Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   ELEX-tech YAC Biest :-) (https://www.trojaner-board.de/182603-elex-tech-yac-biest.html)

Schuhmi 01.11.2016 13:51

3 MBAR LOG mit den inf. Datein
 
Code:

C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_progbar_indicator.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_progbar_indicator_green.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_search_box_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_search_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_software_def_ico_48.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_step_found.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_step_nofound.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_uninst_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_vscroll.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_warning_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_whirling_pic.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_common_btn_bk1.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_common_btn_bk2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_menu_bkg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_menu_item_over.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_remain_ctrl_iconlist.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_software_def_ico_20.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_warning_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\softmgr_res.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\SoftMgrView.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\SoftMgrView2.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\softmgr_guide.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\softmgr_guide2.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\softmgr_result.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\style\softmgr_style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\btn_bg_1.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\btn_bg_2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\smell_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\sorry_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\vscroll.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\wait.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\wait_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\layout\default\softuninstallwnd.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\if_block.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\if_prompt.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\if_warning.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\notify_bk_dang.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\notify_bk_safe.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\notify_bk_warning.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\pop_sys_close.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_bk_dang.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_bk_safe.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_bk_warning.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_btn_dang.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_btn_safe.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_btn_warning.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\traymenu_dlg_bk2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\vscroll.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\layout\traydlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\layout\pop\tippop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\adblock_guide_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\ad_arrow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\pic_ad_off1.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\pic_ad_off2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\pic_ad_on1.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\pic_ad_on2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\rubbish.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\traymenu_iconlist.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\layout\adblockguide.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\layout\cleartrash.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\layout\traydlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\arrowdown_green.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\arrowup_orange.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\clean_junk_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\default_program_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\download.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\download_gray.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\flow_number.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\flow_unit.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\IPicon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\menu_bkg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\menu_item_over.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\pop_memory_btn_green_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\pop_memory_btn_yellow_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\pop_network_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\speed_number.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\speed_unit.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\sys_imglist.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\testspeed_arrow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\testspeed_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\testspeed_light.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\testspeed_light1.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\test_speed_download.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\test_speed_upload.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\traymenu_iconlist.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\upload.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\upload_gray.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\upload_gray_mark.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\yaclogo.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_left_bk_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_rb.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_acc_circle_list_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_acc_circle_list_orange.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_acc_circle_list_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_dec_circle_list_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_dec_circle_list_orange.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_dec_circle_list_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_left_bk_orange.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_left_bk_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_right_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_round_bk_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_round_bk_orange.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_round_bk_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_shadow_bk_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_shadow_bk_orange.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_shadow_bk_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_whirling_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_whirling_orange.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_whirling_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_btn_close_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_menu_iconlist.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_net_down_arrow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_net_flow_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_net_up_arrow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_numer.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_percent_bk_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_percent_bk_orange.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_percent_bk_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_shadow_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_shadow_sh_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_shadow_sv_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_speed_test_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_rb_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_rt.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_rt_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_close_btn.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_go_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_wnd_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_wnd_bk_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_rope_btn_bk_gl.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_rope_btn_bk_roulette.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_swing_anim_bk_gl.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_swing_anim_bk_roulette.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_throw_anim_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_throw_anim_round_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\floatplugin.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\floattipwnd.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\floattipwnd_hide.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\swing_anim.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\throwdlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\traydlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayfloaty2.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayfloatypop2.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\app.ico (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\file.ico (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\folder.ico (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\picture.ico (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\idesk_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\traymenu_iconlist.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\app.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\btn_cancel.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\btn_close.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\btn_green_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\file.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\folder.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\logo_small.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\main_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\picture.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\yac_logo.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\layout\arrange_desktop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\layout\traydlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iWifi\image\iwifi_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iWifi\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iWifi\layout\traydlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iWifi\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\layout\default\MsgCenterDlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\close.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\logo.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\Msg_BG.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\Resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\style\Style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\pop_startup_slow_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\pop_startup_warning_button.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\traymenu_iconlist.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\traymenu_pop_cancel_btn2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\traymenu_pop_ico_query.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\tray_radio_checked.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\tray_radio_unchecked.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\layout\traydlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\layout\traymenupop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\bing_16_16.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\chrome_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_browser2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_browser_dropdown_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_pop_modify.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_pop_modify2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_pop_modify_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_skin4.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\firefix_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\google_16_16.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\ie_16_16.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\ie_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\isafe_16.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\pop_startup_slow_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\pop_startup_warning_button.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\traymenu_iconlist.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\traymenu_pop_cancel_btn2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\traymenu_pop_ico_query.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\tray_radio_checked.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\tray_radio_unchecked.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\yahoo_16_16.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\blockblacklist.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\lock_guide.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\querymodify.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\querymodify2.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\traydlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\traymenupop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\close.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\Location_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\new_left.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\new_right.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_assistant_blue_number.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_assistant_yellow_number.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startupass_comb_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startupass_vscoll.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_fast_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_slow_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_warning_button.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_sys_close.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_sys_Setting.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_sys_star.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_anim_expand_bk_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_anim_expand_bk_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_char_m.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_char_percent.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_char_s.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_close_btn_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_close_btn_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_drop_bk_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_drop_bk_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_skin_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_skin_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_itemhover_bk_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_itemhover_bk_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_location_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_location_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_news_line_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_news_line_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_number.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_number_fuzzy.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_optimize_btn.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_redpoint_large.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_redpoint_middle.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_redpoint_small.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_late_night_blue.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_late_night_yellow.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_morning_blue.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_morning_yellow.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_nightfall_blue.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_nightfall_yellow.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_noon_blue.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_vscoll_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_vscoll_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_cloudy_blue.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_cloudy_yellow.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_icon_large.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_icon_small.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_line_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_line_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_rain_blue.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_nomall_button.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_noon_yellow.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_rain_yellow.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_snow_blue.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_snow_yellow.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_thunder_blue.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_thunder_yellow.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_yac_logo.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\weather_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\daily_news.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist_2.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist_3.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist_weather.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_scan.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\Anti_Malware.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\dtk_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\dtk_dlg_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\green1_bk_new.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\green_bk_new.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\point.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_safe.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_safe_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_safe_btn.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unknow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unkown_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unkown_btn.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unsafe.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unsafe_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unsafe_btn.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unsafe_clear_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unsafe_clear_btn.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unsafe_clear_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\pop_dp_unsafe_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\vip_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\image\vip_dlg_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\layout\detectbrowserriskpop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\layout\detectriskpop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\layout\downloadprotect.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\layout\outdatepop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\layout\premiumuserpop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\layout\PrivilegeTerminateDlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\layout\updatevirussuccesspop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\layout\virusdboutofdatepop.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Virus\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\av_authority_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\combo_list.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\custom_check.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\custom_uncheck.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_combo_skin.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_logo.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_prog_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_prog_meter.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\inst_cover_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\open_dir.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\popup_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\soft_cof_button_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\soft_remove_button_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_acc.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_btn_bg1.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_btn_bg2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_clean.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_complete.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_cry.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func1.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func3.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func_intr.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func_up.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]

Code:

C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_input.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_progress.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_prog_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_protect.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_spliter.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\vscroll.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\yac_side_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\cover.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\install.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\uninstallpro.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\uninstall_logo_fade.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\upgrade.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\avangate.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\avangateflag.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\button_blue.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\button_buy.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\button_green.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\button_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\buy_flag.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\centili.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\chooseoption_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\chooseoption_close.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\close_message_box_warning.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\cseh.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\edit_skin.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\free_flag_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\general_buy_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\green1_bk_new.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\green_bk_new.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\guarantee.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\icoBW.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\icoBW_gray.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\icoDP.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\icoDP_gray.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\icoRS.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\icoRS_gray.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\main_item_status.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\mobileflag.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\new.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\paypal.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\paypaldetail.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\paypalflag.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\pay_cancel.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\point.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\premium_button_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\premium_flag_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\radio_checked.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\radio_unchecked.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\red_bk_new.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\result_danger.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\result_safe.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\risk_item_see_about_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\skrill.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\skrillflag.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\trailfeature_button_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\trail_flag_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\VirusScan_Tab_Vert_Line.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_certification_list_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_common_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_custom_scan.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_custom_scan_green.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_custom_scan_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_delete_btn.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_expdlg_collapse_arrow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_expdlg_expand_arrow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\Virus_feature.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_hover_btn_iconlist.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_hover_tip_arrow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_hover_tip_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_hover_tip_iconlist.jpg (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_hyper_scan.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_hyper_scan_d.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_hyper_scan_green.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_hyper_scan_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_menu_bkg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_menu_item_over.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_normal.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_quick_scan.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_quick_scan_green.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_quick_scan_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_red.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\VirusScan_SetDlg_EditSkin.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\Virus_feature_right.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_restore_btn.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virusopt_btn_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virusopt_but_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\VirusScan_Btn_BG.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\VirusScan_Loading.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\VirusScan_OptDlg_BG.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\VirusScan_res.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\VirusScan_SetDlg_BG.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\VirusScan_SetDlg_Cancel_BTN_BG.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_scan_safe.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_scan_scaning.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_scan_virus.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_setting_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_task_item_combo_skin.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_task_item_edit_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_task_item_save_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_update_db.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_update_db_out.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\virus_yellow.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\wait.gif (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\image\default\yellow_bk_new.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\ChooseOptionMessageBox.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\CloseMessageBox.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\explorer_folder_dlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\FinishScanFirstMessageBox.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\InputEmailDlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\TrialFeatureDlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\virushovertip.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\VirusScanFeatureView.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\VirusScanView.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\virusscan_popdlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\layout\default\virusscan_settingdlg.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\skin2\VirusScan\style\VirusScan_style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\2E3120C6.zip (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\curlpp.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\iCommon.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\iCommu.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\iImportLib.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\install.inst (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\ipcproxy.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\isafemc.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\isafepxy.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\isaferpt.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\isafeupbiz.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\libcurl.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\libeay32.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\libpng.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\main (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\msvcp110.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\msvcr110.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\ouilibx.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\ssleay32.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\uninstall.exe (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\uninstall.inst (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\zlib1.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\cfg\ccc.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\cfg\customscan.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\cfg\hyperscan.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\cfg\quickscan.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\cfg\ucg.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\cfg\updatedb.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\lang\common_lang.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\lang\uninstall_lang.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\arrow_down.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\arrow_up.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\check_checked.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\check_indeterminate.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\check_uncheck.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\close_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\common_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\common_dlg_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\common_faq_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\common_res.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\common_tip_icon.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\feedback_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\head_checked.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\head_indeteminate.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\head_unchecked.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\if_block.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\if_prompt.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\if_question.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\if_warning.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\min_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\msgbox_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\msgbox_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\msgbox_close_btn.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\nation_icon_list.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\progressbar_anim.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\progressbar_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\progressbar_image.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\pvb_line.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\pvb_skin.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\scanview_btn_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\scan_check.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\scan_complete.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\scan_scanning.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\scan_warning.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\switch_button_off.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\switch_button_on.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\toggle_btn_pop_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\image\default\vscroll.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\layout\msgbox.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\common\style\common_style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninstall_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\av_authority_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\combo_list.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\custom_check.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\custom_uncheck.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\install_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\install_combo_skin.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\install_logo.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\install_prog_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\install_prog_meter.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\inst_cover_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\open_dir.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\popup_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\resource.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\soft_cof_button_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\soft_remove_button_bk.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_acc.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_btn_bg1.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_btn_bg2.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_clean.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_complete.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_cry.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_func1.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_func3.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_func_intr.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_func_up.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_input.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_progress.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_prog_bg.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_protect.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\uninst_spliter.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\vscroll.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\image\yac_side_ico.png (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\layout\cover.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\layout\install.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\layout\uninstallpro.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\layout\uninstall_logo_fade.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\layout\upgrade.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tmp\27620C45upgd\skin2\uninstall\style\style.xml (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\fupd.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\antirk.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\common.ini (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\ctools.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\decexp.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\emlib.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\falgorit.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\fddsdb.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\fgui.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filau.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filcmn.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filcpt.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filppi.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filpps.ini (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filup.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filup.ini (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filvss.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filvss.ini (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\fsrexc.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\iSafeSvc2.exe (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\leave.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\lsf.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\mca.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\message.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\plugmgr.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\psmgr.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\quarantine.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\tsc.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\twsdk.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\twsupd.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\twsupd.ini (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\unacev2.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\unchm.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\unemb.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\unmisc.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\unrar.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\unsevzip.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\unzip32.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\vfst.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\w32tools.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\zipexp.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\zlib1.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\defs\base0000.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\defs\base0001.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\defs\catalog.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\filwls\fols000.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\plugins\filavutd.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\plugins\virut.tpl (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\quarantine\catalog.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\tws\x64\psmgr.dll (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\update\Engine0\upcfg.ini (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\update\Engine1\bs.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\update\Engine1\sr.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\update\Engine1\vn.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\update\Engine1\ws.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\update\temp\dlcfg.ini (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\update\temp\upcfg.ini (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\user\brset.ini (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\user\co.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\user\sie.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\user\softcache2.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\user\srd.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]
C:\Program Files (x86)\Elex-tech\YAC\user\svc2_com.dat (FraudTool.YAC) -> Delete on reboot. [b3669229811968ce28a11893b34f4bb5]

