petramueller | 11.09.2014 05:58 | Hallo,
sorry für die späten Posts. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 10.09.2014 18:47:23, SYSTEM, CONVO-MOBILE-NE, Protection, Malware Protection, Starting,
Protection, 10.09.2014 18:47:26, SYSTEM, CONVO-MOBILE-NE, Protection, Malware Protection, Started,
Protection, 10.09.2014 18:47:26, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Starting,
Update, 10.09.2014 18:47:48, SYSTEM, CONVO-MOBILE-NE, Manual, Rootkit Database, 2014.2.20.1, 2014.8.21.1,
Update, 10.09.2014 18:47:58, SYSTEM, CONVO-MOBILE-NE, Manual, Malware Database, 2014.3.4.9, 2014.9.10.7,
Protection, 10.09.2014 18:48:00, SYSTEM, CONVO-MOBILE-NE, Protection, Refresh, Starting,
Protection, 10.09.2014 18:48:21, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Started,
Protection, 10.09.2014 18:48:21, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Stopping,
Protection, 10.09.2014 18:48:21, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Stopped,
Protection, 10.09.2014 18:49:40, SYSTEM, CONVO-MOBILE-NE, Protection, Refresh, Success,
Protection, 10.09.2014 18:49:40, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Starting,
Protection, 10.09.2014 18:49:40, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Started,
Update, 10.09.2014 19:32:44, SYSTEM, CONVO-MOBILE-NE, Scheduler, Rootkit Database, 2014.8.21.1, 2014.9.10.2,
Protection, 10.09.2014 19:32:47, SYSTEM, CONVO-MOBILE-NE, Protection, Refresh, Starting,
Protection, 10.09.2014 19:32:47, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Stopping,
Protection, 10.09.2014 19:32:48, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Stopped,
Protection, 10.09.2014 19:35:56, SYSTEM, CONVO-MOBILE-NE, Protection, Refresh, Success,
Protection, 10.09.2014 19:35:57, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Starting,
Protection, 10.09.2014 19:36:06, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Started,
Update, 10.09.2014 20:45:43, SYSTEM, CONVO-MOBILE-NE, Scheduler, Malware Database, 2014.9.10.7, 2014.9.10.8,
Protection, 10.09.2014 20:45:48, SYSTEM, CONVO-MOBILE-NE, Protection, Refresh, Starting,
Protection, 10.09.2014 20:45:48, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Stopping,
Protection, 10.09.2014 20:45:50, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Stopped,
Protection, 10.09.2014 20:46:07, SYSTEM, CONVO-MOBILE-NE, Protection, Refresh, Success,
Protection, 10.09.2014 20:46:07, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Starting,
Protection, 10.09.2014 20:46:56, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Started,
Protection, 10.09.2014 21:02:39, SYSTEM, CONVO-MOBILE-NE, Protection, Malware Protection, Starting,
Protection, 10.09.2014 21:02:39, SYSTEM, CONVO-MOBILE-NE, Protection, Malware Protection, Started,
Protection, 10.09.2014 21:02:39, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Starting,
Protection, 10.09.2014 21:08:59, SYSTEM, CONVO-MOBILE-NE, Protection, Malicious Website Protection, Started,
(end) Code:
# AdwCleaner v3.309 - Bericht erstellt am 10/09/2014 um 22:11:19
# Aktualisiert 02/09/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : ConVo - CONVO-MOBILE-NE
# Gestartet von : C:\Users\ConVo\Desktop\adwcleaner_3.309.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : DailytoolsUpdateService
Dienst Gelöscht : Search
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Program Files (x86)\DAEMON Tools Toolbar
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\pc speed up
Ordner Gelöscht : C:\Program Files (x86)\Search
[/!\] Nicht Gelöscht ( Junction ) : C:\Program Files\Gemeinsame Dateien
Ordner Gelöscht : C:\Users\ConVo\AppData\Local\genienext
Ordner Gelöscht : C:\Users\ConVo\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\ConVo\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\ConVo\AppData\Roaming\Mozilla\Firefox\Profiles\9ubdfwmg.default\Extensions\DTToolbar@toolbarnet.com
Datei Gelöscht : C:\Windows\SysWOW64\update1.dll
Datei Gelöscht : C:\Windows\System32\update1.dll
Datei Gelöscht : C:\Users\ConVo\daemonprocess.txt
Datei Gelöscht : C:\Users\ConVo\AppData\Roaming\Mozilla\Firefox\Profiles\9ubdfwmg.default\searchplugins\Askcom.xml
Datei Gelöscht : C:\Users\ConVo\AppData\Roaming\Mozilla\Firefox\Profiles\9ubdfwmg.default\user.js
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\ConVo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\ConVo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\ConVo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Wert Gelöscht : HKLM\SOFTWARE\microsoft\windows nt\currentversion\svchost [DailytoolsInstallerService]
Wert Gelöscht : HKLM\SOFTWARE\microsoft\windows nt\currentversion\svchost [DailytoolsUpdateService]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Re_Markit
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\dt soft\daemon tools toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Myfree Codec
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17239
-\\ Mozilla Firefox v
[ Datei : C:\Users\ConVo\AppData\Roaming\Mozilla\Firefox\Profiles\9ubdfwmg.default\prefs.js ]
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.avira.com/?l=dis&o=APN10267&gct=hp&dc=EU&locale=de_NL");
Zeile gelöscht : user_pref("extensions.unitedinternet.search.termsJSON", "[{\"searchterm\":\"Promo codes Las Vegas\",\"visited\":\"2011-12-29T19:52:48.501Z\"},{\"searchterm\":\"delta.com\",\"visited\":\"2012-01-02T11:[...]
