058 __RSH () C:\windows\system32\VFsRegister
2015-01-19 11:20 - 2015-01-21 12:12 - 00000000 ____D () C:\Program Files\Time Stamp
2015-01-19 11:20 - 2015-01-20 12:00 - 00000000 ____D () C:\ProgramData\Farstone
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART007.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART006.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART005.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART004.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART003.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART002.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART001.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART000.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 00004096 __RSH () C:\RESCUMBR.BIN
2015-01-19 11:20 - 2015-01-19 11:20 - 00000532 __RSH () C:\windows\system32\VFsActitvation
2015-01-19 11:20 - 2011-07-12 09:28 - 00162392 _____ () C:\windows\system32\Drivers\VvBackd5.sys
2015-01-19 11:20 - 2011-04-18 04:12 - 00024664 ____N () C:\windows\system32\Drivers\FarMntIo.sys
2015-01-19 11:20 - 2011-01-04 18:18 - 00066136 ____N () C:\windows\system32\Drivers\HCDisk.sys
2015-01-19 11:19 - 2015-01-19 11:19 - 00000006 _____ () C:\windows\silentOnce.tmp
2015-01-19 11:19 - 2015-01-19 11:19 - 00000000 ____D () C:\ProgramData\Remind
2015-01-19 11:19 - 2015-01-19 11:19 - 00000000 ____D () C:\Program Files (x86)\MSI
2015-01-19 11:16 - 2015-01-19 11:16 - 00000000 ____D () C:\Users\User\AppData\Local\VirtualStore
2015-01-19 11:16 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\windows\system32\rdpcore.dll
2015-01-19 11:16 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpcore.dll
2015-01-19 11:16 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdtcp.sys
2015-01-19 11:09 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-01-19 11:09 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-01-19 11:09 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-01-19 11:09 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-01-19 11:09 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-01-19 11:09 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-01-19 11:09 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-01-19 11:09 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-01-19 11:09 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-01-19 11:06 - 2015-01-21 09:37 - 00058016 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-19 11:06 - 2015-01-19 11:06 - 00000020 ___SH () C:\Users\User\ntuser.ini
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Vorlagen
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Startmenü
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Netzwerkumgebung
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Lokale Einstellungen
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Eigene Dateien
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Druckumgebung
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Documents\Eigene Musik
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Documents\Eigene Bilder
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Local\Verlauf
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Local\Anwendungsdaten
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Anwendungsdaten
2015-01-19 11:06 - 2011-08-11 18:21 - 00000000 ____D () C:\Users\User\AppData\Local\SRS Labs
2015-01-19 11:06 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-19 11:06 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-30 15:45 - 2011-08-11 18:10 - 01212808 _____ () C:\windows\WindowsUpdate.log
2015-01-30 15:39 - 2009-07-14 05:45 - 00016752 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-30 15:39 - 2009-07-14 05:45 - 00016752 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-30 15:30 - 2009-07-14 05:46 - 00004857 _____ () C:\windows\DtcInstall.log
2015-01-30 15:28 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-01-30 15:28 - 2009-07-14 05:51 - 00039209 _____ () C:\windows\setupact.log
2015-01-30 15:14 - 2010-11-21 04:47 - 00280546 _____ () C:\windows\PFRO.log
2015-01-30 15:10 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\GroupPolicy
2015-01-29 13:34 - 2011-08-11 19:05 - 00772184 _____ () C:\windows\system32\perfh010.dat
2015-01-29 13:34 - 2011-08-11 19:05 - 00159382 _____ () C:\windows\system32\perfc010.dat
2015-01-29 13:34 - 2011-08-11 18:59 - 00779006 _____ () C:\windows\system32\perfh00C.dat
2015-01-29 13:34 - 2011-08-11 18:59 - 00163544 _____ () C:\windows\system32\perfc00C.dat
2015-01-29 13:34 - 2011-08-11 18:52 - 00779960 _____ () C:\windows\system32\perfh00A.dat
2015-01-29 13:34 - 2011-08-11 18:52 - 00173610 _____ () C:\windows\system32\perfc00A.dat
2015-01-29 13:34 - 2011-08-11 18:45 - 00744432 _____ () C:\windows\system32\perfh007.dat
2015-01-29 13:34 - 2011-08-11 18:45 - 00162272 _____ () C:\windows\system32\perfc007.dat
2015-01-29 13:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\inetsrv
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\inetsrv
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2015-01-25 16:33 - 2011-08-11 18:24 - 00011580 _____ () C:\windows\DPINST.LOG
2015-01-25 16:33 - 2011-05-17 18:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-23 16:06 - 2011-08-11 18:22 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun
2015-01-22 12:24 - 2009-07-14 03:34 - 00000505 _____ () C:\windows\win.ini
2015-01-21 11:57 - 2009-07-14 06:13 - 04190942 _____ () C:\windows\system32\PerfStringBackup.INI
2015-01-21 11:38 - 2011-08-11 18:21 - 00058016 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-21 11:38 - 2011-08-11 18:21 - 00058016 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-21 11:01 - 2009-07-14 05:45 - 00267816 _____ () C:\windows\system32\FNTCACHE.DAT
2015-01-21 10:24 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\zh-HK
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\zh-HK
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\tr-TR
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-21 09:25 - 2010-11-21 08:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-21 09:25 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-21 09:25 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\Dism
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\AppCompat
2015-01-20 13:51 - 2011-08-11 18:29 - 00000000 ____D () C:\Users\Public\Desktop\User Manual
2015-01-20 12:53 - 2010-01-20 11:34 - 00000000 ____D () C:\Users\User\AppData\Roaming\Adobe
2015-01-19 11:31 - 2011-06-08 03:20 - 00000000 ____D () C:\Utility
2015-01-19 11:21 - 2011-03-21 17:37 - 00000000 ____D () C:\log
2015-01-19 11:19 - 2011-05-17 18:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-01-19 11:05 - 2011-05-16 20:37 - 00000000 __SHD () C:\Recovery
2015-01-19 11:05 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-01-19 11:04 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2015-01-08 09:55 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe

==================== Files in the root of some directories =======

2015-01-30 15:22 - 2015-01-30 15:22 - 1498256 _____ () C:\ProgramData\Setup.exe

Files to move or delete:
====================
C:\ProgramData\Setup.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-29 14:50

==================== End Of Log ============================

FRST Additions Logfile:
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2015
Ran by User at 2015-01-30 15:55:45
Running from C:\Users\User\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 16.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.6.156 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.8.1217.36096 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.8.1217.36096 - Alcor Micro Corp.) Hidden
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.36 - Atheros Communications Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1007.2702 - Micro-Star International Co., Ltd.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.37.50 - Conexant)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Finger Sensing Pad Driver (HKLM\...\{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}) (Version: 8.8.0.9 - Sentelic)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.99 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417071FF}) (Version: 7.0.710 - Oracle)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 35.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0 - Mozilla)
MSI Remind Manager (HKLM-x32\...\{89F17DC5-A776-4DF4-8CD1-FAEF29BCE51A}) (Version: 1.11.0104 - MSI)
MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1801 - Micro-Star International Co., Ltd.)
Opera Stable 27.0.1689.54 (HKLM-x32\...\Opera 27.0.1689.54) (Version: 27.0.1689.54 - Opera Software ASA)
PC Sound (HKLM\...\{F3C66EC8-2F33-452D-9CFF-E8C886B3ECC4}) (Version: 1.11.0200 - SRS Labs, Inc.)
PHotkey (HKLM-x32\...\{24047BE4-329D-46F7-9689-8684C7A1CFBB}) (Version: 1.00.0010 - )
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.20.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.20.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
speed browser (HKLM-x32\...\speed browser) (Version: 40.0.2214.45 - Smart Applications)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Time Stamp (HKLM-x32\...\Time Stamp) (Version: 1.0.0.20110711 - Time Stamp Software, Inc.)
USB2.0 UVC 1.3M Webcam (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10275 - Realtek Semiconductor Corp.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{B39AA98E-C966-46C9-ACA2-D2586E300988}) (Version: 2.29.0.3 - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2015-01-30 15:10 - 00000035 ____N C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1D7AFB94-A35F-4B66-AFD6-835D0CCE590A} - System32\Tasks\avastBCLRestartS-1-5-21-2608712115-2613374988-3172207222-1001 => Chrome.exe
Task: {5AACC5E5-EBE4-481F-A36C-AB4006FCBA70} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {94942A87-B26C-4606-BBE6-1F7D27FE0F4A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-21] (Google Inc.)
Task: {9D07084A-F4DC-4F63-AB1F-D1A7BBAF9635} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {B6FEBACB-40C4-42D1-9BF2-F5CA91DF8601} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-21] (Google Inc.)
Task: {FAFC338D-5F94-48D0-B2E8-56F884FC5A81} - System32\Tasks\Opera scheduled Autoupdate 1421871456 => C:\Program Files (x86)\Opera\launcher.exe [2015-01-23] (Opera Software)
Task: {FBDED84C-4500-4D63-B3BB-65F540F4B779} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-01-20] (AVAST Software)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-08-11 18:27 - 2010-12-10 20:19 - 00104968 ____R () C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
2011-08-11 18:27 - 2011-07-21 02:51 - 00824328 _____ () C:\Program Files (x86)\PHotkey\PHotkey.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00117256 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00121864 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00159752 ____R () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
2011-06-03 11:08 - 2011-04-15 03:16 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00126976 ____N () C:\Program Files\Time Stamp\IBP\fsloader.exe
2011-08-11 18:27 - 2010-12-17 22:04 - 00449032 ____R () C:\Program Files (x86)\PHotkey\ATouch64.exe
2011-08-11 18:27 - 2010-12-27 22:14 - 00776200 ____R () C:\Program Files (x86)\PHotkey\PVDesktop.exe
2011-08-11 18:27 - 2011-04-12 22:32 - 00483336 ____R () C:\Program Files (x86)\PHotkey\PVDAgent.exe
2015-01-20 12:57 - 2015-01-20 12:57 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2015-01-20 12:57 - 2015-01-20 12:57 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2015-01-29 21:25 - 2015-01-29 21:25 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15012901\algo.dll
2015-01-20 12:57 - 2015-01-20 12:57 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2011-08-11 18:27 - 2010-12-10 20:19 - 00973432 ____R () C:\Program Files (x86)\PHotkey\acAuth.dll
2011-08-11 18:27 - 2010-12-10 20:19 - 00129544 ____R () C:\Program Files (x86)\PHotkey\GFNEX.dll
2015-01-20 12:58 - 2015-01-20 12:58 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libglesv2.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libegl.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\pdf.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll
2015-01-19 11:20 - 2010-12-07 14:41 - 00151654 ____N () C:\Program Files\Time Stamp\IBP\Snapshot.dll
2015-01-19 11:20 - 2010-03-08 14:53 - 00073779 ____N () C:\Program Files\Time Stamp\IBP\UVFilter.dll
2015-01-19 11:20 - 2010-04-07 11:47 - 00090112 ____N () C:\Program Files\Time Stamp\IBP\VBcfgEx.dll
2015-01-19 11:20 - 2009-08-17 17:33 - 00057403 ____N () C:\Program Files\Time Stamp\IBP\DiskMsg.dll
2015-01-19 11:20 - 2011-01-04 10:09 - 00192607 ____N () C:\Program Files\Time Stamp\IBP\vbioctl.dll
2015-01-19 11:20 - 2010-08-30 11:16 - 00102445 ____N () C:\Program Files\Time Stamp\REG\FsAct.dll
2015-01-19 11:20 - 2010-08-29 12:11 - 00131119 ____N () C:\Program Files\Time Stamp\REG\RegKern.dll
2015-01-21 20:40 - 2015-01-09 01:35 - 14913352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SRS PC Sound.lnk => C:\windows\pss\SRS PC Sound.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WebBrowserFastPlayer.lnk => C:\windows\pss\WebBrowserFastPlayer.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AmIcoSinglun64 => c:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
MSCONFIG\startupreg: GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: NUSB3MON => "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
MSCONFIG\startupreg: SmartAudio => C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-2608712115-2613374988-3172207222-500 - Administrator - Disabled)
Gast (S-1-5-21-2608712115-2613374988-3172207222-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2608712115-2613374988-3172207222-1002 - Limited - Enabled)
User (S-1-5-21-2608712115-2613374988-3172207222-1001 - Administrator - Enabled) => C:\Users\User

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/30/2015 03:30:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2015 03:16:12 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2015 02:45:27 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\revouninstaller.exe Files (x86)\VS Revo Group\Revo Uninstaller\revouninstaller.exe"; Beschreibung = Revo Uninstaller's restore point - Click Caption 1.10.0.6; Fehler = 0x80070422).

Error: (01/30/2015 00:57:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm AdwCleaner_4.109.exe, Version 4.1.0.9 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: de4

Startzeit: 01d03c83861fab14

Endzeit: 0

Anwendungspfad: C:\Users\User\Desktop\AdwCleaner_4.109.exe

Berichts-ID:


System errors:
=============
Error: (01/30/2015 03:31:48 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "RIP-Überwachung" wurde nicht richtig gestartet.

Error: (01/30/2015 03:30:09 PM) (Source: SNMP) (EventID: 1500) (User: )
Description: Beim Zugreifen auf den Registrierungsschlüssel SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration ist ein Fehler aufgetreten.

Error: (01/30/2015 03:30:03 PM) (Source: IPRIP) (EventID: 29048) (User: )
Description: Fehler bei der Installation des RIP-Listenerdiensts

Error: (01/30/2015 03:29:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Apple Mobile Device" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (01/30/2015 03:29:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Apple Mobile Device erreicht.

Error: (01/30/2015 03:28:16 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎30.‎01.‎2015 um 15:26:10 unerwartet heruntergefahren.

Error: (01/30/2015 03:17:43 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "RIP-Überwachung" wurde nicht richtig gestartet.

Error: (01/30/2015 03:15:49 PM) (Source: SNMP) (EventID: 1500) (User: )
Description: Beim Zugreifen auf den Registrierungsschlüssel SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration ist ein Fehler aufgetreten.

Error: (01/30/2015 03:15:41 PM) (Source: IPRIP) (EventID: 29048) (User: )
Description: Fehler bei der Installation des RIP-Listenerdiensts

Error: (01/30/2015 01:25:38 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Microsoft Office Sessions:
=========================
Error: (01/30/2015 03:30:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2015 03:16:12 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2015 02:45:27 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\revouninstaller.exe Files (x86)\VS Revo Group\Revo Uninstaller\revouninstaller.exe"Revo Uninstaller's restore point - Click Caption 1.10.0.60x80070422

Error: (01/30/2015 00:57:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: AdwCleaner_4.109.exe4.1.0.9de401d03c83861fab140C:\Users\User\Desktop\AdwCleaner_4.109.exe


CodeIntegrity Errors:
===================================
  Date: 2015-01-30 15:54:53.120
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 15:54:45.668
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 15:54:20.947
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 15:54:19.060
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 15:52:40.034
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 15:52:38.869
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 15:52:37.850
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 15:52:36.360
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 15:51:59.937
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-30 15:51:59.417
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\CX64AP64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 55%
Total physical RAM: 4008.29 MB
Available physical RAM: 1774 MB
Total Pagefile: 8014.76 MB
Available Pagefile: 5270.09 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:173.39 GB) (Free:103.46 GB) NTFS
Drive d: (Data) (Fixed) (Total:115.6 GB) (Free:104.66 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 5A30F560)
Partition 1: (Not Active) - (Size=9 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=173.4 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=115.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================

--- --- ---


Das sind anscheinend die selben Logfiles wie die letzten male. Das sind aber die einzigen die angezeigt werden.

cosinus 31.01.2015 00:41

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\...\Run: [Gameo] => C:\Users\User\AppData\Roaming\Gameo\gameo.exe "C:\Users\User\AppData\Roaming\Gameo\gameo.dat" mode:minimized
Toolbar: HKU\S-1-5-21-2608712115-2613374988-3172207222-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X]
S2 d924d8dc; c:\Program Files (x86)\Optimizer Pro 3.33\OptProMon.dll [1597008 2015-01-21] ()
C:\Users\Public\Desktop\speed browser.lnk
C:\Users\User\AppData\Local\speed browser
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\speed browser
C:\Program Files (x86)\speed browser
C:\ProgramData\Setup.exe
C:\Users\User\Downloads\SpyHunterKiller.exe
C:\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
C:\ProgramData\xfIwQZvgdh
C:\Program Files (x86)\Optimizer Pro 3.33
C:\Users\User\AppData\Roaming\Gameo
EmptyTemp:
Hosts:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Nero555 31.01.2015 01:16

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015
Ran by User at 2015-01-31 01:07:52 Run:2
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\...\Run: [Gameo] => C:\Users\User\AppData\Roaming\Gameo\gameo.exe "C:\Users\User\AppData\Roaming\Gameo\gameo.dat" mode:minimized
Toolbar: HKU\S-1-5-21-2608712115-2613374988-3172207222-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X]
S2 d924d8dc; c:\Program Files (x86)\Optimizer Pro 3.33\OptProMon.dll [1597008 2015-01-21] ()
C:\Users\Public\Desktop\speed browser.lnk
C:\Users\User\AppData\Local\speed browser
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\speed browser
C:\Program Files (x86)\speed browser
C:\ProgramData\Setup.exe
C:\Users\User\Downloads\SpyHunterKiller.exe
C:\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
C:\ProgramData\xfIwQZvgdh
C:\Program Files (x86)\Optimizer Pro 3.33
C:\Users\User\AppData\Roaming\Gameo
EmptyTemp:
Hosts:
       
*****************

HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Gameo => value deleted successfully.
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully.
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found.
esgiguard => Service deleted successfully.
EsgScanner => Service deleted successfully.
d924d8dc => Service deleted successfully.
C:\Users\Public\Desktop\speed browser.lnk => Moved successfully.
C:\Users\User\AppData\Local\speed browser => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\speed browser => Moved successfully.
C:\Program Files (x86)\speed browser => Moved successfully.
C:\ProgramData\Setup.exe => Moved successfully.
C:\Users\User\Downloads\SpyHunterKiller.exe => Moved successfully.
C:\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f => Moved successfully.
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 => Moved successfully.
C:\ProgramData\xfIwQZvgdh => Moved successfully.
C:\Program Files (x86)\Optimizer Pro 3.33 => Moved successfully.
"C:\Users\User\AppData\Roaming\Gameo" => File/Directory not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 912.3 MB temporary data.


The system needed a reboot.