Physical Sectors Detected: 0
(No malicious items detected)

(end)

glaub hab alles, allerdings is das voll die fummelei mit der Zeichenbeschränkung :party:
... wärs nicht einfacher die .txt Datei hoch zu laden? Oder gibts da bedenken wegen Infizierung un so :-) ....

Der Ordner ELEX-tech ist weg im Programm (x86) Ordner
YAC Virensuche auch bei Maus-rechtsklick-Toolbox auf Desktop

das kann ich schon mal selbst erkennen!

cosinus 01.11.2016 13:57

Adware/Junkware/Toolbars entfernen

Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!
Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren!


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


Schuhmi 01.11.2016 14:36

AdwCleaner und JRT
 
Code:

# AdwCleaner v6.030 - Bericht erstellt am 01/11/2016 um 14:19:38
# Aktualisiert am 19/10/2016 von Malwarebytes
# Datenbank : 2016-11-01.2 [Server]
# Betriebssystem : Windows 10 Pro  (X64)
# Benutzername : Silke - SILKE-LAPI
# Gestartet von : C:\Users\Silke\Desktop\AdwCleaner_6.030.exe
# Modus: Löschen
# Unterstützung : hxxps://www.malwarebytes.com/support



***** [ Dienste ] *****

[-] Dienst gelöscht: swdumon


***** [ Ordner ] *****

[-] Ordner gelöscht: C:\Users\Silke\AppData\Local\slimware utilities inc
[-] Ordner gelöscht: C:\Users\Silke\AppData\Local\YSearchUtil
[#] Ordner mit Neustart gelöscht: C:\Users\Silke\AppData\Local\SlimWare Utilities Inc
[-] Ordner gelöscht: C:\Users\Silke\AppData\Roaming\Elex-tech
[-] Ordner gelöscht: C:\Users\Silke\AppData\Roaming\RPEng
[-] Ordner gelöscht: C:\Users\Public\Documents\Downloaded Installers
[-] Ordner gelöscht: C:\Program Files (x86)\Elex-tech
[-] Ordner gelöscht: C:\Program Files (x86)\myfree codec
[-] Ordner gelöscht: C:\Program Files (x86)\Startfenster
[-] Ordner gelöscht: C:\Users\Silke\AppData\Local\Temp\iSafeRightKeyScan


***** [ Dateien ] *****

[-] Datei gelöscht: C:\WINDOWS\SysNative\log\iSafeKrnlCall.log


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Verknüpfungen ] *****



***** [ Aufgabenplanung ] *****



***** [ Registrierungsdatenbank ] *****

[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.001
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.7z
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.arj
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.bz2
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.bzip2
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.cab
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.cpio
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.deb
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.dmg
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.fat
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.gz
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.gzip
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.hfs
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.iso
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.lha
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.lzh
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.lzma
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.ntfs
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.rar
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.rpm
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.squashfs
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.swm
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.tar
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.taz
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.tbz
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.tbz2
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.tgz
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.tpz
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.txz
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.vhd
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.wim
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.xar
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.xz
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.z
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\WinZipper.zip
[-] Schlüssel gelöscht: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\winzipersvc
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\winzipersvc
[-] Schlüssel gelöscht: HKU\S-1-5-21-1071034996-3370113837-20168928-1000\Software\Classes\AppXrh6feys59dqfzsv9p3s9p6aep0hwtb23
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\Classes\AppXrh6feys59dqfzsv9p3s9p6aep0hwtb23
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Classes\AppXrh6feys59dqfzsv9p3s9p6aep0hwtb23
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[-] Schlüssel gelöscht: HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Schlüssel gelöscht: HKU\S-1-5-21-1071034996-3370113837-20168928-1000\Software\SlimWare Utilities Inc
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1071034996-3370113837-20168928-1000\Software\WebConnect
[#] Schlüssel mit Neustart gelöscht: HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\SlimWare Utilities Inc
[-] Schlüssel gelöscht: HKLM\SOFTWARE\SLIMWARE UTILITIES, INC.
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Elex-tech
[-] Schlüssel gelöscht: HKLM\SOFTWARE\SlimWare Utilities Inc
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1071034996-3370113837-20168928-1000\Software\WebConnect
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\SlimWare Utilities Inc
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Startfenster
[-] Schlüssel gelöscht: HKU\S-1-5-21-1071034996-3370113837-20168928-1000\Software\Microsoft\Internet Explorer\SearchScopes\{77D45C3E-7C44-4F24-B9AF-C01F6A6A9051}
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77D45C3E-7C44-4F24-B9AF-C01F6A6A9051}
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77D45C3E-7C44-4F24-B9AF-C01F6A6A9051}
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77D45C3E-7C44-4F24-B9AF-C01F6A6A9051}
[-] Daten  wiederhergestellt: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\WinZipper


***** [ Browser ] *****



*************************

:: "Tracing" Schlüssel gelöscht
:: Winsock Einstellungen zurückgesetzt
:: Proxy Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [7272 Bytes] - [01/11/2016 14:19:38]
C:\AdwCleaner\AdwCleaner[S0].txt - [6951 Bytes] - [01/11/2016 14:18:21]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [7418 Bytes] ##########

Code:

Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 10 Pro x64
Ran by Silke (Administrator) on 01.11.2016 at 14:23:38,07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 3

Successfully deleted: C:\Users\Silke\Appdata\LocalLow\PaybackToolbar32 (Folder)
Successfully deleted: C:\WINDOWS\system32\Tasks\SlimCleaner Plus (Scheduled Scan - Silke) (Task)
Successfully deleted: C:\WINDOWS\Tasks\SlimCleaner Plus (Scheduled Scan - Silke).job (Task)



Registry: 5

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9613CB43-EA4C-48b5-878D-13DFE1818EFE} (Registry Value)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E141F5C3-2619-4996-8AF8-AA0A9439D986} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E141F5C3-2619-4996-8AF8-AA0A9439D986} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{9613CB43-EA4C-48b5-878D-13DFE1818EFE} (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.11.2016 at 14:26:54,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

bei Adw hieß es nur Google Chrome und IExplorer - wir nutzen Firefox?
Problem?

Nachdem ich Kaspersky wieder eingeschaltet hab nach den beiden Programmen sagt er immer noch unerwünschte Programme ... is das veraltet oder noch aktuell?

cosinus 02.11.2016 09:50

Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken

http://www.trojaner-board.de/picture...&pictureid=611

Schuhmi 02.11.2016 12:12

Hallo cosinus, anbei FRST
 
Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 30-10-2016
durchgeführt von Silke (Administrator) auf SILKE-LAPI (02-11-2016 12:06:09)
Gestartet von C:\Users\Silke\Desktop
Geladene Profile: Silke (Verfügbare Profile: Silke & DefaultAppPool)
Platform: Windows 10 Pro Version 1607 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
() C:\Windows\System32\PnkBstrA.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avpui.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe
(Mister Group) C:\Program Files (x86)\System Explorer\SystemExplorer.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Mister Group) C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3347688 2015-08-15] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184112 2012-05-31] (Intel Corporation)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2782096 2010-07-25] (CANON INC.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-06-15] (NVIDIA Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-10-13] (Apple Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1213848 2010-09-14] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2010-09-09] (CANON INC.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [217632 2015-07-21] (Geek Software GmbH)
HKLM-x32\...\Run: [SystemExplorerAutoStart] => "C:\Program Files (x86)\System Explorer\SystemExplorer.exe" /TRAY
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-12-22] (Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2016-08-22] (Razer Inc.)
HKU\S-1-5-21-1071034996-3370113837-20168928-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Silke\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-09] ()
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  Keine Datei
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Qualcomm Atheros Killer Network Manager.lnk [2013-04-01]
ShortcutTarget: Qualcomm Atheros Killer Network Manager.lnk -> C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{1b371024-6bf4-41f7-a706-df3167e70a89}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{76c38922-90ac-4d28-a0db-c3b480b52f17}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-1071034996-3370113837-20168928-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://de.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1071034996-3370113837-20168928-1000 -> {9E7983ED-682D-421B-BAE3-549288C52D56} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
SearchScopes: HKU\S-1-5-21-1071034996-3370113837-20168928-1000 -> {FBF096FE-6384-48D9-A5E8-231D438D9412} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2016-10-25] (AO Kaspersky Lab)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-02-03] (Oracle Corporation)
BHO-x32: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2016-10-25] (AO Kaspersky Lab)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-02-03] (Oracle Corporation)
Toolbar: HKLM - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2016-10-25] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.)
Toolbar: HKLM-x32 - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2016-10-25] (AO Kaspersky Lab)
Toolbar: HKU\S-1-5-21-1071034996-3370113837-20168928-1000 -> Kein Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  Keine Datei

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-1071034996-3370113837-20168928-1000 -> hxxp://google.de/

FireFox:
========
FF ProfilePath: C:\Users\Silke\AppData\Roaming\TomTom\HOME\Profiles\0xmmd4f4.default [2014-03-08]
FF Extension: (Kein Name) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [nicht gefunden]
FF ProfilePath: C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695 [2016-11-02]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695 -> Google
FF Homepage: Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695 -> www.google.de
FF Extension: (ADB Helper) - C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695\Extensions\adbhelper@mozilla.org [2016-11-01]
FF Extension: (Valence) - C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695\Extensions\fxdevtools-adapters@mozilla.org [2016-06-28]
FF Extension: (NASA Night Launch) - C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695\Extensions\nasanightlaunch@example.com.xpi [2016-03-31]
FF Extension: (PAYBACK Internet Assistent) - C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695\Extensions\toolbar-ff@payback.de-sh.xpi [2016-09-28]
FF Extension: (PAYBACK Internet Assistent) - C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695\Extensions\toolbar-ff@payback.de.xpi [2016-01-27]
FF Extension: (FT DeepDark) - C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2016-10-28]
FF Extension: (YouTube High Definition) - C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2016-10-28]
FF Extension: (Adblock Plus) - C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-10-28]
FF Extension: (Theme Font & Size Changer) - C:\Users\Silke\AppData\Roaming\Mozilla\Firefox\Profiles\9zoi0ii4.default-1439815623695\Extensions\{f69e22c7-bc50-414a-9269-0f5c344cd94c}.xpi [2016-10-25]
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_D772DC8D6FAF43A29B25C4EBAA5AD1DE@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox [2016-10-25]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll [2016-10-30] ()
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll [Keine Datei]
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [Keine Datei]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_23_0_0_205.dll [2016-10-30] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-04-14] (CANON INC.)
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll [Keine Datei]
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [Keine Datei]
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-02-03] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-02-03] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1071034996-3370113837-20168928-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Silke\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-09] (Amazon.com, Inc.)