-\\ Google Chrome v37.0.2062.103
[ Datei : C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Startup_urls] : hxxp://www.trovi.com/?gd=&ctid=CT3325386&octid=EB_ORIGINAL_CTID&ISID=MF7FD9457-2BEB-4E30-8A0E-25ACC90B5DF3&SearchSource=55&CUI=&UM=5&UP=SP01D69680-845A-48BC-A0B6-548C29F8ED19&SSPV=
Gelöscht [Startup_urls] : hxxp://www.sweet-page.com/?type=hp&ts=1403900922&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F396762667626
Gelöscht [Startup_urls] : hxxp://www.sweet-page.com/?type=hppp&ts=1403944179&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F396762667626
Gelöscht [Startup_urls] : hxxp://www.sweet-page.com/?type=hppp&ts=1406280258&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F396762667626
Gelöscht [Homepage] : hxxp://www.trovi.com/?gd=&ctid=CT3325386&octid=EB_ORIGINAL_CTID&ISID=MF7FD9457-2BEB-4E30-8A0E-25ACC90B5DF3&SearchSource=55&CUI=&UM=5&UP=SP01D69680-845A-48BC-A0B6-548C29F8ED19&SSPV=
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gelöscht [Extension] : pljcgbedjplidkdjahbaalanadmjfgop
[ Datei : C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [8289 octets] - [10/09/2014 22:05:30]
AdwCleaner[S0].txt - [7692 octets] - [10/09/2014 22:11:19]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7752 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by ConVo on 11.09.2014 at 0:41:04,61
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\simplitec"
Successfully deleted: [Folder] "C:\Users\ConVo\AppData\Roaming\simplitec"
Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{0108934A-A795-496F-8BB8-E450F4E7837F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{0153ACEA-98DC-46FA-BB03-5601C488EBA3}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{01C855E2-FA99-4896-986D-31AAC99FFBC9}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{06AF7E6B-EE6E-41A3-87DA-63DF15AB0988}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{07473E54-C607-4F9E-81C3-C70821FE5094}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{0877125E-6649-4022-83E3-9776E986CA6F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{09769AF3-0016-4F5E-A508-67E929D94912}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{0C576BB0-6B5A-48C8-B8B6-20D181326FFA}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{0D12B671-00D3-4840-8C5C-3CC3C189D7E6}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{0D28EE94-CA85-4AB3-81B2-5BAD6CD3EED1}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{0E8B08F3-C605-4557-B75B-C647E6337EBE}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{101735FC-FF97-41B4-906A-C3D5B3CFCEE2}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{109FDD22-6CD0-45A1-B987-F0EE5A0889F7}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{1142873E-252F-42DB-A836-2D40BA2507B2}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{125E1728-738D-407E-85E9-6CB243C91A7F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{14AE2ACF-89D1-4D05-B0BC-5D1BA6FEA978}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{153215C5-DDB3-462C-8D63-F6F7CD022876}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{154B4B13-3842-42CC-81CD-91DBA1061A4F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{15832856-206A-4FC0-89A0-F9D22F1870F3}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{172215BC-7AAD-4CBB-9C1B-63BEF3699EA9}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{1755FD77-C01D-44C8-AC85-37E7D61D89C3}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{178596F3-0A3C-4697-8892-8A89DFC984B2}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{17E09F4D-C283-4586-AD9F-7889AAF24C59}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{19DD5AA9-2F8E-4C52-9D14-7EC7E6511BBE}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{1AC60BB4-07B9-4C6B-B515-D8F3A1B9D675}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{1BC860ED-9C50-4CE0-8CFC-96D476B75919}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{1C28DE5F-6E82-4891-8F25-C84DE4C595AA}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{1C4A9B97-F055-4CF9-A2AF-32FC7DDEBCE8}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{1C909561-29E4-452E-A6DC-1CCAF4E05233}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{1CCFFBB5-1F67-40C2-8BAE-8272848F6568}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{1FA0DADE-03C7-4980-B5D7-4FBE7F982C2F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{211849AA-6CE0-4ABC-B6A3-6E717017B2F3}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{21E3F362-82BA-48C3-9B91-1FC4E37B6080}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{239F62B5-9CD8-44D4-8187-354499776779}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{243B6985-7A1B-4692-985F-E48962B2ED52}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{2702268B-0FCF-4D01-9920-C959DAE5A741}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{27A16EC2-8191-4FDD-A4C6-84429E12FF40}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{2875803E-9D67-44DA-B386-63AFEEA3B75A}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{2965A5BD-6C3B-4132-83C2-2E550D86471F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{2B672B97-91AB-4677-AE35-7B4403DA9D82}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{2CCFCA3E-4E2B-49EC-B6C4-D8BC874C83CF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{2D502410-BC53-4198-A55F-2D85A08C0335}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{2E116EFF-C80B-434A-8DC3-0DFD1E4B7655}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{307476FC-85DB-42C2-986E-054A3A1F62FD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{309D44E0-D77E-4EA5-BF59-1A0CAABF8930}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{32E8CB7D-E9A4-4F1E-924A-6480403AC2AF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{3428236F-2313-4516-AE2A-F110D32197A7}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{34F47AD8-B48E-4BA5-8CD0-A169E95008FB}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{354B134A-70CC-4FDA-A2CB-BB2212FF86C1}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{354D4B8A-BA13-4372-9480-03AF5804244B}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{365DD236-278E-40CA-A34E-88ABA8DC8881}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{36FC9080-9D4D-4D7B-A5CA-C8CAADE189EA}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{37C4E637-C593-4E68-9699-6888435B5F15}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{38F2DD49-6D77-4C26-9BFE-BD350FA940FB}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{39690825-1221-4346-B8B7-C32401AD596A}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{3BEC0C53-7493-496A-9BDE-E7EDBAF41847}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{3D330D30-F5E7-4F70-B86A-9621625362BA}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{3DCDD004-195C-4C7F-9D1C-40C84FEF0DDD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{3F8EC7A5-6873-460C-B617-A2062DBA0B0B}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{41268B9C-5109-4604-BC46-4ABF292679A4}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4374CFEE-EE78-4229-8DAB-EC76F73183BC}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4493E549-54C9-486E-BF4A-70F35BC69B28}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4614E2B6-6EFB-424A-B4DF-9B9CC34F9168}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4A22ACBE-3D05-48CD-8647-8706A63324C5}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4B52185A-3A2F-4D4D-9D72-1025E64E4F64}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4C5B9884-981B-4FFA-A500-8CEBCFAC3BAD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4C9672B1-ACCE-4006-94B2-7B052BCD4450}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4D953FB6-4077-4C15-9F57-AEF3C681659C}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4EEFC289-1DE0-47AD-A825-44AE996F67CD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4FCF85D5-6577-45CC-BEA7-8F7DC6B78F63}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{4FEEC6AD-2093-431B-8310-4F8E3F28C67D}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{50F0C0B0-093A-4E01-AF84-13458711A84B}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{53BB37D8-441B-46E7-A325-4E606371AC27}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{5474ACC6-431F-4BDA-A861-77D08D36D4FF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{556938B6-59D2-422D-BCDB-DF1A67FF8ADF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{581279B8-81FF-481E-BA06-86AF2518D356}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{5A8D6153-69B2-4516-896F-AFB507E19968}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{5B5429E7-C465-4F2F-8E93-768B11D529A3}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{5B5AB676-391B-427A-9314-8327D3B1B351}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