==== End of Fixlog 01:07:58 ====


cosinus 31.01.2015 03:15

Bitte neue FRST-Logs erstellen und posten :)

Nero555 31.01.2015 16:08

FRST Addition
 
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-01-2015
Ran by User at 2015-01-31 16:07:36
Running from C:\Users\User\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 16.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.6.156 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.8.1217.36096 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.8.1217.36096 - Alcor Micro Corp.) Hidden
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.36 - Atheros Communications Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1007.2702 - Micro-Star International Co., Ltd.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.37.50 - Conexant)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Finger Sensing Pad Driver (HKLM\...\{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}) (Version: 8.8.0.9 - Sentelic)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.94 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417071FF}) (Version: 7.0.710 - Oracle)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 35.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0 - Mozilla)
MSI Remind Manager (HKLM-x32\...\{89F17DC5-A776-4DF4-8CD1-FAEF29BCE51A}) (Version: 1.11.0104 - MSI)
MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1801 - Micro-Star International Co., Ltd.)
Opera Stable 27.0.1689.54 (HKLM-x32\...\Opera 27.0.1689.54) (Version: 27.0.1689.54 - Opera Software ASA)
PC Sound (HKLM\...\{F3C66EC8-2F33-452D-9CFF-E8C886B3ECC4}) (Version: 1.11.0200 - SRS Labs, Inc.)
PHotkey (HKLM-x32\...\{24047BE4-329D-46F7-9689-8684C7A1CFBB}) (Version: 1.00.0010 - )
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.20.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.20.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
speed browser (HKLM-x32\...\speed browser) (Version: 40.0.2214.45 - Smart Applications)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Time Stamp (HKLM-x32\...\Time Stamp) (Version: 1.0.0.20110711 - Time Stamp Software, Inc.)
USB2.0 UVC 1.3M Webcam (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10275 - Realtek Semiconductor Corp.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{B39AA98E-C966-46C9-ACA2-D2586E300988}) (Version: 2.29.0.3 - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2015-01-31 01:07 - 00000035 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1D7AFB94-A35F-4B66-AFD6-835D0CCE590A} - System32\Tasks\avastBCLRestartS-1-5-21-2608712115-2613374988-3172207222-1001 => Chrome.exe
Task: {5AACC5E5-EBE4-481F-A36C-AB4006FCBA70} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {94942A87-B26C-4606-BBE6-1F7D27FE0F4A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-21] (Google Inc.)
Task: {9D07084A-F4DC-4F63-AB1F-D1A7BBAF9635} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {B6FEBACB-40C4-42D1-9BF2-F5CA91DF8601} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-21] (Google Inc.)
Task: {FAFC338D-5F94-48D0-B2E8-56F884FC5A81} - System32\Tasks\Opera scheduled Autoupdate 1421871456 => C:\Program Files (x86)\Opera\launcher.exe [2015-01-23] (Opera Software)
Task: {FBDED84C-4500-4D63-B3BB-65F540F4B779} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-01-20] (AVAST Software)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-08-11 18:27 - 2010-12-10 20:19 - 00104968 ____R () C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00159752 ____R () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
2011-08-11 18:27 - 2011-07-21 02:51 - 00824328 _____ () C:\Program Files (x86)\PHotkey\PHotkey.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00117256 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2011-08-11 18:27 - 2010-12-10 20:19 - 00121864 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2011-06-03 11:08 - 2011-04-15 03:16 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2011-08-11 18:27 - 2010-12-17 22:04 - 00449032 ____R () C:\Program Files (x86)\PHotkey\ATouch64.exe
2011-08-11 18:27 - 2010-12-27 22:14 - 00776200 ____R () C:\Program Files (x86)\PHotkey\PVDesktop.exe
2011-08-11 18:27 - 2011-04-12 22:32 - 00483336 ____R () C:\Program Files (x86)\PHotkey\PVDAgent.exe
2015-01-20 12:57 - 2015-01-20 12:57 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2015-01-20 12:57 - 2015-01-20 12:57 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2015-01-30 19:01 - 2015-01-30 19:01 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15013000\algo.dll
2015-01-20 12:57 - 2015-01-20 12:57 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2015-01-31 15:47 - 2015-01-31 15:47 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15013100\algo.dll
2011-08-11 18:27 - 2010-12-10 20:19 - 00973432 ____R () C:\Program Files (x86)\PHotkey\acAuth.dll
2011-08-11 18:27 - 2010-12-10 20:19 - 00129544 ____R () C:\Program Files (x86)\PHotkey\GFNEX.dll
2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-20 12:58 - 2015-01-20 12:58 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-01-31 02:46 - 2015-01-27 04:44 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\libglesv2.dll
2015-01-31 02:46 - 2015-01-27 04:44 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\libegl.dll
2015-01-31 02:46 - 2015-01-27 04:44 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\pdf.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SRS PC Sound.lnk => C:\windows\pss\SRS PC Sound.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WebBrowserFastPlayer.lnk => C:\windows\pss\WebBrowserFastPlayer.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AmIcoSinglun64 => c:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
MSCONFIG\startupreg: GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: NUSB3MON => "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
MSCONFIG\startupreg: SmartAudio => C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-2608712115-2613374988-3172207222-500 - Administrator - Disabled)
Gast (S-1-5-21-2608712115-2613374988-3172207222-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2608712115-2613374988-3172207222-1002 - Limited - Enabled)
User (S-1-5-21-2608712115-2613374988-3172207222-1001 - Administrator - Enabled) => C:\Users\User

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/31/2015 03:48:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/31/2015 03:19:11 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/31/2015 03:00:27 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\windows\servicing\TrustedInstaller.exe; Beschreibung = Windows Modules Installer; Fehler = 0x80070422).

Error: (01/31/2015 03:00:15 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\windows\servicing\TrustedInstaller.exe; Beschreibung = Windows Modules Installer; Fehler = 0x80070422).

Error: (01/31/2015 03:00:13 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x80070422).

Error: (01/31/2015 01:13:13 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2015 07:45:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2059

Error: (01/30/2015 07:45:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2059

Error: (01/30/2015 07:45:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/30/2015 07:45:55 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1061


System errors:
=============
Error: (01/31/2015 03:49:53 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "RIP-Überwachung" wurde nicht richtig gestartet.

Error: (01/31/2015 03:48:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MElGfYhtuP" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (01/31/2015 03:48:21 PM) (Source: SNMP) (EventID: 1500) (User: )
Description: Beim Zugreifen auf den Registrierungsschlüssel SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration ist ein Fehler aufgetreten.

Error: (01/31/2015 03:47:58 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst DriveClone Network Client IBP erreicht.

Error: (01/31/2015 03:47:59 PM) (Source: IPRIP) (EventID: 29048) (User: )
Description: Fehler bei der Installation des RIP-Listenerdiensts

Error: (01/31/2015 03:46:20 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎31.‎01.‎2015 um 04:12:30 unerwartet heruntergefahren.

Error: (01/31/2015 03:20:24 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "RIP-Überwachung" wurde nicht richtig gestartet.

Error: (01/31/2015 03:18:57 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MElGfYhtuP" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (01/31/2015 03:18:45 AM) (Source: SNMP) (EventID: 1500) (User: )
Description: Beim Zugreifen auf den Registrierungsschlüssel SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration ist ein Fehler aufgetreten.

Error: (01/31/2015 03:18:39 AM) (Source: IPRIP) (EventID: 29048) (User: )
Description: Fehler bei der Installation des RIP-Listenerdiensts


Microsoft Office Sessions:
=========================
Error: (01/31/2015 03:48:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/31/2015 03:19:11 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/31/2015 03:00:27 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\windows\servicing\TrustedInstaller.exeWindows Modules Installer0x80070422

Error: (01/31/2015 03:00:15 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\windows\servicing\TrustedInstaller.exeWindows Modules Installer0x80070422

Error: (01/31/2015 03:00:13 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\windows\system32\svchost.exe -k netsvcsWindows Update0x80070422

Error: (01/31/2015 01:13:13 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2015 07:45:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2059

Error: (01/30/2015 07:45:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2059

Error: (01/30/2015 07:45:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/30/2015 07:45:55 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1061


CodeIntegrity Errors:
===================================
  Date: 2015-01-31 16:07:27.346
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-31 16:07:13.245
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-31 16:07:12.188
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-31 16:07:11.828
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-31 16:07:10.349
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-31 16:07:09.156
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-31 16:07:07.536
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-31 16:07:06.335
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-31 16:07:04.329
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-01-31 16:06:03.630
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\sluapo64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 55%
Total physical RAM: 4008.29 MB
Available physical RAM: 1794.04 MB
Total Pagefile: 8014.76 MB
Available Pagefile: 5405.01 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:173.39 GB) (Free:103.99 GB) NTFS
Drive d: (Data) (Fixed) (Total:115.6 GB) (Free:104.66 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 5A30F560)
Partition 1: (Not Active) - (Size=9 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=173.4 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=115.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================


Nero555 31.01.2015 16:10

FRST Editor Logfile (1)
 
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-01-2015
Ran by User (administrator) on USER-MSI on 31-01-2015 16:06:16
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files (x86)\PHotkey\AsLdrSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\system32\igfxtray.exe
(Intel Corporation) C:\Windows\system32\hkcmd.exe
(Intel Corporation) C:\Windows\system32\igfxpers.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\system32\CISVC.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(Microsoft Corporation) C:\Windows\system32\mqsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corporation) C:\Windows\system32\TCPSVCS.EXE
(Microsoft Corporation) C:\Windows\system32\snmp.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\PHotkey\Atouch64.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\MsOsd.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [6275424 2014-05-13] (Sentelic Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\...\Run: [GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-01-27] (Google Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-2608712115-2613374988-3172207222-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2608712115-2613374988-3172207222-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\searchplugins\google-avast.xml
FF Extension: firesshnightlightws - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\Extensions\firessh@nightlight.ws [2015-01-29]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-20]

