Malwarebytes Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 25.10.2015
Suchlaufzeit: 08:24
Protokolldatei: Logfile.txt
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2015.10.25.01
Rootkit-Datenbank: v2015.10.23.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: MERCURY
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 477666
Abgelaufene Zeit: 17 Min., 56 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 43
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaPlus_1.3dV24.10, In Quarantäne, [4cd9f566d3b860d66089ff57e71c7e82],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\include, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\include\tools, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\lib, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\module, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\pack, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\en, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\en-US, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\es, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\es-419, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr-BE, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr-CA, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr-CH, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr-LU, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\it, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\it-CH, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\pl, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\pt-BR, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\ru, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\ru-MO, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\tr, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\vi, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\zh-CN, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\zh-TW, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\defaults, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\defaults\preferences, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.GlobalUpdate, C:\Users\MERCURY\AppData\Local\Temp\comh.344638, In Quarantäne, [48ddc2996625a690e337183c9b679c64],
PUP.Optional.MaxDriverUpdater, C:\Program Files (x86)\MaxDrivrUpdater_v121.4491, In Quarantäne, [24018ad12c5f0630e7923028d52d8c74],
PUP.Optional.MaxDriverUpdater, C:\Users\MERCURY\AppData\Local\Temp\MAXDriverUpdater, In Quarantäne, [2401f5667b105fd7c8b3441430d2d030],
PUP.Optional.MBot, C:\Program Files (x86)\mbot_de_014010123, In Quarantäne, [4ed71e3dbdce79bd443a5bfd22e055ab],
PUP.Optional.MindSpark, C:\Users\MERCURY\AppData\LocalLow\Allin1Convert_8h, In Quarantäne, [de47f16aa9e23df97424ee6cd0324db3],
PUP.Optional.MindSpark, C:\Users\MERCURY\AppData\LocalLow\Allin1Convert_8hEI, In Quarantäne, [28fd4b105932c2746a2ee07af90922de],
PUP.Optional.MindSpark, C:\Users\MERCURY\AppData\LocalLow\Allin1Convert_8hEI\Installr, In Quarantäne, [28fd4b105932c2746a2ee07af90922de],
PUP.Optional.MindSpark, C:\Users\MERCURY\AppData\LocalLow\Allin1Convert_8hEI\Installr\Cache, In Quarantäne, [28fd4b105932c2746a2ee07af90922de],
PUP.Optional.Jogotempo.ShrtCln, C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\jogotempo, In Quarantäne, [34f1f6651a7192a4202c1557f60c9967],
Dateien: 66
PUP.Optional.CrossRider, C:\Program Files (x86)\CinemaPlus_1.3dV24.10\bgNova.html, In Quarantäne, [4cd9f566d3b860d66089ff57e71c7e82],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome.manifest, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\install.rdf, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\index.html, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\quick_start.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\quick_start.xul, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\include\speed_dial.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\include\tools\about_blank_hook.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\include\tools\misc.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\include\tools\popup_image_helper.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\include\tools\urlrequestor.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\lib\doT.min.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\lib\jquery-2.1.0.min.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\lib\jquery.autocomplete.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\module\hotSearch.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\module\mostgrid.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\module\search.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\module\stat.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\pack\common.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\pack\ga.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\content\js\pack\xagainit.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\en\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\en-US\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\es\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\es-419\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr-BE\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr-CA\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr-CH\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\fr-LU\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\it\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\it-CH\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\pl\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\pt-BR\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\ru\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\ru-MO\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\tr\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\vi\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\zh-CN\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\locale\zh-TW\locale.properties, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\default_logo.png, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\googlelogo.png, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\google_trends.png, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\icon.png, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\loading.gif, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\logo.png, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\luck.png, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\newtab.ico, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\simple.css, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\chrome\skin\style.css, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\defaults\preferences\fvd.