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 AVP16.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe [194000 2015-09-29] (Kaspersky Lab ZAO)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144104 2015-08-15] (ELAN Microelectronics Corp.)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [137680 2010-07-27] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-07-09] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-06-15] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-06-15] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-06-15] (NVIDIA Corporation)
R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2015-08-22] ()
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2015-08-21] ()
R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [497664 2013-02-19] () [Datei ist nicht signiert]
S4 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187824 2016-07-20] ()
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.)
R3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [820960 2014-12-20] (Mister Group)
S3 vssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\vssbridge64.exe [144640 2015-07-08] (AO Kaspersky Lab)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3831712 2015-07-09] (Intel® Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R1 BfLwf; C:\WINDOWS\system32\DRIVERS\bflwfx64.sys [66928 2013-02-19] (Qualcomm Atheros, Inc.)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [389816 2015-07-05] (Kaspersky Lab ZAO)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 Ke2200; C:\WINDOWS\System32\drivers\e22w7x64.sys [165824 2013-02-19] (Qualcomm Atheros, Inc.)
R3 KillerEth; C:\WINDOWS\System32\drivers\e2xw10x64.sys [170128 2016-02-05] (Qualcomm Atheros, Inc.)
R0 kl1; C:\WINDOWS\System32\DRIVERS\kl1.sys [478392 2015-06-22] (Kaspersky Lab ZAO)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [70512 2015-06-27] (Kaspersky Lab ZAO)
R2 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [77728 2016-03-01] (AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [30328 2015-06-24] (Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [181640 2015-10-19] (AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\system32\DRIVERS\klhk.sys [238000 2016-05-23] (AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [933808 2016-05-23] (AO Kaspersky Lab)
R1 KLIM6; C:\WINDOWS\system32\DRIVERS\klim6.sys [49240 2016-05-23] (AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [41656 2015-06-06] (Kaspersky Lab ZAO)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [41352 2015-09-29] (AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [87984 2016-05-23] (AO Kaspersky Lab)
R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [102584 2015-06-16] (Kaspersky Lab ZAO)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [187056 2015-06-23] (Kaspersky Lab ZAO)
S0 megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [64352 2016-10-05] (Avago Technologies)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3354384 2015-05-04] (Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_03c9192d3331a8fa\nvlddmkm.sys [14242872 2016-09-20] (NVIDIA Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-06-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
S3 rzdaendpt; C:\WINDOWS\System32\drivers\rzdaendpt.sys [43720 2015-08-13] (Razer Inc)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [44144 2016-05-06] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [136312 2016-06-27] (Razer, Inc.)
S3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [44232 2015-08-13] (Razer Inc)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-11-02 12:06 - 2016-11-02 12:06 - 00022236 _____ C:\Users\Silke\Desktop\FRST.txt
2016-11-01 14:26 - 2016-11-01 14:27 - 00001536 _____ C:\Users\Silke\Desktop\JRT.txt
2016-11-01 14:21 - 2016-11-01 14:21 - 00007540 _____ C:\Users\Silke\Desktop\AdwCleaner[C0].txt
2016-11-01 14:11 - 2016-11-01 14:19 - 00000000 ____D C:\AdwCleaner
2016-11-01 14:06 - 2016-11-01 14:23 - 01631928 _____ (Malwarebytes) C:\Users\Silke\Desktop\JRT.exe
2016-11-01 14:05 - 2016-11-01 14:11 - 03910208 _____ C:\Users\Silke\Desktop\AdwCleaner_6.030.exe
2016-11-01 14:05 - 2016-11-01 14:05 - 00000000 ____D C:\Users\Silke\Downloads\Alt
2016-11-01 13:06 - 2016-11-01 13:13 - 00093754 _____ C:\TDSSKiller.3.1.0.11_01.11.2016_13.06.48_log.txt
2016-11-01 13:06 - 2016-11-01 13:06 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Silke\Desktop\tdsskiller.exe
2016-11-01 12:40 - 2016-11-01 12:40 - 00002112 _____ C:\Users\Silke\Desktop\mbar-log-2016-11-01 (12-10-03).txt
2016-11-01 12:02 - 2016-11-01 12:02 - 00562544 _____ C:\Users\Silke\Desktop\mbar-log-2016-11-01 (11-29-06).txt
2016-11-01 11:28 - 2016-11-01 14:20 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-11-01 11:28 - 2016-11-01 12:40 - 00000000 ____D C:\Users\Silke\Desktop\mbar
2016-11-01 11:28 - 2016-11-01 12:09 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-11-01 11:27 - 2016-11-01 11:28 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Silke\Desktop\mbar-1.09.3.1001.exe
2016-11-01 09:48 - 2016-11-01 09:48 - 00000796 _____ C:\Users\Silke\Desktop\Downloads - Verknüpfung.lnk
2016-11-01 09:38 - 2016-11-01 12:09 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-11-01 09:38 - 2016-11-01 11:29 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-11-01 09:36 - 2016-11-01 09:37 - 22851472 _____ (Malwarebytes ) C:\Users\Silke\Desktop\mbam-setup-2.2.1.1043.exe
2016-11-01 09:10 - 2016-11-02 12:06 - 00000000 ____D C:\FRST
2016-11-01 09:07 - 2016-11-01 09:10 - 02408960 _____ (Farbar) C:\Users\Silke\Desktop\FRST64.exe
2016-11-01 08:24 - 2016-11-01 08:24 - 00000000 ___HD C:\$SysReset
2016-11-01 07:49 - 2016-11-01 07:49 - 00001079 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2016-11-01 07:49 - 2016-11-01 07:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-11-01 07:49 - 2016-11-01 07:49 - 00000000 ____D C:\Program Files\VS Revo Group
2016-10-30 19:10 - 2016-10-30 19:10 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-10-30 19:10 - 2016-10-30 19:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-10-30 19:10 - 2016-10-30 19:10 - 00000000 ____D C:\Program Files\iTunes
2016-10-30 19:10 - 2016-10-30 19:10 - 00000000 ____D C:\Program Files\iPod
2016-10-30 09:54 - 2016-10-30 09:54 - 00000000 ____D C:\Program Files\Common Files\AV
2016-10-29 08:20 - 2016-10-15 05:51 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-10-29 08:20 - 2016-10-15 05:51 - 00894088 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-10-29 08:20 - 2016-10-15 05:48 - 07817568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-10-29 08:20 - 2016-10-15 05:48 - 00498952 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2016-10-29 08:20 - 2016-10-15 05:47 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-10-29 08:20 - 2016-10-15 05:26 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-10-29 08:20 - 2016-10-15 05:26 - 04129928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-10-29 08:20 - 2016-10-15 05:26 - 01990648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-10-29 08:20 - 2016-10-15 05:26 - 01472536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-10-29 08:20 - 2016-10-15 05:26 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-10-29 08:20 - 2016-10-15 05:26 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-10-29 08:20 - 2016-10-15 05:26 - 00811416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-10-29 08:20 - 2016-10-15 05:26 - 00691080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2016-10-29 08:20 - 2016-10-15 05:22 - 01608896 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2016-10-29 08:20 - 2016-10-15 05:22 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-10-29 08:20 - 2016-10-15 05:22 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-10-29 08:20 - 2016-10-15 05:22 - 00628040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-10-29 08:20 - 2016-10-15 05:18 - 00749920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll
2016-10-29 08:20 - 2016-10-15 05:18 - 00576400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-10-29 08:20 - 2016-10-15 05:18 - 00186424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2016-10-29 08:20 - 2016-10-15 05:15 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2016-10-29 08:20 - 2016-10-15 05:11 - 01424488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2016-10-29 08:20 - 2016-10-15 05:11 - 01263848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-10-29 08:20 - 2016-10-15 05:01 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-10-29 08:20 - 2016-10-15 04:57 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-10-29 08:20 - 2016-10-15 04:56 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2016-10-29 08:20 - 2016-10-15 04:54 - 00555008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-10-29 08:20 - 2016-10-15 04:54 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-10-29 08:20 - 2016-10-15 04:54 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-10-29 08:20 - 2016-10-15 04:54 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2016-10-29 08:20 - 2016-10-15 04:53 - 00744448 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-10-29 08:20 - 2016-10-15 04:53 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2016-10-29 08:20 - 2016-10-15 04:53 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2016-10-29 08:20 - 2016-10-15 04:52 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-10-29 08:20 - 2016-10-15 04:52 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2016-10-29 08:20 - 2016-10-15 04:50 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-10-29 08:20 - 2016-10-15 04:50 - 00509440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-10-29 08:20 - 2016-10-15 04:48 - 03778560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-10-29 08:20 - 2016-10-15 04:46 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2016-10-29 08:20 - 2016-10-15 04:45 - 00406016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-10-29 08:20 - 2016-10-15 04:44 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-10-29 08:20 - 2016-10-15 04:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-10-29 08:20 - 2016-10-15 04:43 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\energy.dll
2016-10-29 08:20 - 2016-10-15 04:42 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-10-29 08:20 - 2016-10-15 04:42 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2016-10-29 08:20 - 2016-10-15 04:42 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-10-29 08:20 - 2016-10-15 04:41 - 12174848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-10-29 08:20 - 2016-10-15 04:41 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmi.dll
2016-10-29 08:20 - 2016-10-15 04:40 - 13081600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-10-29 08:20 - 2016-10-15 04:39 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-10-29 08:20 - 2016-10-15 04:39 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2016-10-29 08:20 - 2016-10-15 04:39 - 00982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-10-29 08:20 - 2016-10-15 04:38 - 07468032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2016-10-29 08:20 - 2016-10-15 04:38 - 00913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-10-29 08:20 - 2016-10-15 04:37 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-10-29 08:20 - 2016-10-15 04:37 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-10-29 08:20 - 2016-10-15 04:36 - 03617792 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-10-29 08:20 - 2016-10-15 04:36 - 02290176 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-10-29 08:20 - 2016-10-15 04:36 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-10-29 08:20 - 2016-10-15 04:35 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-10-29 08:20 - 2016-10-15 04:34 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2016-10-29 08:20 - 2016-10-15 04:31 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2016-10-29 08:20 - 2016-08-27 06:12 - 00244816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-10-29 08:19 - 2016-10-15 06:11 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 01637728 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 01235296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 00595296 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 00322912 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 00283488 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-10-29 08:19 - 2016-10-15 05:51 - 00232800 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 00137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-10-29 08:19 - 2016-10-15 05:51 - 00078688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-10-29 08:19 - 2016-10-15 05:48 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-10-29 08:19 - 2016-10-15 05:48 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-10-29 08:19 - 2016-10-15 05:48 - 00773712 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2016-10-29 08:19 - 2016-10-15 05:43 - 01356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2016-10-29 08:19 - 2016-10-15 05:41 - 05622088 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-10-29 08:19 - 2016-10-15 05:38 - 00500064 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2016-10-29 08:19 - 2016-10-15 05:37 - 00063328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-10-29 08:19 - 2016-10-15 05:34 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2016-10-29 08:19 - 2016-10-15 05:33 - 00455040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2016-10-29 08:19 - 2016-10-15 05:32 - 01570680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-10-29 08:19 - 2016-10-15 05:31 - 02827864 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-10-29 08:19 - 2016-10-15 05:31 - 02750384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-10-29 08:19 - 2016-10-15 05:31 - 00658272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-10-29 08:19 - 2016-10-15 05:31 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-10-29 08:19 - 2016-10-15 05:30 - 01851696 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2016-10-29 08:19 - 2016-10-15 05:30 - 00682816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-10-29 08:19 - 2016-10-15 05:30 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2016-10-29 08:19 - 2016-10-15 05:30 - 00341936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2016-10-29 08:19 - 2016-10-15 05:30 - 00238056 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2016-10-29 08:19 - 2016-10-15 05:29 - 02913104 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-10-29 08:19 - 2016-10-15 05:29 - 01267504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-10-29 08:19 - 2016-10-15 05:29 - 00908640 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
2016-10-29 08:19 - 2016-10-15 05:29 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-10-29 08:19 - 2016-10-15 05:29 - 00079200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2016-10-29 08:19 - 2016-10-15 05:26 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-10-29 08:19 - 2016-10-15 05:26 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2016-10-29 08:19 - 2016-10-15 05:26 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2016-10-29 08:19 - 2016-10-15 05:25 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-10-29 08:19 - 2016-10-15 05:25 - 00742704 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2016-10-29 08:19 - 2016-10-15 05:21 - 02537824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-10-29 08:19 - 2016-10-15 05:21 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-10-29 08:19 - 2016-10-15 05:21 - 00292872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2016-10-29 08:19 - 2016-10-15 05:19 - 02256592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-10-29 08:19 - 2016-10-15 05:15 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-10-29 08:19 - 2016-10-15 05:15 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-10-29 08:19 - 2016-10-15 05:14 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-10-29 08:19 - 2016-10-15 05:11 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-10-29 08:19 - 2016-10-15 05:10 - 00254656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2016-10-29 08:19 - 2016-10-15 05:06 - 05685760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-10-29 08:19 - 2016-10-15 05:05 - 07216640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-10-29 08:19 - 2016-10-15 05:00 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-10-29 08:19 - 2016-10-15 05:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-10-29 08:19 - 2016-10-15 05:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stdole2.tlb
2016-10-29 08:19 - 2016-10-15 04:59 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
2016-10-29 08:19 - 2016-10-15 04:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfksproxy.dll
2016-10-29 08:19 - 2016-10-15 04:59 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2016-10-29 08:19 - 2016-10-15 04:58 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2016-10-29 08:19 - 2016-10-15 04:58 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll
2016-10-29 08:19 - 2016-10-15 04:58 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll
2016-10-29 08:19 - 2016-10-15 04:57 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2016-10-29 08:19 - 2016-10-15 04:57 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2016-10-29 08:19 - 2016-10-15 04:57 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2016-10-29 08:19 - 2016-10-15 04:56 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentutl.exe
2016-10-29 08:19 - 2016-10-15 04:56 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esentutl.exe
2016-10-29 08:19 - 2016-10-15 04:56 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2016-10-29 08:19 - 2016-10-15 04:56 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2016-10-29 08:19 - 2016-10-15 04:56 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2016-10-29 08:19 - 2016-10-15 04:56 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2016-10-29 08:19 - 2016-10-15 04:56 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-10-29 08:19 - 2016-10-15 04:55 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2016-10-29 08:19 - 2016-10-15 04:55 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2016-10-29 08:19 - 2016-10-15 04:55 - 00329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2016-10-29 08:19 - 2016-10-15 04:55 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2016-10-29 08:19 - 2016-10-15 04:55 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2016-10-29 08:19 - 2016-10-15 04:55 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll
2016-10-29 08:19 - 2016-10-15 04:55 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll
2016-10-29 08:19 - 2016-10-15 04:55 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2016-10-29 08:19 - 2016-10-15 04:54 - 00717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskbarcpl.dll
2016-10-29 08:19 - 2016-10-15 04:54 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2016-10-29 08:19 - 2016-10-15 04:54 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2016-10-29 08:19 - 2016-10-15 04:54 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-10-29 08:19 - 2016-10-15 04:54 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingFolder.dll
2016-10-29 08:19 - 2016-10-15 04:54 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoplay.dll
2016-10-29 08:19 - 2016-10-15 04:54 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
2016-10-29 08:19 - 2016-10-15 04:53 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll
2016-10-29 08:19 - 2016-10-15 04:53 - 00549376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenterCPL.dll
2016-10-29 08:19 - 2016-10-15 04:53 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-10-29 08:19 - 2016-10-15 04:53 - 00240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
2016-10-29 08:19 - 2016-10-15 04:53 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoplay.dll
2016-10-29 08:19 - 2016-10-15 04:52 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2016-10-29 08:19 - 2016-10-15 04:51 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-10-29 08:19 - 2016-10-15 04:51 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2016-10-29 08:19 - 2016-10-15 04:50 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2016-10-29 08:19 - 2016-10-15 04:50 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2016-10-29 08:19 - 2016-10-15 04:50 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-10-29 08:19 - 2016-10-15 04:50 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
2016-10-29 08:19 - 2016-10-15 04:50 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2016-10-29 08:19 - 2016-10-15 04:50 - 00310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-10-29 08:19 - 2016-10-15 04:50 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-10-29 08:19 - 2016-10-15 04:50 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2016-10-29 08:19 - 2016-10-15 04:49 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-10-29 08:19 - 2016-10-15 04:49 - 01913344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2016-10-29 08:19 - 2016-10-15 04:49 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-10-29 08:19 - 2016-10-15 04:49 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-10-29 08:19 - 2016-10-15 04:49 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2016-10-29 08:19 - 2016-10-15 04:49 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-10-29 08:19 - 2016-10-15 04:49 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-10-29 08:19 - 2016-10-15 04:49 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2016-10-29 08:19 - 2016-10-15 04:49 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-10-29 08:19 - 2016-10-15 04:48 - 23680000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-10-29 08:19 - 2016-10-15 04:48 - 01554944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2016-10-29 08:19 - 2016-10-15 04:48 - 01323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2016-10-29 08:19 - 2016-10-15 04:48 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-10-29 08:19 - 2016-10-15 04:47 - 07792640 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-10-29 08:19 - 2016-10-15 04:47 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-10-29 08:19 - 2016-10-15 04:47 - 01113600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2016-10-29 08:19 - 2016-10-15 04:47 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-10-29 08:19 - 2016-10-15 04:47 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2016-10-29 08:19 - 2016-10-15 04:46 - 03287552 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2016-10-29 08:19 - 2016-10-15 04:46 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-10-29 08:19 - 2016-10-15 04:46 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msinfo32.exe
