Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   svchost.exe (Network service) CPU 50% PC funktioniert nicht (https://www.trojaner-board.de/166864-svchost-exe-network-service-cpu-50-pc-funktioniert.html)

H.J.Koch 17.05.2015 22:42

Liste der Anhänge anzeigen (Anzahl: 2)
Hallo Sandra,
ich sende dir mal die hohen CPU Werte.

Bootsektor 17.05.2015 23:08

Seit wann besteht das Problem?

Schritt 1

Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Yes und klicke Scan
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).

H.J.Koch 18.05.2015 13:59

Hallo Sandra, mit leichten Schwierigkeiten aber gelungen
 
FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-05-2015 02
Ran by SYSTEM on MININT-TVBNONF on 18-05-2015 01:10:27
Running from g:\
Platform: Windows 7 Home Premium (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-14] (Synaptics Incorporated)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [500792 2010-03-23] (Hewlett-Packard Company)
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe [1855608 2015-02-19] (G DATA Software AG)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-18] (Adobe Systems Incorporated)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\program files (x86)\g data\totalprotection\avkkid\avkcks.exe,C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI] authuitu.dll <==== ATTENTION!
HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1
HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1
HKU\hermann\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7404312 2015-01-20] (Piriform Ltd)
HKU\hermann\...\Policies\system: [DisableLockWorkstation] 0
HKU\hermann\...\Policies\system: [DisableChangePassword] 0
IFEO\taskmgr.exe: [Debugger] "C:\USERS\HERMANN\DESKTOP\PROCEXP.EXE"