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\defaults\preferences\preferences.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\addonmanager.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\aes.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\config.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\dialogs.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\last_tab.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\misc.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\properties.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\remoterequest.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\restoreprefs.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\extensions\deskCutv2@gmail.com\modules\settings.js, In Quarantäne, [ca5b60fbd9b2b08659b8da76bf43dc24],
PUP.Optional.MindSpark, C:\Users\MERCURY\AppData\LocalLow\Allin1Convert_8hEI\Installr\Cache\0016304C.exe, In Quarantäne, [28fd4b105932c2746a2ee07af90922de],
PUP.Optional.MindSpark, C:\Users\MERCURY\AppData\LocalLow\Allin1Convert_8hEI\Installr\Cache\files.ini, In Quarantäne, [28fd4b105932c2746a2ee07af90922de],
PUP.Optional.QuickStart, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), Ersetzt,[21041744dfac32043a9c490e13f17c84]
PUP.Optional.DeskCut, C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\prefs.js, Gut: (), Schlecht: (deskCutv2@gmail.com), Ersetzt,[4ed71546b8d3f046e5b3cc92d72dc33d]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end)
Adware Code:
# AdwCleaner v5.014 - Bericht erstellt am 25/10/2015 um 08:54:03
# Aktualisiert am 18/10/2015 von Xplode
# Datenbank : 2015-10-18.5 [Server]
# Betriebssystem : Windows 10 Home (x64)
# Benutzername : MERCURY - BILLY
# Gestartet von : C:\Users\MERCURY\Downloads\AdwCleaner_5.014.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
[-] Ordner Gelöscht : C:\Program Files (x86)\RayDld
[-] Ordner Gelöscht : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\ScreenSnapshotTool
***** [ Dateien ] *****
[-] Datei Gelöscht : C:\END
***** [ DLLs ] *****
***** [ Verknüpfungen ] *****
***** [ Geplante Tasks ] *****
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{363F46BE-27B4-4C8D-99E7-B1E049B84376}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{90A9B7D2-3794-45EA-9E23-140E3938D2D9}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A753A1EC-973E-4718-AF8E-A3F554D45C44}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02AFA80F-4BEE-41FD-8572-214B58A9EF90}
[-] Schlüssel Gelöscht : HKCU\Software\OCS
[!] Schlüssel Nicht Gelöscht : [x64] HKCU\Software\OCS
***** [ Internetbrowser ] *****
[-] [C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\prefs.js] [Preference] Gelöscht : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
[-] [C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\prefs.js] [Preference] Gelöscht : user_pref("extensions.quick_start.enable_search1", false);
[-] [C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\prefs.js] [Preference] Gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
*************************
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Chrome Richtlinien gelöscht
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1969 Bytes] ##########
junkware Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 10 Home x64
Ran by MERCURY on 25.10.2015 at 8:58:20,75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\Users\MERCURY\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\users\Public\Documents\guid
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.10.2015 at 9:02:17,90
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ frst Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:25-10-2015
durchgeführt von MERCURY (Administrator) auf BILLY (25-10-2015 09:07:58)
Gestartet von C:\Users\MERCURY\Downloads
Geladene Profile: MERCURY (Verfügbare Profile: MERCURY & Gast)
Platform: Windows 10 Home (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Emsisoft Ltd) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Emsisoft Ltd) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\reader_sl.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [519408 2013-07-18] (Acronis)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-09-15] (Apple Inc.)
HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft anti-malware\a2guard.exe [5836888 2015-10-01] (Emsisoft Ltd)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [7843744 2014-02-04] (Acronis)
HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1104616 2013-10-10] (Acronis International GmbH)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-16] (Apple Inc.)
HKLM-x32\...\Run: [Syncios device service] => C:\Program Files (x86)\Syncios\SynciosDeviceService.exe
HKU\S-1-5-21-4024391792-2930209080-385294340-1001\...\Run: [Spotify Web Helper] => C:\Users\MERCURY\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2025016 2015-09-19] (Spotify Ltd)
HKU\S-1-5-21-4024391792-2930209080-385294340-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-4024391792-2930209080-385294340-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-4024391792-2930209080-385294340-1001\...\Run: [AudialsNotifier] => C:\Program Files (x86)\Audials\Audials 12\AudialsNotifier.exe [2412440 2015-09-18] ()
HKU\S-1-5-21-4024391792-2930209080-385294340-1001\...\Run: [Dropbox Update] => C:\Users\MERCURY\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-21] (Dropbox, Inc.)
HKU\S-1-5-21-4024391792-2930209080-385294340-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-4024391792-2930209080-385294340-1001\...\RunOnce: [Uninstall C:\Users\MERCURY\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\MERCURY\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64"