Chrome:
=======
CHR HomePage: Default -> https://www.google.de/
CHR StartupUrls: Default -> "https://twitter.com/", "https://www.youtube.com/feed/subscriptions", "https://www.google.de/"
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-21]
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-21]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-21]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-21]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-21]
CHR Extension: (Adblock Plus) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-01-21]
CHR Extension: (Google-Suche) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-21]
CHR Extension: (Google Tabellen) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-21]
CHR Extension: (AdBlock) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-21]
CHR Extension: (Avast Online Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-01-21]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-21]
CHR Extension: (Google Mail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-20]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2010-12-10] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-20] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2015-01-20] (Avast Software)
S2 DriveClone Network Client IBP; C:\Program Files\Time Stamp\IBP\fsloader.exe [126976 2009-08-17] () [File not signed]
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-12-10] ()
U2 iprip; C:\Windows\System32\iprip.dll [35328 2009-07-14] (Microsoft Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 SNMP; C:\Windows\System32\snmp.exe [49664 2010-11-21] (Microsoft Corporation)
R2 SNMP; C:\Windows\SysWOW64\snmp.exe [47616 2010-11-21] (Microsoft Corporation)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 MElGfYhtuP; "C:\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-20] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2015-01-20] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-20] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-20] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-20] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-20] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-20] ()
S3 FARMNTIO; c:\windows\system32\drivers\farmntio.sys [24664 2011-04-18] ()
R3 fspad_win764; C:\Windows\System32\DRIVERS\fspad_win764.sys [173408 2014-05-13] (Sentelic Corporation)
S3 fspad_wlh64; C:\Windows\System32\DRIVERS\fspad_wlh64.sys [68608 2010-11-08] (Sentelic Corporation) [File not signed]
R2 HCDisk; C:\Windows\System32\Drivers\HCDisk.sys [66136 2011-01-04] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2014-04-24] (Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [129224 2013-11-29] (Qualcomm Atheros Co., Ltd.)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2010-12-10] (PEGATRON)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [9112792 2014-05-02] (Realtek Semiconductor Corp.)
R3 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2015-01-20] (Avast Software)
R0 VVBackd5; C:\Windows\System32\Drivers\VVBackd5.sys [162392 2011-07-12] ()
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-31 16:06 - 2015-01-31 16:06 - 00016051 _____ () C:\Users\User\Desktop\FRST.txt
2015-01-31 16:06 - 2015-01-31 16:06 - 00000000 ____D () C:\Users\User\Desktop\FRST-OlderVersion
2015-01-30 15:21 - 2015-01-30 15:21 - 00000000 ____D () C:\ProgramData\Browser
2015-01-30 15:19 - 2015-01-30 18:15 - 00000000 ____D () C:\Users\User\AppData\Local\ZombieNews
2015-01-30 15:09 - 2015-01-30 15:09 - 00000000 ____D () C:\Users\User\Documents\Neuer Ordner
2015-01-30 15:07 - 2015-01-30 15:09 - 00001796 _____ () C:\Users\User\Documents\Fixlist.txt
2015-01-30 14:43 - 2015-01-30 14:43 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\User\Downloads\revosetup95.exe
2015-01-30 14:43 - 2015-01-30 14:43 - 00001278 _____ () C:\Users\User\Desktop\Revo Uninstaller.lnk
2015-01-30 14:43 - 2015-01-30 14:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-01-30 12:58 - 2015-01-30 12:58 - 00000000 ___DC () C:\Users\User\AppData\Local\MigWiz
2015-01-30 12:51 - 2015-01-30 12:51 - 00000758 _____ () C:\Users\User\Desktop\JRT.txt
2015-01-30 12:49 - 2014-12-06 05:17 - 00105472 _____ (Microsoft Corporation) C:\windows\system32\tlntsess.exe
2015-01-30 12:45 - 2012-06-01 06:39 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\wamregps.dll
2015-01-30 12:45 - 2012-06-01 06:36 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\iisRtl.dll
2015-01-30 12:45 - 2012-06-01 06:36 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\iisrstap.dll
2015-01-30 12:45 - 2012-06-01 06:35 - 00060928 _____ (Microsoft Corporation) C:\windows\system32\ahadmin.dll
2015-01-30 12:45 - 2012-06-01 06:34 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\admwprox.dll
2015-01-30 12:45 - 2012-06-01 06:33 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\iisreset.exe
2015-01-30 12:45 - 2012-06-01 05:40 - 00010752 _____ (Microsoft Corporation) C:\windows\SysWOW64\wamregps.dll
2015-01-30 12:45 - 2012-06-01 05:37 - 00154624 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisRtl.dll
2015-01-30 12:45 - 2012-06-01 05:37 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisrstap.dll
2015-01-30 12:45 - 2012-06-01 05:35 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\admwprox.dll
2015-01-30 12:45 - 2012-06-01 05:35 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ahadmin.dll
2015-01-30 12:45 - 2012-06-01 05:34 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisreset.exe
2015-01-30 12:38 - 2015-01-30 12:38 - 01707939 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2015-01-30 12:21 - 2015-01-30 12:21 - 02194432 _____ () C:\Users\User\Desktop\AdwCleaner_4.109.exe
2015-01-29 23:18 - 2015-01-29 23:36 - 00000000 ____D () C:\Users\User\Downloads\SSF2DemoV0_9b1978 (1)
2015-01-29 21:46 - 2015-01-29 21:46 - 00000000 ____D () C:\Users\User\data
2015-01-29 16:17 - 2015-01-29 17:00 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-29 16:17 - 2015-01-29 16:31 - 00136408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-29 16:17 - 2015-01-29 16:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-29 16:15 - 2015-01-29 17:01 - 00000000 ____D () C:\Users\User\Desktop\mbar
2015-01-29 16:15 - 2015-01-29 16:29 - 00097496 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-01-29 16:14 - 2015-01-29 16:15 - 16466552 _____ (Malwarebytes Corp.) C:\Users\User\Desktop\mbar-1.08.3.1004.exe
2015-01-29 14:56 - 2015-01-31 16:06 - 02130944 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2015-01-29 14:56 - 2015-01-31 16:06 - 00000000 ____D () C:\FRST
2015-01-29 13:34 - 2015-01-31 03:20 - 00044948 _____ () C:\windows\iis7.log
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\SysWOW64\BestPractices
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\system32\msmq
2015-01-29 13:31 - 2015-01-29 13:31 - 00000000 ____D () C:\windows\system32\BestPractices
2015-01-29 13:31 - 2015-01-29 13:30 - 00000862 _____ () C:\windows\system32\termcap
2015-01-29 13:30 - 2015-01-29 13:31 - 00000000 ____D () C:\inetpub
2015-01-23 21:14 - 2015-01-23 21:14 - 00000000 ____D () C:\windows\pss
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 ____D () C:\sh4ldr
2015-01-23 19:14 - 2015-01-23 19:14 - 00000000 _____ () C:\autoexec.bat
2015-01-23 18:57 - 2015-01-23 18:57 - 00000247 _____ () C:\windows\system32\2015-01-23-17-57-45.092-aswFe.exe-5340.log
2015-01-23 18:57 - 2015-01-23 18:57 - 00000197 _____ () C:\windows\system32\2015-01-23-17-57-38.027-AvastVBoxSVC.exe-1312.log
2015-01-23 17:59 - 2015-01-30 12:56 - 00000000 ____D () C:\AdwCleaner
2015-01-23 17:49 - 2015-01-23 17:49 - 00000197 _____ () C:\windows\system32\2015-01-23-16-49-31.016-AvastVBoxSVC.exe-3784.log
2015-01-23 16:23 - 2015-01-23 16:23 - 00000197 _____ () C:\windows\system32\2015-01-23-15-23-49.010-AvastVBoxSVC.exe-6012.log
2015-01-23 16:08 - 2015-01-23 16:08 - 00000000 ____D () C:\Users\User\AppData\Local\com
2015-01-23 15:52 - 2015-01-23 15:52 - 00000197 _____ () C:\windows\system32\2015-01-23-14-52-16.032-AvastVBoxSVC.exe-5244.log
2015-01-23 13:21 - 2015-01-23 18:55 - 00001557 _____ () C:\Users\User\Desktop\Chrome.lnk
2015-01-23 13:14 - 2015-01-23 13:14 - 00000197 _____ () C:\windows\system32\2015-01-23-12-14-23.097-AvastVBoxSVC.exe-3880.log
2015-01-23 13:12 - 2015-01-30 15:16 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-22 18:29 - 2015-01-23 15:58 - 00000000 ____D () C:\Users\User\AppData\Roaming\Apple Computer
2015-01-22 18:29 - 2015-01-22 18:29 - 00001793 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-01-22 18:29 - 2015-01-22 18:29 - 00000000 ____D () C:\Users\User\AppData\Local\Apple Computer
2015-01-22 18:29 - 2015-01-22 18:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-01-22 18:28 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\windows\system32\Drivers\GEARAspiWDM.sys
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\Program Files\iTunes
2015-01-22 18:26 - 2015-01-22 18:28 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-22 18:26 - 2015-01-22 18:26 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-01-22 18:26 - 2015-01-22 18:26 - 00000000 ____D () C:\Program Files\iPod
2015-01-22 18:25 - 2015-01-22 18:25 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\windows\System32\Tasks\Apple
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\Users\User\AppData\Local\Apple
2015-01-22 18:25 - 2015-01-22 18:25 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2015-01-22 18:24 - 2015-01-22 18:26 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-01-22 18:23 - 2015-01-22 18:23 - 00000000 ____D () C:\Program Files\Bonjour
2015-01-22 18:23 - 2015-01-22 18:23 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-01-22 18:21 - 2015-01-22 18:25 - 00000000 ____D () C:\ProgramData\Apple
2015-01-22 18:18 - 2015-01-22 18:20 - 122418480 _____ (Apple Inc.) C:\Users\User\Downloads\iTunes64Setup.exe
2015-01-22 12:40 - 2015-01-22 12:40 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps
2015-01-22 12:36 - 2015-01-22 12:36 - 00000000 ____D () C:\Users\User\AppData\Local\Macromedia
2015-01-22 12:32 - 2015-01-29 13:18 - 00003276 _____ () C:\windows\System32\Tasks\avastBCLRestartS-1-5-21-2608712115-2613374988-3172207222-1001
2015-01-22 12:30 - 2015-01-22 12:31 - 00000000 ____D () C:\Users\User\AppData\Roaming\Mozilla
2015-01-22 12:30 - 2015-01-22 12:31 - 00000000 ____D () C:\Users\User\AppData\Local\Mozilla
2015-01-22 12:24 - 2015-01-22 12:25 - 00000197 _____ () C:\windows\system32\2015-01-22-11-24-48.051-AvastVBoxSVC.exe-3272.log
2015-01-21 23:15 - 2015-01-21 23:15 - 00000197 _____ () C:\windows\system32\2015-01-21-22-15-00.076-AvastVBoxSVC.exe-4408.log
2015-01-21 22:09 - 2015-01-21 22:10 - 00021976 _____ () C:\windows\system32\Drivers\SPPD.sys
2015-01-21 22:05 - 2015-01-21 22:05 - 00000280 _____ () C:\windows\system32\2015-01-21-21-05-13.073-aswFe.exe-6612.log
2015-01-21 22:01 - 2015-01-21 22:01 - 00000000 ___HD () C:\Users\User\AppData\Roaming\GoldenGate
2015-01-21 22:00 - 2015-01-21 22:00 - 00000170 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2015-01-21 21:47 - 2015-01-21 21:47 - 00000000 ____D () C:\ProgramData\McAfee
2015-01-21 21:18 - 2015-01-21 21:18 - 00000000 ____D () C:\Users\User\AppData\Roaming\Opera Software
2015-01-21 21:18 - 2015-01-21 21:18 - 00000000 ____D () C:\Users\User\AppData\Local\Opera Software
2015-01-21 21:17 - 2015-01-29 12:48 - 00003852 _____ () C:\windows\System32\Tasks\Opera scheduled Autoupdate 1421871456
2015-01-21 21:17 - 2015-01-21 21:17 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-01-21 21:16 - 2015-01-29 12:48 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-01-21 21:03 - 2015-01-21 21:03 - 00000280 _____ () C:\windows\system32\2015-01-21-20-03-26.006-aswFe.exe-3824.log
2015-01-21 20:40 - 2015-01-22 12:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-21 20:39 - 2015-01-31 15:47 - 00001102 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-21 20:39 - 2015-01-31 04:12 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-21 20:39 - 2015-01-21 20:40 - 00000000 ____D () C:\Users\User\AppData\Local\Google
2015-01-21 20:39 - 2015-01-21 20:40 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-21 20:39 - 2015-01-21 20:39 - 00004102 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-01-21 20:39 - 2015-01-21 20:39 - 00003850 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-01-21 20:34 - 2015-01-21 20:38 - 00000000 ____D () C:\Users\User\AppData\Local\Deployment
2015-01-21 20:34 - 2015-01-21 20:34 - 00000000 ____D () C:\Users\User\AppData\Local\Apps\2.0
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieUserList
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieSiteList
2015-01-21 20:30 - 2015-01-21 20:30 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieBrowserModeList
2015-01-21 20:27 - 2015-01-21 20:27 - 00000197 _____ () C:\windows\system32\2015-01-21-19-27-14.097-AvastVBoxSVC.exe-3556.log
2015-01-21 16:40 - 2015-01-21 16:40 - 00000197 _____ () C:\windows\system32\2015-01-21-15-40-25.087-AvastVBoxSVC.exe-2804.log
2015-01-21 12:12 - 2015-01-21 12:12 - 00000197 _____ () C:\windows\system32\2015-01-21-11-12-09.083-AvastVBoxSVC.exe-3988.log
2015-01-21 11:42 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-01-21 11:42 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-01-21 11:42 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-01-21 11:42 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-01-21 11:42 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-01-21 11:04 - 2015-01-21 11:04 - 00000197 _____ () C:\windows\system32\2015-01-21-10-04-40.059-AvastVBoxSVC.exe-2880.log
2015-01-21 10:35 - 2014-06-27 03:08 - 02777088 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2015-01-21 10:35 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2vdec.dll
2015-01-21 10:33 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2015-01-21 10:33 - 2014-05-08 10:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2015-01-21 10:33 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2015-01-21 10:33 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-01-21 10:33 - 2011-02-25 07:19 - 02871808 _____ (Microsoft Corporation) C:\windows\explorer.exe
2015-01-21 10:33 - 2011-02-25 06:30 - 02616320 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2015-01-21 10:32 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\windows\SysWOW64\d2d1.dll
2015-01-21 10:32 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2015-01-21 10:32 - 2011-03-11 07:41 - 00410496 _____ (Intel Corporation) C:\windows\system32\Drivers\iaStorV.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00166272 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvstor.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00148352 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvraid.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00107904 _____ (Advanced Micro Devices) C:\windows\system32\Drivers\amdsata.sys
2015-01-21 10:32 - 2011-03-11 07:41 - 00027008 _____ (Advanced Micro Devices) C:\windows\system32\Drivers\amdxata.sys
2015-01-21 10:32 - 2011-03-11 07:33 - 02565632 _____ (Microsoft Corporation) C:\windows\system32\esent.dll
2015-01-21 10:32 - 2011-03-11 07:30 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\fsutil.exe
2015-01-21 10:32 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\windows\SysWOW64\esent.dll
2015-01-21 10:32 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\fsutil.exe
2015-01-21 10:32 - 2011-03-11 05:37 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2015-01-21 10:31 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
2015-01-21 10:31 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDYAK.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDTAT.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU1.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU.DLL
2015-01-21 10:31 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDBASH.DLL
2015-01-21 10:31 - 2014-07-08 23:38 - 00419992 _____ () C:\windows\system32\locale.nls
2015-01-21 10:31 - 2014-07-08 23:30 - 00419992 _____ () C:\windows\SysWOW64\locale.nls
2015-01-21 10:31 - 2014-06-24 04:29 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-01-21 10:31 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2015-01-21 10:31 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2015-01-21 10:31 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\windows\splwow64.exe
2015-01-21 10:27 - 2015-01-21 10:28 - 00000197 _____ () C:\windows\system32\2015-01-21-09-27-50.087-AvastVBoxSVC.exe-2660.log
2015-01-21 10:08 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2015-01-21 10:08 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-21 10:08 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-21 10:08 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2015-01-21 10:07 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2015-01-21 10:07 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2015-01-21 10:07 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-01-21 10:07 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-01-21 10:07 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2015-01-21 10:07 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2015-01-21 10:07 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-01-21 10:07 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2015-01-21 10:07 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2015-01-21 10:07 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-01-21 10:07 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2015-01-21 10:03 - 2015-01-21 11:57 - 04190942 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2015-01-21 09:56 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2015-01-21 09:56 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2015-01-21 09:56 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2015-01-21 09:56 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2015-01-21 09:56 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2015-01-21 09:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-01-21 09:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-01-21 09:35 - 2015-01-21 09:35 - 00000197 _____ () C:\windows\system32\2015-01-21-08-35-45.076-AvastVBoxSVC.exe-2464.log
2015-01-21 09:25 - 2015-01-21 09:25 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-01-21 09:25 - 2015-01-21 09:25 - 00000000 ____D () C:\windows\system32\appraiser
2015-01-21 09:23 - 2015-01-21 09:24 - 00000197 _____ () C:\windows\system32\2015-01-21-08-23-41.005-AvastVBoxSVC.exe-168.log
2015-01-21 09:21 - 2015-01-21 09:21 - 1140010868 _____ () C:\windows\MEMORY.DMP
2015-01-21 09:21 - 2015-01-21 09:21 - 00000000 ____D () C:\windows\Minidump
2015-01-20 21:00 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-01-20 21:00 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-01-20 21:00 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2015-01-20 21:00 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-01-20 20:01 - 2015-01-20 20:01 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-01-20 20:01 - 2015-01-20 20:01 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-01-20 20:01 - 2015-01-20 20:01 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-01-20 20:01 - 2015-01-20 20:01 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat
2015-01-20 20:01 - 2015-01-20 20:01 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2015-01-20 20:01 - 2015-01-20 20:01 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-01-20 20:01 - 2015-01-20 20:01 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-01-20 20:01 - 2015-01-20 20:01 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-01-20 20:01 - 2015-01-20 20:01 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll
2015-01-20 20:01 - 2015-01-20 20:01 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe
2015-01-20 20:01 - 2015-01-20 20:01 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01682432 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01643520 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01247744 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01238528 _____ (Microsoft Corporation) C:\windows\system32\d3d10.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01175552 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01158144 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsPrint.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 01080832 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00648192 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00604160 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10level9.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00522752 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsGdiConverter.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00363008 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00333312 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\d3d10core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00293376 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00249856 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10_1core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00245248 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10core.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00207872 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecsExt.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00194560 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00187392 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAnimation.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00161792 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10_1.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00010752 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00010752 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00009728 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00009728 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00002560 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-01-20 19:47 - 2015-01-20 19:47 - 00002560 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-01-20 14:53 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-01-20 14:53 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2015-01-20 14:53 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-01-20 14:53 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-01-20 14:53 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-01-20 14:53 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-01-20 14:53 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2015-01-20 14:53 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2015-01-20 14:53 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2015-01-20 14:53 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\windows\system32\WUDFx.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe
2015-01-20 14:51 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll
2015-01-20 14:51 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\windows\system32\WUDFCoinstaller.dll
2015-01-20 14:51 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys
2015-01-20 14:51 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys
2015-01-20 14:51 - 2012-06-02 15:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-01-20 14:27 - 2015-01-20 14:27 - 00000197 _____ () C:\windows\system32\2015-01-20-13-27-06.064-AvastVBoxSVC.exe-2964.log
2015-01-20 13:56 - 2015-01-20 13:56 - 00000197 _____ () C:\windows\system32\2015-01-20-12-56-28.062-AvastVBoxSVC.exe-4596.log
2015-01-20 13:20 - 2015-01-20 13:20 - 00000247 _____ () C:\windows\system32\2015-01-20-12-20-48.046-aswFe.exe-6056.log
2015-01-20 13:13 - 2015-01-20 13:20 - 00000247 _____ () C:\windows\system32\2015-01-20-12-13-29.071-aswFe.exe-4372.log
2015-01-20 13:13 - 2015-01-20 13:13 - 00000197 _____ () C:\windows\system32\2015-01-20-12-13-23.011-AvastVBoxSVC.exe-4364.log
2015-01-20 13:04 - 2015-01-20 13:04 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVAST Software
2015-01-20 13:00 - 2015-01-20 13:00 - 00000000 ____D () C:\windows\SysWOW64\vbox
2015-01-20 13:00 - 2015-01-20 13:00 - 00000000 ____D () C:\windows\system32\vbox
2015-01-20 12:59 - 2015-01-20 12:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-01-20 12:58 - 2015-01-31 15:48 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2015-01-20 12:58 - 2015-01-21 09:40 - 01050432 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00436624 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00364512 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2015-01-20 12:58 - 2015-01-20 12:58 - 00267632 _____ () C:\windows\system32\Drivers\aswVmm.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00116728 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00083280 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2015-01-20 12:58 - 2015-01-20 12:58 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2015-01-20 12:58 - 2015-01-20 12:58 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys
2015-01-20 12:57 - 2015-01-20 12:57 - 00000000 ____D () C:\Program Files\AVAST Software
2015-01-20 12:56 - 2015-01-20 12:57 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-01-20 12:56 - 2015-01-20 12:56 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-01-20 12:56 - 2015-01-20 12:56 - 00002029 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-01-20 12:55 - 2015-01-20 12:55 - 00001080 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\windows\SysWOW64\Adobe
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-01-20 12:55 - 2015-01-20 12:55 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2015-01-20 12:54 - 2015-01-20 12:54 - 00319912 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2015-01-20 12:54 - 2015-01-20 12:54 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2015-01-20 12:54 - 2015-01-20 12:54 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\ProgramData\Sun
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\Program Files\Java
2015-01-20 12:54 - 2015-01-20 12:54 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-20 12:53 - 2015-01-21 22:02 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
2015-01-20 12:53 - 2015-01-20 12:56 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-20 12:53 - 2015-01-20 12:56 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-01-20 12:53 - 2015-01-20 12:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-01-20 12:52 - 2015-01-20 12:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-01-20 12:52 - 2015-01-20 12:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-01-20 12:51 - 2015-01-22 12:32 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-20 12:51 - 2015-01-22 12:32 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\ProgramData\Mozilla
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-20 12:51 - 2015-01-20 12:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-20 12:48 - 2015-01-31 03:24 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-01-20 12:48 - 2015-01-25 17:24 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-01-20 12:48 - 2015-01-25 17:24 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-20 12:48 - 2015-01-25 17:24 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-01-20 12:48 - 2015-01-20 12:48 - 00000000 ____D () C:\windows\system32\Macromed
2015-01-19 14:18 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE
2015-01-19 13:38 - 2015-01-20 20:35 - 00041009 _____ () C:\windows\IE11_main.log
2015-01-19 12:14 - 2015-01-19 12:16 - 00000000 ____D () C:\windows\system32\MRT
2015-01-19 12:14 - 2014-12-31 13:12 - 113365784 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-01-19 12:12 - 2015-01-19 12:12 - 00000000 ____D () C:\Users\User\AppData\Local\WindowsUpdate
2015-01-19 12:12 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\windows\system32\icardres.dll
2015-01-19 12:12 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardres.dll
2015-01-19 12:12 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\windows\SysWOW64\TsWpfWrp.exe
2015-01-19 12:12 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
2015-01-19 12:12 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\windows\system32\icardagt.exe
2015-01-19 12:12 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\windows\system32\infocardapi.dll
2015-01-19 12:12 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardagt.exe
2015-01-19 12:12 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\windows\SysWOW64\infocardapi.dll
2015-01-19 12:10 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2015-01-19 12:10 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2015-01-19 12:10 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\windows\SysWOW64\certutil.exe
2015-01-19 12:10 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\certenc.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-01-19 12:09 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-01-19 12:09 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-01-19 12:09 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-01-19 12:09 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-01-19 12:09 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-01-19 12:09 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-01-19 12:08 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2015-01-19 12:08 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2015-01-19 12:08 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2015-01-19 12:08 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2015-01-19 12:08 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2015-01-19 12:08 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2015-01-19 12:08 - 2014-03-04 10:44 - 00722944 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2015-01-19 12:08 - 2014-03-04 10:44 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-01-19 12:08 - 2014-03-04 10:44 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:43 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\objsel.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\windows\SysWOW64\adprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\capiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapiprovider.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsroam.dll
2015-01-19 12:08 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredprovider.dll
2015-01-19 12:08 - 2014-03-04 10:16 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll
2015-01-19 12:08 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll
2015-01-19 12:08 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2015-01-19 12:08 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe
2015-01-19 12:08 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe
2015-01-19 12:08 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_isv.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_ssp_isv.dll
2015-01-19 12:08 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\secproc_ssp.dll
2015-01-19 12:08 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdrm.dll
2015-01-19 12:08 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_isv.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_ssp.exe
2015-01-19 12:08 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\windows\SysWOW64\RMActivate_ssp_isv.exe
2015-01-19 12:08 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2015-01-19 12:08 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2015-01-19 12:08 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2015-01-19 12:08 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys
2015-01-19 12:08 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\Wdfres.dll
2015-01-19 12:08 - 2012-11-28 23:56 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-01-19 12:08 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\rdpwsx.dll
2015-01-19 12:08 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\windows\system32\rdrmemptylst.exe
2015-01-19 12:07 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2015-01-19 12:07 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-01-19 12:07 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-01-19 12:07 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-01-19 12:07 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-01-19 12:07 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-01-19 12:07 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-01-19 12:07 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-01-19 12:07 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-01-19 12:07 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-01-19 12:07 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-01-19 12:07 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2015-01-19 12:07 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d11.dll
2015-01-19 12:07 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2015-01-19 12:07 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll
2015-01-19 12:07 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\windows\system32\gameux.dll
2015-01-19 12:07 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wpc.dll
2015-01-19 12:07 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\windows\SysWOW64\gameux.dll
2015-01-19 12:07 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\windows\system32\oflc-nz.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\windows\system32\pegibbfc.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\windows\system32\csrr.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\windows\system32\usk.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\windows\system32\oflc.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-pt.rs
2015-01-19 12:07 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-fi.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\windows\system32\cero.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\windows\system32\esrb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\windows\system32\fpb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\windows\system32\cob-au.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\windows\system32\grb.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\windows\system32\pegi.rs
2015-01-19 12:07 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\windows\system32\djctq.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\windows\SysWOW64\cero.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\windows\SysWOW64\esrb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\windows\SysWOW64\fpb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\windows\SysWOW64\oflc-nz.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\windows\SysWOW64\pegibbfc.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\windows\SysWOW64\csrr.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\windows\SysWOW64\cob-au.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\windows\SysWOW64\usk.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\windows\SysWOW64\oflc.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\windows\SysWOW64\grb.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi-pt.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi-fi.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\windows\SysWOW64\pegi.rs
2015-01-19 12:07 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\windows\SysWOW64\djctq.rs
2015-01-19 12:06 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-01-19 12:06 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-01-19 12:06 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-01-19 12:06 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-01-19 12:06 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-01-19 12:06 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-01-19 12:06 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-01-19 12:06 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-01-19 12:06 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2015-01-19 12:06 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-01-19 12:06 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\windows\SysWOW64\pku2u.dll
2015-01-19 12:06 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-01-19 12:06 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-01-19 12:06 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-01-19 12:06 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-01-19 12:06 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2015-01-19 12:06 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-01-19 12:06 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2015-01-19 12:06 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2015-01-19 12:06 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2015-01-19 12:06 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2015-01-19 12:06 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2015-01-19 12:06 - 2014-08-01 12:53 - 01031168 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2015-01-19 12:06 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll
2015-01-19 12:06 - 2014-04-12 03:22 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-01-19 12:06 - 2014-04-12 03:19 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-01-19 12:06 - 2014-04-12 03:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-01-19 12:06 - 2014-04-12 03:19 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-01-19 12:06 - 2014-04-12 03:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-01-19 12:06 - 2014-03-04 10:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-01-19 12:06 - 2014-03-04 10:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-01-19 12:06 - 2014-03-04 10:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-01-19 12:06 - 2014-03-04 10:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-01-19 12:06 - 2014-03-04 10:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-01-19 12:06 - 2014-03-04 09:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-01-19 12:06 - 2014-03-04 09:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-01-19 12:06 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2015-01-19 12:06 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll
2015-01-19 12:06 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-01-19 12:06 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-01-19 12:06 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-01-19 12:06 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-01-19 12:06 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2015-01-19 12:06 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\shdocvw.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\windows\system32\netcorehc.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2015-01-19 12:06 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\netevent.dll
2015-01-19 12:06 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2015-01-19 12:06 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\netcorehc.dll
2015-01-19 12:06 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\netevent.dll
2015-01-19 12:06 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2015-01-19 12:05 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-01-19 12:05 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2015-01-19 12:05 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2015-01-19 12:05 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10K.DLL
2015-01-19 12:05 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-01-19 12:05 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-01-19 12:05 - 2014-06-18 03:18 - 00692736 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2015-01-19 12:05 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
2015-01-19 12:05 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2015-01-19 12:05 - 2014-06-06 11:10 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2015-01-19 12:05 - 2014-06-06 10:44 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2015-01-19 12:05 - 2014-04-05 03:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2015-01-19 12:05 - 2014-04-05 03:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2015-01-19 12:05 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2015-01-19 12:05 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2015-01-19 12:05 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-01-19 12:05 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-01-19 12:05 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-01-19 12:05 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-01-19 12:05 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2015-01-19 12:05 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptdlg.dll
2015-01-19 12:05 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2015-01-19 12:05 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2015-01-19 12:05 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2015-01-19 12:05 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wwanprotdim.dll
2015-01-19 12:05 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll
2015-01-19 12:05 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll
2015-01-19 12:05 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore6.dll
2015-01-19 12:05 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc6.dll
2015-01-19 12:05 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\windows\system32\OxpsConverter.exe
2015-01-19 12:05 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\netapi32.dll
2015-01-19 12:05 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\browser.dll
2015-01-19 12:05 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\browcli.dll
2015-01-19 12:05 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\windows\SysWOW64\netapi32.dll
2015-01-19 12:05 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\windows\SysWOW64\browcli.dll
2015-01-19 12:05 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\windows\system32\ntshrui.dll
2015-01-19 12:05 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntshrui.dll
2015-01-19 12:05 - 2011-10-26 06:25 - 01572864 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-01-19 12:05 - 2011-10-26 05:32 - 01328128 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2015-01-19 12:05 - 2011-07-09 03:46 - 00288768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-01-19 12:05 - 2011-05-04 06:25 - 02315776 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 02223616 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00778752 _____ (Microsoft Corporation) C:\windows\system32\mssvp.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00491520 _____ (Microsoft Corporation) C:\windows\system32\mssph.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00288256 _____ (Microsoft Corporation) C:\windows\system32\mssphtb.dll
2015-01-19 12:05 - 2011-05-04 06:22 - 00075264 _____ (Microsoft Corporation) C:\windows\system32\msscntrs.dll
2015-01-19 12:05 - 2011-05-04 06:19 - 00591872 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe
2015-01-19 12:05 - 2011-05-04 06:19 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\SearchProtocolHost.exe
2015-01-19 12:05 - 2011-05-04 06:19 - 00113664 _____ (Microsoft Corporation) C:\windows\system32\SearchFilterHost.exe
2015-01-19 12:05 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssvp.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssph.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssphtb.dll
2015-01-19 12:05 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscntrs.dll
2015-01-19 12:05 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe
2015-01-19 12:05 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchProtocolHost.exe
2015-01-19 12:05 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFilterHost.exe
2015-01-19 12:05 - 2011-04-27 03:40 - 00158208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-01-19 12:05 - 2011-04-27 03:39 - 00128000 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-01-19 12:05 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\poqexec.exe
2015-01-19 12:05 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\poqexec.exe
2015-01-19 12:05 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2015-01-19 12:04 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-01-19 12:04 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-01-19 12:04 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2015-01-19 12:04 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncsi.dll
2015-01-19 12:04 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlaapi.dll
2015-01-19 12:04 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-01-19 12:04 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-01-19 12:04 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2015-01-19 12:04 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2015-01-19 12:04 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-01-19 12:04 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-01-19 12:04 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-01-19 12:04 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2015-01-19 12:04 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2015-01-19 12:04 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-01-19 12:04 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-01-19 12:04 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2015-01-19 12:04 - 2014-05-30 07:45 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-01-19 12:04 - 2014-04-25 03:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2015-01-19 12:04 - 2014-04-25 03:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2015-01-19 12:04 - 2014-03-26 15:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-01-19 12:04 - 2014-03-26 15:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-01-19 12:04 - 2014-03-26 15:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-01-19 12:04 - 2014-03-26 15:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2015-01-19 12:04 - 2014-02-04 03:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2015-01-19 12:04 - 2014-02-04 03:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2015-01-19 12:04 - 2014-02-04 03:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2015-01-19 12:04 - 2014-02-04 03:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2015-01-19 12:04 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2015-01-19 12:04 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2015-01-19 12:04 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2015-01-19 12:04 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2015-01-19 12:04 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2015-01-19 12:04 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-01-19 12:04 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-01-19 12:04 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2015-01-19 12:04 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2015-01-19 12:04 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2015-01-19 12:04 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\SysWOW64\SmartcardCredentialProvider.dll
2015-01-19 12:04 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\credui.dll
2015-01-19 12:04 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2015-01-19 12:04 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2015-01-19 12:04 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2015-01-19 12:04 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2015-01-19 12:04 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-01-19 12:04 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-01-19 12:04 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-01-19 12:04 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2015-01-19 12:04 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-01-19 12:04 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2015-01-19 12:04 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-01-19 12:04 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-01-19 12:04 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-01-19 12:04 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
2015-01-19 12:04 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-01-19 12:04 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-01-19 12:04 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-01-19 12:04 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-01-19 12:04 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-01-19 12:04 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-01-19 12:04 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-01-19 12:04 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-01-19 12:04 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-01-19 12:04 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-01-19 12:04 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-01-19 12:04 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2015-01-19 12:04 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\dpnet.dll
2015-01-19 12:04 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpnet.dll
2015-01-19 12:04 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-01-19 12:04 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\Drivers\RNDISMP.sys
2015-01-19 12:04 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\partmgr.sys
2015-01-19 12:04 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fs_rec.sys
2015-01-19 12:04 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\wmi.dll
2015-01-19 12:04 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmi.dll
2015-01-19 12:04 - 2011-11-17 07:35 - 00395776 _____ (Microsoft Corporation) C:\windows\system32\webio.dll
2015-01-19 12:04 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\windows\SysWOW64\webio.dll