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
S2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2528888 2015-04-15] (G Data Software AG)
S2 AVKService; C:\Program Files (x86)\G Data\TotalProtection\AVK\AVKService.exe [965240 2015-02-19] (G Data Software AG)
S2 AVKWCtl; C:\Program Files (x86)\G Data\TotalProtection\AVK\AVKWCtlx64.exe [3672560 2015-04-06] (G Data Software AG)
S2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [2231616 2010-07-19] ()
S2 DiagTrack; C:\Windows\system32\diagtrack.dll [1254400 2015-04-27] (Microsoft Corporation)
S2 GDBackupSvc; C:\Program Files (x86)\G Data\TotalProtection\AVKBackup\AVKBackupService.exe [3881080 2015-02-19] (G Data Software AG)
S3 GDFwSvc; C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFwSvcx64.exe [3193080 2015-02-19] (G Data Software AG)
S3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [789112 2015-03-04] (G Data Software AG)
S3 GDTunerSvc; C:\Program Files (x86)\G Data\TotalProtection\AVKTuner\AVKTunerService.exe [2235512 2015-02-19] (G Data Software AG)
S2 HOSTS Anti-PUPs; C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [285795 2014-01-21] ()
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-13] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-13] (Malwarebytes Corporation)
S3 Qualli.Updater; C:\Program Files (x86)\Nistech GmbH\Qualli.life 7\Qualli.Updater.exe [330056 2014-12-17] (Nistech GmbH)
S2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] ()
S2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\STacSV64.exe [240640 2009-08-13] (IDT, Inc.)
S3 TSNxGService; C:\Program Files (x86)\G Data\TotalProtection\TSNxG\TSNxGService.exe [255608 2014-07-01] (G DATA Software)
S3 TuneUp.Defrag; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [607048 2010-04-13] (TuneUp Software)
S2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [1353544 2009-10-30] (TuneUp Software)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [150016 2015-04-19] (G Data Software AG)
S3 gddcd; C:\Windows\system32\drivers\gddcd64.sys [79872 2015-01-04] (G Data Software AG)
S1 gddcv; C:\Windows\system32\drivers\gddcv64.sys [59904 2015-01-04] (G Data Software AG)
S3 GDKBB; C:\Windows\system32\drivers\GDKBB64.sys [27648 2015-04-19] (G Data Software AG)
S1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [20992 2015-04-19] (G Data Software AG)
S1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [230400 2015-04-19] (G Data Software AG)
S3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [75776 2015-04-19] (G Data Software AG)
S1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64512 2015-04-22] (G Data Software AG)
S1 GLogin; No ImagePath
S1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2015-05-10] (G Data Software)
S1 GRD; C:\Windows\SysWOW64\drivers\GRD.sys [106224 2011-02-14] (G Data Software)
S1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [124928 2015-04-19] (G Data Software AG)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-13] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-13] (Malwarebytes Corporation)
S2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2010-06-10] (CACE Technologies)
S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-02] (Realtek Semiconductor Corp.)
S3 s1018bus; C:\Windows\System32\DRIVERS\s1018bus.sys [113704 2009-03-25] (MCCI Corporation)
S3 s1018mdfl; C:\Windows\System32\DRIVERS\s1018mdfl.sys [19496 2009-03-25] (MCCI Corporation)
S3 s1018mdm; C:\Windows\System32\DRIVERS\s1018mdm.sys [153128 2009-03-25] (MCCI Corporation)
S3 s1018mgmt; C:\Windows\System32\DRIVERS\s1018mgmt.sys [133160 2009-03-25] (MCCI Corporation)
S3 s1018nd5; C:\Windows\System32\DRIVERS\s1018nd5.sys [34856 2009-03-25] (MCCI Corporation)
S3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [128552 2009-03-25] (MCCI Corporation)
S3 s1018unic; C:\Windows\System32\DRIVERS\s1018unic.sys [146472 2009-03-25] (MCCI Corporation)
S3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications)
S3 SilvrLnk; C:\Windows\SysWOW64\DRIVERS\silvrlnk.sys [21456 2004-01-28] (Texas Instruments Incorporated)
S0 TS4NT; C:\Windows\System32\Drivers\TS4nt.sys [98760 2015-04-22] (G Data Software)
S3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [11856 2009-10-13] (TuneUp Software)
S4 eabfiltr; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-17 14:54 - 2015-05-16 13:24 - 02107392 _____ (Farbar) C:\Users\hermann\Desktop\FRST64.exe
2015-05-17 13:20 - 2015-05-16 14:40 - 02480312 _____ (Sysinternals - www.sysinternals.com) C:\Users\hermann\Desktop\procexp.exe
2015-05-17 12:36 - 2015-05-17 12:33 - 02347384 _____ (ESET) C:\Users\hermann\Desktop\esetsmartinstaller_deu.exe
2015-05-17 01:27 - 2015-05-16 23:08 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\hermann\Desktop\tdsskiller.exe
2015-05-17 00:46 - 2015-05-17 01:23 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-05-17 00:41 - 2015-05-17 00:41 - 00000000 ____D () C:\Users\hermann\Desktop\mbar
2015-05-16 13:50 - 2015-05-16 13:46 - 02209792 _____ () C:\Users\hermann\Desktop\AdwCleaner_4.204.exe
2015-05-16 10:04 - 2015-05-16 10:04 - 00000640 _____ () C:\Windows\PFRO.log
2015-05-15 11:45 - 2015-05-17 14:48 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2015-05-15 11:42 - 2015-05-17 00:42 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys
2015-05-15 11:42 - 2015-05-15 11:42 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-15 11:42 - 2015-05-15 11:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-15 11:42 - 2015-04-13 23:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mwac.sys