{5E5D5C90-C14C-4CFC-BF95-B811B0321C71}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{5E74A068-8EDD-423B-8DDE-6FE7FCE19E23}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{60C7BBBC-EF6B-4D93-AB34-713E06B0536A}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{60E397FC-C686-48AC-AB3D-C95C50A6A480}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{613679B6-1DAD-43AE-9C6E-361F8973CF97}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{6338FF3C-4858-444A-9CAE-7414C266AD35}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{63EABF81-836A-4807-9529-54FF37E428ED}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{64326A5B-5906-4AAE-8E9A-0AD0B70E44DB}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{64440CBA-ABA5-4E9F-928E-3194240BC8B8}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{66DCDC64-81D5-4112-814B-D5FB32D9C427}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{69512740-C62B-4742-B62F-9E922E595A6D}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{6A8DD756-E4C4-4754-A262-7D5D9A8504CD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{6C583D27-8BF6-4884-953B-99B3C3264450}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{6E2CF597-0D6D-45BE-A000-F3D4CCE04CAC}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{6F2F4CE8-DB47-4797-AE38-C7B98F4CAFF5}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7058A83F-4D53-43F6-AD24-B22A577AB6A3}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{708C82A6-FFAB-4C24-8816-8B999B594F63}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{71B03A56-D96D-4153-B7B7-B2CF54D707B5}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{726A48B6-695F-420F-831E-1BEEEF16AF9F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{73313CF6-F5C3-4478-BD79-2E8F4D2AC04E}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{760207BD-3EAF-4D20-97CF-5205E3AA73C1}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{760CD843-057C-4CB4-ACBE-67F9E6449FDD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{78444A20-84B3-4951-8998-DF6C1DA3DE1A}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{793C4A21-1BF5-4EFF-AC6F-A37F08C6BBD1}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7B04AB04-23F4-4D8F-A716-7B0F4D66019B}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7B3CFEE5-A5C0-4EF3-BF46-9B21F31B9F9C}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7B553DCB-6274-4433-A690-9E52FD4CFA8E}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7C1F0F8F-B455-4009-8E84-F96FA198EE60}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7C91D007-E6D4-4548-9A4D-5A123F93A6CF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7CE4BEBC-2FE1-4894-AB16-D20E2A11A7CB}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7CF4E23E-BF38-4ABE-8592-3F51CA6904C0}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7DE7731A-73CF-4B16-92BF-40EF63E24F3A}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7E934087-868D-43F0-86FF-F4D747F0CE64}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7EED3717-CA96-43D4-9AEA-51A107A521D0}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{7F4ACC46-C985-4BCA-B5F1-ECA1F74F1DB7}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{800761C0-93DC-48C8-961E-2F82DC3B52FB}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{810FFD1C-EE2C-4D52-8B02-B6ED56744AD4}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{813E9040-9449-4946-AC74-221EC985073A}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{83B6E9A7-FE55-4FE1-86FD-F55111E11B3B}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{83D985F4-FEC5-4C7D-B710-A9FA08B7467F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{85C43283-D757-4E5E-BCE5-FDADC804D5A0}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{85F3973E-B460-48B6-90DB-4BA60D500FB9}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{8674DC29-6B99-4FBA-833C-7ADC50BA903B}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{868FF6E8-FE41-4516-9977-63659F3AE3C7}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{882D1E54-A376-4C82-9A27-FACE866DE76D}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{8882D797-D736-497D-B470-7B780D563899}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{88B8B2CE-05D1-48C2-B498-45026BD6A0F9}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{88CED6EB-B7B5-4069-A655-AC4EC8147383}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{88F679AB-E05F-438F-85CA-80D6D93127C5}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{89255068-BEE7-42D3-8BC1-E18E63D5C8BD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{8AB6A583-ACDA-4CFF-937C-49CFD23A9140}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{8F3976E4-8533-47AB-865A-25455DCF9D89}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{8F7C3A72-209A-4863-BD1F-BD4940A9D309}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{8FEEA7DB-BDAD-4030-A805-C399AF1FCF07}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{90333366-7807-4B5A-9EB8-F8B584B7D98E}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{90CC5CF2-D065-4006-A5A5-3199F3823993}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{91E5B568-9F18-4611-AFA5-A914811C49A2}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{94DF8E77-AEFD-40B3-B14A-48BE35572E5C}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{953D7C18-2330-4AF4-9791-E5ED378B393B}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{95AFA5F6-BBA9-4A2E-96E6-15B05E722DDD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{96F44660-59D4-43FD-BD86-1B4CCF1A289A}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{96F5FE91-4816-4132-ABCA-9BBB0CB85586}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{98F780AE-72BA-4304-8D19-8A6C64B9B1A3}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{999A3045-70B1-49BD-B97F-163919758B0B}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{999AC43D-9E21-4F12-BF06-0C7A59B87E9E}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{9B8EAEC0-015B-455A-B8AE-91514253A099}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{9C03A1B6-3DD8-42D2-8EBB-EBDC69FCD7E4}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{9E1A7FFA-77AF-4646-AFE5-2477F5A5D745}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{9E60C477-8776-4D64-9E88-2B925866030E}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A04D379C-E9FB-456A-AEF9-B4D2460B67A7}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A15EFEF9-02D7-42A2-9855-F9381E23B7DA}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A32068E3-9666-42E2-A7E8-F00FB002FE27}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A4E748F7-40D3-4C31-9D11-C11D24ED6BA8}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A5EF872B-6580-45F6-8ACB-75D1810A68E4}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A7545F37-C1B7-4FD4-87B2-4DEB1F6914C3}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A7965C3F-1796-430B-91BE-D5ED8B7A3119}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A7BFBE84-C396-45A3-BBDF-DBB51CE99D1E}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A7D8583A-D541-4E2B-AAC8-B271AB2B5D24}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{A9EB1F44-B0D3-48DC-A3CE-FBB8C38E9477}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{AB3662FD-25BC-4CE3-83CE-7058A78B2902}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{AE39709E-78F6-464C-A8E3-19389DE42DED}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{AEA38027-FAE0-4B9D-B106-A06B5DBCD7AE}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{AEE1B408-F42E-430E-BC63-847FC6A9B2AA}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{AF6ED8BF-1127-47D2-86B1-0052EA13E561}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{AFD74182-8CB6-483F-9928-BD9E5A5CC626}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{B020C975-FB6D-458C-BBDC-DA8C338DF9CD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{B186A6CA-7C18-4AB3-A8C5-E88EEAF32CF0}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{B344B384-4B2C-4F6E-BC90-E83544E67494}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{B5BB1C76-53FB-455C-8D71-2A3901DD091D}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{B712CFAE-30DC-4AA4-83A4-6D8CCF494A3C}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{B8BF7B3E-E2EC-44E2-97EB-9410AE673BD1}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{B8D7EA2C-566C-47C6-9CC9-92BDB7E629EA}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{B9810BE2-03EF-477F-9580-1CDA830426E5}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{BA280BBC-E722-4762-820F-CAAAED4A79BE}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{BE7F7514-90DA-4E0D-84FE-BB0C2A3D0D46}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C05D81E0-1E5F-4B12-9ABB-6F0A9B7ADFCF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C0B9C47B-E4B2-4818-9A91-A056D813EA9F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C126A54C-39AA-468F-9986-B2765D9A5C93}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C19C873C-67FE-4EAB-BCCE-D72D49B6CCAE}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C2D984EC-B345-4E65-A727-83D220BBFAD5}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C398CB0C-EE0F-4662-80E5-3FEC552147B3}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C44E1602-6604-4DB9-A573-FB81A9D94DFF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C49B975C-F659-4FCA-8EE9-221112D9C771}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C5971345-A16B-494E-AFE0-0DC122E76A2C}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C5B1ACF6-26D5-482F-BEFD-B812BCDAE497}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C6EC581D-DD38-417E-9E4A-C1A5740BB0E5}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C6EDF10E-CDF5-459E-AF45-A4AEA4B99724}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C87DA143-AFA8-4D9F-AFBA-18DF3722A744}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C936F07E-DF63-4C01-A701-182FB87538F6}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C9377AB8-EDED-4287-A89B-369623C4E7FD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{C9DC81BE-85BF-45A6-A3F5-34E3CCE44A05}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{CA3A1EBF-D6B7-4AB7-B2D6-B5006485ED73}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{CAAA8328-A0CB-4B14-8208-95178E51EF10}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{CAEFC465-E83C-48B0-9362-29CD39006EAA}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{CBFACF39-553C-4658-9276-AAC25E2431EB}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{CDFB7DF3-CDDC-4EA7-AF43-C6C1BCD9CD82}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{CEC4C459-86FE-49DD-A924-417521778663}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{CF3B6DD6-AACA-47A7-8172-3E70DB6596CD}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{CF63A9B4-2532-47AA-B9CA-723938F45376}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{D036B7A0-DB8E-4957-9BE2-FF7A4DB3253C}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{D05B0365-6AED-479A-B3E2-B7B6382CCE24}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{D2ED7105-3526-4C95-BB41-DF277E9CA3CF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{D39B335B-17AD-4691-945A-CFF9E614DF40}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{D3CCC883-2ADD-4233-AC78-41B569F09C09}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{D3D99AC8-84C2-4653-B392-92E1B78FEF6E}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{D3F72DA5-D5F1-49EC-922F-D8C323984633}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{D9358CEC-E90F-462E-9DF3-8B1987C8FF1F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{DC15BC16-C410-41B8-8DB9-564BB8BD0EDE}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{DC93CEFF-4E11-46C7-9D57-A60484AFAE7E}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{E01B957D-A69F-4395-B0EE-DFD465EED2D8}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{E4BA6903-5E27-485A-AD90-4EBE7C271E21}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{E61B45BC-AB6C-49D0-9CC4-59777CEEB45F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{E63B74EA-1A6C-4C5F-A666-A8C56775A0CF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{E7D439BB-D10A-4823-9626-202764AA6D73}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{E813CAC7-D2EF-43A3-BDE4-CD33403EB973}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{E997697F-584F-4692-BC46-455817D5D288}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{EA4C6CFB-AA9D-499A-8150-786CE46BEE0F}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{EBA325AF-FD57-463A-8E26-AAA6635598CF}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{EBE60764-AFE8-4032-8BFB-9FD30E51C823}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{ED74DB43-0296-42C1-AF11-794056A480E6}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{EDD16DDC-E477-42B2-9B0B-E1AF7107DE0A}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{EE38A3CC-C7E2-43B2-A8EB-6567CF409AF2}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{EFFD5BBE-88A1-482F-8DCB-2A4A6046664B}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{F24369C9-7034-4805-82BE-0CF0EF17548C}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{F2B8E922-D8BD-415E-844B-CC7D26927AA8}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{F4AC87A2-A24F-4779-A737-D7AF832F7E4D}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{F57F6D3E-5775-4F44-87A9-2649FFD54B21}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{F87449AC-AD2B-48D1-8BC8-86AA806E8576}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{FA808D03-8C42-425C-94E8-047D009E74D8}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{FAD2605A-C88D-41CC-B4C2-A1C18C68D8E4}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{FCEAC551-61EC-4987-A939-501169C1F4BC}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{FF207882-BCD7-4FBC-AA58-288E57FD4CCE}
Successfully deleted: [Empty Folder] C:\Users\ConVo\appdata\local\{FFA02413-2AB3-4F07-9BF7-92073F08F0CA}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.09.2014 at 1:06:49,27
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-09-2014
Ran by ConVo (administrator) on CONVO-MOBILE-NE on 11-09-2014 01:08:08
Running from C:\Users\ConVo\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
() C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(BUFFALO INC.) C:\Program Files (x86)\BUFFALO\NASNAVI\nassvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(NovaStor) C:\Program Files (x86)\NovaStor\NovaStor NovaBACKUP\nsService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Windows\System32\atwtusb.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
() C:\Windows\System32\atwtusb.exe
() C:\Program Files\OO Software\DiskImage\oodiag.exe
(Microsoft Corporation) C:\Windows\System32\vdsldr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_WLM\TMAS_WLMMon.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
(1&1 Mail & Media GmbH) C:\Users\ConVo\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [229824 2013-10-09] (Trend Micro Inc.)
HKLM\...\Run: [WLM] => C:\Program Files\Trend Micro\Titanium\Plugin\TMAS\TMAS_WLM\TMAS_WLMMon.exe [44152 2013-07-23] (Trend Micro Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-22] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-11] (Dritek System Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Photo Downloader] => C:\Program Files (x86)\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [63712 2007-03-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [619008 2010-05-25] (Nikon Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKU\S-1-5-21-851625814-3518592554-1989338486-1000\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [578560 2013-03-20] (Samsung Electronics)
HKU\S-1-5-21-851625814-3518592554-1989338486-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia)
HKU\S-1-5-21-851625814-3518592554-1989338486-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-851625814-3518592554-1989338486-1000\...\Run: [GMX Application {sync-000021}] => C:\Users\ConVo\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe [792064 2014-06-04] (1&1 Mail & Media GmbH)
HKU\S-1-5-21-851625814-3518592554-1989338486-1000\...\Run: [1und1DispatcherCorp] => C:\Users\ConVo\AppData\Local\1und1UpdaterCorpE\SchedDispatcher.exe [213640 2013-05-29] (1&1 Mail & Media GmbH)
HKU\S-1-5-21-851625814-3518592554-1989338486-1000\...\Run: [GoogleChromeAutoLaunch_176129A81A4855DA76CA6BB73E9E1CEC] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808 2014-08-30] (Google Inc.)
ShellIconOverlayIdentifiers: 1&1 Sync Overlay 1 -> {02B2B772-B8A8-4DA4-9B18-42551A54A1A8} => C:\Program Files\Common Files\1&1 Sync\1&1SyncShellExtension64_1_0_0_1_20140623183337509.dll (1&1 Mail & Media GmbH)
ShellIconOverlayIdentifiers: 1&1 Sync Overlay 2 -> {0575AB16-E932-4160-8936-4DBE195BDBD7} => C:\Program Files\Common Files\1&1 Sync\1&1SyncShellExtension64_1_0_0_1_20140623183337509.dll (1&1 Mail & Media GmbH)
ShellIconOverlayIdentifiers: 1&1 Sync Overlay 3 -> {0E9EF89A-96D3-4DE6-B2F8-E9548AA5321E} => C:\Program Files\Common Files\1&1 Sync\1&1SyncShellExtension64_1_0_0_1_20140623183337509.dll (1&1 Mail & Media GmbH)
ShellIconOverlayIdentifiers: 1&1 Sync Overlay 4 -> {1A4AFFE1-B2F9-483D-B627-D9A339DBFD34} => C:\Program Files\Common Files\1&1 Sync\1&1SyncShellExtension64_1_0_0_1_20140623183337509.dll (1&1 Mail & Media GmbH)
ShellIconOverlayIdentifiers: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll (Egis Technology Inc.)