HKU\S-1-5-21-4024391792-2930209080-385294340-1001\...\RunOnce: [Uninstall C:\Users\MERCURY\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\MERCURY\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64"
HKU\S-1-5-18\...\RunOnce: [iCloud] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe [43816 2014-12-01] (Apple Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\MERCURY\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\MERCURY\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\MERCURY\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\MERCURY\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\MERCURY\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\MERCURY\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\MERCURY\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\MERCURY\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] ()
ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] ()
ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] ()
Startup: C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2015-10-25]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
Startup: C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-10-25]
ShortcutTarget: Dropbox.lnk -> C:\Users\MERCURY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{a0a490e2-89f6-4e4a-a04c-a750cf07901a}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-08-04] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-18] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-18] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-10-17] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-17] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-07-11] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-18] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-01-27] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Extension: ColorfulTabs - C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\Extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} [2015-10-17]
FF Extension: FireFTP - C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\Extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} [2015-05-30]
FF Extension: anonymoX - C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\Extensions\client@anonymox.net.xpi [2015-09-30]
FF Extension: Ghostery - C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\Extensions\firefox@ghostery.com.xpi [2015-09-19]
FF Extension: yaBeat - YouTube to MP3 - C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\Extensions\jid0-uqZgom7deYId1IGHnMog6eoQ2cI@jetpack.xpi [2015-05-30]
FF Extension: Google Selection Translate - For AltKey - C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\Extensions\jid1-f7dnBeTj8ElpOQ@jetpack.xpi [2015-09-13]
FF Extension: Zoom Page - C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\Extensions\zoompage@DW-dev.xpi [2015-10-17]
FF Extension: ImTranslator - C:\Users\MERCURY\AppData\Roaming\Mozilla\Firefox\Profiles\k89j4gwx.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2015-10-17]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [7084784 2015-10-01] (Emsisoft Ltd)
S2 AAV UpdateService; C:\Programme (x86)\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2774104 2015-09-11] (Microsoft Corporation)
S2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-07-17] (Intel Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448464 2015-03-30] (TeamViewer GmbH)
S2 Virtual CDAudio Service; C:\Program Files (x86)\Audials\Audials 12\VCDWriter\64\VCDAudioService.exe [179608 2015-09-18] (RapidSolution Software AG)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 epp64; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\epp64.sys [138504 2015-10-01] (Emsisoft GmbH)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-10-25] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-08-28] (Intel Corporation)
R1 RrNetCapFilterDriver; C:\Windows\system32\DRIVERS\RrNetCapFilterDriver.sys [25256 2015-04-21] (Audials AG)
R3 rsvcdwdr; C:\Windows\System32\drivers\rsvcdwdr.sys [45192 2015-04-21] (RapidSolution Software AG)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2015-01-25] (Acronis International GmbH)
S0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [198432 2015-01-25] (Acronis International GmbH)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-10-25 09:06 - 2015-10-25 09:06 - 02196992 _____ (Farbar) C:\Users\MERCURY\Downloads\FRST64.exe
2015-10-25 09:02 - 2015-10-25 09:02 - 00000737 _____ C:\Users\MERCURY\Desktop\JRT.txt
2015-10-25 08:58 - 2015-10-05 23:23 - 01801288 _____ (Malwarebytes) C:\Users\MERCURY\Desktop\JRT.exe
2015-10-25 08:55 - 2015-10-25 08:55 - 00016148 _____ C:\WINDOWS\system32\BILLY_MERCURY_HistoryPrediction.bin
2015-10-25 08:53 - 2015-10-25 08:54 - 00000000 ____D C:\AdwCleaner
2015-10-25 08:47 - 2015-10-25 08:47 - 00000000 ___HD C:\OneDriveTemp
2015-10-25 08:33 - 2015-10-25 08:57 - 01798976 _____ (Malwarebytes) C:\Users\MERCURY\Downloads\JRT.exe
2015-10-25 08:32 - 2015-10-25 08:52 - 01691648 _____ C:\Users\MERCURY\Downloads\AdwCleaner_5.014.exe
2015-10-25 08:23 - 2015-10-25 08:56 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-10-25 08:22 - 2015-10-25 08:43 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-10-25 08:22 - 2015-10-25 08:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-10-25 08:22 - 2015-10-25 08:22 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-10-25 08:22 - 2015-10-25 08:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-25 08:22 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-10-25 08:22 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-10-25 08:22 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-25 08:19 - 2015-10-25 08:22 - 22908888 _____ (Malwarebytes ) C:\Users\MERCURY\Downloads\mbam-setup-2.2.0.1024.exe
2015-10-24 17:40 - 2015-10-24 17:40 - 00000000 ____D C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-10-24 16:34 - 2015-10-24 16:44 - 00041917 _____ C:\Users\MERCURY\Downloads\Addition.txt
2015-10-24 16:33 - 2015-10-25 09:07 - 00015423 _____ C:\Users\MERCURY\Downloads\FRST.txt
2015-10-24 16:19 - 2015-10-24 16:19 - 00000000 ____D C:\Users\MERCURY\AppData\Roaming\Opera Software
2015-10-24 16:19 - 2015-10-24 16:19 - 00000000 ____D C:\Users\MERCURY\AppData\Local\Opera Software
2015-10-24 16:15 - 2015-10-24 16:22 - 00000000 ____D C:\Program Files (x86)\Opera