2016-10-29 08:19 - 2016-10-15 04:45 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-10-29 08:19 - 2016-10-15 04:45 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2016-10-29 08:19 - 2016-10-15 04:45 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-10-29 08:19 - 2016-10-15 04:44 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2016-10-29 08:19 - 2016-10-15 04:44 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercfg.exe
2016-10-29 08:19 - 2016-10-15 04:43 - 02748928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2016-10-29 08:19 - 2016-10-15 04:43 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-10-29 08:19 - 2016-10-15 04:43 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
2016-10-29 08:19 - 2016-10-15 04:42 - 12349440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-10-29 08:19 - 2016-10-15 04:42 - 06108672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-10-29 08:19 - 2016-10-15 04:42 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-10-29 08:19 - 2016-10-15 04:42 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2016-10-29 08:19 - 2016-10-15 04:42 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2016-10-29 08:19 - 2016-10-15 04:42 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\chartv.dll
2016-10-29 08:19 - 2016-10-15 04:42 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-10-29 08:19 - 2016-10-15 04:41 - 07654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-10-29 08:19 - 2016-10-15 04:41 - 05376000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-10-29 08:19 - 2016-10-15 04:41 - 00940032 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2016-10-29 08:19 - 2016-10-15 04:41 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2016-10-29 08:19 - 2016-10-15 04:41 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-10-29 08:19 - 2016-10-15 04:41 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2016-10-29 08:19 - 2016-10-15 04:40 - 01690112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-10-29 08:19 - 2016-10-15 04:40 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 01005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\chartv.dll
2016-10-29 08:19 - 2016-10-15 04:39 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-10-29 08:19 - 2016-10-15 04:38 - 13441024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-10-29 08:19 - 2016-10-15 04:38 - 02458112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2016-10-29 08:19 - 2016-10-15 04:38 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-10-29 08:19 - 2016-10-15 04:38 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2016-10-29 08:19 - 2016-10-15 04:38 - 00675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-10-29 08:19 - 2016-10-15 04:38 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2016-10-29 08:19 - 2016-10-15 04:37 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-10-29 08:19 - 2016-10-15 04:37 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2016-10-29 08:19 - 2016-10-15 04:37 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-10-29 08:19 - 2016-10-15 04:37 - 01980416 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-10-29 08:19 - 2016-10-15 04:37 - 01029632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-10-29 08:19 - 2016-10-15 04:37 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-10-29 08:19 - 2016-10-15 04:37 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmifw.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 02512384 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 01492480 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-10-29 08:19 - 2016-10-15 04:36 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-10-29 08:19 - 2016-10-15 04:36 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 00580608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2016-10-29 08:19 - 2016-10-15 04:36 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmifw.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 03054080 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 02999808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-10-29 08:19 - 2016-10-15 04:35 - 02708992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 02670592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 02315264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 01512960 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-10-29 08:19 - 2016-10-15 04:35 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-10-29 08:19 - 2016-10-15 04:35 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2016-10-29 08:19 - 2016-10-15 04:34 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-10-29 08:19 - 2016-10-15 04:34 - 01840640 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2016-10-29 08:19 - 2016-10-15 04:34 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-10-29 08:19 - 2016-10-15 04:34 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-10-29 08:19 - 2016-10-15 04:32 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2016-10-29 08:19 - 2016-09-10 14:21 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2016-10-29 08:19 - 2016-08-06 05:17 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-10-29 08:18 - 2016-10-15 05:38 - 00409952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2016-10-29 08:18 - 2016-10-15 05:32 - 00601712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2016-10-29 08:18 - 2016-10-15 05:31 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-10-29 08:18 - 2016-10-15 05:30 - 00557408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2016-10-29 08:18 - 2016-10-15 05:26 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-10-29 08:18 - 2016-10-15 05:26 - 00160096 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2016-10-29 08:18 - 2016-10-15 05:21 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2016-10-29 08:18 - 2016-10-15 05:20 - 02276736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-10-29 08:18 - 2016-10-15 05:19 - 00272720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2016-10-29 08:18 - 2016-10-15 05:18 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-10-29 08:18 - 2016-10-15 05:18 - 01556712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2016-10-29 08:18 - 2016-10-15 05:18 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-10-29 08:18 - 2016-10-15 05:15 - 03892352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-10-29 08:18 - 2016-10-15 05:15 - 01853776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-10-29 08:18 - 2016-10-15 05:15 - 01123368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-10-29 08:18 - 2016-10-15 05:15 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-10-29 08:18 - 2016-10-15 05:15 - 00687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2016-10-29 08:18 - 2016-10-15 05:11 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-10-29 08:18 - 2016-10-15 05:02 - 22568960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-10-29 08:18 - 2016-10-15 05:00 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2016-10-29 08:18 - 2016-10-15 04:59 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\stdole2.tlb
2016-10-29 08:18 - 2016-10-15 04:57 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2016-10-29 08:18 - 2016-10-15 04:56 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2016-10-29 08:18 - 2016-10-15 04:56 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-10-29 08:18 - 2016-10-15 04:56 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2016-10-29 08:18 - 2016-10-15 04:55 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-10-29 08:18 - 2016-10-15 04:54 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2016-10-29 08:18 - 2016-10-15 04:54 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2016-10-29 08:18 - 2016-10-15 04:53 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2016-10-29 08:18 - 2016-10-15 04:52 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-10-29 08:18 - 2016-10-15 04:52 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2016-10-29 08:18 - 2016-10-15 04:51 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-10-29 08:18 - 2016-10-15 04:51 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2016-10-29 08:18 - 2016-10-15 04:50 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-10-29 08:18 - 2016-10-15 04:49 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2016-10-29 08:18 - 2016-10-15 04:47 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-10-29 08:18 - 2016-10-15 04:47 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinfo32.exe
2016-10-29 08:18 - 2016-10-15 04:46 - 19418112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-10-29 08:18 - 2016-10-15 04:46 - 19416576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-10-29 08:18 - 2016-10-15 04:45 - 01790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2016-10-29 08:18 - 2016-10-15 04:44 - 03307520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-10-29 08:18 - 2016-10-15 04:44 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-10-29 08:18 - 2016-10-15 04:42 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercfg.exe
2016-10-29 08:18 - 2016-10-15 04:41 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2016-10-29 08:18 - 2016-10-15 04:39 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2016-10-29 08:18 - 2016-10-15 04:37 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2016-10-29 08:18 - 2016-10-15 04:37 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-10-29 08:18 - 2016-10-15 04:37 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2016-10-29 08:18 - 2016-10-15 04:37 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2016-10-29 08:18 - 2016-10-15 04:36 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2016-10-29 08:18 - 2016-10-15 04:36 - 01637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-10-29 08:18 - 2016-10-15 04:36 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-10-29 08:18 - 2016-10-15 04:36 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-10-29 08:18 - 2016-10-15 04:35 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-10-29 08:18 - 2016-10-15 04:34 - 02476544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2016-10-29 08:09 - 2016-10-29 11:19 - 00000000 ____D C:\Users\Silke\AppData\Roaming\TS3Client
2016-10-29 08:09 - 2016-10-29 08:09 - 00001008 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2016-10-29 08:09 - 2016-10-29 08:09 - 00000970 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
2016-10-29 08:09 - 2016-10-29 08:09 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2016-10-22 08:57 - 2016-10-30 09:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-10-12 13:12 - 2016-10-12 13:12 - 00000000 ____D C:\WINDOWS\PCHEALTH
2016-10-12 12:58 - 2016-10-05 11:17 - 01322848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2016-10-12 12:58 - 2016-10-05 11:13 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-10-12 12:58 - 2016-10-05 11:13 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2016-10-12 12:58 - 2016-10-05 11:12 - 02446696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-10-12 12:58 - 2016-10-05 11:09 - 00064352 _____ (Avago Technologies) C:\WINDOWS\system32\Drivers\MegaSas2i.sys
2016-10-12 12:58 - 2016-10-05 10:38 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2016-10-12 12:58 - 2016-10-05 10:36 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-12 12:58 - 2016-10-05 10:35 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2016-10-12 12:58 - 2016-10-05 10:35 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2016-10-12 12:58 - 2016-10-05 10:33 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2016-10-12 12:58 - 2016-10-05 10:33 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-10-12 12:58 - 2016-10-05 10:33 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2016-10-12 12:58 - 2016-10-05 10:32 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2016-10-12 12:58 - 2016-10-05 10:32 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-10-12 12:58 - 2016-10-05 10:31 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2016-10-12 12:58 - 2016-10-05 10:31 - 00425472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2016-10-12 12:58 - 2016-10-05 10:30 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2016-10-12 12:58 - 2016-10-05 10:29 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2016-10-12 12:58 - 2016-10-05 10:28 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2016-10-12 12:58 - 2016-10-05 10:26 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-10-12 12:58 - 2016-10-05 10:26 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-10-12 12:58 - 2016-10-05 10:26 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2016-10-12 12:58 - 2016-10-05 10:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll
2016-10-12 12:58 - 2016-10-05 10:25 - 01589248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2016-10-12 12:58 - 2016-10-05 10:25 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-10-12 12:58 - 2016-10-05 10:25 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2016-10-12 12:58 - 2016-10-05 10:25 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-10-12 12:58 - 2016-10-05 10:25 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
2016-10-12 12:58 - 2016-10-05 10:24 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
2016-10-12 12:58 - 2016-10-05 10:24 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2016-10-12 12:58 - 2016-10-05 10:23 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2016-10-12 12:58 - 2016-10-05 10:23 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll
2016-10-12 12:58 - 2016-10-05 10:23 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2016-10-12 12:58 - 2016-10-05 10:23 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2016-10-12 12:58 - 2016-10-05 10:23 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2016-10-12 12:58 - 2016-10-05 10:21 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-10-12 12:58 - 2016-10-05 10:21 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-10-12 12:58 - 2016-10-05 10:20 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2016-10-12 12:58 - 2016-10-05 10:20 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-10-12 12:58 - 2016-10-05 10:19 - 02390016 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2016-10-12 12:58 - 2016-10-05 10:18 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-10-12 12:58 - 2016-10-05 10:18 - 00858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-10-12 12:58 - 2016-10-05 10:18 - 00759296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-10-12 12:58 - 2016-10-05 10:17 - 08126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-10-12 12:58 - 2016-10-05 10:17 - 02914304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-10-12 12:58 - 2016-10-05 10:16 - 04747776 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-10-12 12:58 - 2016-10-05 10:16 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-10-12 12:58 - 2016-10-05 10:15 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2016-10-12 12:58 - 2016-10-05 10:15 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialclient.dll
2016-10-12 12:58 - 2016-10-05 10:14 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-10-12 12:58 - 2016-10-05 10:14 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2016-10-12 12:58 - 2016-10-05 10:13 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2016-10-12 12:58 - 2016-10-05 10:12 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2016-10-12 12:58 - 2016-10-05 10:11 - 06043136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-10-12 12:58 - 2016-10-05 10:11 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-10-12 12:58 - 2016-10-05 10:10 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2016-10-12 12:58 - 2016-10-05 10:09 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-10-12 12:58 - 2016-10-05 10:09 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-10-12 12:58 - 2016-10-05 10:08 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2016-10-12 12:58 - 2016-10-05 10:07 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-10-12 12:58 - 2016-10-05 10:07 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2016-10-12 12:58 - 2016-10-05 10:07 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2016-10-12 12:58 - 2016-10-05 10:07 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2016-10-12 12:58 - 2016-10-05 10:06 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-10-12 12:58 - 2016-09-07 06:34 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-10-12 12:57 - 2016-10-05 11:35 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-10-12 12:57 - 2016-10-05 11:33 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2016-10-12 12:57 - 2016-10-05 11:31 - 02213248 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-10-12 12:57 - 2016-10-05 11:22 - 01181536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-10-12 12:57 - 2016-10-05 11:16 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-10-12 12:57 - 2016-10-05 11:12 - 01112928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-10-12 12:57 - 2016-10-05 11:09 - 01071728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-10-12 12:57 - 2016-10-05 11:08 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-10-12 12:57 - 2016-10-05 11:03 - 01705976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-10-12 12:57 - 2016-10-05 10:51 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-10-12 12:57 - 2016-10-05 10:50 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2016-10-12 12:57 - 2016-10-05 10:49 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2016-10-12 12:57 - 2016-10-05 10:48 - 01022304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-10-12 12:57 - 2016-10-05 10:46 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-10-12 12:57 - 2016-10-05 10:46 - 00980824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-10-12 12:57 - 2016-10-05 10:38 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2016-10-12 12:57 - 2016-10-05 10:36 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthpan.sys
2016-10-12 12:57 - 2016-10-05 10:36 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2016-10-12 12:57 - 2016-10-05 10:35 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2016-10-12 12:57 - 2016-10-05 10:35 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-10-12 12:57 - 2016-10-05 10:34 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-10-12 12:57 - 2016-10-05 10:32 - 00379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2016-10-12 12:57 - 2016-10-05 10:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
2016-10-12 12:57 - 2016-10-05 10:31 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-10-12 12:57 - 2016-10-05 10:31 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-10-12 12:57 - 2016-10-05 10:31 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-10-12 12:57 - 2016-10-05 10:31 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2016-10-12 12:57 - 2016-10-05 10:31 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll
2016-10-12 12:57 - 2016-10-05 10:29 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-10-12 12:57 - 2016-10-05 10:28 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-10-12 12:57 - 2016-10-05 10:28 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2016-10-12 12:57 - 2016-10-05 10:28 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2016-10-12 12:57 - 2016-10-05 10:28 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll
2016-10-12 12:57 - 2016-10-05 10:27 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-10-12 12:57 - 2016-10-05 10:27 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2016-10-12 12:57 - 2016-10-05 10:27 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-12 12:57 - 2016-10-05 10:23 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-10-12 12:57 - 2016-10-05 10:22 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2016-10-12 12:57 - 2016-10-05 10:21 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
2016-10-12 12:57 - 2016-10-05 10:20 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-10-12 12:57 - 2016-10-05 10:18 - 01656832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-10-12 12:57 - 2016-10-05 10:17 - 04136960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2016-10-12 12:57 - 2016-10-05 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
2016-10-12 12:57 - 2016-10-05 10:16 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-10-12 12:57 - 2016-10-05 10:16 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-10-12 12:57 - 2016-10-05 10:16 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-10-12 12:57 - 2016-10-05 10:15 - 00833024 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-10-12 12:57 - 2016-10-05 10:15 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-10-12 12:57 - 2016-10-05 10:15 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2016-10-12 12:57 - 2016-10-05 10:14 - 01013760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-10-12 12:57 - 2016-10-05 10:13 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-10-12 12:57 - 2016-10-05 10:12 - 00998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2016-10-12 12:57 - 2016-10-05 10:12 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-10-12 12:57 - 2016-10-05 10:11 - 03496960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2016-10-12 12:57 - 2016-10-05 10:09 - 03369984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2016-10-12 12:57 - 2016-10-05 10:08 - 02356736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2016-10-12 12:57 - 2016-10-05 10:08 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-10-12 12:57 - 2016-10-05 10:07 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2016-10-12 12:57 - 2016-10-05 10:06 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-10-12 12:57 - 2016-10-05 10:05 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2016-10-12 12:57 - 2016-10-05 10:05 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-10-12 12:57 - 2016-10-05 01:01 - 00446124 _____ C:\WINDOWS\system32\ApnDatabase.xml