2015-05-15 11:42 - 2015-04-13 23:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2015-05-15 11:28 - 2015-05-15 11:28 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-14 13:59 - 2015-05-01 05:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 13:59 - 2015-05-01 05:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 13:09 - 2015-05-04 17:29 - 00342016 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2015-05-14 13:09 - 2015-05-04 17:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-14 13:09 - 2015-04-21 18:28 - 00389840 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2015-05-14 13:09 - 2015-04-21 17:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-14 13:09 - 2015-04-21 09:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2015-05-14 13:09 - 2015-04-21 09:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2015-05-14 13:09 - 2015-04-21 09:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2015-05-14 13:09 - 2015-04-21 08:51 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2015-05-14 13:09 - 2015-04-21 08:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2015-05-14 13:09 - 2015-04-21 08:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2015-05-14 13:09 - 2015-04-21 08:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2015-05-14 13:09 - 2015-04-21 08:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2015-05-14 13:09 - 2015-04-21 08:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2015-05-14 13:09 - 2015-04-21 08:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2015-05-14 13:09 - 2015-04-21 08:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2015-05-14 13:09 - 2015-04-21 08:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2015-05-14 13:09 - 2015-04-21 08:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2015-05-14 13:09 - 2015-04-21 08:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2015-05-14 13:09 - 2015-04-21 08:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2015-05-14 13:09 - 2015-04-21 08:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2015-05-14 13:09 - 2015-04-21 08:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2015-05-14 13:09 - 2015-04-21 08:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2015-05-14 13:09 - 2015-04-21 08:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-05-14 13:09 - 2015-04-21 08:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-14 13:09 - 2015-04-21 08:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2015-05-14 13:09 - 2015-04-21 08:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-05-14 13:09 - 2015-04-21 08:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-14 13:09 - 2015-04-21 08:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-05-14 13:09 - 2015-04-21 08:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-05-14 13:09 - 2015-04-21 08:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-14 13:09 - 2015-04-21 08:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2015-05-14 13:09 - 2015-04-21 08:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2015-05-14 13:09 - 2015-04-21 08:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-05-14 13:09 - 2015-04-21 08:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2015-05-14 13:09 - 2015-04-21 08:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-14 13:09 - 2015-04-21 08:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-05-14 13:09 - 2015-04-21 08:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-05-14 13:09 - 2015-04-21 08:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-05-14 13:09 - 2015-04-21 07:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-14 13:09 - 2015-04-21 07:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-05-14 13:09 - 2015-04-21 07:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-05-14 13:09 - 2015-04-21 07:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2015-05-14 13:09 - 2015-04-21 07:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2015-05-14 13:09 - 2015-04-21 07:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-05-14 13:09 - 2015-04-21 07:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2015-05-14 13:09 - 2015-04-21 07:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2015-05-14 13:09 - 2015-04-21 07:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-05-14 13:09 - 2015-04-21 07:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2015-05-14 13:09 - 2015-04-21 07:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-05-14 13:09 - 2015-04-21 07:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-14 13:09 - 2015-04-21 07:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-14 13:09 - 2015-04-21 07:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-14 13:09 - 2015-04-21 07:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2015-05-14 13:09 - 2015-04-21 07:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-14 13:09 - 2015-04-21 07:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-14 13:09 - 2015-04-21 07:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-05-14 13:09 - 2015-04-21 07:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-14 13:09 - 2015-04-21 07:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2015-05-14 13:09 - 2015-04-21 07:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2015-05-14 13:09 - 2015-04-21 07:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-14 13:09 - 2015-04-21 06:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-14 13:09 - 2015-04-21 06:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-14 13:09 - 2015-04-17 19:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll
2015-05-14 13:09 - 2015-04-17 18:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-14 13:04 - 2015-04-12 19:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\System32\services.exe
2015-05-14 13:02 - 2015-04-07 19:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\System32\InkEd.dll
2015-05-14 13:02 - 2015-04-07 19:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-05-14 12:55 - 2015-04-19 19:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2015-05-14 12:55 - 2015-04-19 19:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\System32\FntCache.dll
2015-05-14 12:55 - 2015-04-19 18:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-14 12:55 - 2015-04-19 18:11 - 03204608 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2015-05-14 12:33 - 2015-02-17 23:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-05-14 12:33 - 2015-02-17 23:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\System32\poqexec.exe
2015-05-14 12:24 - 2015-04-27 11:23 - 01254400 _____ (Microsoft Corporation) C:\Windows\System32\diagtrack.dll
2015-05-14 12:24 - 2015-04-27 10:06 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\UtcResources.dll