Nero555 31.01.2015 16:12

FRST Editor Logfile (2)
 
Code:

2015-01-19 12:04 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\windows\system32\psisdecd.dll
2015-01-19 12:04 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\psisrndr.ax
2015-01-19 12:04 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\windows\SysWOW64\psisdecd.dll
2015-01-19 12:04 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\windows\SysWOW64\psisrndr.ax
2015-01-19 12:04 - 2011-06-16 06:49 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\xmllite.dll
2015-01-19 12:04 - 2011-06-16 05:33 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\xmllite.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00212992 _____ (Microsoft Corporation) C:\windows\system32\odbctrac.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\odbccp32.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\odbccu32.dll
2015-01-19 12:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\odbccr32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00319488 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbcjt32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbctrac.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00122880 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccp32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccu32.dll
2015-01-19 12:04 - 2011-06-15 09:55 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbccr32.dll
2015-01-19 12:04 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\umpnpmgr.dll
2015-01-19 12:04 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\windows\SysWOW64\devobj.dll
2015-01-19 12:04 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\windows\SysWOW64\devrtl.dll
2015-01-19 12:04 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cfgmgr32.dll
2015-01-19 12:04 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\windows\SysWOW64\drvinst.exe
2015-01-19 12:04 - 2011-04-29 04:06 - 00467456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2015-01-19 12:04 - 2011-04-29 04:05 - 00410112 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2015-01-19 12:04 - 2011-04-29 04:05 - 00168448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2015-01-19 12:03 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2015-01-19 12:03 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\charmap.exe
2015-01-19 12:03 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2015-01-19 12:03 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2015-01-19 12:03 - 2014-09-25 03:08 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-01-19 12:03 - 2014-09-25 02:40 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2015-01-19 12:03 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2015-01-19 12:03 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2015-01-19 12:03 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2015-01-19 12:03 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2015-01-19 12:03 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2015-01-19 12:03 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2015-01-19 12:03 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-01-19 12:03 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\windows\SysWOW64\synceng.dll
2015-01-19 12:03 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\synceng.dll
2015-01-19 12:03 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\windows\system32\cdosys.dll
2015-01-19 12:03 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\windows\SysWOW64\cdosys.dll
2015-01-19 12:03 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\windows\system32\timedate.cpl
2015-01-19 12:03 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\windows\SysWOW64\timedate.cpl
2015-01-19 12:03 - 2011-02-18 11:51 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\prevhost.exe
2015-01-19 12:03 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\prevhost.exe
2015-01-19 12:02 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-01-19 12:02 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-01-19 12:01 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-01-19 12:01 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2015-01-19 12:01 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-01-19 12:01 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-01-19 12:01 - 2014-01-24 03:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2015-01-19 12:01 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2015-01-19 12:01 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2015-01-19 12:01 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2015-01-19 12:01 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2015-01-19 12:01 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2015-01-19 12:01 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx
2015-01-19 12:01 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2015-01-19 12:01 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2015-01-19 12:01 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2015-01-19 12:01 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2015-01-19 12:01 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2015-01-19 12:01 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe
2015-01-19 12:01 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2015-01-19 12:01 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-01-19 12:01 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2015-01-19 12:01 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2015-01-19 12:01 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\windows\system32\msvcrt.dll
2015-01-19 12:01 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcrt.dll
2015-01-19 12:01 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\windows\system32\EncDec.dll
2015-01-19 12:01 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\EncDec.dll
2015-01-19 12:01 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\windows\system32\oleacc.dll
2015-01-19 12:01 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleacc.dll
2015-01-19 11:50 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-01-19 11:50 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-01-19 11:49 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2015-01-19 11:32 - 2015-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\Virtual Desktop Manager
2015-01-19 11:32 - 2015-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Local\FSP
2015-01-19 11:31 - 2015-01-23 18:06 - 00001003 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-19 11:21 - 2015-01-19 11:21 - 524288000 __RSH () C:\VPART015.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART014.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART013.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART012.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART011.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART010.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART009.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 2097152000 __RSH () C:\VPART008.RIT
2015-01-19 11:21 - 2015-01-19 11:21 - 00000790 _____ () C:\Users\User\Desktop\Time Stamp.lnk
2015-01-19 11:21 - 2015-01-19 11:21 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Time Stamp
2015-01-19 11:20 - 2015-01-31 04:12 - 00001058 __RSH () C:\windows\system32\VFsRegister
2015-01-19 11:20 - 2015-01-21 12:12 - 00000000 ____D () C:\Program Files\Time Stamp
2015-01-19 11:20 - 2015-01-20 12:00 - 00000000 ____D () C:\ProgramData\Farstone
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART007.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART006.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART005.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART004.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART003.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART002.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART001.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 2097152000 __RSH () C:\VPART000.RIT
2015-01-19 11:20 - 2015-01-19 11:20 - 00004096 __RSH () C:\RESCUMBR.BIN
2015-01-19 11:20 - 2015-01-19 11:20 - 00000532 __RSH () C:\windows\system32\VFsActitvation
2015-01-19 11:20 - 2011-07-12 09:28 - 00162392 _____ () C:\windows\system32\Drivers\VvBackd5.sys
2015-01-19 11:20 - 2011-04-18 04:12 - 00024664 ____N () C:\windows\system32\Drivers\FarMntIo.sys
2015-01-19 11:20 - 2011-01-04 18:18 - 00066136 ____N () C:\windows\system32\Drivers\HCDisk.sys
2015-01-19 11:19 - 2015-01-19 11:19 - 00000006 _____ () C:\windows\silentOnce.tmp
2015-01-19 11:19 - 2015-01-19 11:19 - 00000000 ____D () C:\ProgramData\Remind
2015-01-19 11:19 - 2015-01-19 11:19 - 00000000 ____D () C:\Program Files (x86)\MSI
2015-01-19 11:16 - 2015-01-19 11:16 - 00000000 ____D () C:\Users\User\AppData\Local\VirtualStore
2015-01-19 11:16 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\windows\system32\rdpcore.dll
2015-01-19 11:16 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpcore.dll
2015-01-19 11:16 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdtcp.sys
2015-01-19 11:09 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-01-19 11:09 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-01-19 11:09 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-01-19 11:09 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-01-19 11:09 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-01-19 11:09 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-01-19 11:09 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-01-19 11:09 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-01-19 11:09 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-01-19 11:09 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-01-19 11:06 - 2015-01-21 09:37 - 00058016 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-19 11:06 - 2015-01-19 11:06 - 00000020 ___SH () C:\Users\User\ntuser.ini
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Vorlagen
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Startmenü
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Netzwerkumgebung
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Lokale Einstellungen
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Eigene Dateien
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Druckumgebung
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Documents\Eigene Musik
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Documents\Eigene Bilder
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Local\Verlauf
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\AppData\Local\Anwendungsdaten
2015-01-19 11:06 - 2015-01-19 11:06 - 00000000 _SHDL () C:\Users\User\Anwendungsdaten
2015-01-19 11:06 - 2011-08-11 18:21 - 00000000 ____D () C:\Users\User\AppData\Local\SRS Labs
2015-01-19 11:06 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-19 11:06 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-31 15:59 - 2009-07-14 05:45 - 00016752 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-31 15:59 - 2009-07-14 05:45 - 00016752 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-31 15:55 - 2011-08-11 18:10 - 01266802 _____ () C:\windows\WindowsUpdate.log
2015-01-31 15:48 - 2009-07-14 05:46 - 00005389 _____ () C:\windows\DtcInstall.log
2015-01-31 15:46 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-01-31 15:46 - 2009-07-14 05:51 - 00039433 _____ () C:\windows\setupact.log
2015-01-31 03:16 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\inetsrv
2015-01-31 03:16 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\inetsrv
2015-01-30 15:14 - 2010-11-21 04:47 - 00280546 _____ () C:\windows\PFRO.log
2015-01-30 15:10 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\GroupPolicy
2015-01-29 13:34 - 2011-08-11 19:05 - 00772184 _____ () C:\windows\system32\perfh010.dat
2015-01-29 13:34 - 2011-08-11 19:05 - 00159382 _____ () C:\windows\system32\perfc010.dat
2015-01-29 13:34 - 2011-08-11 18:59 - 00779006 _____ () C:\windows\system32\perfh00C.dat
2015-01-29 13:34 - 2011-08-11 18:59 - 00163544 _____ () C:\windows\system32\perfc00C.dat
2015-01-29 13:34 - 2011-08-11 18:52 - 00779960 _____ () C:\windows\system32\perfh00A.dat
2015-01-29 13:34 - 2011-08-11 18:52 - 00173610 _____ () C:\windows\system32\perfc00A.dat
2015-01-29 13:34 - 2011-08-11 18:45 - 00744432 _____ () C:\windows\system32\perfh007.dat
2015-01-29 13:34 - 2011-08-11 18:45 - 00162272 _____ () C:\windows\system32\perfc007.dat
2015-01-29 13:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-29 13:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2015-01-25 16:33 - 2011-08-11 18:24 - 00011580 _____ () C:\windows\DPINST.LOG
2015-01-25 16:33 - 2011-05-17 18:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-23 16:06 - 2011-08-11 18:22 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun
2015-01-22 12:24 - 2009-07-14 03:34 - 00000505 _____ () C:\windows\win.ini
2015-01-21 11:57 - 2009-07-14 06:13 - 04190942 _____ () C:\windows\system32\PerfStringBackup.INI
2015-01-21 11:38 - 2011-08-11 18:21 - 00058016 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-21 11:38 - 2011-08-11 18:21 - 00058016 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-21 11:01 - 2009-07-14 05:45 - 00267816 _____ () C:\windows\system32\FNTCACHE.DAT
2015-01-21 10:24 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\zh-HK
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\zh-HK
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\tr-TR
2015-01-21 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-21 09:25 - 2010-11-21 08:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-21 09:25 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-21 09:25 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\Dism
2015-01-21 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\AppCompat
2015-01-20 13:51 - 2011-08-11 18:29 - 00000000 ____D () C:\Users\Public\Desktop\User Manual
2015-01-20 12:53 - 2010-01-20 11:34 - 00000000 ____D () C:\Users\User\AppData\Roaming\Adobe
2015-01-19 11:31 - 2011-06-08 03:20 - 00000000 ____D () C:\Utility
2015-01-19 11:21 - 2011-03-21 17:37 - 00000000 ____D () C:\log
2015-01-19 11:19 - 2011-05-17 18:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-01-19 11:05 - 2011-05-16 20:37 - 00000000 __SHD () C:\Recovery
2015-01-19 11:05 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-01-19 11:04 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2015-01-08 09:55 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-29 14:50

==================== End Of Log ============================


cosinus 31.01.2015 16:14

Da ist ja immer noch was :balla:

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

S2 MElGfYhtuP; "C:\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe" [X]
C:\ProgramData\xfIwQZvgdh
C:\Users\User\AppData\Local\ZombieNews
cmd: dir /s C:\ProgramData\Browser
EmptyTemp:
Hosts:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Nero555 31.01.2015 16:35

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-01-2015
Ran by User at 2015-01-31 16:28:18 Run:1
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
S2 MElGfYhtuP; "C:\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe" [X]
C:\ProgramData\xfIwQZvgdh
C:\Users\User\AppData\Local\ZombieNews
cmd: dir /s C:\ProgramData\Browser
EmptyTemp:
Hosts:
       
*****************

MElGfYhtuP => Service deleted successfully.
"C:\ProgramData\xfIwQZvgdh" => File/Directory not found.
C:\Users\User\AppData\Local\ZombieNews => Moved successfully.

=========  dir /s C:\ProgramData\Browser =========

 Datentr�ger in Laufwerk C: ist OS_Install
 Volumeseriennummer: 18DF-F7AE

 Verzeichnis von C:\ProgramData\Browser

30.01.2015  15:21    <DIR>          .
30.01.2015  15:21    <DIR>          ..
30.01.2015  15:35            31.433 prompt.exe
30.01.2015  15:35              188 prompt.exe.config
              2 Datei(en),        31.621 Bytes

    Anzahl der angezeigten Dateien:
              2 Datei(en),        31.621 Bytes
              2 Verzeichnis(se), 111.637.639.168 Bytes frei

========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 342.8 MB temporary data.


The system needed a reboot.

==== End of Fixlog 16:28:28 ====


cosinus 31.01.2015 18:37

Zitat:

C:\ProgramData\Browser\prompt.exe
Bitte diese Datei bei Virustotal auswerten lassen und den Ergebnislink posten. Falls Du die Datei nicht siehst, musst Du sie evtl. vorher sichtbar machen.
Wenn die Datei schon ausgewertet sein sollte, bitte eine weitere Auswertung starten.

Nero555 31.01.2015 18:51

https://www.virustotal.com/de/file/acde76e15e86baa5b4de0c8dc9fd1c0f7b1ea5f21d59780f8cfe0f1e3abaf16c/analysis/

cosinus 31.01.2015 18:54

Und noch ein Fix :D

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\ProgramData\Browser

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Nero555 31.01.2015 18:59

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-01-2015
Ran by User at 2015-01-31 18:56:34 Run:2
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\ProgramData\Browser
       
*****************

C:\ProgramData\Browser => Moved successfully.