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-11-01 18:49 - 2016-09-29 03:40 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-11-01 16:33 - 2016-09-29 03:47 - 02269906 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-11-01 16:33 - 2016-07-16 23:51 - 00888130 _____ C:\WINDOWS\system32\perfh007.dat
2016-11-01 16:33 - 2016-07-16 23:51 - 00209018 _____ C:\WINDOWS\system32\perfc007.dat
2016-11-01 16:33 - 2015-09-29 14:13 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2016-11-01 16:32 - 2015-12-23 10:29 - 00000000 ____D C:\Users\Silke\AppData\Local\CrashDumps
2016-11-01 16:30 - 2015-08-15 18:10 - 00000000 __SHD C:\Users\Silke\IntelGraphicsProfiles
2016-11-01 16:30 - 2013-04-01 17:25 - 00000000 ____D C:\ProgramData\Bigfoot Networks
2016-11-01 16:29 - 2016-09-29 04:10 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-11-01 16:29 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-11-01 14:19 - 2015-01-18 16:39 - 00000000 ____D C:\WINDOWS\system32\log
2016-11-01 07:21 - 2016-09-29 03:48 - 00000000 ____D C:\Users\Silke
2016-11-01 07:18 - 2014-11-12 11:51 - 00000000 ____D C:\Users\Silke\AppData\Local\NVIDIA Corporation
2016-11-01 07:18 - 2014-11-12 11:51 - 00000000 ____D C:\Users\Silke\AppData\Local\NVIDIA
2016-11-01 07:11 - 2013-04-02 19:04 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-11-01 07:08 - 2016-07-16 07:04 - 00008192 _____ C:\WINDOWS\system32\config\ELAM
2016-10-30 19:10 - 2014-05-13 18:12 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-10-30 10:13 - 2016-09-29 04:10 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-10-30 10:13 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-10-30 10:13 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-10-30 10:13 - 2014-08-16 18:52 - 00000000 ____D C:\Users\Silke\AppData\Local\Adobe
2016-10-30 10:11 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-10-30 09:56 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2016-10-30 09:55 - 2015-08-15 18:10 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-10-30 09:53 - 2016-09-29 03:40 - 00352720 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-10-30 09:53 - 2015-03-18 18:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-10-29 12:22 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-10-29 12:21 - 2016-07-16 12:47 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2016-10-29 12:21 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-10-29 12:21 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-10-29 12:21 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-10-29 12:21 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-10-29 08:38 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-10-29 08:21 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2016-10-25 00:30 - 2016-07-16 12:49 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-10-25 00:30 - 2016-07-16 12:49 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-22 11:44 - 2013-09-08 19:33 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-10-22 08:59 - 2016-09-29 03:44 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-10-22 08:59 - 2016-09-29 03:44 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-10-22 08:59 - 2016-09-29 03:44 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-10-14 11:56 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache
2016-10-14 11:35 - 2016-09-29 04:10 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-10-14 11:35 - 2015-11-04 17:59 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-10-12 16:49 - 2015-03-17 19:49 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-10-12 16:49 - 2015-03-17 19:49 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-10-12 16:46 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-10-12 16:46 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-10-12 16:46 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-10-12 16:46 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-10-12 16:46 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-10-12 13:11 - 2015-03-17 19:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-10-12 13:10 - 2013-07-30 19:30 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-10-12 13:06 - 2013-04-04 03:59 - 143495576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-10-12 12:47 - 2016-07-16 12:42 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll
2016-10-12 12:46 - 2016-07-16 12:43 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2016-10-10 11:08 - 2013-09-16 15:29 - 00000000 ____D C:\ProgramData\CanonIJPLM
2016-10-05 08:13 - 2016-09-04 11:09 - 00000000 ____D C:\ProgramData\Sonos,_Inc