2015-10-24 16:14 - 2015-10-24 16:14 - 00000000 ____D C:\Users\Public\Documents\Baidu
2015-10-17 14:13 - 2015-10-17 14:13 - 00000000 ____D C:\Users\MERCURY\AppData\Roaming\PhotoSync
2015-10-17 14:11 - 2015-10-25 08:43 - 00002597 _____ C:\Users\Public\Desktop\PhotoSync.lnk
2015-10-17 14:11 - 2015-10-17 14:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoSync
2015-10-17 13:59 - 2015-10-24 17:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2015-10-17 10:11 - 2015-10-17 10:36 - 71807792 _____ (Apple Inc.) C:\Users\MERCURY\Downloads\iCloudSetup(2).exe
2015-10-17 09:59 - 2015-10-17 14:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-10-14 12:54 - 2015-10-10 08:12 - 00078528 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-14 12:54 - 2015-10-10 07:40 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-14 12:54 - 2015-10-10 07:07 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-14 12:54 - 2015-10-06 04:03 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-14 12:54 - 2015-10-06 03:46 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-14 12:54 - 2015-10-01 05:01 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-10-14 12:54 - 2015-10-01 05:01 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-10-14 12:54 - 2015-10-01 05:01 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-10-14 12:54 - 2015-10-01 05:01 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-10-14 12:54 - 2015-10-01 05:00 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-14 12:54 - 2015-10-01 04:03 - 00757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2015-10-14 12:54 - 2015-09-25 05:01 - 02573768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-10-14 12:54 - 2015-09-25 05:01 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-10-14 12:54 - 2015-09-25 04:56 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-10-14 12:54 - 2015-09-25 04:52 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-10-14 12:54 - 2015-09-25 04:33 - 01997336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-10-14 12:54 - 2015-09-25 04:26 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-10-14 12:54 - 2015-09-25 04:17 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-14 12:54 - 2015-09-25 04:11 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-14 12:54 - 2015-09-25 04:11 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-14 12:54 - 2015-09-25 04:09 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-10-14 12:54 - 2015-09-25 04:07 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-14 12:54 - 2015-09-25 04:04 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-14 12:54 - 2015-09-25 04:04 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-10-14 12:54 - 2015-09-25 04:04 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-14 12:54 - 2015-09-25 04:03 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-14 12:54 - 2015-09-25 04:03 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-10-14 12:54 - 2015-09-25 04:02 - 07523840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-14 12:54 - 2015-09-25 04:02 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-10-14 12:54 - 2015-09-25 04:02 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-14 12:54 - 2015-09-25 04:02 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-14 12:54 - 2015-09-25 04:01 - 04792320 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-14 12:54 - 2015-09-25 04:01 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-14 12:54 - 2015-09-25 04:00 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-14 12:54 - 2015-09-25 04:00 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-14 12:54 - 2015-09-25 04:00 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-14 12:54 - 2015-09-25 04:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-14 12:54 - 2015-09-25 03:59 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-14 12:54 - 2015-09-25 03:59 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-14 12:54 - 2015-09-25 03:59 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-14 12:54 - 2015-09-25 03:59 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-14 12:54 - 2015-09-25 03:59 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-14 12:54 - 2015-09-25 03:59 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-14 12:54 - 2015-09-25 03:59 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-14 12:54 - 2015-09-25 03:58 - 01871360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-10-14 12:54 - 2015-09-25 03:48 - 19325952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-14 12:54 - 2015-09-25 03:47 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-14 12:54 - 2015-09-25 03:47 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-14 12:54 - 2015-09-25 03:38 - 03580416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-14 12:54 - 2015-09-25 03:38 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-10-14 12:54 - 2015-09-25 03:38 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-14 12:54 - 2015-09-25 03:38 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-10-14 12:54 - 2015-09-25 03:37 - 00766976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-10-14 12:54 - 2015-09-25 03:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-14 12:54 - 2015-09-25 03:37 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-14 12:54 - 2015-09-25 03:36 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-10-14 12:54 - 2015-09-25 03:36 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-14 12:54 - 2015-09-25 03:34 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-14 12:54 - 2015-09-25 03:34 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-14 12:54 - 2015-09-25 03:34 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-14 12:54 - 2015-09-25 03:34 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-14 12:54 - 2015-09-25 03:34 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-14 12:54 - 2015-09-25 03:33 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-14 12:54 - 2015-09-25 03:32 - 01594368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-10-14 12:54 - 2015-09-25 03:32 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-04 10:55 - 2015-10-04 11:05 - 58777218 _____ C:\Users\MERCURY\Downloads\Ecos Audio - Supersticiones_2.wma