ShellIconOverlayIdentifiers: OODIIcon -> {14A94384-BBED-47ed-86C0-6BF63FD892D0} => C:\Program Files\OO Software\DiskImage\oodishi.dll (O&O Software GmbH)
ShellIconOverlayIdentifiers-x32: 1&1 Sync Overlay 1 -> {02B2B772-B8A8-4DA4-9B18-42551A54A1A8} => C:\Program Files (x86)\Common Files\1&1 Sync\1&1SyncShellExtension_1_0_0_1_20140623183337509.dll (1&1 Mail & Media GmbH)
ShellIconOverlayIdentifiers-x32: 1&1 Sync Overlay 2 -> {0575AB16-E932-4160-8936-4DBE195BDBD7} => C:\Program Files (x86)\Common Files\1&1 Sync\1&1SyncShellExtension_1_0_0_1_20140623183337509.dll (1&1 Mail & Media GmbH)
ShellIconOverlayIdentifiers-x32: 1&1 Sync Overlay 3 -> {0E9EF89A-96D3-4DE6-B2F8-E9548AA5321E} => C:\Program Files (x86)\Common Files\1&1 Sync\1&1SyncShellExtension_1_0_0_1_20140623183337509.dll (1&1 Mail & Media GmbH)
ShellIconOverlayIdentifiers-x32: 1&1 Sync Overlay 4 -> {1A4AFFE1-B2F9-483D-B627-D9A339DBFD34} => C:\Program Files (x86)\Common Files\1&1 Sync\1&1SyncShellExtension_1_0_0_1_20140623183337509.dll (1&1 Mail & Media GmbH)
ShellIconOverlayIdentifiers-x32: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll (Egis Technology Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: TmIEPlugInBHO Class -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> C:\Program Files\Trend Micro\AMSP\module\20004\3.0.1313\6.8.1120\TmIEPlg.dll (Trend Micro Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: TmBpIeBHO Class -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\8.0.1173\8.0.1173\TmBpIe64.dll (Trend Micro Inc.)
BHO-x32: TmIEPlugInBHO Class -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> C:\Program Files\Trend Micro\AMSP\module\20004\3.0.1313\6.8.1120\TmIEPlg32.dll (Trend Micro Inc.)
BHO-x32: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
BHO-x32: TSToolbarBHO -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: TmBpIeBHO Class -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\8.0.1173\8.0.1173\TmBpIe32.dll (Trend Micro Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\8.0.1173\8.0.1173\TmBpIe64.dll (Trend Micro Inc.)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\3.0.1313\6.8.1120\TmIEPlg.dll (Trend Micro Inc.)
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - No File
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\8.0.1173\8.0.1173\TmBpIe32.dll (Trend Micro Inc.)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\3.0.1313\6.8.1120\TmIEPlg32.dll (Trend Micro Inc.)
Handler-x32: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\ConVo\AppData\Roaming\Mozilla\Firefox\Profiles\9ubdfwmg.default
FF SelectedSearchEngine: Ask.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: GMX MailCheck - C:\Users\ConVo\AppData\Roaming\Mozilla\Firefox\Profiles\9ubdfwmg.default\Extensions\toolbar@gmx.net.xpi [2012-06-24]
FF HKLM\...\Firefox\Extensions: [tmbepff@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\module\20002\8.0.1173\8.0.1173\firefoxextension
FF Extension: Trend Micro BEP Firefox Extension - C:\Program Files\Trend Micro\AMSP\module\20002\8.0.1173\8.0.1173\firefoxextension [2014-08-28]
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2014-03-04]
FF HKLM-x32\...\Firefox\Extensions: [tmbepff@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\module\20002\8.0.1173\8.0.1173\firefoxextension
FF HKLM-x32\...\Firefox\Extensions: [{22181a4d-af90-4ca3-a569-faed9118d6bc}] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension
FF Extension: Trend Micro Toolbar - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2014-08-28]
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension
FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension [2014-08-28]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3325386&octid=EB_ORIGINAL_CTID&ISID=MF7FD9457-2BEB-4E30-8A0E-25ACC90B5DF3&SearchSource=55&CUI=&UM=5&UP=SP01D69680-845A-48BC-A0B6-548C29F8ED19&SSPV=
CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3325386&octid=EB_ORIGINAL_CTID&ISID=MF7FD9457-2BEB-4E30-8A0E-25ACC90B5DF3&SearchSource=55&CUI=&UM=5&UP=SP01D69680-845A-48BC-A0B6-548C29F8ED19&SSPV=", "hxxp://www.sweet-page.com/?type=hp&ts=1403900922&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F396762667626", "hxxp://www.sweet-page.com/?type=hppp&ts=1403944179&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F396762667626", "hxxp://www.sweet-page.com/?type=hppp&ts=1406280258&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F396762667626"
CHR DefaultSearchKeyword: Default -> 190BEB7DB8D35DDAB98510C1D2FA8B1ED66DCC5D55B19A02DEE60F61C7302800
CHR DefaultSearchURL: Default -> D4DCF2C5A68EEDF11D99EA5879FCE3B2ED40E060CF6BA8195DF8C1E945F251B4
CHR Profile: C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-22]
CHR Extension: (Google Drive) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-22]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06]
CHR Extension: (YouTube) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-22]
CHR Extension: (Google-Suche) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-22]
CHR Extension: (Email this page (by Google)) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbeoemfhkdniadbojeencpkgmobndpai [2014-01-24]
CHR Extension: (Print Using Google Cloud Print™) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffaifmgpcdjedlffbhenaloimajbdkfg [2014-01-24]
CHR Extension: (AdBlock) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-01-25]
CHR Extension: (Night Time In New York City) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnimonidkipnhnpgkhgliocfnnpgkhek [2014-06-06]
CHR Extension: (Print) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmiefodmmloajakmcfnpnjpkldellhlj [2014-01-24]
CHR Extension: (Google Wallet) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-22]
CHR Extension: (Trend Micro Toolbar) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohhcpmplhhiiaoiddkfboafbhiknefdf [2014-08-28]
CHR Extension: (Google Mail) - C:\Users\ConVo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-22]
CHR HKLM-x32\...\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - C:\Program Files\Trend Micro\AMSP\module\20002\8.0.1095\8.0.1095\chrome_tmbep.crx []
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ALDITALKVerbindungsassistent_Service; C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [358968 2013-11-07] ()
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1876816 2014-04-16] (SurfRight B.V.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 jswpsapi; C:\Program Files (x86)\NETGEAR\WNDA3100\jswpsapi.exe [942080 2008-02-29] (Atheros Communications, Inc.) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.)