2015-05-14 12:23 - 2015-04-27 11:28 - 05569984 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2015-05-14 12:23 - 2015-04-27 11:28 - 00155584 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2015-05-14 12:23 - 2015-04-27 11:28 - 00095680 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2015-05-14 12:23 - 2015-04-27 11:26 - 01728960 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 01461760 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 01162752 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\System32\tdh.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00728064 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00314880 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00309760 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00215040 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00210944 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00136192 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00113664 _____ (Microsoft Corporation) C:\Windows\System32\sechost.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00029184 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2015-05-14 12:23 - 2015-04-27 11:23 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2015-05-14 12:23 - 2015-04-27 11:22 - 00404992 _____ (Microsoft Corporation) C:\Windows\System32\tracerpt.exe
2015-05-14 12:23 - 2015-04-27 11:22 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe
2015-05-14 12:23 - 2015-04-27 11:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2015-05-14 12:23 - 2015-04-27 11:22 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe
2015-05-14 12:23 - 2015-04-27 11:22 - 00104448 _____ (Microsoft Corporation) C:\Windows\System32\logman.exe
2015-05-14 12:23 - 2015-04-27 11:22 - 00047104 _____ (Microsoft Corporation) C:\Windows\System32\typeperf.exe
2015-05-14 12:23 - 2015-04-27 11:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\relog.exe
2015-05-14 12:23 - 2015-04-27 11:22 - 00031232 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2015-05-14 12:23 - 2015-04-27 11:22 - 00019456 _____ (Microsoft Corporation) C:\Windows\System32\diskperf.exe
2015-05-14 12:23 - 2015-04-27 11:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
2015-05-14 12:23 - 2015-04-27 11:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
2015-05-14 12:23 - 2015-04-27 11:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00686080 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 11:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-05-14 12:23 - 2015-04-27 11:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-05-14 12:23 - 2015-04-27 11:08 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-05-14 12:23 - 2015-04-27 11:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-05-14 12:23 - 2015-04-27 11:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-05-14 12:23 - 2015-04-27 11:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-05-14 12:23 - 2015-04-27 11:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-05-14 12:23 - 2015-04-27 11:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-05-14 12:23 - 2015-04-27 11:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-05-14 12:23 - 2015-04-27 11:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-05-14 12:23 - 2015-04-27 11:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-05-14 12:23 - 2015-04-27 11:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-05-14 12:23 - 2015-04-27 11:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-05-14 12:23 - 2015-04-27 11:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-05-14 12:23 - 2015-04-27 11:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-05-14 12:23 - 2015-04-27 11:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-05-14 12:23 - 2015-04-27 11:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-05-14 12:23 - 2015-04-27 11:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-05-14 12:23 - 2015-04-27 11:04 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-05-14 12:23 - 2015-04-27 11:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-05-14 12:23 - 2015-04-27 11:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-05-14 12:23 - 2015-04-27 11:03 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-05-14 12:23 - 2015-04-27 11:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-05-14 12:23 - 2015-04-27 11:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-05-14 12:23 - 2015-04-27 11:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-05-14 12:23 - 2015-04-27 11:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-05-14 12:23 - 2015-04-27 11:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-05-14 12:23 - 2015-04-27 11:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 10:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 09:57 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-05-14 12:23 - 2015-04-27 09:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-05-14 12:23 - 2015-04-27 09:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 09:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 09:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-14 12:23 - 2015-04-27 09:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-14 09:50 - 2015-01-28 19:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\System32\wpdshext.dll
2015-05-14 09:50 - 2015-01-28 19:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-05-14 09:41 - 2015-03-03 20:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\System32\apphelp.dll
2015-05-14 09:41 - 2015-03-03 20:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\System32\aelupsvc.dll
2015-05-14 09:41 - 2015-03-03 20:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\System32\sdbinst.exe
2015-05-14 09:41 - 2015-03-03 20:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\shimeng.dll
2015-05-14 09:41 - 2015-03-03 20:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-05-14 09:41 - 2015-03-03 20:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-05-14 09:41 - 2015-03-03 20:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-13 02:31 - 2015-05-18 01:10 - 00000000 ____D () C:\FRST
2015-05-11 13:42 - 2015-05-11 13:32 - 00540072 _____ (Neuber Software) C:\Users\hermann\Desktop\SvchostAnalyzer.exe
2015-05-11 03:17 - 2015-05-17 14:46 - 00000728 _____ () C:\Windows\setupact.log
2015-05-11 03:17 - 2015-05-11 03:17 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-09 08:04 - 2015-05-16 14:09 - 00000000 ____D () C:\AdwCleaner
2015-05-09 08:03 - 2015-05-09 08:03 - 02204160 _____ () C:\Users\hermann\Downloads\adwcleaner_4.203.exe
2015-04-21 23:05 - 2015-05-14 08:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-04-19 12:25 - 2015-04-19 12:25 - 00027648 _____ (G Data Software AG) C:\Windows\System32\Drivers\GDKBB64.sys
2015-04-19 12:25 - 2015-04-19 12:25 - 00000000 ____H () C:\Windows\System32\Drivers\Msft_Kernel_GDKBB64_01007.Wdf