==== End of Fixlog 18:56:35 ====


cosinus 31.01.2015 19:00

Okay, dann Kontrollscans mit MBAM und ESET bitte:

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Nero555 31.01.2015 23:19

Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 31.01.2015
Suchlauf-Zeit: 19:05:42
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.4.1028
Malware Datenbank: v2015.01.31.04
Rootkit Datenbank: v2015.01.14.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: User

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 335307
Verstrichene Zeit: 12 Min, 23 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente erkannt)

Module: 0
(Keine schädliche Elemente erkannt)

Registrierungsschlüssel: 14
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [b43c5e9fc2c74ee87380a955c9396d93],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [b43c5e9fc2c74ee87380a955c9396d93],
PUP.Optional.BoBrowser.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\BoBrowser.VFDGMHJOB6PCY7EWWDLA3EFEVM, In Quarantäne, [7f71827b0e7b79bd855c3f41b35040c0],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, In Quarantäne, [44acd429dfaa8ea826c2b34e5aabd32d],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [f4fcfeffc7c285b10fd842bf3ec70bf5],
PUP.Optional.BoBrowser.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\bobrowser.exe, In Quarantäne, [40b033ca0e7b5ed8056b136e3dc640c0],
PUP.Optional.MediaPlayerVideo.A, HKLM\SOFTWARE\WOW6432NODE\MedPvid2.3-nv, In Quarantäne, [6987d825d8b188ae5e90bac5946fed13],
PUP.Optional.BoBrowser.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\BoBrowser.VFDGMHJOB6PCY7EWWDLA3EFEVM, In Quarantäne, [d21e43ba94f537ff08d9433d5ca7d828],
PUP.Optional.BoBrowser.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\bobrowser.exe, In Quarantäne, [e30d76873653c6708de3ee930ef57789],
PUP.Optional.Booster.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{d924d8dc}, In Quarantäne, [a34d05f89fea290d49bfccd8d1321ee2],
PUP.Optional.FastPlayer.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\FastPlayerUpdaterService, In Quarantäne, [6888ac511772a1953b5ca2e4a65da858],
PUP.Optional.MediaPlayerVideo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MedPvid2.3-nv, In Quarantäne, [44ac02fb59303402e00fa0df20e39c64],
PUP.Optional.MediaPlayerVideo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MedPvid2.3, In Quarantäne, [b13f9865fa8f50e6d41c3b4480832bd5],
PUP.Optional.MediaPlayerVideo.A, HKU\S-1-5-21-2608712115-2613374988-3172207222-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MedPvid2.3-nv, In Quarantäne, [e709ae4f0c7d5cdaa9465f20ca39d42c],

Registrierungswerte: 0
(Keine schädliche Elemente erkannt)

Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)

Ordner: 2
PUP.Optional.FastPlayer.A, C:\Users\User\AppData\Local\com\FastPlayer.exe_Url_ypw5ldaz5xtubzl3ykl5vaw3nmhswq1q, In Quarantäne, [fdf376875f2a4fe7e4d117640cf7d52b],
PUP.Optional.FastPlayer.A, C:\Users\User\AppData\Local\com\FastPlayer.exe_Url_ypw5ldaz5xtubzl3ykl5vaw3nmhswq1q\1.0.0.6, In Quarantäne, [fdf376875f2a4fe7e4d117640cf7d52b],

Dateien: 4
PUP.Optional.Nova.A, C:\Program Files (x86)\AmIcoSingLun\e7337cf2-54a3-43a6-839a-884175f84829.dll, In Quarantäne, [57996a93ec9d5dd9fd7c996cd42e946c],
PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\AppPatch64\VCLdr64.dll, In Quarantäne, [ea0643bafa8f58ded93e149e2dd49868],
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [9c54a5580584f442a44725dc000551af],
PUP.Optional.FastPlayer.A, C:\Users\User\AppData\Local\com\FastPlayer.exe_Url_ypw5ldaz5xtubzl3ykl5vaw3nmhswq1q\1.0.0.6\user.config, In Quarantäne, [fdf376875f2a4fe7e4d117640cf7d52b],

Physische Sektoren: 0
(Keine schädliche Elemente erkannt)


(end)

Ich habe nun 2 mal mit dem ESET online Scanner gesucht ,aber nach den scann habe ich die Logfile nirgendswo gefunden.

cosinus 01.02.2015 01:08

Anleitung lesen und umsetzen => C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).

Nero555 01.02.2015 01:12

Muss man einen Lokalen Datenträger angeschlossen haben?

