kiwilina | 24.01.2017 16:55 | Hallo Matthias,
so geschafft:
Hier sind die gewünschten logfiles: Code:
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 22-01-2017
durchgeführt von Kiwilina (23-01-2017 20:02:08) Run:1
Gestartet von C:\Users\Kiwilina\Desktop
Geladene Profile: Kiwilina (Verfügbare Profile: Kiwilina)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
start
CloseProcesses:
C:\Users\Kiwilina\Downloads\vlc-2.2.4-win64.exe
EmptyTemp:
end
*****************
Prozesse erfolgreich geschlossen.
C:\Users\Kiwilina\Downloads\vlc-2.2.4-win64.exe => erfolgreich verschoben
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 16796180 B Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=fd929c94f9621e4fb8f6b2abe9b21cf2
# end=init
# utc_time=2017-01-23 07:55:36
# local_time=2017-01-23 08:55:36 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 32163
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=fd929c94f9621e4fb8f6b2abe9b21cf2
# end=updated
# utc_time=2017-01-23 08:05:18
# local_time=2017-01-23 09:05:18 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=fd929c94f9621e4fb8f6b2abe9b21cf2
# engine=32163
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2017-01-23 09:57:00
# local_time=2017-01-23 10:57:00 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode=freeze
# scanned=219231
# found=3
# cleaned=0
# scan_time=6701
sh=8AFA2F7551E0D6EA1B58C30C82C8028D97A5B44E ft=1 fh=cf8215d29364221c vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Kiwilina\Music\musik\Downloads\Audacity - CHIP-Installer.exe"
sh=40F6CA5EF25B7DBD42AE8B4FDA5F98144B1AD360 ft=1 fh=08965c270c124c2f vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung" ac=I fn="C:\Users\Kiwilina\Music\musik\Downloads\ccsetup519.exe"
sh=1238A14EFFA037B4A397312AA56D2952DBE464F5 ft=0 fh=0000000000000000 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Kiwilina\Music\musik\Downloads\winzip205-32.msi" Code:
HitmanPro 3.7.15.281
www.hitmanpro.com
Computer name . . . . : FRIDOLIN
Windows . . . . . . . : 6.3.0.9600.X64/4
User name . . . . . . : Fridolin\Kiwilina
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2017-01-24 16:14:43
Scan mode . . . . . . : Normal
Scan duration . . . . : 7m 24s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 1
Traces . . . . . . . : 6
Objects scanned . . . : 1.587.451
Files scanned . . . . : 31.156
Remnants scanned . . : 319.053 files / 1.237.242 keys
Malware _____________________________________________________________________
C:\Users\Kiwilina\Music\musik\Downloads\Audacity - CHIP-Installer.exe
Size . . . . . . . : 1.496.584 bytes
Age . . . . . . . : 29.2 days (2016-12-26 12:22:35)
Entropy . . . . . : 7.1
SHA-256 . . . . . : 851DDC6BBEA78EF4B52356C7898DFB912B300883259EB8A87E2932CA1752C6FF
Needs elevation . : Yes
RSA Key Size . . . : 2048
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:Downloader.Win32.DownloadSponsor.pe
Fuzzy . . . . . . : 103.0
Suspicious files ____________________________________________________________
C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\HE5SSX4E\FRST64[1].exe
Size . . . . . . . : 2.419.712 bytes
Age . . . . . . . : 3.8 days (2017-01-20 20:07:02)
Entropy . . . . . : 7.6
SHA-256 . . . . . : A6F5705974D580CD90356F383715E682E824FFE3E81E121AA97181C7CD7414AC
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-13.9s C:\FRST\
-13.9s C:\FRST\Logs\
-13.9s C:\FRST\Quarantine\
-13.9s C:\FRST\Hives\
-13.3s C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\706YIZE8\ShowMessage[4].htm
-12.5s C:\FRST\Hives\ERDNT.INF
-12.5s C:\FRST\Hives\ERDNT.CON
-12.4s C:\FRST\Hives\SYSTEM
-12.0s C:\FRST\Hives\SOFTWARE
-9.9s C:\FRST\Hives\SAM
-9.6s C:\FRST\Hives\SECURITY
-9.1s C:\FRST\Hives\DEFAULT
-9.0s C:\FRST\Hives\Users\
-9.0s C:\FRST\Hives\Users\00000001\
-9.0s C:\FRST\Hives\Users\00000001\NTUSER.DAT
-8.9s C:\FRST\Hives\Users\00000002\
-8.9s C:\FRST\Hives\Users\00000002\UsrClass.dat
-8.7s C:\FRST\Hives\COMPONENTS
-6.5s C:\FRST\Hives\SCHEMA.DAT
-5.1s C:\FRST\Hives\BCD
-5.0s C:\FRST\Hives\DRIVERS
-4.8s C:\FRST\Hives\ERDNT.EXE
-4.8s C:\FRST\Hives\ERDNTWIN.LOC
-4.8s C:\FRST\Hives\ERDNTDOS.LOC
-2.0s C:\Users\Kiwilina\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1BB09BEEC155258835C193A7AA85AA5B_43C47E83D9759203A117D940601E62BD