2015-10-04 10:54 - 2015-10-04 11:07 - 73507735 _____ C:\Users\MERCURY\Downloads\Letzter Gruss aus Granada_2.wma
2015-10-01 11:25 - 2015-09-19 06:14 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-10-01 11:25 - 2015-09-17 07:50 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-10-01 11:25 - 2015-09-17 07:50 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-10-01 11:25 - 2015-09-17 07:50 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-10-01 11:25 - 2015-09-17 07:50 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-01 11:25 - 2015-09-17 07:49 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-10-01 11:25 - 2015-09-17 07:49 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-10-01 11:25 - 2015-09-17 07:49 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-10-01 11:25 - 2015-09-17 07:49 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-01 11:25 - 2015-09-17 07:49 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-10-01 11:25 - 2015-09-17 07:48 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-10-01 11:25 - 2015-09-17 07:48 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-10-01 11:25 - 2015-09-17 07:48 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-10-01 11:25 - 2015-09-17 07:48 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-01 11:25 - 2015-09-17 07:48 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-10-01 11:25 - 2015-09-17 07:48 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-10-01 11:25 - 2015-09-17 07:48 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-10-01 11:25 - 2015-09-17 07:48 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-10-01 11:25 - 2015-09-17 07:48 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-10-01 11:25 - 2015-09-17 07:47 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-01 11:25 - 2015-09-17 07:44 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-10-01 11:25 - 2015-09-17 07:43 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-01 11:25 - 2015-09-17 07:37 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-10-01 11:25 - 2015-09-17 07:37 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-10-01 11:25 - 2015-09-17 07:28 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-10-01 11:25 - 2015-09-17 07:28 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-10-01 11:25 - 2015-09-17 07:28 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-10-01 11:25 - 2015-09-17 07:28 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-10-01 11:25 - 2015-09-17 07:28 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-10-01 11:25 - 2015-09-17 07:28 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-10-01 11:25 - 2015-09-17 07:27 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-10-01 11:25 - 2015-09-17 07:27 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-10-01 11:25 - 2015-09-17 07:26 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-10-01 11:25 - 2015-09-17 07:26 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-10-01 11:25 - 2015-09-17 07:26 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-10-01 11:25 - 2015-09-17 07:26 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-10-01 11:25 - 2015-09-17 07:26 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-10-01 11:25 - 2015-09-17 07:26 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-10-01 11:25 - 2015-09-17 07:25 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-01 11:25 - 2015-09-17 07:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-10-01 11:25 - 2015-09-17 07:20 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-10-01 11:25 - 2015-09-17 07:11 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-10-01 11:25 - 2015-09-17 07:10 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-10-01 11:25 - 2015-09-17 07:09 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-10-01 11:25 - 2015-09-17 07:09 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-10-01 11:25 - 2015-09-17 07:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-10-01 11:25 - 2015-09-17 07:08 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-01 11:25 - 2015-09-17 07:08 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-01 11:25 - 2015-09-17 07:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-10-01 11:25 - 2015-09-17 07:06 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-10-01 11:25 - 2015-09-17 07:06 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-10-01 11:25 - 2015-09-17 07:05 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-01 11:25 - 2015-09-17 07:05 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-01 11:25 - 2015-09-17 07:04 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-10-01 11:25 - 2015-09-17 07:04 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-10-01 11:25 - 2015-09-17 07:04 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-01 11:25 - 2015-09-17 07:03 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-01 11:25 - 2015-09-17 07:03 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-10-01 11:25 - 2015-09-17 07:03 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-10-01 11:25 - 2015-09-17 07:03 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-10-01 11:25 - 2015-09-17 07:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-01 11:25 - 2015-09-17 07:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-10-01 11:25 - 2015-09-17 07:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-01 11:25 - 2015-09-17 07:00 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-01 11:25 - 2015-09-17 07:00 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-01 11:25 - 2015-09-17 07:00 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-10-01 11:25 - 2015-09-17 07:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-01 11:25 - 2015-09-17 06:58 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-10-01 11:25 - 2015-09-17 06:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-10-01 11:25 - 2015-09-17 06:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-10-01 11:25 - 2015-09-17 06:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-01 11:25 - 2015-09-17 06:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-01 11:25 - 2015-09-17 06:56 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-10-01 