R2 NasPmService; C:\Program Files (x86)\BUFFALO\NASNAVI\nassvc.exe [251184 2009-05-15] (BUFFALO INC.)
R2 nsService; C:\Program Files (x86)\NovaStor\NovaStor NovaBACKUP\nsService.exe [261256 2010-04-15] (NovaStor) [File not signed]
R2 OO DiskImage; C:\Program Files\OO Software\DiskImage\oodiag.exe [4034376 2011-03-14] ()
R2 WTService; C:\Windows\system32\atwtusb.exe [897536 2011-07-19] () [File not signed]
S2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad -bt=0 [X]
S2 LanmanWorkstation; %SystemRoot%\System32\aptwwxm4j.dll [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 ew_hwusbdev; C:\Windows\SysWOW64\DRIVERS\ew_hwusbdev.sys [117248 2013-03-03] (Huawei Technologies Co., Ltd.)
S3 ew_usbenumfilter; C:\Windows\SysWOW64\DRIVERS\ew_usbenumfilter.sys [13952 2013-03-03] (Huawei Technologies Co., Ltd.)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () [File not signed]
R2 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [93144 2014-04-16] ()
S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [121600 2013-03-03] (Huawei Technologies Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-11] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 moufiltr; C:\Windows\System32\DRIVERS\moufiltr.sys [7680 2009-03-08] (Windows (R) Codename Longhorn DDK provider)
R0 oodisr; C:\Windows\System32\DRIVERS\oodisr.sys [117328 2011-03-14] (O&O Software GmbH)
R0 oodisrh; C:\Windows\System32\DRIVERS\oodisrh.sys [40016 2011-03-14] (O&O Software GmbH)
R0 oodivd; C:\Windows\System32\DRIVERS\oodivd.sys [215120 2011-03-14] (O&O Software GmbH)
R0 oodivdh; C:\Windows\System32\DRIVERS\oodivdh.sys [43600 2011-03-14] (O&O Software GmbH)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2012-01-18] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2012-01-18] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2013-11-15] (Duplex Secure Ltd.)
R1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [117312 2013-12-03] (Trend Micro Inc.)
R0 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [283160 2013-12-03] (Trend Micro Inc.)
R0 TMEBC; C:\Windows\System32\DRIVERS\TMEBC64.sys [50976 2013-07-01] (Trend Micro Inc.)
R3 tmeevw; C:\Windows\System32\DRIVERS\tmeevw.sys [100640 2013-06-13] (Trend Micro Inc.)
R1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [85936 2013-12-03] (Trend Micro Inc.)
R3 tmnciesc; C:\Windows\System32\DRIVERS\tmnciesc.sys [303392 2013-05-15] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105744 2011-08-22] (Trend Micro Inc.)
R3 vhidmini; C:\Windows\System32\DRIVERS\walvhid.sys [7552 2009-08-26] (Windows (R) Win 7 DDK provider)
U3 a9zny2h6; C:\Windows\System32\Drivers\a9zny2h6.sys [0 ] (Elaborate Bytes AG)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U5 ewusbnet; C:\Windows\SysWOW64\Drivers\ewusbnet.sys [256000 2013-03-03] (Huawei Technologies Co., Ltd.)
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
U2 TMAgent; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-11 01:08 - 2014-09-11 01:08 - 00026936 _____ () C:\Users\ConVo\Desktop\FRST.txt
2014-09-11 01:08 - 2014-09-11 01:08 - 00000000 ____D () C:\Users\ConVo\Desktop\FRST-OlderVersion
2014-09-11 01:06 - 2014-09-11 01:07 - 00025544 _____ () C:\Users\ConVo\Desktop\JRT.txt
2014-09-11 00:40 - 2014-09-11 00:40 - 00000000 ____D () C:\Windows\ERUNT
2014-09-11 00:39 - 2014-09-11 00:39 - 01016261 _____ (Thisisu) C:\Users\ConVo\Desktop\JRT.exe
2014-09-10 22:32 - 2014-09-10 22:32 - 00007864 _____ () C:\Users\ConVo\Desktop\AdwCleaner[S0].txt
2014-09-10 22:05 - 2014-09-10 22:12 - 00000000 ____D () C:\AdwCleaner
2014-09-10 21:55 - 2014-09-10 21:55 - 01370483 _____ () C:\Users\ConVo\Desktop\adwcleaner_3.309.exe
2014-09-10 21:22 - 2014-09-10 21:22 - 00003230 _____ () C:\Users\ConVo\Desktop\mbam.txt
2014-09-10 18:42 - 2014-09-10 18:42 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\ConVo\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-08 19:13 - 2014-09-08 19:13 - 00035650 _____ () C:\ComboFix.txt
2014-09-08 18:10 - 2014-09-08 19:13 - 00000000 ____D () C:\Qoobox
2014-09-08 18:10 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-08 18:10 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-08 18:10 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-08 18:10 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-08 18:10 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-08 18:10 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-08 18:10 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-08 18:10 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-08 18:09 - 2014-09-08 19:09 - 00000000 ____D () C:\Windows\erdnt
2014-09-08 18:06 - 2014-09-08 18:07 - 05576440 ____R (Swearware) C:\Users\ConVo\Desktop\ComboFix.exe
2014-09-08 17:56 - 2014-09-08 17:56 - 00001228 _____ () C:\Users\ConVo\Desktop\Revo Uninstaller.lnk
2014-09-08 17:56 - 2014-09-08 17:56 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-09-08 17:54 - 2014-09-08 17:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\ConVo\Desktop\revosetup95.exe
2014-09-07 14:50 - 2014-09-07 14:53 - 00054967 _____ () C:\Users\ConVo\Desktop\Addition.txt
2014-09-07 14:47 - 2014-09-11 01:08 - 00000000 ____D () C:\FRST
2014-09-07 14:47 - 2014-09-07 14:53 - 00053811 _____ () C:\Users\ConVo\Desktop\FRST1.txt
2014-09-07 14:41 - 2014-09-07 14:41 - 00380416 _____ () C:\Users\ConVo\Desktop\vbikl2xq.exe
2014-09-07 14:40 - 2014-09-11 01:08 - 02105856 _____ (Farbar) C:\Users\ConVo\Desktop\FRST64.exe
2014-09-07 14:39 - 2014-09-07 14:39 - 00050477 _____ () C:\Users\ConVo\Desktop\Defogger.exe
2014-09-06 08:34 - 2014-09-10 22:14 - 00000392 _____ () C:\Windows\setupact.log
2014-09-06 08:34 - 2014-09-06 08:34 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-06 08:33 - 2014-09-10 22:13 - 00001418 _____ () C:\Windows\PFRO.log
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\OLEPRO32.DLL
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\ElbyVCD.dll
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\ElbyCDIO.dll
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\atiumdva.dll
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\atiumdag.dll
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\atiu9pag.DLL
2014-08-28 09:53 - 2014-08-28 09:53 - 00000000 ____D () C:\TMRescueDisk
2014-08-28 09:50 - 2014-08-28 09:50 - 00001431 _____ () C:\Users\ConVo\Desktop\Trend Micro Titanium Maximum Security.lnk
2014-08-28 09:50 - 2014-08-28 09:50 - 00000000 ____D () C:\Users\ConVo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium Maximum Security
2014-08-28 09:49 - 2013-06-13 08:35 - 00100640 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmeevw.sys
2014-08-28 09:49 - 2013-05-15 12:23 - 00303392 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmnciesc.sys
2014-08-28 09:48 - 2013-12-03 10:57 - 00283160 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmcomm.sys
2014-08-28 09:48 - 2013-12-03 10:57 - 00117312 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmactmon.sys
2014-08-28 09:48 - 2013-12-03 10:57 - 00085936 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmevtmgr.sys
2014-08-28 09:48 - 2013-07-01 15:08 - 00050976 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\TMEBC64.sys
2014-08-28 09:48 - 2011-08-22 17:33 - 00105744 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmtdi.sys
2014-08-28 09:47 - 2014-08-28 09:47 - 00003282 _____ () C:\Windows\System32\Tasks\Titanium BTC
2014-08-28 09:44 - 2014-08-28 09:44 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-08-28 09:44 - 2014-08-28 09:44 - 00000059 _____ () C:\Windows\system32\SupportTool.exe.bat
2014-08-28 09:42 - 2014-09-07 14:08 - 00000000 ____D () C:\ProgramData\Trend Micro
2014-08-28 09:42 - 2014-08-28 09:43 - 00000000 ____D () C:\Program Files\Trend Micro