cosinus 01.02.2015 01:25

Das steht alles in der Anleitung :D

Nero555 01.02.2015 17:35

Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=6c77c72b4d0f4b46a142f9fd1dd014cc
# engine=22242
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-01-31 08:08:04
# local_time=2015-01-31 09:08:04 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 71 94 289301 983462 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 116198 174364734 0 0
# scanned=193033
# found=102
# cleaned=0
# scan_time=6019
sh=39FEE51538F713D63BD3D2351F9FF4F7F4C75E9D ft=1 fh=f2eefd68ba8dc0d6 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\AspManager.exe.vir"
sh=0D8B18706A7D0B4188799F7C1F992FD2CA6FECAE ft=1 fh=beb1278ff8542fc3 vn="Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\ASPUninstall.exe.vir"
sh=C6D88BC2353AA0DD082914D604E1CB9E8DCC0D57 ft=1 fh=c0cb3b5fdf7d9689 vn="Variante von Win32/Systweak.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\Communication.dll.vir"
sh=0414F0E46A6BCA94A95A634401F16EA943A4E05E ft=1 fh=f7a37ef503e2d6af vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\filetypehelper.exe.vir"
sh=CCC2EC71F56E030A77369EBEDEEDAB41A0741694 ft=1 fh=9b4b2ad80b5519e2 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\scandll.dll.vir"
sh=5A31DB6D3F33926C43A9D69A6F8E39516DC49EF5 ft=1 fh=ae5d22e27bb4f6bf vn="Variante von Win32/BrowseFox.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\DynamoCombobho.dll.vir"
sh=BC69AACBDFC22BA7E81327BB73AC98F270CB25D0 ft=0 fh=0000000000000000 vn="Win32/BrowseFox.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\kpgkaimemdlpgfgohekgcjddinhmphfb.crx.vir"
sh=DAFA3D5E56F324891FF80E0C4FA5420C93FDE06C ft=1 fh=4229cda79b7d9d40 vn="Variante von MSIL/BrowseFox.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe.vir"
sh=CF3C8D97FA776DD3550D42FD482406E053A680F7 ft=1 fh=6586e1c2ced6cac6 vn="Variante von Win32/BrowseFox.N evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb.dll.vir"
sh=AFC0858DB66B8BB1AE80A4F7CFB6A8E196140D44 ft=1 fh=e12ac4571d7e5293 vn="Variante von Win64/BrowseFox.CI evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb64.dll.vir"
sh=C7CF934A16D70C1D2E186DA5D9C933DE8D91241F ft=1 fh=47171caf85ed870e vn="Variante von Win32/BrowseFox.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b0.dll.vir"
sh=FBCB49FCBFDE90789D3BD49B3190929B2D4A26E2 ft=1 fh=85105a51ac24be4c vn="Variante von Win64/BrowseFox.CH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b064.dll.vir"
sh=DCE9BB5584C721DDCF4C99E8850B558FD4AA628F ft=1 fh=52f2456adf013abf vn="Variante von Win64/BrowseFox.CJ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expextdll.dll.vir"
sh=F868B2C175A3D365C43624982E8286FA11B9CA14 ft=1 fh=0eb934d768c75478 vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BroStats.dll.vir"
sh=072D874AE1528F2F5F67C91E9A7FDD18B4E5824B ft=1 fh=a23537f2da71e327 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BrowserAdapter.dll.vir"
sh=845F1F7DFDC3716511C0D2A6C127CBAE382C3333 ft=1 fh=09d69173a21ef64f vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.ExpExt.dll.vir"
sh=565F78E6685243532D492A430931546D0A54A6FF ft=1 fh=ae0b23db060ede77 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.FFUpdate.dll.vir"
sh=D6953679D2056F9121FDAE25427227BBC242F73C ft=1 fh=7b1357ed388bbf18 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.GCUpdate.dll.vir"
sh=AEEFE7CE09F6329EDF8B6576D42DA45FEC0C5AF1 ft=1 fh=2b94a5d4c855e1c7 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.IEUpdate.dll.vir"
sh=2FC4107A34C1DBE6CD1A6801661E33F86F825C83 ft=1 fh=46bb283e7caec55f vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.PurBrowseG.dll.vir"
sh=9C712CCB24E1FB86A85A46872A5896543A263D1C ft=1 fh=b84793b35d529d47 vn="Variante von MSIL/NewPlayer.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\FastPlayer.exe.vir"
sh=7E3006A3E9518195A56DF0A3BA0F1F3365E8EC28 ft=1 fh=ef7079c6c55b225a vn="Variante von MSIL/NewPlayer.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\fastUpdater.exe.vir"
sh=5A41BDE23C59ED77C3AA628D249BCBAC212F8874 ft=1 fh=85ecec98e9859fb8 vn="MSIL/NewPlayer.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\WebBrowser.exe.vir"
sh=5ACA9CEA9D6A0FBF1D679552388DDE0205B8AA7C ft=1 fh=64759f2098d1d6a6 vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\gamesdesktop_widget.exe.vir"
sh=4CBC3F900232E1CFD1BA7E9C1724912FE6CFADD0 ft=1 fh=8bc90044e286ad0e vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\gmsd_de_131.exe.vir"
sh=F86AC47AF64D439AA46CBB6AF9116D27011A775E ft=1 fh=6f77d625878dae13 vn="Win32/Adware.EoRezo Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\predm.exe.vir"
sh=B9AAB290C82AD1585C0CBEE7F206F71F248DD9BD ft=1 fh=d8998ea63e9f3b36 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-10.exe.vir"
sh=7F83DD6443AAAF85D772A9FEDE1D4E988AA0F7F0 ft=1 fh=fe8fcabbcaacdf41 vn="Variante von Win32/Toolbar.CrossRider.BV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-11.exe.vir"
sh=1D35327230AC7E5B96220FBA31D69C9F49F3D078 ft=1 fh=f0886b782f698aa4 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-2.exe.vir"
sh=B11FF4B9B5B146FC445C59FA4169E0736FA16648 ft=1 fh=552faa579ce3b981 vn="Variante von Win32/Toolbar.CrossRider.BV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-4.exe.vir"
sh=296CD5F101C2B4F1B1D6CBB30A85A6C80FC41B28 ft=1 fh=d7b05babaa58c9a3 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-5.exe.vir"
sh=FD27D574F7D3288447C7A916D187A1B7D2B5D2AA ft=1 fh=f9857d4c1a3d975b vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-6.exe.vir"
sh=45A0F332330A26D522155B884A4DFCC6E8315313 ft=1 fh=1d5949a9f8955486 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-64.exe.vir"
sh=2ABABEE75FD81E79B4950AFC859C420B4A00B1DD ft=1 fh=73bb817d53f1cb19 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-7.exe.vir"
sh=A0D2EA8A230949C9162BB143591A982EDDE7BF1E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d.crx.vir"
sh=ECCEA4A6092C8ABBAC550EC5FF5343F6EA01F981 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d.xpi.vir"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\b9e007cd-5336-4e7b-8a24-3cbe7d1c52d9.dll.vir"
sh=D736C28E0F60F5E6F2E1012A3000E399117BA623 ft=1 fh=532645e6f0fdba3c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\c7ecf604-b1fc-4f95-85be-62bfc0577943.dll.vir"
sh=C38A1DC097EC82DA39CFF23C2C0DE840F3AE21D2 ft=1 fh=3eba6a964580a025 vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bg.exe.vir"
sh=AEF8CC900BF7F7084886B7AA00E243E94A827A12 ft=1 fh=a6d225d94f74e01a vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bho.dll.vir"
sh=F43520AD7F1AA8018C5ACDD05C38E2D7DE958169 ft=1 fh=62bede15c6b2a0f5 vn="Variante von Win64/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bho64.dll.vir"
sh=2ABABEE75FD81E79B4950AFC859C420B4A00B1DD ft=1 fh=73bb817d53f1cb19 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-codedownloader.exe.vir"
sh=924069355F65A0A0EE316139D08D4FE04654EDBE ft=1 fh=45a7871de67c6e1c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\Uninstall.exe.vir"
sh=0B6B24DBFEF11B73D87470186C3829A50588003A ft=1 fh=418c4879d13c66d7 vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\utils.exe.vir"
sh=AAA623029121715DD514658EB72C344C182CE5D4 ft=1 fh=2063f527e15bc225 vn="Variante von MSIL/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\BackupStackUI.dll.vir"
sh=BAFC87AA0D99C347EA00A77BB09CE78915DF75E5 ft=1 fh=edcb43f436e617cd vn="MSIL/MyPCBackup.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\MyPC Backup.exe.vir"
sh=CB0EE05C61C3F9446D600359C65FA0FD314E6548 ft=1 fh=5f0fc3daa463974a vn="Variante von Win32/AdWare.SpeedingUpMyPC.S Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir"
sh=7925144AF2DD189B4EE5DA34E38A04409DD418B7 ft=1 fh=84a76f28a91f334b vn="Win32/Systweak.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\CleanSchedule.exe.vir"
sh=FC28EB51B58694E0BEB7997AC4BE2CB2A7E80CC1 ft=1 fh=dcb4450fa2ef403d vn="Variante von Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RCPUninstall.exe.vir"
sh=8FCB7D118C793F41B90C576CDDEC7AA3A2941493 ft=1 fh=aed6e0cb456c1b6d vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RegCleanPro.exe.vir"
sh=E69EF66B5CC919B8E29A9761CD44809D05556ED8 ft=1 fh=f46c5436c547759e vn="Win32/Systweak.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\systweakasp.exe.vir"
sh=8743F255E80C6A0A95A94CC668553686FF170120 ft=1 fh=0e8260637ee8e1d9 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\RN32.dll.vir"
sh=A704B6A7928A66851D5D0C251F975B52F6755053 ft=1 fh=3a141fdd6276f642 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPtool64.exe.vir"
sh=3010A616F191A1AB67BAA394F95094E43E1B0F05 ft=1 fh=1d4eab4a3a54531e vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll.vir"
sh=275F649C7C4613C61B59BD33393AA245AD3D3816 ft=1 fh=ecf7e3ee1d6b314e vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll.vir"
sh=FC3A455F0FB2672BC95CB6935C777FC86FD76978 ft=1 fh=0b3b4934b4c0b40c vn="Variante von Win32/Verti.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\StormWatch\StormWatchApp.exe.vir"
sh=CC754C436679DF3C9CAA3B4FA21E4E8C7D5F56B3 ft=1 fh=19c0721a1cb98727 vn="Variante von Win32/Adware.AddLyrics.DN Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver0BlockAndSurf\temp\Uninstall.exe.vir"
sh=497D88F38E21229D95650E02708207190CB6849E ft=1 fh=64a74ba51bf40770 vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchCH.dll.vir"
sh=5468230F587DE9F869DB9E22083131DCFD9451F2 ft=1 fh=07a842c13464288e vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchFF.dll.vir"
sh=5D628376391A827A818B0A079B64EE457AE9B82A ft=1 fh=c71c0011e2e7a7a5 vn="Variante von Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowserAction.dll.vir"
sh=1DFF39C0F7B7617C8292510F1833B282CD0A1F21 ft=1 fh=18ddbd645dd0ae9c vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\IeWatchDog.dll.vir"
sh=606D4414333C04E362F60B505926C78BB0B6C694 ft=1 fh=2f7c44d7fdd8d932 vn="Variante von Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\SupTab.dll.vir"
sh=AF36570D737043FEBEC5FA3DDB416A4CF5FDFBE9 ft=1 fh=c71c0011100f33aa vn="Variante von Win32/ELEX.BH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir"
sh=B06EE6E97D30DB38C3E8FEA66B396DB00EC79616 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\Application\36.0.1985.136\default_apps\crossbrowser.crx.vir"
sh=05F6C33F5A45CD34A9CAF61E295E886922448732 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\Application\36.0.1985.136\Installer\chrome.7z.vir"
sh=DC3B46CDAB1D97E3F9BFC4C4B570D22BDEE96A3B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Cache\f_000002.vir"
sh=03517F89D3F20D2D4E2B1A956F8248C9DA9FFC18 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Extensions\ebpeonjdeofpjegbdiibbdjlgfohngee\1.26.14_0\extensionData\plugins\91.js.vir"
sh=03517F89D3F20D2D4E2B1A956F8248C9DA9FFC18 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Extensions\ebpeonjdeofpjegbdiibbdjlgfohngee\1.26.14_1\extensionData\plugins\91.js.vir"
sh=CBE86D7679B057BF534B45289D1ABCD8E1F77EAB ft=1 fh=cff6049dec1b8116 vn="Variante von Win32/Adware.AdService.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\ConvertAd\CASrv.exe.vir"
sh=5930DD4374564C947E45AEAFB5C634C27F1889F0 ft=1 fh=915e502c9714d06b vn="Variante von Win32/Adware.ConvertAd.O Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\ConvertAd\ConvertAd.exe.vir"
sh=038E68041CC5D1C49823F6867BD87F44A12C74E7 ft=1 fh=bfa4bdd95b0f360e vn="Variante von Win32/Adware.EoRezo.AJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\gmsd_de_131\upgmsd_de_131.exe.vir"
sh=FB696DD11A897BE783D2203BB44A9AF0BB08E083 ft=1 fh=3e4b1ae17324d848 vn="Variante von Win32/Adware.ConvertAd.L Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\wincheck\wincheck.exe.vir"
sh=DB4D5C550C59D20F5972E6CA38E3F4209E39C374 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\Extensions\b6e4f54065ff48dd97db30ca@c9b45f807bf54a45a4669e51c.com\extensionData\plugins\91.js.vir"
sh=DB4D5C550C59D20F5972E6CA38E3F4209E39C374 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\hniiadklfgdhjcmmkpggffjngihaaoip\1.26.38_0\extensionData\plugins\91.js.vir"
sh=5F0B7CF4A550BAAB1349464184E6E38694FB5B79 ft=1 fh=eccc746ec41c7f77 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\VOPackage\VOPackage.exe.vir"
sh=C22D8A49BB848CE60C334A2732AE7465B85DC9C6 ft=1 fh=07fa81e8f77d963b vn="Variante von Win32/Adware.AdService.H Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\VOPackage\VOsrv.exe.vir"
sh=08A5CE348D319335A92076C65C1091277AFED1B9 ft=1 fh=158b9db86261fb7d vn="Variante von Win64/Systweak.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\roboot64.exe.vir"
sh=AAA29097B1E5A7098E19A38F1200E636EE1C3A1E ft=1 fh=6b75069f13c3f94c vn="Win64/AdvancedSystemProtector.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\sasnative64.exe.vir"
sh=DEC806DC9DB9CE68018F8014BB83AC235E770769 ft=1 fh=358281a880d92594 vn="Variante von Win64/BrowseFox.CG evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}Gw64.sys.vir"
sh=D736C28E0F60F5E6F2E1012A3000E399117BA623 ft=1 fh=532645e6f0fdba3c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f\14a4de29-fef9-4220-8fbd-45468eae533e.dll"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f\f6b9c335-c41f-462e-b202-dcf7218c3464.dll"
sh=650581AE9AB01682F3BF4614E07B23F159206571 ft=1 fh=77e15956281daff0 vn="Variante von Win32/SpeedingUpMyPC Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Optimizer Pro 3.33\OptimizerPro.exe"
sh=5461848B30BFCC2C51A294C70AE94A93EE9CAF0B ft=1 fh=0205e271a8b6efa7 vn="Variante von Win32/Adware.SpeedingUpMyPC.C Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Optimizer Pro 3.33\OptProSmartScan.exe"
sh=68F5BABE6637AEF769CE56430749E2AE836BB50B ft=1 fh=41744573fd8379d7 vn="Variante von MSIL/Adware.PullUpdate.J.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\Setup.exe.xBAD"
sh=45B16506B6AC644EC10E194F7FC2ADBA996B68E4 ft=1 fh=3bd3e9e515cbb0bc vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe"
sh=1BFE06F3388C77420BACCBBDF27BBCE2D560717D ft=1 fh=556665db5d7ff889 vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\iBfDaCGfSb.exe"
sh=1FD64E6F84C961E538106D37A391987833E2FEA3 ft=1 fh=277dac96893679ce vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\mewHuD.exe"
sh=B0568F9B5C2606FD7D66FCC12CE95CD4639AC3A8 ft=1 fh=449a0154f80f9379 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\SWOWBzI.dll"
sh=24B8EB148FB663F58001B4689144FFD941342C8B ft=1 fh=5b635cbffa37f361 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\WdmHULmJ.dll"
sh=4495024B25F21088902FBD82FC915E621187FE85 ft=1 fh=cc5f08593bdd79bc vn="MSIL/MyPCBackup.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\BackupSetup.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i33FC.tmp.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i3874.tmp.exe.xBAD"
sh=DD9768DF9FC2EB0F7B0B16167A1FC7FCCCCFAA8F ft=1 fh=9a3c5ad0ee04cfbe vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i9602.tmp.exe.xBAD"
sh=78359B36EDF68FB1BF6E1E18D7E1FFF69FABED5B ft=1 fh=999ab1e308902740 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i9924.tmp.exe.xBAD"
sh=F0E208C30074CBB8E174DDE10CE68BBFD502B055 ft=1 fh=4ad95e97f7c0929b vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iBA4.tmp.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iE3FA.tmp.exe.xBAD"
sh=5F0B7CF4A550BAAB1349464184E6E38694FB5B79 ft=1 fh=eccc746ec41c7f77 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iE714.tmp.exe.xBAD"
sh=471DC01F5CFFCE6035652296AED25B815B260346 ft=1 fh=d304f79d7beb47b1 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\nst712.exe.xBAD"
sh=471DC01F5CFFCE6035652296AED25B815B260346 ft=1 fh=d304f79d7beb47b1 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\nszF70B.exe.xBAD"
sh=86796560DB0AE55C365CEC423A5B78809AADC139 ft=1 fh=8c7a4ac81187f375 vn="Variante von Win32/OptimizerEliteMax.C evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\optprosetup.exe.xBAD"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\AmIcoSingLun\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f.dll"
sh=9CFFB00618B8B4249E40CEA0ADC4557E9D40A806 ft=1 fh=daeb3c17d4759ec4 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="D:\$RECYCLE.BIN\S-1-5-21-2608712115-2613374988-3172207222-1004\$R5R2M1B.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=6c77c72b4d0f4b46a142f9fd1dd014cc
# engine=22245
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-01-31 10:13:10
# local_time=2015-01-31 11:13:10 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 71 94 300407 990968 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 127304 174372240 0 0
# scanned=193239
# found=102
# cleaned=0
# scan_time=6185
sh=39FEE51538F713D63BD3D2351F9FF4F7F4C75E9D ft=1 fh=f2eefd68ba8dc0d6 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\AspManager.exe.vir"
sh=0D8B18706A7D0B4188799F7C1F992FD2CA6FECAE ft=1 fh=beb1278ff8542fc3 vn="Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\ASPUninstall.exe.vir"
sh=C6D88BC2353AA0DD082914D604E1CB9E8DCC0D57 ft=1 fh=c0cb3b5fdf7d9689 vn="Variante von Win32/Systweak.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\Communication.dll.vir"
sh=0414F0E46A6BCA94A95A634401F16EA943A4E05E ft=1 fh=f7a37ef503e2d6af vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\filetypehelper.exe.vir"
sh=CCC2EC71F56E030A77369EBEDEEDAB41A0741694 ft=1 fh=9b4b2ad80b5519e2 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\scandll.dll.vir"
sh=5A31DB6D3F33926C43A9D69A6F8E39516DC49EF5 ft=1 fh=ae5d22e27bb4f6bf vn="Variante von Win32/BrowseFox.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\DynamoCombobho.dll.vir"
sh=BC69AACBDFC22BA7E81327BB73AC98F270CB25D0 ft=0 fh=0000000000000000 vn="Win32/BrowseFox.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\kpgkaimemdlpgfgohekgcjddinhmphfb.crx.vir"
sh=DAFA3D5E56F324891FF80E0C4FA5420C93FDE06C ft=1 fh=4229cda79b7d9d40 vn="Variante von MSIL/BrowseFox.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe.vir"
sh=CF3C8D97FA776DD3550D42FD482406E053A680F7 ft=1 fh=6586e1c2ced6cac6 vn="Variante von Win32/BrowseFox.N evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb.dll.vir"
sh=AFC0858DB66B8BB1AE80A4F7CFB6A8E196140D44 ft=1 fh=e12ac4571d7e5293 vn="Variante von Win64/BrowseFox.CI evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb64.dll.vir"
sh=C7CF934A16D70C1D2E186DA5D9C933DE8D91241F ft=1 fh=47171caf85ed870e vn="Variante von Win32/BrowseFox.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b0.dll.vir"
sh=FBCB49FCBFDE90789D3BD49B3190929B2D4A26E2 ft=1 fh=85105a51ac24be4c vn="Variante von Win64/BrowseFox.CH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b064.dll.vir"
sh=DCE9BB5584C721DDCF4C99E8850B558FD4AA628F ft=1 fh=52f2456adf013abf vn="Variante von Win64/BrowseFox.CJ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expextdll.dll.vir"
sh=F868B2C175A3D365C43624982E8286FA11B9CA14 ft=1 fh=0eb934d768c75478 vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BroStats.dll.vir"
sh=072D874AE1528F2F5F67C91E9A7FDD18B4E5824B ft=1 fh=a23537f2da71e327 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BrowserAdapter.dll.vir"
sh=845F1F7DFDC3716511C0D2A6C127CBAE382C3333 ft=1 fh=09d69173a21ef64f vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.ExpExt.dll.vir"
sh=565F78E6685243532D492A430931546D0A54A6FF ft=1 fh=ae0b23db060ede77 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.FFUpdate.dll.vir"
sh=D6953679D2056F9121FDAE25427227BBC242F73C ft=1 fh=7b1357ed388bbf18 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.GCUpdate.dll.vir"
sh=AEEFE7CE09F6329EDF8B6576D42DA45FEC0C5AF1 ft=1 fh=2b94a5d4c855e1c7 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.IEUpdate.dll.vir"
sh=2FC4107A34C1DBE6CD1A6801661E33F86F825C83 ft=1 fh=46bb283e7caec55f vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.PurBrowseG.dll.vir"
sh=9C712CCB24E1FB86A85A46872A5896543A263D1C ft=1 fh=b84793b35d529d47 vn="Variante von MSIL/NewPlayer.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\FastPlayer.exe.vir"
sh=7E3006A3E9518195A56DF0A3BA0F1F3365E8EC28 ft=1 fh=ef7079c6c55b225a vn="Variante von MSIL/NewPlayer.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\fastUpdater.exe.vir"
sh=5A41BDE23C59ED77C3AA628D249BCBAC212F8874 ft=1 fh=85ecec98e9859fb8 vn="MSIL/NewPlayer.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\WebBrowser.exe.vir"
sh=5ACA9CEA9D6A0FBF1D679552388DDE0205B8AA7C ft=1 fh=64759f2098d1d6a6 vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\gamesdesktop_widget.exe.vir"
sh=4CBC3F900232E1CFD1BA7E9C1724912FE6CFADD0 ft=1 fh=8bc90044e286ad0e vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\gmsd_de_131.exe.vir"
sh=F86AC47AF64D439AA46CBB6AF9116D27011A775E ft=1 fh=6f77d625878dae13 vn="Win32/Adware.EoRezo Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\predm.exe.vir"
sh=B9AAB290C82AD1585C0CBEE7F206F71F248DD9BD ft=1 fh=d8998ea63e9f3b36 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-10.exe.vir"
sh=7F83DD6443AAAF85D772A9FEDE1D4E988AA0F7F0 ft=1 fh=fe8fcabbcaacdf41 vn="Variante von Win32/Toolbar.CrossRider.BV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-11.exe.vir"
sh=1D35327230AC7E5B96220FBA31D69C9F49F3D078 ft=1 fh=f0886b782f698aa4 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-2.exe.vir"
sh=B11FF4B9B5B146FC445C59FA4169E0736FA16648 ft=1 fh=552faa579ce3b981 vn="Variante von Win32/Toolbar.CrossRider.BV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-4.exe.vir"
sh=296CD5F101C2B4F1B1D6CBB30A85A6C80FC41B28 ft=1 fh=d7b05babaa58c9a3 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-5.exe.vir"
sh=FD27D574F7D3288447C7A916D187A1B7D2B5D2AA ft=1 fh=f9857d4c1a3d975b vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-6.exe.vir"
sh=45A0F332330A26D522155B884A4DFCC6E8315313 ft=1 fh=1d5949a9f8955486 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-64.exe.vir"
sh=2ABABEE75FD81E79B4950AFC859C420B4A00B1DD ft=1 fh=73bb817d53f1cb19 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-7.exe.vir"
sh=A0D2EA8A230949C9162BB143591A982EDDE7BF1E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d.crx.vir"
sh=ECCEA4A6092C8ABBAC550EC5FF5343F6EA01F981 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d.xpi.vir"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\b9e007cd-5336-4e7b-8a24-3cbe7d1c52d9.dll.vir"
sh=D736C28E0F60F5E6F2E1012A3000E399117BA623 ft=1 fh=532645e6f0fdba3c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\c7ecf604-b1fc-4f95-85be-62bfc0577943.dll.vir"
sh=C38A1DC097EC82DA39CFF23C2C0DE840F3AE21D2 ft=1 fh=3eba6a964580a025 vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bg.exe.vir"
sh=AEF8CC900BF7F7084886B7AA00E243E94A827A12 ft=1 fh=a6d225d94f74e01a vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bho.dll.vir"
sh=F43520AD7F1AA8018C5ACDD05C38E2D7DE958169 ft=1 fh=62bede15c6b2a0f5 vn="Variante von Win64/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bho64.dll.vir"
sh=2ABABEE75FD81E79B4950AFC859C420B4A00B1DD ft=1 fh=73bb817d53f1cb19 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-codedownloader.exe.vir"
sh=924069355F65A0A0EE316139D08D4FE04654EDBE ft=1 fh=45a7871de67c6e1c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\Uninstall.exe.vir"
sh=0B6B24DBFEF11B73D87470186C3829A50588003A ft=1 fh=418c4879d13c66d7 vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\utils.exe.vir"
sh=AAA623029121715DD514658EB72C344C182CE5D4 ft=1 fh=2063f527e15bc225 vn="Variante von MSIL/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\BackupStackUI.dll.vir"
sh=BAFC87AA0D99C347EA00A77BB09CE78915DF75E5 ft=1 fh=edcb43f436e617cd vn="MSIL/MyPCBackup.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\MyPC Backup.exe.vir"
sh=CB0EE05C61C3F9446D600359C65FA0FD314E6548 ft=1 fh=5f0fc3daa463974a vn="Variante von Win32/AdWare.SpeedingUpMyPC.S Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir"
sh=7925144AF2DD189B4EE5DA34E38A04409DD418B7 ft=1 fh=84a76f28a91f334b vn="Win32/Systweak.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\CleanSchedule.exe.vir"
sh=FC28EB51B58694E0BEB7997AC4BE2CB2A7E80CC1 ft=1 fh=dcb4450fa2ef403d vn="Variante von Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RCPUninstall.exe.vir"
sh=8FCB7D118C793F41B90C576CDDEC7AA3A2941493 ft=1 fh=aed6e0cb456c1b6d vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RegCleanPro.exe.vir"
sh=E69EF66B5CC919B8E29A9761CD44809D05556ED8 ft=1 fh=f46c5436c547759e vn="Win32/Systweak.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\systweakasp.exe.vir"
sh=8743F255E80C6A0A95A94CC668553686FF170120 ft=1 fh=0e8260637ee8e1d9 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\RN32.dll.vir"
sh=A704B6A7928A66851D5D0C251F975B52F6755053 ft=1 fh=3a141fdd6276f642 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPtool64.exe.vir"
sh=3010A616F191A1AB67BAA394F95094E43E1B0F05 ft=1 fh=1d4eab4a3a54531e vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll.vir"
sh=275F649C7C4613C61B59BD33393AA245AD3D3816 ft=1 fh=ecf7e3ee1d6b314e vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll.vir"
sh=FC3A455F0FB2672BC95CB6935C777FC86FD76978 ft=1 fh=0b3b4934b4c0b40c vn="Variante von Win32/Verti.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\StormWatch\StormWatchApp.exe.vir"
sh=CC754C436679DF3C9CAA3B4FA21E4E8C7D5F56B3 ft=1 fh=19c0721a1cb98727 vn="Variante von Win32/Adware.AddLyrics.DN Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver0BlockAndSurf\temp\Uninstall.exe.vir"
sh=497D88F38E21229D95650E02708207190CB6849E ft=1 fh=64a74ba51bf40770 vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchCH.dll.vir"
sh=5468230F587DE9F869DB9E22083131DCFD9451F2 ft=1 fh=07a842c13464288e vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchFF.dll.vir"
sh=5D628376391A827A818B0A079B64EE457AE9B82A ft=1 fh=c71c0011e2e7a7a5 vn="Variante von Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowserAction.dll.vir"
sh=1DFF39C0F7B7617C8292510F1833B282CD0A1F21 ft=1 fh=18ddbd645dd0ae9c vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\IeWatchDog.dll.vir"
sh=606D4414333C04E362F60B505926C78BB0B6C694 ft=1 fh=2f7c44d7fdd8d932 vn="Variante von Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\SupTab.dll.vir"
sh=AF36570D737043FEBEC5FA3DDB416A4CF5FDFBE9 ft=1 fh=c71c0011100f33aa vn="Variante von Win32/ELEX.BH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir"
sh=B06EE6E97D30DB38C3E8FEA66B396DB00EC79616 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\Application\36.0.1985.136\default_apps\crossbrowser.crx.vir"
sh=05F6C33F5A45CD34A9CAF61E295E886922448732 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\Application\36.0.1985.136\Installer\chrome.7z.vir"
sh=DC3B46CDAB1D97E3F9BFC4C4B570D22BDEE96A3B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Cache\f_000002.vir"
sh=03517F89D3F20D2D4E2B1A956F8248C9DA9FFC18 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Extensions\ebpeonjdeofpjegbdiibbdjlgfohngee\1.26.14_0\extensionData\plugins\91.js.vir"
sh=03517F89D3F20D2D4E2B1A956F8248C9DA9FFC18 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Extensions\ebpeonjdeofpjegbdiibbdjlgfohngee\1.26.14_1\extensionData\plugins\91.js.vir"
sh=CBE86D7679B057BF534B45289D1ABCD8E1F77EAB ft=1 fh=cff6049dec1b8116 vn="Variante von Win32/Adware.AdService.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\ConvertAd\CASrv.exe.vir"
sh=5930DD4374564C947E45AEAFB5C634C27F1889F0 ft=1 fh=915e502c9714d06b vn="Variante von Win32/Adware.ConvertAd.O Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\ConvertAd\ConvertAd.exe.vir"
sh=038E68041CC5D1C49823F6867BD87F44A12C74E7 ft=1 fh=bfa4bdd95b0f360e vn="Variante von Win32/Adware.EoRezo.AJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\gmsd_de_131\upgmsd_de_131.exe.vir"
sh=FB696DD11A897BE783D2203BB44A9AF0BB08E083 ft=1 fh=3e4b1ae17324d848 vn="Variante von Win32/Adware.ConvertAd.L Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\wincheck\wincheck.exe.vir"
sh=DB4D5C550C59D20F5972E6CA38E3F4209E39C374 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\Extensions\b6e4f54065ff48dd97db30ca@c9b45f807bf54a45a4669e51c.com\extensionData\plugins\91.js.vir"
sh=DB4D5C550C59D20F5972E6CA38E3F4209E39C374 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\hniiadklfgdhjcmmkpggffjngihaaoip\1.26.38_0\extensionData\plugins\91.js.vir"
sh=5F0B7CF4A550BAAB1349464184E6E38694FB5B79 ft=1 fh=eccc746ec41c7f77 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\VOPackage\VOPackage.exe.vir"
sh=C22D8A49BB848CE60C334A2732AE7465B85DC9C6 ft=1 fh=07fa81e8f77d963b vn="Variante von Win32/Adware.AdService.H Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\VOPackage\VOsrv.exe.vir"
sh=08A5CE348D319335A92076C65C1091277AFED1B9 ft=1 fh=158b9db86261fb7d vn="Variante von Win64/Systweak.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\roboot64.exe.vir"
sh=AAA29097B1E5A7098E19A38F1200E636EE1C3A1E ft=1 fh=6b75069f13c3f94c vn="Win64/AdvancedSystemProtector.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\sasnative64.exe.vir"
sh=DEC806DC9DB9CE68018F8014BB83AC235E770769 ft=1 fh=358281a880d92594 vn="Variante von Win64/BrowseFox.CG evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}Gw64.sys.vir"
sh=D736C28E0F60F5E6F2E1012A3000E399117BA623 ft=1 fh=532645e6f0fdba3c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f\14a4de29-fef9-4220-8fbd-45468eae533e.dll"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f\f6b9c335-c41f-462e-b202-dcf7218c3464.dll"
sh=650581AE9AB01682F3BF4614E07B23F159206571 ft=1 fh=77e15956281daff0 vn="Variante von Win32/SpeedingUpMyPC Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Optimizer Pro 3.33\OptimizerPro.exe"
sh=5461848B30BFCC2C51A294C70AE94A93EE9CAF0B ft=1 fh=0205e271a8b6efa7 vn="Variante von Win32/Adware.SpeedingUpMyPC.C Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Optimizer Pro 3.33\OptProSmartScan.exe"
sh=68F5BABE6637AEF769CE56430749E2AE836BB50B ft=1 fh=41744573fd8379d7 vn="Variante von MSIL/Adware.PullUpdate.J.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\Setup.exe.xBAD"
sh=45B16506B6AC644EC10E194F7FC2ADBA996B68E4 ft=1 fh=3bd3e9e515cbb0bc vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe"
sh=1BFE06F3388C77420BACCBBDF27BBCE2D560717D ft=1 fh=556665db5d7ff889 vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\iBfDaCGfSb.exe"
sh=1FD64E6F84C961E538106D37A391987833E2FEA3 ft=1 fh=277dac96893679ce vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\mewHuD.exe"
sh=B0568F9B5C2606FD7D66FCC12CE95CD4639AC3A8 ft=1 fh=449a0154f80f9379 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\SWOWBzI.dll"
sh=24B8EB148FB663F58001B4689144FFD941342C8B ft=1 fh=5b635cbffa37f361 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\WdmHULmJ.dll"
sh=4495024B25F21088902FBD82FC915E621187FE85 ft=1 fh=cc5f08593bdd79bc vn="MSIL/MyPCBackup.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\BackupSetup.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i33FC.tmp.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i3874.tmp.exe.xBAD"
sh=DD9768DF9FC2EB0F7B0B16167A1FC7FCCCCFAA8F ft=1 fh=9a3c5ad0ee04cfbe vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i9602.tmp.exe.xBAD"
sh=78359B36EDF68FB1BF6E1E18D7E1FFF69FABED5B ft=1 fh=999ab1e308902740 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i9924.tmp.exe.xBAD"
sh=F0E208C30074CBB8E174DDE10CE68BBFD502B055 ft=1 fh=4ad95e97f7c0929b vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iBA4.tmp.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iE3FA.tmp.exe.xBAD"
sh=5F0B7CF4A550BAAB1349464184E6E38694FB5B79 ft=1 fh=eccc746ec41c7f77 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iE714.tmp.exe.xBAD"
sh=471DC01F5CFFCE6035652296AED25B815B260346 ft=1 fh=d304f79d7beb47b1 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\nst712.exe.xBAD"
sh=471DC01F5CFFCE6035652296AED25B815B260346 ft=1 fh=d304f79d7beb47b1 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\nszF70B.exe.xBAD"
sh=86796560DB0AE55C365CEC423A5B78809AADC139 ft=1 fh=8c7a4ac81187f375 vn="Variante von Win32/OptimizerEliteMax.C evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\optprosetup.exe.xBAD"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\AmIcoSingLun\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f.dll"
sh=9CFFB00618B8B4249E40CEA0ADC4557E9D40A806 ft=1 fh=daeb3c17d4759ec4 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="D:\$RECYCLE.BIN\S-1-5-21-2608712115-2613374988-3172207222-1004\$R5R2M1B.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=6c77c72b4d0f4b46a142f9fd1dd014cc