11:25 - 2015-09-17 06:56 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-01 11:25 - 2015-09-17 06:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-10-01 11:25 - 2015-09-17 06:55 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-10-01 11:25 - 2015-09-17 06:55 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-01 11:25 - 2015-09-17 06:55 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-10-01 11:25 - 2015-09-17 06:55 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-10-01 11:25 - 2015-09-17 06:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-10-01 11:25 - 2015-09-17 06:55 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-10-01 11:25 - 2015-09-17 06:55 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-10-01 11:25 - 2015-09-17 06:55 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-10-01 11:25 - 2015-09-17 06:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-10-01 11:25 - 2015-09-17 06:54 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-01 11:25 - 2015-09-17 06:54 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-01 11:25 - 2015-09-17 06:54 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 11:25 - 2015-09-17 06:53 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-10-01 11:25 - 2015-09-17 06:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-01 11:25 - 2015-09-17 06:51 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-01 11:25 - 2015-09-17 06:51 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-10-01 11:25 - 2015-09-17 06:51 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-01 11:25 - 2015-09-17 06:51 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-01 11:25 - 2015-09-17 06:51 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-10-01 11:25 - 2015-09-17 06:51 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-10-01 11:25 - 2015-09-17 06:50 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-01 11:25 - 2015-09-17 06:50 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-10-01 11:25 - 2015-09-17 06:50 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-01 11:25 - 2015-09-17 06:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-01 11:25 - 2015-09-17 06:50 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-10-01 11:25 - 2015-09-17 06:50 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-10-01 11:25 - 2015-09-17 06:49 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-10-01 11:25 - 2015-09-17 06:49 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-01 11:25 - 2015-09-17 06:49 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-10-01 11:25 - 2015-09-17 06:49 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-01 11:25 - 2015-09-17 06:49 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-10-01 11:25 - 2015-09-17 06:49 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-10-01 11:25 - 2015-09-17 06:49 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-01 11:25 - 2015-09-17 06:49 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-10-01 11:25 - 2015-09-17 06:49 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-01 11:25 - 2015-09-17 06:49 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-10-01 11:25 - 2015-09-17 06:48 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-10-01 11:25 - 2015-09-17 06:48 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-10-01 11:25 - 2015-09-17 06:48 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-01 11:25 - 2015-09-17 06:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-10-01 11:25 - 2015-09-17 06:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-10-01 11:25 - 2015-09-17 06:48 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-01 11:25 - 2015-09-17 06:47 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-10-01 11:25 - 2015-09-17 06:47 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-10-01 11:25 - 2015-09-17 06:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-10-01 11:25 - 2015-09-17 06:46 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-10-01 11:25 - 2015-09-17 06:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-10-01 11:25 - 2015-09-17 06:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-01 11:25 - 2015-09-17 06:46 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-10-01 11:25 - 2015-09-17 06:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-10-01 11:25 - 2015-09-17 06:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-01 11:25 - 2015-09-17 06:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-01 11:25 - 2015-09-17 06:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-10-01 11:25 - 2015-09-17 06:45 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-01 11:25 - 2015-09-17 06:45 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-10-01 11:25 - 2015-09-17 06:45 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-10-01 11:25 - 2015-09-17 06:45 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-01 11:25 - 2015-09-17 06:45 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-10-01 11:25 - 2015-09-17 06:44 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-10-01 11:25 - 2015-09-17 06:44 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-10-01 11:25 - 2015-09-17 06:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-10-01 11:25 - 2015-09-17 06:44 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-10-01 11:25 - 2015-09-17 06:43 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-01 11:25 - 2015-09-17 06:43 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-01 11:25 - 2015-09-17 06:43 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-10-01 11:25 - 2015-09-17 06:43 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-10-01 11:25 - 2015-09-17 06:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-01 11:25 - 2015-09-17 06:41 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-10-01 11:25 - 2015-09-17 06:40 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-10-01 11:25 - 2015-09-17 06:40 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-01 11:25 - 2015-09-17 06:40 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-10-01 11:25 - 2015-09-17 06:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-10-01 11:25 - 2015-09-17 06:39 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 