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2013-12-20 13:16 - 2015-03-17 19:04 - 0000183 _____ () C:\Users\Silke\AppData\Roaming\WB.CFG
2013-04-01 17:24 - 2013-04-01 17:32 - 0000351 _____ () C:\Users\Silke\AppData\Local\killertool.log

Einige Dateien in TEMP:
====================
C:\Users\Silke\AppData\Local\Temp\libeay32.dll
C:\Users\Silke\AppData\Local\Temp\msvcr120.dll
C:\Users\Silke\AppData\Local\Temp\sqlite3.dll
C:\Users\Silke\AppData\Local\Temp\VSUSetup.exe


==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-10-29 08:22

==================== Ende von FRST.txt ============================


Schuhmi 02.11.2016 12:13

Addittion
 
Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 30-10-2016
durchgeführt von Silke (02-11-2016 12:07:14)
Gestartet von C:\Users\Silke\Desktop
Windows 10 Pro Version 1607 (X64) (2016-09-29 03:13:39)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-1071034996-3370113837-20168928-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1071034996-3370113837-20168928-503 - Limited - Disabled)
Gast (S-1-5-21-1071034996-3370113837-20168928-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-1071034996-3370113837-20168928-1002 - Limited - Enabled)
Silke (S-1-5-21-1071034996-3370113837-20168928-1000 - Administrator - Enabled) => C:\Users\Silke
Sonos (S-1-5-21-1071034996-3370113837-20168928-1006 - Limited - Enabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Kaspersky Internet Security (Enabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.020.20039 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.205 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-1071034996-3370113837-20168928-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC)
Amyuni PDF Converter (HKLM-x32\...\{F3036434-FFF7-449A-AC9E-7D5C5F18875B}) (Version: 1.0.0 - Amyuni Technologies)
Ansel (Version: 372.90 - NVIDIA Corporation) Hidden
Apple Application Support (32-Bit) (HKLM-x32\...\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version:  - )
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.3.5.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version:  - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version:  - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version:  - )
Canon Kurzwahlprogramm (HKLM-x32\...\Speed Dial Utility) (Version:  - )
Canon MP Navigator EX 4.1 (HKLM-x32\...\MP Navigator EX 4.1) (Version:  - )
Canon MX880 series Benutzerregistrierung (HKLM-x32\...\Canon MX880 series Benutzerregistrierung) (Version:  - )
Canon MX880 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX880_series) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version:  - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DLLEscort version 2014 (HKLM-x32\...\{2F13CA65-0FFB-4760-824B-D459836AACFE}_is1) (Version: 2014 - )
ELAN Touchpad 15.13.1.1_X64_WHQL (HKLM\...\Elantech) (Version: 15.13.1.1 - ELAN Microelectronic Corp.)
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Free YouTube Download version 3.2.60.713 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.60.713 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.59.525 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.59.525 - DVDVideoSoft Ltd.)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1262 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{A10B1524-63B5-40F2-B272-D841CF671C16}) (Version: 2.2.0.0266 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{795ee3a0-97fa-489a-9543-7564ccc43be4}) (Version: 18.12.0 - Intel Corporation)
Intel® PROSet/Wireless WiFi-Software (HKLM\...\{54EB8041-1115-4406-AA4B-44D236E84B3B}) (Version: 15.01.1000.0927 - Intel Corporation)
iTunes (HKLM\...\{F11677B7-0D8E-4F34-BEBB-6869FE861CDF}) (Version: 12.5.2.36 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{77E7AE5C-181C-4CAF-ADBF-946F11C1CE26}) (Version: 16.0.0.614 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 16.0.0.614 - Kaspersky Lab) Hidden
Meine CEWE FOTOWELT (HKLM-x32\...\Meine CEWE FOTOWELT) (Version: 6.1.3 - CEWE Stiftung u Co. KGaA)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 49.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 49.0.2 (x86 de)) (Version: 49.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.2.6136 - Mozilla)
NVIDIA Grafiktreiber 372.90 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 372.90 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
paint.net (HKLM\...\{F509C1F4-0029-49F9-B145-A4C4E8DF481A}) (Version: 4.0.3 - dotPDN LLC)
PAYBACK Toolbar 1.2 (HKLM-x32\...\PAYBACK Toolbar_is1) (Version: 1.2.0 - PAYBACK GmbH)
PDF24 Creator 7.0.6 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
Qualcomm Atheros Killer Network Manager (HKLM-x32\...\InstallShield_{DF446558-ADF7-4884-9B2D-281979CCE71F}) (Version: 6.1.0.546 - Qualcomm Atheros)
Qualcomm Atheros Killer Network Manager (Version: 6.1.0.546 - Qualcomm Atheros) Hidden
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.20.15.822 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.50.1123.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.92 - Realtek Semiconductor Corp.)
Revo Uninstaller 2.0.1 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.1 - VS Revo Group, Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.)
SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.11.4.1 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.16034.4 - Samsung Electronics Co., Ltd.)
Smart Switch (x32 Version: 4.1.16034.4 - Samsung Electronics Co., Ltd.) Hidden
Sonos Controller (HKLM-x32\...\{7BBA9BF8-05DF-47D8-8880-82A9B99505B9}) (Version: 33.15.32221 - Sonos, Inc.)
System Explorer 7.0.0 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version:  - Mister Group)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Movie Maker Packages (HKU\S-1-5-21-1071034996-3370113837-20168928-1000\...\Windows Movie Maker Packages) (Version:  - ) <==== ACHTUNG
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WISO steuer:Start 2016 (HKLM-x32\...\{94E846D3-31D1-438D-9F48-03B9DCBDA6FF}) (Version: 23.00.1146 - Buhl Data Service GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-1071034996-3370113837-20168928-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Silke\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay => Keine Datei
CustomCLSID: HKU\S-1-5-21-1071034996-3370113837-20168928-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Silke\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1071034996-3370113837-20168928-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {0C15F3CC-C0E5-4C6C-87A1-60AD925E8F2A} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {0CA0E2BD-70C3-42DD-907D-DD9AD6D7142F} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {163B24DB-5E52-47AE-AE44-A6B64DDE158F} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {1F824AF6-4E12-443E-9F9D-EC311DEFCDC8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {21261D13-BD65-4507-89BC-B236D14F9F3E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {2CF758F7-A5C7-4613-8C1A-6BC441CF7480} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated)
Task: {3B54B6AC-DB6D-4750-A516-943EED0408C9} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {42977585-ED9A-4157-8FE1-A374DB38BCF3} - System32\Tasks\{3D6DD0F5-D265-4701-9155-ADE0F309BE73} => pcalua.exe -a C:\Users\Silke\Downloads\wlsetup-web.exe -d C:\Users\Silke\Downloads
Task: {43A80589-A2BF-4F1C-B4CD-E39799F45A4B} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {479574CB-D019-4517-BCBD-475F8C05BA89} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4A7F390C-C9A1-4CD1-8DEE-3E46D444B246} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {4CA30E77-F2FC-4CF5-91ED-01FA6317CA76} - System32\Tasks\{17F07EA4-C09C-4B43-8FB2-C7CCED501F5C} => Firefox.exe hxxp://ui.skype.com/ui/0/6.9.0.106/de/abandoninstall?source=lightinstaller&amp;page=tsInstall
Task: {53EFDABC-F6B3-4012-9488-F7901C696B14} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {60479927-93B8-4B38-8730-56D6301C88CF} - \{59D238D8-938B-4672-954A-693E8EB20C34} -> Keine Datei <==== ACHTUNG
Task: {662D35FA-DCE4-4A07-94B9-2A3296198198} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-30] (Adobe Systems Incorporated)
Task: {6C689DF8-220C-4583-9904-C721F175B186} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {746EDE2B-549E-4EA7-8274-AFCAB3069221} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {74D76C5F-EBA9-4A21-8FD4-7C2620A8E16D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {84F01F13-8490-46F5-B64E-38CD6126BE0D} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {88C43CA2-B85B-4CE6-A062-0BB841A95234} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {998816CB-441D-4DC6-8370-7932BD60C79B} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {9CF76BFB-F4EF-4D60-97FC-81977D2CF196} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {9DDEA542-7F26-4A97-92EF-178D3B562703} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {A0569719-C494-4A10-A08D-55F6F8A46797} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {A058EE6E-3817-4B40-8ABE-49D6A4F48AB5} - System32\Tasks\{912C7E8E-4F51-478E-A516-771DD4B448CD} => pcalua.exe -a C:\Users\Silke\Downloads\WISOSteuersoftware2016.exe -d C:\Users\Silke\Downloads
Task: {A11C333B-98BF-404A-9F2F-E8F6F4C2E6AF} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A58890ED-A733-4946-AE86-205FB3AFA81B} - System32\Tasks\{A14EE0AA-1084-4F7B-A5AB-B535B1BDB143} => pcalua.exe -a "C:\Users\Silke\AppData\Local\Temp\Temp2_lan_rtl8111e_vl_cg_7.50.1123.2011 _w700.zip\Install_Win7_7050_01162012\AutoInst.exe" <==== ACHTUNG
Task: {B1DD1866-BDEC-452A-86EF-E2142AB7BB7F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {B5539F83-A1D2-476C-BE6A-D8CD9C0BAA82} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {B9D51507-6E49-4605-8E65-850AA70402C5} - System32\Tasks\{561C364D-BF8F-43D7-9014-63E30C5981D3} => pcalua.exe -a C:\Users\Silke\Downloads\wlsetup-all_16.4.3508.0205.exe -d C:\Users\Silke\Downloads
Task: {C148D101-F8CF-491E-8394-F8CF1B7E8496} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {C48BA690-A17B-4E4C-8F00-AFDFC69D1B49} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {C973BF7C-C325-411C-956A-CC8C3866975F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {CCE15754-B147-4EAC-85D6-01431D8F7BE2} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {CF2CA425-4CEF-4D52-B6D6-162648D88CF8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-10-12] (Microsoft Corporation)
Task: {DA493BF3-EB43-4838-BBBF-A9B5F4551EC0} - System32\Tasks\{7A551689-1465-4F7B-9CAB-8E56CEB9BC2E} => Firefox.exe hxxp://ui.skype.com/ui/0/6.9.0.106/de/abandoninstall?source=lightinstaller&amp;page=tsPlugin
Task: {DBBCEC75-1DD8-4E79-845F-1B9CFB09F430} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DF0F847F-019B-477F-9F8D-1E58743EF896} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E20CCB9F-FB11-4C72-9C65-DD6808674C8F} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E6CA9D5D-5383-4C00-9AFC-96121A80E6FE} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {E7EF2823-D70A-4EDD-A9D4-87F50D5C061A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EB07B510-93DC-4865-8397-35326BCF2025} - \{F2AA9CDE-5984-48D8-B1D6-054646284C72} -> Keine Datei <==== ACHTUNG
Task: {EBC7FD1C-0FFF-4A80-B319-621005A9B529} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {EE996A7A-4BD9-4C02-BA16-B7554D5DD162} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {F22C4B54-C60C-48B2-A7D4-C06722FFFB6E} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {F2B08D0A-FAE2-4C7F-BED7-A94C029F1B8C} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {FEA0131B-DBE1-4B47-B9AB-526F589382E0} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-09-30 04:09 - 2016-09-15 18:25 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-09-29 03:44 - 2016-09-16 23:54 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-09-17 17:15 - 2010-07-27 01:44 - 00137680 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2016-09-01 17:12 - 2016-09-01 17:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-05-02 19:59 - 2016-06-15 02:14 - 00369208 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2015-12-23 10:17 - 2016-06-15 02:14 - 00289848 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-05-02 19:59 - 2016-06-15 02:14 - 01148984 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll
2016-05-02 19:59 - 2016-06-15 02:14 - 03613240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2013-02-19 18:31 - 2013-02-19 18:31 - 00497664 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe
2011-05-09 18:56 - 2011-05-09 18:56 - 09856000 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtGui4.dll
2011-05-09 18:46 - 2011-05-09 18:46 - 02760192 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtCore4.dll
2011-05-09 18:47 - 2011-05-09 18:47 - 00416256 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtXml4.dll
2013-02-19 18:31 - 2013-02-19 18:31 - 00217600 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFCommon.dll
2011-05-09 18:48 - 2011-05-09 18:48 - 00990720 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtNetwork4.dll
2011-05-10 10:32 - 2011-05-10 10:32 - 00731648 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\qwt5.dll
2014-11-12 16:12 - 2015-08-22 16:38 - 00076152 _____ () C:\WINDOWS\system32\PnkBstrA.exe
2016-05-02 19:59 - 2016-06-15 02:14 - 02667576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll
2016-05-02 19:59 - 2016-06-15 02:14 - 01990200 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll
2016-05-02 19:59 - 2016-06-15 02:14 - 01842232 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll
2016-01-28 14:44 - 2016-06-15 02:14 - 00208952 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll
2016-09-30 04:09 - 2016-09-15 18:25 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-09-29 06:29 - 2016-09-29 06:29 - 00959168 _____ () C:\Users\Silke\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-09-29 04:28 - 2016-09-29 04:28 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-10-12 12:57 - 2016-10-05 10:35 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2016-10-29 08:20 - 2016-10-15 04:41 - 09760256 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-10-29 08:20 - 2016-10-15 04:34 - 01401344 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-10-29 08:20 - 2016-10-15 04:34 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-10-29 08:20 - 2016-10-15 04:34 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-10-29 08:20 - 2016-10-15 04:34 - 02424832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-10-29 08:20 - 2016-10-15 04:38 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-10-21 04:37 - 2016-10-21 04:38 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2016-10-21 04:37 - 2016-10-21 04:38 - 00178176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2016-10-21 04:37 - 2016-10-21 04:38 - 35253760 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2013-02-19 18:31 - 2013-02-19 18:31 - 00553984 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe
2013-02-19 18:32 - 2013-02-19 18:32 - 00404992 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modApplications.dll
2013-02-19 18:32 - 2013-02-19 18:32 - 00036864 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modFeatures.dll
2013-02-19 18:32 - 2013-02-19 18:32 - 00025088 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modFraps.dll
2013-02-19 18:32 - 2013-02-19 18:32 - 00240128 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modGraph.dll
2013-02-19 18:32 - 2013-02-19 18:32 - 00062464 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modlcd.dll
2013-02-19 18:32 - 2013-02-19 18:32 - 00291328 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modNetwork.dll
2013-02-19 18:32 - 2013-02-19 18:32 - 00184832 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modNpu.dll
2013-02-19 18:32 - 2013-02-19 18:32 - 00211456 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modOptions.dll
2013-02-19 18:32 - 2013-02-19 18:32 - 00064000 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modOverview.dll
2013-02-19 18:32 - 2013-02-19 18:32 - 00317440 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\plugins\modSystemInfo.dll
2016-05-02 19:59 - 2016-06-15 02:14 - 00035896 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll
2016-05-02 19:59 - 2016-06-15 02:14 - 00921656 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll
2015-07-08 22:18 - 2015-07-08 22:18 - 00794920 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\kpcengine.2.3.dll
2015-08-17 14:24 - 2016-06-15 02:14 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-1071034996-3370113837-20168928-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Silke\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\8 lindos (100).jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