2014-08-28 09:27 - 2014-08-28 09:50 - 00000000 ____D () C:\Users\ConVo\AppData\Local\Trend Micro
2014-08-28 09:13 - 2014-08-28 09:19 - 116265320 _____ (Trend Micro Inc.) C:\Users\Public\Desktop\Trend_Micro.exe
2014-08-27 23:35 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-27 23:35 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-27 23:35 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 05:01 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-22 05:01 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-22 05:01 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-22 05:01 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-22 05:01 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-22 05:01 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-22 05:01 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-22 05:01 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-22 05:01 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-22 05:01 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-22 05:00 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-22 05:00 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-22 05:00 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-22 05:00 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-21 18:36 - 2014-08-21 18:36 - 00000000 ____D () C:\Users\Stephan\AppData\Roaming\Nero
2014-08-18 07:27 - 2014-08-18 07:28 - 04813544 _____ (Piriform Ltd) C:\Users\Stephan\Downloads\ccsetup416.exe
2014-08-17 18:53 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-17 18:53 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-17 18:53 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-17 18:53 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-17 18:53 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-17 18:53 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-17 18:53 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-17 18:53 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-17 17:34 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-17 17:34 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-17 17:34 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-17 17:34 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-17 17:34 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-17 17:34 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-17 17:34 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-17 17:34 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-17 17:34 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-17 17:34 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-17 17:34 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-17 17:34 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-17 17:34 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-17 17:34 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-17 17:34 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-17 17:34 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-17 17:34 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-17 17:34 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-17 17:33 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-17 17:33 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-17 17:33 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-17 17:33 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-17 17:33 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-17 17:33 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-17 17:33 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-17 17:33 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-17 17:33 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-17 17:33 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-17 17:33 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-17 17:33 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-17 17:33 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-17 17:33 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-17 17:33 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-17 17:33 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-17 17:33 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-17 17:33 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-17 17:33 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-17 17:33 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-17 17:33 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-17 17:33 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-17 17:33 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-17 17:33 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-17 17:33 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-17 17:33 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-17 17:33 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-17 17:33 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-17 17:33 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-17 17:33 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-17 17:33 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-17 17:33 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-17 17:33 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-17 17:33 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-17 17:33 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-17 17:33 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-17 17:33 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-17 17:33 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-17 17:22 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-17 17:22 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-17 17:04 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-17 17:04 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-17 17:02 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-17 17:02 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-17 17:02 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-17 17:02 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-17 17:02 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-17 17:02 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-17 17:02 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-17 16:57 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-17 16:50 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-17 16:50 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-17 16:49 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-17 16:49 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-11 01:10 - 2014-09-11 01:08 - 00026936 _____ () C:\Users\ConVo\Desktop\FRST.txt
2014-09-11 01:08 - 2014-09-11 01:08 - 00000000 ____D () C:\Users\ConVo\Desktop\FRST-OlderVersion
2014-09-11 01:08 - 2014-09-07 14:47 - 00000000 ____D () C:\FRST
2014-09-11 01:08 - 2014-09-07 14:40 - 02105856 _____ (Farbar) C:\Users\ConVo\Desktop\FRST64.exe
2014-09-11 01:08 - 2014-07-05 21:54 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-11 01:07 - 2014-09-11 01:06 - 00025544 _____ () C:\Users\ConVo\Desktop\JRT.txt
2014-09-11 01:00 - 2011-10-27 21:52 - 00000386 _____ () C:\Windows\Tasks\Acer Registration - Data Sending task.job
2014-09-11 00:46 - 2014-01-22 22:29 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-11 00:45 - 2012-04-06 13:53 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-11 00:40 - 2014-09-11 00:40 - 00000000 ____D () C:\Windows\ERUNT
2014-09-11 00:39 - 2014-09-11 00:39 - 01016261 _____ (Thisisu) C:\Users\ConVo\Desktop\JRT.exe
2014-09-10 23:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-09-10 22:32 - 2014-09-10 22:32 - 00007864 _____ () C:\Users\ConVo\Desktop\AdwCleaner[S0].txt