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-17 14:56 - 2010-03-04 16:03 - 01244870 _____ () C:\Windows\WindowsUpdate.log
2015-05-17 14:56 - 2009-07-13 20:45 - 00026192 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-17 14:56 - 2009-07-13 20:45 - 00026192 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-17 14:55 - 2013-07-20 21:34 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{0406F3A2-4020-4F5B-B4A5-FDA2167DB720}
2015-05-17 14:47 - 2012-11-01 05:51 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-17 14:46 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-17 13:57 - 2012-11-01 05:51 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-17 12:52 - 2012-11-01 05:51 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-17 12:52 - 2012-11-01 05:51 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-16 13:21 - 2009-11-07 19:20 - 03853888 _____ () C:\Windows\System32\perfh007.dat
2015-05-16 13:21 - 2009-11-07 19:20 - 01159568 _____ () C:\Windows\System32\perfc007.dat
2015-05-16 13:21 - 2009-07-13 21:13 - 00006508 _____ () C:\Windows\System32\PerfStringBackup.INI
2015-05-15 11:06 - 2014-02-28 01:41 - 00000000 __SHD () C:\#GDATA.Trash.Store#
2015-05-14 22:21 - 2009-07-13 20:45 - 00447512 _____ () C:\Windows\System32\FNTCACHE.DAT
2015-05-14 22:17 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\System32\AdvancedInstallers
2015-05-14 14:17 - 2009-11-07 11:39 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-05-14 14:16 - 2013-07-12 12:01 - 00000000 ____D () C:\Windows\System32\MRT
2015-05-14 14:08 - 2010-04-10 12:24 - 140425016 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2015-05-12 14:10 - 2013-07-18 01:48 - 00007666 _____ () C:\Users\hermann\AppData\Local\Resmon.ResmonCfg
2015-05-12 13:25 - 2010-05-15 23:07 - 00000000 ____D () C:\Users\hermann\FCMP
2015-05-12 13:04 - 2010-05-08 12:56 - 00000000 ____D () C:\Users\hermann\Geschäft
2015-05-12 13:04 - 2010-04-01 05:59 - 00000000 ____D () C:\users\hermann
2015-05-11 01:05 - 2010-04-01 06:18 - 00000000 ____D () C:\Users\hermann\AppData\Roaming\HpUpdate
2015-05-10 12:35 - 2015-01-27 01:50 - 00018160 _____ (G Data Software) C:\Windows\System32\Drivers\GdPhyMem.sys
2015-05-10 12:35 - 2010-04-13 01:39 - 00106272 _____ (G Data Software) C:\Windows\System32\Drivers\GRD.sys
2015-05-10 12:34 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\System32\NDF
2015-05-10 12:23 - 2009-07-13 19:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-05-09 11:49 - 2010-06-24 21:24 - 00000000 ____D () C:\Users\hermann\Documents\Schriftverkehr
2015-05-09 11:20 - 2010-04-13 04:17 - 00000000 ____D () C:\Users\hermann\Documents\Turbo Lister Backup
2015-05-08 11:10 - 2014-02-28 01:54 - 00000000 ____D () C:\Users\hermann\PC Fritzbox Anleitungen
2015-05-07 10:15 - 2013-11-04 11:17 - 00031214 _____ () C:\Users\hermann\Desktop\hermjos Ebay nicht verkauft.xlsx
2015-05-03 10:41 - 2013-11-10 09:39 - 00010222 _____ () C:\Users\hermann\Desktop\kosmea verkauft nicht verkauft.xlsx
2015-05-02 23:37 - 2013-12-27 08:52 - 00000000 ___RD () C:\Users\hermann\Dropbox
2015-05-02 23:37 - 2013-12-27 08:46 - 00000000 ____D () C:\Users\hermann\AppData\Roaming\Dropbox
2015-05-02 23:36 - 2013-12-27 08:52 - 00001025 _____ () C:\Users\hermann\Desktop\Dropbox.lnk
2015-04-26 22:58 - 2010-05-07 22:06 - 00000000 ____D () C:\Users\hermann\Ebay
2015-04-26 21:15 - 2012-04-10 14:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-26 14:16 - 2012-04-10 14:31 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-26 14:16 - 2012-04-10 14:31 - 00003824 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-26 14:16 - 2011-09-11 07:44 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-26 00:17 - 2012-12-12 12:41 - 00000061 _____ () C:\Users\hermann\Desktop\uploader.cfg
2015-04-22 22:01 - 2015-01-04 09:39 - 00001931 _____ () C:\Users\Public\Desktop\G DATA TOTAL PROTECTION.lnk
2015-04-22 22:01 - 2014-02-28 01:09 - 00098760 _____ (G Data Software) C:\Windows\System32\Drivers\TS4nt.sys
2015-04-22 21:59 - 2010-04-13 01:25 - 00064512 _____ (G Data Software AG) C:\Windows\System32\Drivers\gdwfpcd64.sys
2015-04-22 21:43 - 2012-05-05 08:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-19 12:32 - 2010-04-13 01:26 - 00075776 _____ (G Data Software AG) C:\Windows\System32\Drivers\PktIcpt.sys
2015-04-19 12:24 - 2014-04-13 00:47 - 00020992 _____ (G Data Software AG) C:\Windows\System32\Drivers\GDKBFlt64.sys
2015-04-19 12:24 - 2014-02-28 01:08 - 00124928 _____ (G Data Software AG) C:\Windows\System32\Drivers\HookCentre.sys
2015-04-19 12:24 - 2010-04-13 01:26 - 00230400 _____ (G Data Software AG) C:\Windows\System32\Drivers\MiniIcpt.sys
2015-04-19 12:24 - 2010-04-13 01:25 - 00150016 _____ (G Data Software AG) C:\Windows\System32\Drivers\GDBehave.sys