11:25 - 2015-09-17 06:38 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-10-01 11:25 - 2015-09-17 06:37 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-10-01 11:25 - 2015-09-17 06:36 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-10-01 11:25 - 2015-09-17 06:35 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-10-01 11:25 - 2015-09-17 06:35 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-10-01 11:25 - 2015-09-17 06:35 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-10-01 11:25 - 2015-09-17 06:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-10-01 11:25 - 2015-09-17 06:34 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-01 11:25 - 2015-09-17 06:32 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-10-01 11:25 - 2015-09-17 06:32 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-10-01 11:25 - 2015-09-17 06:32 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-01 11:25 - 2015-09-17 06:31 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-10-01 11:25 - 2015-09-17 06:30 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-10-01 11:25 - 2015-09-17 06:29 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-10-01 11:25 - 2015-09-17 06:29 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-10-01 11:25 - 2015-09-17 06:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-10-01 11:25 - 2015-09-17 06:29 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-01 11:25 - 2015-09-17 06:28 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-10-01 11:25 - 2015-09-17 06:26 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-10-01 11:25 - 2015-09-17 06:16 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-10-01 11:25 - 2015-09-13 03:05 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-01 11:25 - 2015-09-13 02:41 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-09-30 14:29 - 2015-10-25 08:43 - 00000966 _____ C:\Users\Public\Desktop\Audials 12.lnk
2015-09-30 14:14 - 2015-10-25 08:17 - 00004154 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{DD6E9A90-2E3B-4A9E-82CF-290362D3D5B2}
2015-09-30 13:52 - 2015-09-30 14:05 - 00000000 ____D C:\Users\MERCURY\AppData\Roaming\iFunbox_UserCache
2015-09-30 12:48 - 2015-09-30 13:57 - 00000000 ____D C:\Users\MERCURY\Downloads\Spanisch lernen PONS Sprachkurs fur Anf303244nger [PONS GmbH] (v2 60 2 3GS Univ i8 os61)-teflon rc325
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-10-25 09:08 - 2015-06-21 14:57 - 00001244 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-4024391792-2930209080-385294340-1001UA.job
2015-10-25 09:07 - 2015-01-25 18:47 - 00000000 ____D C:\FRST
2015-10-25 09:03 - 2015-04-28 18:51 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-25 08:59 - 2015-01-16 14:06 - 00000000 ___DO C:\Users\MERCURY\SkyDrive
2015-10-25 08:56 - 2015-05-25 13:44 - 00000000 ___RD C:\Users\MERCURY\iCloudDrive
2015-10-25 08:56 - 2015-01-25 15:22 - 00000000 ____D C:\Users\MERCURY\AppData\Roaming\Dropbox
2015-10-25 08:56 - 2015-01-25 14:43 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware
2015-10-25 08:56 - 2014-05-07 16:22 - 00000000 ___RD C:\Users\MERCURY\Dropbox
2015-10-25 08:55 - 2015-07-29 14:13 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-10-25 08:55 - 2015-07-10 13:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-25 08:55 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-25 08:54 - 2015-07-29 14:09 - 00056310 _____ C:\WINDOWS\PFRO.log
2015-10-25 08:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-25 08:54 - 2015-07-10 10:05 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-10-25 08:50 - 2015-07-29 14:30 - 01790124 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-25 08:50 - 2015-07-10 17:34 - 00771100 _____ C:\WINDOWS\system32\perfh007.dat
2015-10-25 08:50 - 2015-07-10 17:34 - 00153964 _____ C:\WINDOWS\system32\perfc007.dat
2015-10-25 08:43 - 2015-09-19 12:33 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-10-25 08:43 - 2015-09-06 10:54 - 00002318 _____ C:\Users\MERCURY\Desktop\Kindle.lnk
2015-10-25 08:43 - 2015-09-06 10:46 - 00001200 _____ C:\Users\Public\Desktop\Epubor Ultimate.lnk
2015-10-25 08:43 - 2015-07-29 15:31 - 00001047 _____ C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk
2015-10-25 08:43 - 2015-07-29 15:21 - 00002360 _____ C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-10-25 08:43 - 2015-07-29 14:21 - 00001552 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-10-25 08:43 - 2015-07-22 12:12 - 00001492 _____ C:\Users\Public\Desktop\ElsterFormular.lnk
2015-10-25 08:43 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-25 08:43 - 2015-07-01 15:05 - 00001857 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2015-10-25 08:43 - 2015-06-28 17:09 - 00002119 _____ C:\Users\MERCURY\Desktop\JDownloader 2.lnk
2015-10-25 08:43 - 2015-06-08 12:52 - 00001484 _____ C:\Users\Public\Desktop\LibreOffice 4.3.lnk
2015-10-25 08:43 - 2015-05-20 16:09 - 00001167 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2015-10-25 08:43 - 2015-05-20 16:09 - 00001117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2015-10-25 08:43 - 2015-05-20 11:25 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-10-25 08:43 - 2015-05-20 11:25 - 00002067 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-10-25 08:43 - 2015-05-10 11:08 - 00002192 _____ C:\Users\Public\Desktop\Adobe Digital Editions 3.0.lnk
2015-10-25 08:43 - 2015-04-12 11:06 - 00001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-10-25 08:43 - 2015-04-12 11:06 - 00001043 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-10-25 08:43 - 2015-04-04 11:24 - 00001714 _____ C:\Users\Public\Desktop\Recuva.lnk
2015-10-25 08:43 - 2015-03-28 16:58 - 00000966 _____ C:\Users\MERCURY\Desktop\VirtualDJ 8.lnk
2015-10-25 08:43 - 2015-03-27 14:23 - 00001103 _____ C:\Users\Public\Desktop\RarZilla Free Unrar.lnk
2015-10-25 08:43 - 2015-03-07 13:47 - 00001849 _____ C:\Users\Public\Desktop\BILD Steuer 2015.lnk
2015-10-25 08:43 - 2015-02-25 11:37 - 00001524 _____ C:\Users\MERCURY\Desktop\RippMe - Verknüpfung.lnk
2015-10-25 08:43 - 2015-02-15 11:39 - 00001437 _____ C:\Users\MERCURY\Desktop\CopyTrans Control Center.lnk
2015-10-25 08:43 - 2015-02-04 13:57 - 00002073 _____ C:\Users\MERCURY\Desktop\waterMark V2.lnk