HKLM\...\StartupApproved\StartupFolder: => "WISO Mein Steuer-Sparbuch heute.lnk"
HKLM\...\StartupApproved\Run: => "ETDCtrl"
HKLM\...\StartupApproved\Run: => "RTHDVCPL"
HKLM\...\StartupApproved\Run: => "BLEServicesCtrl"
HKLM\...\StartupApproved\Run: => "CanonMyPrinter"
HKLM\...\StartupApproved\Run: => "HotKeysCmds"
HKLM\...\StartupApproved\Run: => "Persistence"
HKLM\...\StartupApproved\Run: => "IgfxTray"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run: => "NvBackend"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run32: => "IJNetworkScannerSelectorEX"
HKLM\...\StartupApproved\Run32: => "CanonSolutionMenuEx"
HKLM\...\StartupApproved\Run32: => "IAStorIcon"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKLM\...\StartupApproved\Run32: => "USB3MON"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKLM\...\StartupApproved\Run32: => "Reader Application Helper"
HKU\S-1-5-21-1071034996-3370113837-20168928-1000\...\StartupApproved\Run: => "AmazonMP3DownloaderHelper"
HKU\S-1-5-21-1071034996-3370113837-20168928-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1071034996-3370113837-20168928-1000\...\StartupApproved\Run: => "TomTomHOME.exe"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{27FFD39E-2BD3-40FB-B065-D8CE85C71154}] => (Allow) C:\Program Files (x86)\Sonos\Sonos.exe
FirewallRules: [{35A0372A-3948-4E10-935C-A087EA60A5F5}] => (Allow) C:\Program Files (x86)\Sonos\Sonos.exe
FirewallRules: [{23414197-80E6-4D67-B4E0-7D2F617F0163}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{583DBB9A-D589-4C64-A19F-7CA4898A82F8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AC4ABB19-D56F-4C0E-A936-29722BD004F8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{98261C7D-03AA-42EA-8D25-F75FB785CF66}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{52BB2281-887D-4734-A472-39DE1A227837}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{50C3477C-988C-4FAA-9CD9-940855ABCE83}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0BB6E180-4509-45B4-90CD-39920BBC6F13}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{787E35A5-0FFD-45D7-A719-51AF59406850}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{D85294AA-9FAD-4005-93E6-E3BEFFED3E7B}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{30F388BB-65DB-4EFC-A942-8A51C57DC928}] => (Allow) LPort=3659
FirewallRules: [{347B4D8D-6C60-4980-A1E8-77CFD1C72A1D}] => (Allow) LPort=3659
FirewallRules: [{4B056E01-23E1-4C19-8D08-1236A0562899}] => (Allow) LPort=3659
FirewallRules: [{77AB59E1-3275-4B7B-8A72-F254F8E69F82}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [{B71A36F8-2D2E-4784-804D-3B1FE5E27C47}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [{2A63E604-F2A8-40B2-8E75-95A483AFA42C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{A0D91ADE-C521-47EA-A71A-E2CC33723417}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{688B0A58-1C3B-4AC7-9517-2032AC39B2AB}] => (Allow) LPort=1900
FirewallRules: [{F7311CAB-F77B-49C3-8FA2-7A14B78F2B5C}] => (Allow) LPort=2869
FirewallRules: [{DB4015EC-DA79-44A4-84E2-1C1ACD7CF9B9}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{A5B325EB-665E-4B57-97E3-20F912FDC7D0}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{DAB09708-EE85-4D82-AB67-51158F8C8AC6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{3BD97D36-7B8B-4C59-B67F-F732C986DBE4}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{413EE43D-A26E-4A04-8804-FAE5946B91AE}] => (Allow) C:\Users\Silke\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C00A5D9C-672C-425A-A697-C26199F13602}] => (Allow) C:\Users\Silke\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{8D2C524B-8949-4DAA-BCF7-0B06B446CDBA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{AC56AE81-D11A-40D7-AE04-11F0ABB0BD65}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{6F712854-B670-4F38-9C32-3ED6F5C0C42A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{F785DEE3-49FE-4897-ABA4-FAD16EA11EAB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{7558DC77-3ED4-4287-8708-25EC87CB813C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{CA897A56-3A5B-4EF6-B5DF-C95400AFD2DD}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{2339E12B-F769-4600-8920-4072B22B4DA0}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BD178D7-433A-4612-8F05-9F0574148D69}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{602586B3-E3DF-46F2-BAA3-236BE73CB85C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{5EB8DA83-7CF0-4135-84D9-1F79D1F05970}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0DD54DC5-7E2A-45BC-87F3-59CCDB91E599}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CDFE99B4-B024-4BF9-ABDC-7DDF27D3165F}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{F68EE878-99D7-45F2-86EC-25290647BC88}] => (Allow) C:\Program Files\iTunes\iTunes.exe

==================== Wiederherstellungspunkte =========================

21-10-2016 16:00:41 Windows Update
29-10-2016 08:23:01 Windows Update
01-11-2016 07:29:51 Removed Amyuni PDF Converter
01-11-2016 14:23:42 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (11/02/2016 12:03:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SILKE-LAPI)
Description: Bei der Aktivierung der App „Microsoft.MicrosoftJigsaw_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927148. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (11/02/2016 12:03:26 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 62013610