# engine=22251
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-02-01 02:48:39
# local_time=2015-02-01 03:48:39 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 71 94 360136 1050697 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 57566 174431969 0 0
# scanned=4829
# found=100
# cleaned=0
# scan_time=298
sh=39FEE51538F713D63BD3D2351F9FF4F7F4C75E9D ft=1 fh=f2eefd68ba8dc0d6 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\AspManager.exe.vir"
sh=0D8B18706A7D0B4188799F7C1F992FD2CA6FECAE ft=1 fh=beb1278ff8542fc3 vn="Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\ASPUninstall.exe.vir"
sh=C6D88BC2353AA0DD082914D604E1CB9E8DCC0D57 ft=1 fh=c0cb3b5fdf7d9689 vn="Variante von Win32/Systweak.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\Communication.dll.vir"
sh=0414F0E46A6BCA94A95A634401F16EA943A4E05E ft=1 fh=f7a37ef503e2d6af vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\filetypehelper.exe.vir"
sh=CCC2EC71F56E030A77369EBEDEEDAB41A0741694 ft=1 fh=9b4b2ad80b5519e2 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\scandll.dll.vir"
sh=5A31DB6D3F33926C43A9D69A6F8E39516DC49EF5 ft=1 fh=ae5d22e27bb4f6bf vn="Variante von Win32/BrowseFox.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\DynamoCombobho.dll.vir"
sh=BC69AACBDFC22BA7E81327BB73AC98F270CB25D0 ft=0 fh=0000000000000000 vn="Win32/BrowseFox.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\kpgkaimemdlpgfgohekgcjddinhmphfb.crx.vir"
sh=DAFA3D5E56F324891FF80E0C4FA5420C93FDE06C ft=1 fh=4229cda79b7d9d40 vn="Variante von MSIL/BrowseFox.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe.vir"
sh=CF3C8D97FA776DD3550D42FD482406E053A680F7 ft=1 fh=6586e1c2ced6cac6 vn="Variante von Win32/BrowseFox.N evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb.dll.vir"
sh=AFC0858DB66B8BB1AE80A4F7CFB6A8E196140D44 ft=1 fh=e12ac4571d7e5293 vn="Variante von Win64/BrowseFox.CI evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb64.dll.vir"
sh=C7CF934A16D70C1D2E186DA5D9C933DE8D91241F ft=1 fh=47171caf85ed870e vn="Variante von Win32/BrowseFox.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b0.dll.vir"
sh=FBCB49FCBFDE90789D3BD49B3190929B2D4A26E2 ft=1 fh=85105a51ac24be4c vn="Variante von Win64/BrowseFox.CH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b064.dll.vir"
sh=DCE9BB5584C721DDCF4C99E8850B558FD4AA628F ft=1 fh=52f2456adf013abf vn="Variante von Win64/BrowseFox.CJ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expextdll.dll.vir"
sh=F868B2C175A3D365C43624982E8286FA11B9CA14 ft=1 fh=0eb934d768c75478 vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BroStats.dll.vir"
sh=072D874AE1528F2F5F67C91E9A7FDD18B4E5824B ft=1 fh=a23537f2da71e327 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BrowserAdapter.dll.vir"
sh=845F1F7DFDC3716511C0D2A6C127CBAE382C3333 ft=1 fh=09d69173a21ef64f vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.ExpExt.dll.vir"
sh=565F78E6685243532D492A430931546D0A54A6FF ft=1 fh=ae0b23db060ede77 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.FFUpdate.dll.vir"
sh=D6953679D2056F9121FDAE25427227BBC242F73C ft=1 fh=7b1357ed388bbf18 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.GCUpdate.dll.vir"
sh=AEEFE7CE09F6329EDF8B6576D42DA45FEC0C5AF1 ft=1 fh=2b94a5d4c855e1c7 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.IEUpdate.dll.vir"
sh=2FC4107A34C1DBE6CD1A6801661E33F86F825C83 ft=1 fh=46bb283e7caec55f vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.PurBrowseG.dll.vir"
sh=9C712CCB24E1FB86A85A46872A5896543A263D1C ft=1 fh=b84793b35d529d47 vn="Variante von MSIL/NewPlayer.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\FastPlayer.exe.vir"
sh=7E3006A3E9518195A56DF0A3BA0F1F3365E8EC28 ft=1 fh=ef7079c6c55b225a vn="Variante von MSIL/NewPlayer.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\fastUpdater.exe.vir"
sh=5A41BDE23C59ED77C3AA628D249BCBAC212F8874 ft=1 fh=85ecec98e9859fb8 vn="MSIL/NewPlayer.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\WebBrowser.exe.vir"
sh=5ACA9CEA9D6A0FBF1D679552388DDE0205B8AA7C ft=1 fh=64759f2098d1d6a6 vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\gamesdesktop_widget.exe.vir"
sh=4CBC3F900232E1CFD1BA7E9C1724912FE6CFADD0 ft=1 fh=8bc90044e286ad0e vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\gmsd_de_131.exe.vir"
sh=F86AC47AF64D439AA46CBB6AF9116D27011A775E ft=1 fh=6f77d625878dae13 vn="Win32/Adware.EoRezo Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\predm.exe.vir"
sh=B9AAB290C82AD1585C0CBEE7F206F71F248DD9BD ft=1 fh=d8998ea63e9f3b36 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-10.exe.vir"
sh=7F83DD6443AAAF85D772A9FEDE1D4E988AA0F7F0 ft=1 fh=fe8fcabbcaacdf41 vn="Variante von Win32/Toolbar.CrossRider.BV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-11.exe.vir"
sh=1D35327230AC7E5B96220FBA31D69C9F49F3D078 ft=1 fh=f0886b782f698aa4 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-2.exe.vir"
sh=B11FF4B9B5B146FC445C59FA4169E0736FA16648 ft=1 fh=552faa579ce3b981 vn="Variante von Win32/Toolbar.CrossRider.BV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-4.exe.vir"
sh=296CD5F101C2B4F1B1D6CBB30A85A6C80FC41B28 ft=1 fh=d7b05babaa58c9a3 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-5.exe.vir"
sh=FD27D574F7D3288447C7A916D187A1B7D2B5D2AA ft=1 fh=f9857d4c1a3d975b vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-6.exe.vir"
sh=45A0F332330A26D522155B884A4DFCC6E8315313 ft=1 fh=1d5949a9f8955486 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-64.exe.vir"
sh=2ABABEE75FD81E79B4950AFC859C420B4A00B1DD ft=1 fh=73bb817d53f1cb19 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-7.exe.vir"
sh=A0D2EA8A230949C9162BB143591A982EDDE7BF1E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d.crx.vir"
sh=ECCEA4A6092C8ABBAC550EC5FF5343F6EA01F981 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d.xpi.vir"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\b9e007cd-5336-4e7b-8a24-3cbe7d1c52d9.dll.vir"
sh=D736C28E0F60F5E6F2E1012A3000E399117BA623 ft=1 fh=532645e6f0fdba3c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\c7ecf604-b1fc-4f95-85be-62bfc0577943.dll.vir"
sh=C38A1DC097EC82DA39CFF23C2C0DE840F3AE21D2 ft=1 fh=3eba6a964580a025 vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bg.exe.vir"
sh=AEF8CC900BF7F7084886B7AA00E243E94A827A12 ft=1 fh=a6d225d94f74e01a vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bho.dll.vir"
sh=F43520AD7F1AA8018C5ACDD05C38E2D7DE958169 ft=1 fh=62bede15c6b2a0f5 vn="Variante von Win64/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bho64.dll.vir"
sh=2ABABEE75FD81E79B4950AFC859C420B4A00B1DD ft=1 fh=73bb817d53f1cb19 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-codedownloader.exe.vir"
sh=924069355F65A0A0EE316139D08D4FE04654EDBE ft=1 fh=45a7871de67c6e1c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\Uninstall.exe.vir"
sh=0B6B24DBFEF11B73D87470186C3829A50588003A ft=1 fh=418c4879d13c66d7 vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\utils.exe.vir"
sh=AAA623029121715DD514658EB72C344C182CE5D4 ft=1 fh=2063f527e15bc225 vn="Variante von MSIL/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\BackupStackUI.dll.vir"
sh=BAFC87AA0D99C347EA00A77BB09CE78915DF75E5 ft=1 fh=edcb43f436e617cd vn="MSIL/MyPCBackup.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\MyPC Backup.exe.vir"
sh=CB0EE05C61C3F9446D600359C65FA0FD314E6548 ft=1 fh=5f0fc3daa463974a vn="Variante von Win32/AdWare.SpeedingUpMyPC.S Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir"
sh=7925144AF2DD189B4EE5DA34E38A04409DD418B7 ft=1 fh=84a76f28a91f334b vn="Win32/Systweak.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\CleanSchedule.exe.vir"
sh=FC28EB51B58694E0BEB7997AC4BE2CB2A7E80CC1 ft=1 fh=dcb4450fa2ef403d vn="Variante von Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RCPUninstall.exe.vir"
sh=8FCB7D118C793F41B90C576CDDEC7AA3A2941493 ft=1 fh=aed6e0cb456c1b6d vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RegCleanPro.exe.vir"
sh=E69EF66B5CC919B8E29A9761CD44809D05556ED8 ft=1 fh=f46c5436c547759e vn="Win32/Systweak.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\systweakasp.exe.vir"
sh=8743F255E80C6A0A95A94CC668553686FF170120 ft=1 fh=0e8260637ee8e1d9 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\RN32.dll.vir"
sh=A704B6A7928A66851D5D0C251F975B52F6755053 ft=1 fh=3a141fdd6276f642 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPtool64.exe.vir"
sh=3010A616F191A1AB67BAA394F95094E43E1B0F05 ft=1 fh=1d4eab4a3a54531e vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll.vir"
sh=275F649C7C4613C61B59BD33393AA245AD3D3816 ft=1 fh=ecf7e3ee1d6b314e vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll.vir"
sh=FC3A455F0FB2672BC95CB6935C777FC86FD76978 ft=1 fh=0b3b4934b4c0b40c vn="Variante von Win32/Verti.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\StormWatch\StormWatchApp.exe.vir"
sh=CC754C436679DF3C9CAA3B4FA21E4E8C7D5F56B3 ft=1 fh=19c0721a1cb98727 vn="Variante von Win32/Adware.AddLyrics.DN Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver0BlockAndSurf\temp\Uninstall.exe.vir"
sh=497D88F38E21229D95650E02708207190CB6849E ft=1 fh=64a74ba51bf40770 vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchCH.dll.vir"
sh=5468230F587DE9F869DB9E22083131DCFD9451F2 ft=1 fh=07a842c13464288e vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchFF.dll.vir"
sh=5D628376391A827A818B0A079B64EE457AE9B82A ft=1 fh=c71c0011e2e7a7a5 vn="Variante von Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowserAction.dll.vir"
sh=1DFF39C0F7B7617C8292510F1833B282CD0A1F21 ft=1 fh=18ddbd645dd0ae9c vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\IeWatchDog.dll.vir"
sh=606D4414333C04E362F60B505926C78BB0B6C694 ft=1 fh=2f7c44d7fdd8d932 vn="Variante von Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\SupTab.dll.vir"
sh=AF36570D737043FEBEC5FA3DDB416A4CF5FDFBE9 ft=1 fh=c71c0011100f33aa vn="Variante von Win32/ELEX.BH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir"
sh=B06EE6E97D30DB38C3E8FEA66B396DB00EC79616 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\Application\36.0.1985.136\default_apps\crossbrowser.crx.vir"
sh=05F6C33F5A45CD34A9CAF61E295E886922448732 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\Application\36.0.1985.136\Installer\chrome.7z.vir"
sh=DC3B46CDAB1D97E3F9BFC4C4B570D22BDEE96A3B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Cache\f_000002.vir"
sh=03517F89D3F20D2D4E2B1A956F8248C9DA9FFC18 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Extensions\ebpeonjdeofpjegbdiibbdjlgfohngee\1.26.14_0\extensionData\plugins\91.js.vir"
sh=03517F89D3F20D2D4E2B1A956F8248C9DA9FFC18 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Extensions\ebpeonjdeofpjegbdiibbdjlgfohngee\1.26.14_1\extensionData\plugins\91.js.vir"
sh=CBE86D7679B057BF534B45289D1ABCD8E1F77EAB ft=1 fh=cff6049dec1b8116 vn="Variante von Win32/Adware.AdService.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\ConvertAd\CASrv.exe.vir"
sh=5930DD4374564C947E45AEAFB5C634C27F1889F0 ft=1 fh=915e502c9714d06b vn="Variante von Win32/Adware.ConvertAd.O Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\ConvertAd\ConvertAd.exe.vir"
sh=038E68041CC5D1C49823F6867BD87F44A12C74E7 ft=1 fh=bfa4bdd95b0f360e vn="Variante von Win32/Adware.EoRezo.AJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\gmsd_de_131\upgmsd_de_131.exe.vir"
sh=FB696DD11A897BE783D2203BB44A9AF0BB08E083 ft=1 fh=3e4b1ae17324d848 vn="Variante von Win32/Adware.ConvertAd.L Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\wincheck\wincheck.exe.vir"
sh=DB4D5C550C59D20F5972E6CA38E3F4209E39C374 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\Extensions\b6e4f54065ff48dd97db30ca@c9b45f807bf54a45a4669e51c.com\extensionData\plugins\91.js.vir"
sh=DB4D5C550C59D20F5972E6CA38E3F4209E39C374 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\hniiadklfgdhjcmmkpggffjngihaaoip\1.26.38_0\extensionData\plugins\91.js.vir"
sh=5F0B7CF4A550BAAB1349464184E6E38694FB5B79 ft=1 fh=eccc746ec41c7f77 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\VOPackage\VOPackage.exe.vir"
sh=C22D8A49BB848CE60C334A2732AE7465B85DC9C6 ft=1 fh=07fa81e8f77d963b vn="Variante von Win32/Adware.AdService.H Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\VOPackage\VOsrv.exe.vir"
sh=08A5CE348D319335A92076C65C1091277AFED1B9 ft=1 fh=158b9db86261fb7d vn="Variante von Win64/Systweak.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\roboot64.exe.vir"
sh=AAA29097B1E5A7098E19A38F1200E636EE1C3A1E ft=1 fh=6b75069f13c3f94c vn="Win64/AdvancedSystemProtector.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\sasnative64.exe.vir"
sh=DEC806DC9DB9CE68018F8014BB83AC235E770769 ft=1 fh=358281a880d92594 vn="Variante von Win64/BrowseFox.CG evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}Gw64.sys.vir"
sh=D736C28E0F60F5E6F2E1012A3000E399117BA623 ft=1 fh=532645e6f0fdba3c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f\14a4de29-fef9-4220-8fbd-45468eae533e.dll"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f\f6b9c335-c41f-462e-b202-dcf7218c3464.dll"
sh=650581AE9AB01682F3BF4614E07B23F159206571 ft=1 fh=77e15956281daff0 vn="Variante von Win32/SpeedingUpMyPC Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Optimizer Pro 3.33\OptimizerPro.exe"
sh=5461848B30BFCC2C51A294C70AE94A93EE9CAF0B ft=1 fh=0205e271a8b6efa7 vn="Variante von Win32/Adware.SpeedingUpMyPC.C Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Optimizer Pro 3.33\OptProSmartScan.exe"
sh=68F5BABE6637AEF769CE56430749E2AE836BB50B ft=1 fh=41744573fd8379d7 vn="Variante von MSIL/Adware.PullUpdate.J.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\Setup.exe.xBAD"
sh=45B16506B6AC644EC10E194F7FC2ADBA996B68E4 ft=1 fh=3bd3e9e515cbb0bc vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe"
sh=1BFE06F3388C77420BACCBBDF27BBCE2D560717D ft=1 fh=556665db5d7ff889 vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\iBfDaCGfSb.exe"
sh=1FD64E6F84C961E538106D37A391987833E2FEA3 ft=1 fh=277dac96893679ce vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\mewHuD.exe"
sh=B0568F9B5C2606FD7D66FCC12CE95CD4639AC3A8 ft=1 fh=449a0154f80f9379 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\SWOWBzI.dll"
sh=24B8EB148FB663F58001B4689144FFD941342C8B ft=1 fh=5b635cbffa37f361 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\WdmHULmJ.dll"
sh=4495024B25F21088902FBD82FC915E621187FE85 ft=1 fh=cc5f08593bdd79bc vn="MSIL/MyPCBackup.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\BackupSetup.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i33FC.tmp.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i3874.tmp.exe.xBAD"
sh=DD9768DF9FC2EB0F7B0B16167A1FC7FCCCCFAA8F ft=1 fh=9a3c5ad0ee04cfbe vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i9602.tmp.exe.xBAD"
sh=78359B36EDF68FB1BF6E1E18D7E1FFF69FABED5B ft=1 fh=999ab1e308902740 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i9924.tmp.exe.xBAD"
sh=F0E208C30074CBB8E174DDE10CE68BBFD502B055 ft=1 fh=4ad95e97f7c0929b vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iBA4.tmp.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iE3FA.tmp.exe.xBAD"
sh=5F0B7CF4A550BAAB1349464184E6E38694FB5B79 ft=1 fh=eccc746ec41c7f77 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iE714.tmp.exe.xBAD"
sh=471DC01F5CFFCE6035652296AED25B815B260346 ft=1 fh=d304f79d7beb47b1 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\nst712.exe.xBAD"
sh=471DC01F5CFFCE6035652296AED25B815B260346 ft=1 fh=d304f79d7beb47b1 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\nszF70B.exe.xBAD"
sh=86796560DB0AE55C365CEC423A5B78809AADC139 ft=1 fh=8c7a4ac81187f375 vn="Variante von Win32/OptimizerEliteMax.C evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\optprosetup.exe.xBAD"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=6c77c72b4d0f4b46a142f9fd1dd014cc
# engine=22251
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-02-01 04:30:36
# local_time=2015-02-01 05:30:36 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 71 94 366253 1056814 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 63683 174438086 0 0
# scanned=193796
# found=102
# cleaned=0
# scan_time=6017
sh=39FEE51538F713D63BD3D2351F9FF4F7F4C75E9D ft=1 fh=f2eefd68ba8dc0d6 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\AspManager.exe.vir"
sh=0D8B18706A7D0B4188799F7C1F992FD2CA6FECAE ft=1 fh=beb1278ff8542fc3 vn="Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\ASPUninstall.exe.vir"
sh=C6D88BC2353AA0DD082914D604E1CB9E8DCC0D57 ft=1 fh=c0cb3b5fdf7d9689 vn="Variante von Win32/Systweak.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\Communication.dll.vir"
sh=0414F0E46A6BCA94A95A634401F16EA943A4E05E ft=1 fh=f7a37ef503e2d6af vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\filetypehelper.exe.vir"
sh=CCC2EC71F56E030A77369EBEDEEDAB41A0741694 ft=1 fh=9b4b2ad80b5519e2 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\scandll.dll.vir"
sh=5A31DB6D3F33926C43A9D69A6F8E39516DC49EF5 ft=1 fh=ae5d22e27bb4f6bf vn="Variante von Win32/BrowseFox.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\DynamoCombobho.dll.vir"
sh=BC69AACBDFC22BA7E81327BB73AC98F270CB25D0 ft=0 fh=0000000000000000 vn="Win32/BrowseFox.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\kpgkaimemdlpgfgohekgcjddinhmphfb.crx.vir"
sh=DAFA3D5E56F324891FF80E0C4FA5420C93FDE06C ft=1 fh=4229cda79b7d9d40 vn="Variante von MSIL/BrowseFox.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe.vir"
sh=CF3C8D97FA776DD3550D42FD482406E053A680F7 ft=1 fh=6586e1c2ced6cac6 vn="Variante von Win32/BrowseFox.N evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb.dll.vir"
sh=AFC0858DB66B8BB1AE80A4F7CFB6A8E196140D44 ft=1 fh=e12ac4571d7e5293 vn="Variante von Win64/BrowseFox.CI evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb64.dll.vir"
sh=C7CF934A16D70C1D2E186DA5D9C933DE8D91241F ft=1 fh=47171caf85ed870e vn="Variante von Win32/BrowseFox.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b0.dll.vir"
sh=FBCB49FCBFDE90789D3BD49B3190929B2D4A26E2 ft=1 fh=85105a51ac24be4c vn="Variante von Win64/BrowseFox.CH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b064.dll.vir"
sh=DCE9BB5584C721DDCF4C99E8850B558FD4AA628F ft=1 fh=52f2456adf013abf vn="Variante von Win64/BrowseFox.CJ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expextdll.dll.vir"
sh=F868B2C175A3D365C43624982E8286FA11B9CA14 ft=1 fh=0eb934d768c75478 vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BroStats.dll.vir"
sh=072D874AE1528F2F5F67C91E9A7FDD18B4E5824B ft=1 fh=a23537f2da71e327 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BrowserAdapter.dll.vir"
sh=845F1F7DFDC3716511C0D2A6C127CBAE382C3333 ft=1 fh=09d69173a21ef64f vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.ExpExt.dll.vir"
sh=565F78E6685243532D492A430931546D0A54A6FF ft=1 fh=ae0b23db060ede77 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.FFUpdate.dll.vir"
sh=D6953679D2056F9121FDAE25427227BBC242F73C ft=1 fh=7b1357ed388bbf18 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.GCUpdate.dll.vir"
sh=AEEFE7CE09F6329EDF8B6576D42DA45FEC0C5AF1 ft=1 fh=2b94a5d4c855e1c7 vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.IEUpdate.dll.vir"
sh=2FC4107A34C1DBE6CD1A6801661E33F86F825C83 ft=1 fh=46bb283e7caec55f vn="Variante von MSIL/BrowseFox.L evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.PurBrowseG.dll.vir"
sh=9C712CCB24E1FB86A85A46872A5896543A263D1C ft=1 fh=b84793b35d529d47 vn="Variante von MSIL/NewPlayer.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\FastPlayer.exe.vir"
sh=7E3006A3E9518195A56DF0A3BA0F1F3365E8EC28 ft=1 fh=ef7079c6c55b225a vn="Variante von MSIL/NewPlayer.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\fastUpdater.exe.vir"
sh=5A41BDE23C59ED77C3AA628D249BCBAC212F8874 ft=1 fh=85ecec98e9859fb8 vn="MSIL/NewPlayer.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FastPlayer\WebBrowser.exe.vir"
sh=5ACA9CEA9D6A0FBF1D679552388DDE0205B8AA7C ft=1 fh=64759f2098d1d6a6 vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\gamesdesktop_widget.exe.vir"
sh=4CBC3F900232E1CFD1BA7E9C1724912FE6CFADD0 ft=1 fh=8bc90044e286ad0e vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\gmsd_de_131.exe.vir"
sh=F86AC47AF64D439AA46CBB6AF9116D27011A775E ft=1 fh=6f77d625878dae13 vn="Win32/Adware.EoRezo Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_131\predm.exe.vir"
sh=B9AAB290C82AD1585C0CBEE7F206F71F248DD9BD ft=1 fh=d8998ea63e9f3b36 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-10.exe.vir"
sh=7F83DD6443AAAF85D772A9FEDE1D4E988AA0F7F0 ft=1 fh=fe8fcabbcaacdf41 vn="Variante von Win32/Toolbar.CrossRider.BV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-11.exe.vir"
sh=1D35327230AC7E5B96220FBA31D69C9F49F3D078 ft=1 fh=f0886b782f698aa4 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-2.exe.vir"
sh=B11FF4B9B5B146FC445C59FA4169E0736FA16648 ft=1 fh=552faa579ce3b981 vn="Variante von Win32/Toolbar.CrossRider.BV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-4.exe.vir"
sh=296CD5F101C2B4F1B1D6CBB30A85A6C80FC41B28 ft=1 fh=d7b05babaa58c9a3 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-5.exe.vir"
sh=FD27D574F7D3288447C7A916D187A1B7D2B5D2AA ft=1 fh=f9857d4c1a3d975b vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-6.exe.vir"
sh=45A0F332330A26D522155B884A4DFCC6E8315313 ft=1 fh=1d5949a9f8955486 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-64.exe.vir"
sh=2ABABEE75FD81E79B4950AFC859C420B4A00B1DD ft=1 fh=73bb817d53f1cb19 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d-7.exe.vir"
sh=A0D2EA8A230949C9162BB143591A982EDDE7BF1E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d.crx.vir"
sh=ECCEA4A6092C8ABBAC550EC5FF5343F6EA01F981 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\3e55c78d-a1ea-4123-8c62-bd4af939b50d.xpi.vir"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\b9e007cd-5336-4e7b-8a24-3cbe7d1c52d9.dll.vir"
sh=D736C28E0F60F5E6F2E1012A3000E399117BA623 ft=1 fh=532645e6f0fdba3c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\c7ecf604-b1fc-4f95-85be-62bfc0577943.dll.vir"
sh=C38A1DC097EC82DA39CFF23C2C0DE840F3AE21D2 ft=1 fh=3eba6a964580a025 vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bg.exe.vir"
sh=AEF8CC900BF7F7084886B7AA00E243E94A827A12 ft=1 fh=a6d225d94f74e01a vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bho.dll.vir"
sh=F43520AD7F1AA8018C5ACDD05C38E2D7DE958169 ft=1 fh=62bede15c6b2a0f5 vn="Variante von Win64/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-bho64.dll.vir"
sh=2ABABEE75FD81E79B4950AFC859C420B4A00B1DD ft=1 fh=73bb817d53f1cb19 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\MedPvid2.3-codedownloader.exe.vir"
sh=924069355F65A0A0EE316139D08D4FE04654EDBE ft=1 fh=45a7871de67c6e1c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\Uninstall.exe.vir"
sh=0B6B24DBFEF11B73D87470186C3829A50588003A ft=1 fh=418c4879d13c66d7 vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MedPvid2.3\utils.exe.vir"
sh=AAA623029121715DD514658EB72C344C182CE5D4 ft=1 fh=2063f527e15bc225 vn="Variante von MSIL/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\BackupStackUI.dll.vir"
sh=BAFC87AA0D99C347EA00A77BB09CE78915DF75E5 ft=1 fh=edcb43f436e617cd vn="MSIL/MyPCBackup.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\MyPC Backup.exe.vir"
sh=CB0EE05C61C3F9446D600359C65FA0FD314E6548 ft=1 fh=5f0fc3daa463974a vn="Variante von Win32/AdWare.SpeedingUpMyPC.S Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir"
sh=7925144AF2DD189B4EE5DA34E38A04409DD418B7 ft=1 fh=84a76f28a91f334b vn="Win32/Systweak.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\CleanSchedule.exe.vir"
sh=FC28EB51B58694E0BEB7997AC4BE2CB2A7E80CC1 ft=1 fh=dcb4450fa2ef403d vn="Variante von Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RCPUninstall.exe.vir"
sh=8FCB7D118C793F41B90C576CDDEC7AA3A2941493 ft=1 fh=aed6e0cb456c1b6d vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RegCleanPro.exe.vir"
sh=E69EF66B5CC919B8E29A9761CD44809D05556ED8 ft=1 fh=f46c5436c547759e vn="Win32/Systweak.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\systweakasp.exe.vir"
sh=8743F255E80C6A0A95A94CC668553686FF170120 ft=1 fh=0e8260637ee8e1d9 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\RN32.dll.vir"
sh=A704B6A7928A66851D5D0C251F975B52F6755053 ft=1 fh=3a141fdd6276f642 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPtool64.exe.vir"
sh=3010A616F191A1AB67BAA394F95094E43E1B0F05 ft=1 fh=1d4eab4a3a54531e vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll.vir"
sh=275F649C7C4613C61B59BD33393AA245AD3D3816 ft=1 fh=ecf7e3ee1d6b314e vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll.vir"
sh=FC3A455F0FB2672BC95CB6935C777FC86FD76978 ft=1 fh=0b3b4934b4c0b40c vn="Variante von Win32/Verti.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\StormWatch\StormWatchApp.exe.vir"
sh=CC754C436679DF3C9CAA3B4FA21E4E8C7D5F56B3 ft=1 fh=19c0721a1cb98727 vn="Variante von Win32/Adware.AddLyrics.DN Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver0BlockAndSurf\temp\Uninstall.exe.vir"
sh=497D88F38E21229D95650E02708207190CB6849E ft=1 fh=64a74ba51bf40770 vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchCH.dll.vir"
sh=5468230F587DE9F869DB9E22083131DCFD9451F2 ft=1 fh=07a842c13464288e vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchFF.dll.vir"
sh=5D628376391A827A818B0A079B64EE457AE9B82A ft=1 fh=c71c0011e2e7a7a5 vn="Variante von Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowserAction.dll.vir"
sh=1DFF39C0F7B7617C8292510F1833B282CD0A1F21 ft=1 fh=18ddbd645dd0ae9c vn="Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\IeWatchDog.dll.vir"
sh=606D4414333C04E362F60B505926C78BB0B6C694 ft=1 fh=2f7c44d7fdd8d932 vn="Variante von Win32/ELEX.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\SupTab.dll.vir"
sh=AF36570D737043FEBEC5FA3DDB416A4CF5FDFBE9 ft=1 fh=c71c0011100f33aa vn="Variante von Win32/ELEX.BH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir"
sh=B06EE6E97D30DB38C3E8FEA66B396DB00EC79616 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\Application\36.0.1985.136\default_apps\crossbrowser.crx.vir"
sh=05F6C33F5A45CD34A9CAF61E295E886922448732 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\Application\36.0.1985.136\Installer\chrome.7z.vir"
sh=DC3B46CDAB1D97E3F9BFC4C4B570D22BDEE96A3B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Cache\f_000002.vir"
sh=03517F89D3F20D2D4E2B1A956F8248C9DA9FFC18 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Extensions\ebpeonjdeofpjegbdiibbdjlgfohngee\1.26.14_0\extensionData\plugins\91.js.vir"
sh=03517F89D3F20D2D4E2B1A956F8248C9DA9FFC18 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\BoBrowser\User Data\Default\Extensions\ebpeonjdeofpjegbdiibbdjlgfohngee\1.26.14_1\extensionData\plugins\91.js.vir"
sh=CBE86D7679B057BF534B45289D1ABCD8E1F77EAB ft=1 fh=cff6049dec1b8116 vn="Variante von Win32/Adware.AdService.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\ConvertAd\CASrv.exe.vir"
sh=5930DD4374564C947E45AEAFB5C634C27F1889F0 ft=1 fh=915e502c9714d06b vn="Variante von Win32/Adware.ConvertAd.O Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\ConvertAd\ConvertAd.exe.vir"
sh=038E68041CC5D1C49823F6867BD87F44A12C74E7 ft=1 fh=bfa4bdd95b0f360e vn="Variante von Win32/Adware.EoRezo.AJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\gmsd_de_131\upgmsd_de_131.exe.vir"
sh=FB696DD11A897BE783D2203BB44A9AF0BB08E083 ft=1 fh=3e4b1ae17324d848 vn="Variante von Win32/Adware.ConvertAd.L Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Local\wincheck\wincheck.exe.vir"
sh=DB4D5C550C59D20F5972E6CA38E3F4209E39C374 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\vwj5huu5.default\Extensions\b6e4f54065ff48dd97db30ca@c9b45f807bf54a45a4669e51c.com\extensionData\plugins\91.js.vir"
sh=DB4D5C550C59D20F5972E6CA38E3F4209E39C374 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\hniiadklfgdhjcmmkpggffjngihaaoip\1.26.38_0\extensionData\plugins\91.js.vir"
sh=5F0B7CF4A550BAAB1349464184E6E38694FB5B79 ft=1 fh=eccc746ec41c7f77 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\VOPackage\VOPackage.exe.vir"
sh=C22D8A49BB848CE60C334A2732AE7465B85DC9C6 ft=1 fh=07fa81e8f77d963b vn="Variante von Win32/Adware.AdService.H Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\VOPackage\VOsrv.exe.vir"
sh=08A5CE348D319335A92076C65C1091277AFED1B9 ft=1 fh=158b9db86261fb7d vn="Variante von Win64/Systweak.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\roboot64.exe.vir"
sh=AAA29097B1E5A7098E19A38F1200E636EE1C3A1E ft=1 fh=6b75069f13c3f94c vn="Win64/AdvancedSystemProtector.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\sasnative64.exe.vir"
sh=DEC806DC9DB9CE68018F8014BB83AC235E770769 ft=1 fh=358281a880d92594 vn="Variante von Win64/BrowseFox.CG evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}Gw64.sys.vir"
sh=D736C28E0F60F5E6F2E1012A3000E399117BA623 ft=1 fh=532645e6f0fdba3c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f\14a4de29-fef9-4220-8fbd-45468eae533e.dll"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f\f6b9c335-c41f-462e-b202-dcf7218c3464.dll"
sh=650581AE9AB01682F3BF4614E07B23F159206571 ft=1 fh=77e15956281daff0 vn="Variante von Win32/SpeedingUpMyPC Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Optimizer Pro 3.33\OptimizerPro.exe"
sh=5461848B30BFCC2C51A294C70AE94A93EE9CAF0B ft=1 fh=0205e271a8b6efa7 vn="Variante von Win32/Adware.SpeedingUpMyPC.C Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Optimizer Pro 3.33\OptProSmartScan.exe"
sh=68F5BABE6637AEF769CE56430749E2AE836BB50B ft=1 fh=41744573fd8379d7 vn="Variante von MSIL/Adware.PullUpdate.J.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\Setup.exe.xBAD"
sh=45B16506B6AC644EC10E194F7FC2ADBA996B68E4 ft=1 fh=3bd3e9e515cbb0bc vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\MElGfYhtuP.exe"
sh=1BFE06F3388C77420BACCBBDF27BBCE2D560717D ft=1 fh=556665db5d7ff889 vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\iBfDaCGfSb.exe"
sh=1FD64E6F84C961E538106D37A391987833E2FEA3 ft=1 fh=277dac96893679ce vn="Variante von MSIL/Adware.PullUpdate.G.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\mewHuD.exe"
sh=B0568F9B5C2606FD7D66FCC12CE95CD4639AC3A8 ft=1 fh=449a0154f80f9379 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\SWOWBzI.dll"
sh=24B8EB148FB663F58001B4689144FFD941342C8B ft=1 fh=5b635cbffa37f361 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\FRST\Quarantine\C\ProgramData\xfIwQZvgdh\dat\WdmHULmJ.dll"
sh=4495024B25F21088902FBD82FC915E621187FE85 ft=1 fh=cc5f08593bdd79bc vn="MSIL/MyPCBackup.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\BackupSetup.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i33FC.tmp.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i3874.tmp.exe.xBAD"
sh=DD9768DF9FC2EB0F7B0B16167A1FC7FCCCCFAA8F ft=1 fh=9a3c5ad0ee04cfbe vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i9602.tmp.exe.xBAD"
sh=78359B36EDF68FB1BF6E1E18D7E1FFF69FABED5B ft=1 fh=999ab1e308902740 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\i9924.tmp.exe.xBAD"
sh=F0E208C30074CBB8E174DDE10CE68BBFD502B055 ft=1 fh=4ad95e97f7c0929b vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iBA4.tmp.exe.xBAD"
sh=A4B1634B016AEEA9DA6700807C77949FE5EA0463 ft=1 fh=c29faebcf21903c3 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iE3FA.tmp.exe.xBAD"
sh=5F0B7CF4A550BAAB1349464184E6E38694FB5B79 ft=1 fh=eccc746ec41c7f77 vn="Win32/VOPackage.BM evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\iE714.tmp.exe.xBAD"
sh=471DC01F5CFFCE6035652296AED25B815B260346 ft=1 fh=d304f79d7beb47b1 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\nst712.exe.xBAD"
sh=471DC01F5CFFCE6035652296AED25B815B260346 ft=1 fh=d304f79d7beb47b1 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\nszF70B.exe.xBAD"
sh=86796560DB0AE55C365CEC423A5B78809AADC139 ft=1 fh=8c7a4ac81187f375 vn="Variante von Win32/OptimizerEliteMax.C evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\User\AppData\Local\Temp\optprosetup.exe.xBAD"
sh=1DB9474C99160E7A9606A71CE2BC0A96670EA9A9 ft=1 fh=104e4e5c8e1477a5 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\AmIcoSingLun\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f.dll"
sh=9CFFB00618B8B4249E40CEA0ADC4557E9D40A806 ft=1 fh=daeb3c17d4759ec4 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="D:\$RECYCLE.BIN\S-1-5-21-2608712115-2613374988-3172207222-1004\$R5R2M1B.exe"