2015-10-25 08:43 - 2015-02-02 12:40 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-10-25 08:43 - 2015-01-31 10:41 - 00001144 _____ C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware Guard.lnk
2015-10-25 08:43 - 2015-01-31 10:00 - 00001336 _____ C:\Users\Public\Desktop\Freemake Video Converter.lnk
2015-10-25 08:43 - 2015-01-27 19:37 - 00001122 _____ C:\Users\Public\Desktop\Picasa 3.lnk
2015-10-25 08:43 - 2015-01-25 16:50 - 00000999 _____ C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk
2015-10-25 08:43 - 2015-01-25 16:14 - 00001217 _____ C:\Users\Public\Desktop\Acronis True Image 2014.lnk
2015-10-25 08:43 - 2015-01-25 15:41 - 00000991 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2015-10-25 08:43 - 2015-01-25 15:30 - 00001023 _____ C:\Users\MERCURY\Desktop\Dropbox.lnk
2015-10-25 08:43 - 2015-01-25 15:29 - 00001014 _____ C:\Users\MERCURY\Desktop\IrfanView.lnk
2015-10-25 08:43 - 2015-01-25 15:07 - 00001082 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-10-25 08:43 - 2015-01-25 14:56 - 00001823 _____ C:\Users\MERCURY\Desktop\Spotify.lnk
2015-10-25 08:43 - 2015-01-25 14:56 - 00001809 _____ C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-10-25 08:43 - 2015-01-25 14:49 - 00001171 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-10-25 08:43 - 2015-01-25 14:49 - 00001159 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-10-25 08:43 - 2015-01-25 14:43 - 00001103 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2015-10-25 08:43 - 2014-05-10 12:27 - 00000640 _____ C:\Users\MERCURY\Desktop\Total Commander.lnk
2015-10-24 19:09 - 2015-01-25 14:56 - 00000000 ____D C:\Users\MERCURY\AppData\Local\Spotify
2015-10-24 18:53 - 2015-01-25 14:53 - 00000000 ____D C:\Users\MERCURY\AppData\Roaming\Spotify
2015-10-24 17:32 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-24 17:11 - 2015-07-29 14:16 - 00000000 ____D C:\Users\MERCURY
2015-10-24 17:08 - 2015-09-19 12:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-10-24 17:08 - 2015-09-19 12:33 - 00000000 ____D C:\Program Files\iTunes
2015-10-24 17:08 - 2015-07-29 14:16 - 00000000 ___RD C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-24 17:08 - 2015-07-29 14:16 - 00000000 ____D C:\Users\Gast
2015-10-24 17:08 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-10-24 17:08 - 2015-02-24 13:50 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-10-24 17:08 - 2015-01-25 14:17 - 00000000 ___HD C:\$SysReset
2015-10-24 17:01 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\registration
2015-10-24 17:00 - 2015-06-28 17:07 - 00000000 ____D C:\Users\MERCURY\AppData\Local\JDownloader 2.0
2015-10-24 17:00 - 2015-05-25 13:44 - 00000000 ____D C:\Users\MERCURY\AppData\Local\Apple Inc
2015-10-24 16:59 - 2015-09-19 12:33 - 00000000 ____D C:\Program Files\iPod
2015-10-24 16:59 - 2015-02-02 12:40 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-10-24 14:21 - 2015-07-10 13:20 - 00054163 _____ C:\WINDOWS\setupact.log
2015-10-22 19:35 - 2015-09-06 10:46 - 00000000 ____D C:\Users\MERCURY\Ultimate
2015-10-22 19:35 - 2015-09-06 10:46 - 00000000 ____D C:\Users\MERCURY\AppData\Roaming\.Ultimate
2015-10-22 19:25 - 2014-11-12 12:05 - 00000000 ____D C:\Users\MERCURY\Documents\My Digital Editions
2015-10-18 13:08 - 2015-06-21 14:57 - 00001192 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-4024391792-2930209080-385294340-1001Core.job
2015-10-18 10:42 - 2015-01-25 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2015-10-18 10:42 - 2015-01-25 16:50 - 00000000 ____D C:\Program Files\Calibre2
2015-10-17 14:11 - 2015-01-25 15:45 - 00000000 ____D C:\Program Files (x86)\PhotoSync
2015-10-17 14:04 - 2015-02-02 12:41 - 00000000 ____D C:\Users\MERCURY\AppData\Roaming\Apple Computer
2015-10-17 14:00 - 2015-01-25 14:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-17 13:03 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-16 10:08 - 2015-05-20 11:25 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-10-16 10:08 - 2015-01-25 19:09 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-10-16 10:06 - 2015-01-25 19:09 - 143481208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-10-16 04:10 - 2015-07-10 12:06 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-16 04:10 - 2015-07-10 12:06 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-09 12:49 - 2014-05-07 15:28 - 00000000 ____D C:\Users\MERCURY\AppData\Local\Packages
2015-10-04 14:04 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-01 15:39 - 2015-09-06 10:54 - 00000000 ____D C:\Users\MERCURY\Documents\My Kindle Content
2015-10-01 15:05 - 2015-07-10 12:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-01 15:05 - 2015-07-10 12:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-01 15:05 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-01 15:05 - 2015-07-10 12:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-01 15:05 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-01 15:05 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-01 15:05 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-01 15:05 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-09-30 14:29 - 2015-05-30 14:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 12
2015-09-30 14:14 - 2015-02-02 12:41 - 00000000 __SHD C:\Users\MERCURY\AppData\Local\EmieUserList
2015-09-30 14:14 - 2015-02-02 12:41 - 00000000 __SHD C:\Users\MERCURY\AppData\Local\EmieSiteList
2015-09-30 13:22 - 2015-02-15 11:39 - 00000000 ____D C:\Users\MERCURY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Control Center
2015-09-30 11:23 - 2015-01-27 19:36 - 00000000 ____D C:\Program Files\Microsoft Office 15
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-07-29 14:14 - 2015-07-29 14:14 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Einige Dateien in TEMP:
====================
C:\Users\MERCURY\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpssnjih.dll
C:\Users\MERCURY\AppData\Local\Temp\proxy_vole5674692022462984289.dll
C:\Users\MERCURY\AppData\Local\Temp\proxy_vole8817783468969832925.dll
C:\Users\MERCURY\AppData\Local\Temp\sqlite3.dll
C:\Users\MERCURY\AppData\Local\Temp\SynciosDeviceService.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-10-20 11:34
==================== Ende von FRST.txt ============================ |