2014-09-10 22:28 - 2009-07-14 06:45 - 00025840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-10 22:28 - 2009-07-14 06:45 - 00025840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-10 22:17 - 2014-01-22 22:29 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-10 22:15 - 2011-11-15 23:46 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-09-10 22:15 - 2009-07-14 04:34 - 00000493 _____ () C:\Windows\win.ini
2014-09-10 22:14 - 2014-09-06 08:34 - 00000392 _____ () C:\Windows\setupact.log
2014-09-10 22:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-10 22:13 - 2014-09-06 08:33 - 00001418 _____ () C:\Windows\PFRO.log
2014-09-10 22:13 - 2011-10-27 15:15 - 01198531 _____ () C:\Windows\WindowsUpdate.log
2014-09-10 22:12 - 2014-09-10 22:05 - 00000000 ____D () C:\AdwCleaner
2014-09-10 22:11 - 2011-12-08 10:48 - 00000999 _____ () C:\Users\ConVo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-10 22:11 - 2011-10-27 21:49 - 00000000 ____D () C:\Users\ConVo
2014-09-10 21:55 - 2014-09-10 21:55 - 01370483 _____ () C:\Users\ConVo\Desktop\adwcleaner_3.309.exe
2014-09-10 21:22 - 2014-09-10 21:22 - 00003230 _____ () C:\Users\ConVo\Desktop\mbam.txt
2014-09-10 18:46 - 2012-04-06 13:53 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 18:46 - 2012-04-06 13:53 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-10 18:46 - 2011-10-28 13:38 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-10 18:44 - 2014-07-05 21:52 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-10 18:44 - 2014-07-05 21:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-10 18:44 - 2014-07-05 21:52 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-10 18:42 - 2014-09-10 18:42 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\ConVo\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-08 19:13 - 2014-09-08 19:13 - 00035650 _____ () C:\ComboFix.txt
2014-09-08 19:13 - 2014-09-08 18:10 - 00000000 ____D () C:\Qoobox
2014-09-08 19:09 - 2014-09-08 18:09 - 00000000 ____D () C:\Windows\erdnt
2014-09-08 19:07 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-09-08 18:07 - 2014-09-08 18:06 - 05576440 ____R (Swearware) C:\Users\ConVo\Desktop\ComboFix.exe
2014-09-08 17:56 - 2014-09-08 17:56 - 00001228 _____ () C:\Users\ConVo\Desktop\Revo Uninstaller.lnk
2014-09-08 17:56 - 2014-09-08 17:56 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-09-08 17:54 - 2014-09-08 17:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\ConVo\Desktop\revosetup95.exe
2014-09-07 22:12 - 2011-10-28 12:59 - 00000000 ____D () C:\Users\ConVo\Documents\Outlook-Dateien
2014-09-07 20:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-07 14:53 - 2014-09-07 14:50 - 00054967 _____ () C:\Users\ConVo\Desktop\Addition.txt
2014-09-07 14:53 - 2014-09-07 14:47 - 00053811 _____ () C:\Users\ConVo\Desktop\FRST1.txt
2014-09-07 14:41 - 2014-09-07 14:41 - 00380416 _____ () C:\Users\ConVo\Desktop\vbikl2xq.exe
2014-09-07 14:39 - 2014-09-07 14:39 - 00050477 _____ () C:\Users\ConVo\Desktop\Defogger.exe
2014-09-07 14:08 - 2014-08-28 09:42 - 00000000 ____D () C:\ProgramData\Trend Micro
2014-09-06 08:34 - 2014-09-06 08:34 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\OLEPRO32.DLL
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\ElbyVCD.dll
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\ElbyCDIO.dll
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\atiumdva.dll
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\atiumdag.dll
2014-09-06 01:42 - 2014-09-06 01:42 - 00000000 _____ () C:\Windows\system32\atiu9pag.DLL
2014-09-06 00:58 - 2014-01-23 20:22 - 00000036 _____ () C:\Users\ConVo\AppData\Local\housecall.guid.cache
2014-09-06 00:30 - 2012-11-16 00:10 - 00000000 ____D () C:\ProgramData\Avira
2014-09-06 00:29 - 2012-11-16 00:10 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-02 22:33 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-08-29 23:44 - 2011-10-27 04:18 - 00699682 _____ () C:\Windows\system32\perfh007.dat
2014-08-29 23:44 - 2011-10-27 04:18 - 00149790 _____ () C:\Windows\system32\perfc007.dat
2014-08-29 23:44 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-28 11:40 - 2014-04-29 22:02 - 00002394 _____ () C:\Users\ConVo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2014-08-28 11:40 - 2013-12-09 22:00 - 00001458 _____ () C:\Users\ConVo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GMX MediaCenter.lnk
2014-08-28 09:53 - 2014-08-28 09:53 - 00000000 ____D () C:\TMRescueDisk
2014-08-28 09:50 - 2014-08-28 09:50 - 00001431 _____ () C:\Users\ConVo\Desktop\Trend Micro Titanium Maximum Security.lnk
2014-08-28 09:50 - 2014-08-28 09:50 - 00000000 ____D () C:\Users\ConVo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium Maximum Security
2014-08-28 09:50 - 2014-08-28 09:27 - 00000000 ____D () C:\Users\ConVo\AppData\Local\Trend Micro
2014-08-28 09:47 - 2014-08-28 09:47 - 00003282 _____ () C:\Windows\System32\Tasks\Titanium BTC
2014-08-28 09:44 - 2014-08-28 09:44 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-08-28 09:44 - 2014-08-28 09:44 - 00000059 _____ () C:\Windows\system32\SupportTool.exe.bat
2014-08-28 09:44 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-08-28 09:43 - 2014-08-28 09:42 - 00000000 ____D () C:\Program Files\Trend Micro
2014-08-28 09:19 - 2014-08-28 09:13 - 116265320 _____ (Trend Micro Inc.) C:\Users\Public\Desktop\Trend_Micro.exe
2014-08-28 08:58 - 2009-07-14 06:45 - 00428424 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-25 06:53 - 2011-10-28 11:37 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-23 04:07 - 2014-08-27 23:35 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-27 23:35 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-27 23:35 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 18:36 - 2014-08-21 18:36 - 00000000 ____D () C:\Users\Stephan\AppData\Roaming\Nero
2014-08-21 18:34 - 2014-03-21 20:39 - 00000000 ____D () C:\Users\Stephan\AppData\Roaming\Apple Computer
2014-08-20 20:37 - 2013-02-01 11:52 - 00000000 ____D () C:\001-Daten
2014-08-19 22:53 - 2011-12-11 22:18 - 00000000 ____D () C:\Users\ConVo\AppData\Roaming\Skype
2014-08-19 22:33 - 2013-02-13 22:58 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-19 22:33 - 2011-12-11 22:17 - 00000000 ____D () C:\ProgramData\Skype
2014-08-18 07:30 - 2013-04-07 00:00 - 00000000 ____D () C:\Windows\Minidump
2014-08-18 07:28 - 2014-08-18 07:27 - 04813544 _____ (Piriform Ltd) C:\Users\Stephan\Downloads\ccsetup416.exe
2014-08-18 07:28 - 2013-12-22 17:13 - 00000826 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-18 07:28 - 2012-08-27 05:27 - 00002776 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-18 07:28 - 2012-08-27 05:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-18 07:28 - 2012-08-27 05:27 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-18 04:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-17 19:21 - 2011-10-28 11:14 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-17 19:11 - 2013-08-14 21:17 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-17 19:01 - 2011-11-01 18:14 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-17 18:52 - 2014-05-12 08:32 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-17 18:48 - 2014-03-21 20:47 - 00000000 ____D () C:\Users\Stephan\AppData\Local\Google
2014-08-17 16:14 - 2014-03-21 20:39 - 00115344 _____ () C:\Users\Stephan\AppData\Local\GDIPFONTCACHEV1.DAT
Some content of TEMP:
====================
C:\Users\ConVo\AppData\Local\Temp\NOSEventMessages.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-23 20:19
==================== End Of Log ============================ --- --- ---
--- --- ---
Wie immer herzlichen Dank für die tolle Unterstützung.
Petra |