cosinus 01.02.2015 21:41

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Program Files (x86)\AmIcoSingLun\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f.dll
D:\$RECYCLE.BIN\S-1-5-21-2608712115-2613374988-3172207222-1004\$R5R2M1B.exe
EmptyTemp:
Hosts:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Nero555 01.02.2015 22:13

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015
Ran by User at 2015-02-01 21:43:55 Run:3
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Program Files (x86)\AmIcoSingLun\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f.dll
D:\$RECYCLE.BIN\S-1-5-21-2608712115-2613374988-3172207222-1004\$R5R2M1B.exe
EmptyTemp:
Hosts:
       
*****************

C:\Program Files (x86)\AmIcoSingLun\3470da51-0d6c-4c4f-ba32-e5a51dbf2d6f.dll => Moved successfully.
D:\$RECYCLE.BIN\S-1-5-21-2608712115-2613374988-3172207222-1004\$R5R2M1B.exe => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 419.8 MB temporary data.


The system needed a reboot.

==== End of Fixlog 21:44:04 ====


cosinus 01.02.2015 22:15

Sieht soweit ok aus :daumenhoc

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) empfehle ich die Erweiterung Ghostery, diese verhindert weitgehend Usertracking bzw. das Anzeigen von Werbebannern.

Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Nero555 01.02.2015 22:32

Erstmal vielen vielen Dank für ihre Hilfe! Ja, mir ist ein weiters Problem aufgefallen. Soll ich ein neues Thema erstellen oder hier weiterschreiben?

cosinus 02.02.2015 09:56

Wenn das nichts mehr mit der Bereinigung zu tun hat bitte ein neues Thema im Windows- oder Hardwarebereich eröffnen

Dann wären wir durch! :daumenhoc


Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board

Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden. Es empfiehlt sich Malwarebytes Anti-Malware zu behalten und damit wöchentlich nach Malware zu scannen.

Helfen kann dir dabei delfix:


Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.






Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

Nero555 02.02.2015 15:32

Danke nochmal für ihre Hilfe! Ich hätte da noch eine Frage. Ich wollte ein neues Thema erstellen aber die Schaltfläche dafür ist nirgendswo zu finden.
Wo kann ich ein neues Thema erstellen?


Alle Zeitangaben in WEZ +1. Es ist jetzt 20:03 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131