Files to move or delete:
====================
C:\ProgramData\hpe17BB.dll


Some content of TEMP:
====================
C:\Users\hermann\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmptmej_l.dll
C:\Users\hermann\AppData\Local\Temp\Quarantine.exe
C:\Users\hermann\AppData\Local\Temp\sqlite3.dll
C:\Users\hermann\AppData\Local\Temp\VSafe100Vista.exe


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2015-05-14 13:04] - [2015-04-12 19:28] - 0328704 ____A (Microsoft Corporation) 71C85477DF9347FE8E7BC55768473FCA

C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points  =========================

Restore point made on: 2015-04-27 22:08:02
Restore point made on: 2015-04-30 22:30:05
Restore point made on: 2015-05-05 22:13:16
Restore point made on: 2015-05-12 03:29:37
Restore point made on: 2015-05-14 08:22:17
Restore point made on: 2015-05-14 08:25:32
Restore point made on: 2015-05-14 08:26:53
Restore point made on: 2015-05-14 13:59:08

==================== Memory info ===========================

Percentage of memory in use: 18%
Total physical RAM: 3998.93 MB
Available physical RAM: 3243.48 MB
Total Pagefile: 3997.07 MB
Available Pagefile: 3231.13 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:285.22 GB) (Free:199.25 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (RECOVERY) (Fixed) (Total:12.68 GB) (Free:2.12 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive g: (STORE'N'GO) (Removable) (Total:0.94 GB) (Free:0.87 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 5B1FB528)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=285.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=12.7 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 964 MB) (Disk ID: 91F72D24)
Partition 1: (Not Active) - (Size=964 MB) - (Type=06)


LastRegBack: 2015-05-03 20:56

==================== End Of Log ============================

--- --- ---

--- --- ---


Hallo Sandra,
ich habe mal einen Restore versucht.
Er zeigt mir folgenden Fehler: 0x80070002
System Restore did not complete

Bootsektor 18.05.2015 22:33

Hallo,

auch das sieht so nicht weiter ungewöhnlich aus. Ich hab dich jetzt schon mehrfach gefragt, ob du das Problem zeitlich eingrenzen kannst.

Schritt 1
Bitte nochmals im abgesicherten Modus:

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

SaveMbr: drive=0
SaveMbr: drive=1


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Schritt 2
Bitte schalte mal dein Antivirus aus und teste ob es besser dadurch ist.

H.J.Koch 18.05.2015 22:46

Hall Sandra,
Am 14.5. habe ich darauf geantwortet: Das Problem trat erstmalig vor etwa 2 Wochen auf. Ich habe daraufhin den awdcleaner benutzt und entsprechende Dateien gelöscht. Erneutes Problem letzte Woche. Awdcleaner findet nichts mehr.

Bootsektor 18.05.2015 22:48

Hallo Hermann,

dann entschuldige bitte, das hatte ich dann wohl überlesen. Kannst du mal schauen, ob du das alte AdwarecleanerLog noch findest?

H.J.Koch 19.06.2015 20:53

Hallo Sandra, ich habe zwischenzeitlich Windows 7 neu aufspielen lassen, weil ich den Pc unbedingt brauche. Jetzt funktioniert er wieder fehlerfrei. Vielen Dank für Deine Mühe. Mit freundlichen Grüßen H.J.Koch


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:22 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55