Error: (11/02/2016 12:03:26 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 62013610

Error: (11/02/2016 12:03:26 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (11/01/2016 04:32:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: backgroundTaskHost.exe, Version: 10.0.14393.0, Zeitstempel: 0x57899bb2
Name des fehlerhaften Moduls: twinapi.appcore.dll, Version: 10.0.14393.206, Zeitstempel: 0x57daca78
Ausnahmecode: 0xc000027b
Fehleroffset: 0x000000000006d1c4
ID des fehlerhaften Prozesses: 0x1c1c
Startzeit der fehlerhaften Anwendung: 0x01d2345516917434
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\backgroundTaskHost.exe
Pfad des fehlerhaften Moduls: C:\Windows\System32\twinapi.appcore.dll
Berichtskennung: f0a7d6a3-078c-467f-a556-9572e6ae0d50
Vollständiger Name des fehlerhaften Pakets: Microsoft.People_10.0.11902.0_x64__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x

Error: (11/01/2016 04:32:06 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SILKE-LAPI)
Description: Bei der Aktivierung der App „Microsoft.MicrosoftJigsaw_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927148. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (11/01/2016 04:30:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NvStreamUserAgent.exe, Version: 7.1.2084.9592, Zeitstempel: 0x57605c64
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.14393.351, Zeitstempel: 0x5801a332
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000003061d
ID des fehlerhaften Prozesses: 0x19c8
Startzeit der fehlerhaften Anwendung: 0x01d23454d3d2f772
Pfad der fehlerhaften Anwendung: C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll
Berichtskennung: e5261840-8d08-43e8-8ffa-7e98830c22f5
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (11/01/2016 02:25:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NvStreamUserAgent.exe, Version: 7.1.2084.9592, Zeitstempel: 0x57605c64
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.14393.351, Zeitstempel: 0x5801a332
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000003061d
ID des fehlerhaften Prozesses: 0x1a64
Startzeit der fehlerhaften Anwendung: 0x01d234436406afa6
Pfad der fehlerhaften Anwendung: C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll
Berichtskennung: a09e1952-6b19-4282-bbd4-09d55898dbed
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (11/01/2016 02:25:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NvStreamUserAgent.exe, Version: 7.1.2084.9592, Zeitstempel: 0x57605c64
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.14393.351, Zeitstempel: 0x5801a332
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000003061d
ID des fehlerhaften Prozesses: 0x1354
Startzeit der fehlerhaften Anwendung: 0x01d234435ce5d6a5
Pfad der fehlerhaften Anwendung: C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll
Berichtskennung: 38c9cd28-e761-41a5-8635-2263dffa4dfd
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (11/01/2016 02:24:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NvStreamUserAgent.exe, Version: 7.1.2084.9592, Zeitstempel: 0x57605c64
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.14393.351, Zeitstempel: 0x5801a332
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000003061d
ID des fehlerhaften Prozesses: 0x1d88
Startzeit der fehlerhaften Anwendung: 0x01d23443574c5aa1
Pfad der fehlerhaften Anwendung: C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll
Berichtskennung: 54961375-818b-4216-8358-12e7f8906d20
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:


Systemfehler:
=============
Error: (11/01/2016 04:30:08 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 und der APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (11/01/2016 04:30:08 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 und der APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (11/01/2016 04:30:08 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 und der APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (11/01/2016 04:29:52 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden.

Error: (11/01/2016 02:24:42 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 und der APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (11/01/2016 02:23:53 PM) (Source: DCOM) (EventID: 10010) (User: SILKE-LAPI)
Description: Der Server "{DABF28BE-F6B4-4E40-8F40-C4FB26F3116C}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (11/01/2016 02:21:13 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 und der APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (11/01/2016 02:21:13 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 und der APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (11/01/2016 02:21:13 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 und der APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (11/01/2016 02:20:43 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz
Prozentuale Nutzung des RAM: 42%
Installierter physikalischer RAM: 8080.66 MB
Verfügbarer physikalischer RAM: 4625.93 MB
Summe virtueller Speicher: 16272.66 MB
Verfügbarer virtueller Speicher: 12846.34 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:697.7 GB) (Free:562.82 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: A4F564EA)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=697.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=855 MB) - (Type=27)

==================== Ende von Addition.txt ============================

Kaspersky hat sich heut beim boot auch normal verhalten ... keine Warnungen, war wohl dch noch alt der Hinweis gestern ...

cosinus 02.11.2016 12:29

Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    Windows Movie Maker Packages

  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 


Schuhmi 02.11.2016 12:36

erledigt ... gab noch einiges, gelöscht!

cosinus 02.11.2016 12:39

Okay, dann Kontrollscans mit (1) MBAM, (2) ESET und (3) SecurityCheck bitte:


1. Schritt: MBAM

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




2. Schritt: ESET

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




3. Schritt: SecurityCheck

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

Schuhmi 02.11.2016 15:35

MBAM hat wieder angeschlagen wegen windows movie maker/ 2 Datein ... ompf, hab aber alles angeklickt und deinstall soweit ich konnte ... kagge^^ ... Logs folgen, ESET braucht ewig.

Zudem ist mir dies hier noch aufgefallen nach löschen&neustart durch mbam

http://fs5.directupload.net/images/161102/euvfvmj3.jpg

mabam
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlaufdatum: 02.11.2016
Suchlaufzeit: 12:48
Protokolldatei: mbamlog.txt
Administrator: Ja

Version: 2.2.1.1043
Malware-Datenbank: v2016.11.02.05
Rootkit-Datenbank: v2016.10.31.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: Silke

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 390100
Abgelaufene Zeit: 17 Min., 13 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 2
PUP.Optional.InstallCore, C:\Users\Silke\AppData\Roaming\0C1I1L1R1J0C1F1G1G1P1R2Z\Windows Movie Maker Packages\uninstaller.exe, In Quarantäne, [b0cdf8c3ebaf2313a8546398ae53cb35],
PUP.Optional.InstallCore, C:\Users\Silke\AppData\Local\Temp\72275578.Uninstall\uninstaller.exe, In Quarantäne, [25580ead6634a88ef00c23d87e835ca4],

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)

Eset
Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=635cc8f88fd8ee4490c0916ec17d6ea6
# end=init
# utc_time=2016-11-02 12:15:32
# local_time=2016-11-02 01:15:32 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 31273
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=635cc8f88fd8ee4490c0916ec17d6ea6
# end=updated
# utc_time=2016-11-02 12:18:03
# local_time=2016-11-02 01:18:03 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=635cc8f88fd8ee4490c0916ec17d6ea6
# engine=31273
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-11-02 02:23:16
# local_time=2016-11-02 03:23:16 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1305 16777213 100 100 11407 42318848 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 2976838 32021664 0 0
# scanned=295752
# found=1
# cleaned=0
# scan_time=7512
sh=928A536FBFF196495B90E4BD51B932485B84A099 ft=1 fh=748b6a41a833329e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Silke\AppData\Local\Temp\DMR\dmr_72.exe"

Security
Code:

Results of screen317's Security Check version 1.009 
  x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
Kaspersky Internet Security 
Windows Defender             
 Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````
 Java 8 Update 71 
 Java version 32-bit out of Date!
 Adobe Flash Player        23.0.0.205 
 Mozilla Firefox (49.0.2)
 Google Chrome 41.0.2272.89 Google Chrome out of date! 
````````Process Check: objlist.exe by Laurent```````` 
 Malwarebytes Anti-Malware mbamservice.exe 
 Malwarebytes Anti-Malware mbam.exe 
 Malwarebytes Anti-Malware mbamscheduler.exe 
 Kaspersky Lab Kaspersky Internet Security 16.0.0 avp.exe 
 Kaspersky Lab Kaspersky Internet Security 16.0.0 avpui.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````

das hat gedauert mit ESET :-)

cosinus 02.11.2016 15:39

Zitat:

Google Chrome 41.0.2272.89 Google Chrome out of date!
Deinstallieren
Aber nicht einfach da drauf lassen. Wenn du Software nutzen willst muss sie immer aktuell gehalten werden. Ansosnten halt weg damit.


Zitat:

Adobe Flash Player 23.0.0.205
Java 8 Update 71
Auch weg damit.

Flash Player: Was Adobe mit seinem Flash Player veranstaltet, ist irgendwo zwischen Frechheit und Inkompetenz einzustufen; in dem Teil werden ständig neue dicke Sicherheitslücken gefunden - für YT reicht meistens HTML5 aus, das ist der Standardplayer wenn der Flash Player inaktiv oder nicht installiert ist; für spezielle Browsergames kann es aber sein, dass du den Flash Player brauchst. Nutze Flash so sparsam wie möglich und wenn dann immer aktuell halten!!

Java: Spielt kaum noch eine Rolle. Fast nirgendwo werden mehr Java-Applets eingesetzt. Wird noch für spezielles Zeugs in OpenOffice genutzt, IIRC brauchen auch manche Games Java. Aber wirklich sehr selten.

Schuhmi 02.11.2016 15:47

verstanden ... wie bekomm ich die 3 sauber weg?

Edit: Java & FlashPL deinstalliert über WinProg / Chrome nicht gefunden = Programme x86 Chrome Ordner gelöscht
Hoffe das passt so ...



... wir sind aber noch nicht fertig mit dem Hauptproblem nehm ich an oder?
ESET hab ich den Fund nicht gelöscht ... war ja so in der Anleitung vermerkt?!

cosinus 02.11.2016 20:46

Das ist doch nur irrelevanter Müll im Tempordner!

Was ist jetzt mit diesem YAC? Wo ist das noch zu sehen?

Schuhmi 02.11.2016 21:54

unklar:-)
 
Zitat:

Zitat von cosinus (Beitrag 1620209)
Das ist doch nur irrelevanter Müll im Tempordner!

was ist irrelevanter Müll im Temp-Ordner? Der Eset-Fund? oder was jetzt?

Zitat:

Zitat von cosinus (Beitrag 1620209)
Was ist jetzt mit diesem YAC? Wo ist das noch zu sehen?

Das fragst du mich :rofl:? Du bist doch der Fachmann^^ ... sieht denn alles sauber aus?

--------------------
Das einzige was ich noch sehen kann und nicht lösen kann, ist das ... ...http://fs5.directupload.net/images/161102/ssm6uo43.jpg
RECHTSKLICK auf Papierkorb, da wird YAC noch angezeigt, als weißes Blatt, wenn man draufklickt kommt iwas mim Explorer ... habs mal zusammen auf ein Bild zum verdeutlichen. Was kann ich da tun?

Ansonsten keine Ahnung, Kaspersky sagt nix mehr ... MBAM nochmal laufen lassen auch nix mehr ... :party:

cosinus 03.11.2016 10:48

Du hast doch etxra gefragt was der ESET Fund ist, du siehst doch selbst, dass sich das auf einen TEMP-Order bezieht :wtf:

Und nein zu YAC hab ich DICH gefragt wo du das noch alles in Windows siehst, das hat doch nix mit Fachmann zu tun!

Aber gut, lass mal nach ELEX und YAC suchen:

Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop:
SystemLook (32 bit) | SystemLook (64 bit)
  • Doppelklicke auf die SystemLook.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:
    Code:

    :filefind
    *elex*
    *yac*

    :folderfind
    *elex*
    *yac*

    :regfind
    elex
    yac

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auch auf dem Desktop als SystemLook.txt gespeichert.



Alle Zeitangaben in WEZ +1. Es ist jetzt 14:43 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130