-2.0s C:\Users\Kiwilina\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1BB09BEEC155258835C193A7AA85AA5B_43C47E83D9759203A117D940601E62BD
-0.3s C:\Users\Kiwilina\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_556BB0FF4D382D90E7703209690E089E
-0.3s C:\Users\Kiwilina\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_556BB0FF4D382D90E7703209690E089E
0.0s C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\HE5SSX4E\FRST64[1].exe
C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\HE5SSX4E\FRST64[2].exe
Size . . . . . . . : 2.420.736 bytes
Age . . . . . . . : 0.8 days (2017-01-23 20:00:43)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 945C56ADCD33C43D4D6954E99B4427C92C0528C797B08783CD9BE3E9D95A5299
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-17.6s C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\706YIZE8\82[1].htm
0.0s C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\HE5SSX4E\FRST64[2].exe
1.0s C:\Users\Kiwilina\Desktop\FRST64.exe
27.7s C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\JCZMO0Y4\up64[1]
C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\JCZMO0Y4\FRST64[1].exe
Size . . . . . . . : 2.420.736 bytes
Age . . . . . . . : 0.8 days (2017-01-23 19:59:13)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 945C56ADCD33C43D4D6954E99B4427C92C0528C797B08783CD9BE3E9D95A5299
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
0.0s C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\JCZMO0Y4\FRST64[1].exe
3.8s C:\Users\Kiwilina\Desktop\FRST-OlderVersion\
C:\Users\Kiwilina\Desktop\FRST-OlderVersion\FRST64.exe
Size . . . . . . . : 2.419.712 bytes
Age . . . . . . . : 5.8 days (2017-01-18 21:43:26)
Entropy . . . . . : 7.6
SHA-256 . . . . . : A6F5705974D580CD90356F383715E682E824FFE3E81E121AA97181C7CD7414AC
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-8.4s C:\Windows\WinSxS\x86_microsoft-windows-msident_31bf3856ad364e35_6.3.9600.16384_none_acc4fe01684f7040\msident.dll
-7.7s C:\Windows\WinSxS\x86_microsoft-windows-msidle_31bf3856ad364e35_6.3.9600.16384_none_6021a161be407b88\msidle.dll
-6.8s C:\Windows\WinSxS\x86_microsoft-windows-msieftp.resources_31bf3856ad364e35_6.3.9600.16384_de-de_a022fad68d682532\msieftp.dll.mui
-6.3s C:\Windows\WinSxS\x86_microsoft-windows-msieftp.resources_31bf3856ad364e35_6.3.9600.16456_de-de_a0456d148d4e0134\msieftp.dll.mui
-5.7s C:\Windows\WinSxS\x86_microsoft-windows-msieftp_31bf3856ad364e35_6.3.9600.16477_none_ab025ba769705a6d\msieftp.dll
-4.3s C:\Windows\WinSxS\x86_microsoft-windows-msinfo32-exe-common_31bf3856ad364e35_6.3.9600.16384_none_1ae4c3a2067a738e\msinfo32.exe
-2.2s C:\Windows\WinSxS\x86_microsoft-windows-mskeyprotcli-dll_31bf3856ad364e35_6.3.9600.16384_none_5d08b497f59344e3\mskeyprotcli.dll
-1.4s C:\Windows\WinSxS\x86_microsoft-windows-mskeyprotect-dll_31bf3856ad364e35_6.3.9600.16384_none_66f44054eb167e85\mskeyprotect.dll
0.0s C:\Users\Kiwilina\Desktop\FRST-OlderVersion\FRST64.exe
0.1s C:\Windows\WinSxS\x86_microsoft-windows-msls31_31bf3856ad364e35_11.0.9600.16384_none_73a69a3fcd0ae0a2\msls31.dll
1.5s C:\Windows\WinSxS\x86_microsoft-windows-msmpeg2adec_31bf3856ad364e35_6.3.9600.16384_none_267a17a8d2f1523e\msmpeg2adec.dll
C:\Users\Kiwilina\Desktop\FRST64.exe
Size . . . . . . . : 2.420.736 bytes
Age . . . . . . . : 0.8 days (2017-01-23 20:00:44)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 945C56ADCD33C43D4D6954E99B4427C92C0528C797B08783CD9BE3E9D95A5299
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-18.6s C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\706YIZE8\82[1].htm
-1.0s C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\HE5SSX4E\FRST64[2].exe
0.0s C:\Users\Kiwilina\Desktop\FRST64.exe
26.6s C:\Users\Kiwilina\AppData\Local\Microsoft\Windows\INetCache\IE\JCZMO0Y4\up64[1] und FRST mit den folgenden posts Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 22-01-2017
durchgeführt von Kiwilina (Administrator) auf FRIDOLIN (24-01-2017 16:27:05)
Gestartet von C:\Users\Kiwilina\Desktop
Geladene Profile: Kiwilina (Verfügbare Profile: Kiwilina)
Platform: Windows 8.1 (Update) (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\AsusWSWinService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\ModuleCore\ModuleCoreService.exe
(Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\VSCore_15_5\mcapexe.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\CSP\2.2.351.0\McCSPServiceHost.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Spotify Ltd) C:\Users\Kiwilina\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\AsusWSPanel.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(Intel Security) C:\Program Files\Common Files\mcafee\ClientAnalytics\Legacy\McClientAnalytics.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [1080992 2014-05-15] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\ASUSWSLoader.exe [63296 2014-02-25] ()
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-4115519731-4286334722-3467942832-1001\...\Run: [Spotify Web Helper] => C:\Users\Kiwilina\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2016-12-26] (Spotify Ltd)
HKU\S-1-5-21-4115519731-4286334722-3467942832-1001\...\Run: [Spotify] => C:\Users\Kiwilina\AppData\Roaming\Spotify\Spotify.exe [7153264 2016-12-26] (Spotify Ltd)
HKU\S-1-5-21-4115519731-4286334722-3467942832-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-11-17] (Apple Inc.)
HKU\S-1-5-21-4115519731-4286334722-3467942832-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2016-11-17] (Apple Inc.)
HKU\S-1-5-21-4115519731-4286334722-3467942832-1001\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2016-11-17] (Apple Inc.)
HKU\S-1-5-21-4115519731-4286334722-3467942832-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2016-11-17] (Apple Inc.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.1.2.301\ASUSWSShellExt64.dll [2013-06-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.1.2.301\ASUSWSShellExt64.dll [2013-06-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.1.2.301\ASUSWSShellExt64.dll [2013-06-26] (ASUS Cloud Corporation.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{49788763-CAC8-4A1B-9AB8-D15308906AA9}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{75221F87-D20F-4C9B-97A1-033F102B22A8}: [DhcpNameServer] 192.13.128.24
Internet Explorer:
==================
HKU\S-1-5-21-4115519731-4286334722-3467942832-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com
HKU\S-1-5-21-4115519731-4286334722-3467942832-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB
SearchScopes: HKU\S-1-5-21-4115519731-4286334722-3467942832-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4115519731-4286334722-3467942832-1001 -> {85A60A59-D3D8-468F-B598-FB4393789EF4} URL = hxxps://www.google.de/search?q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-01-09] (McAfee, Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-01-09] (McAfee, Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-01-09] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-01-09] (McAfee, Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-01-09] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-01-09] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2016-11-18] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2016-11-18] (McAfee, Inc.)
FireFox:
========
FF DefaultProfile: kd3m7foc.default
FF ProfilePath: C:\Users\Kiwilina\AppData\Roaming\Mozilla\Firefox\Profiles\kd3m7foc.default [2017-01-24]
FF NewTab: Mozilla\Firefox\Profiles\kd3m7foc.default -> about:home
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\kd3m7foc.default -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\kd3m7foc.default -> Google
FF Homepage: Mozilla\Firefox\Profiles\kd3m7foc.default -> about:home
FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-01-16]
FF SearchPlugin: C:\Users\Kiwilina\AppData\Roaming\Mozilla\Firefox\Profiles\kd3m7foc.default\searchplugins\google-lavasoft.xml [2017-01-21]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2017-01-19] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2016-11-18] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2016-11-18] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\AsusWSWinService.exe [71680 2014-02-25] (ASUS Cloud Corporation) [Datei ist nicht signiert]
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-01-28] (WildTangent)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [135496 2017-01-24] (SurfRight B.V.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-17] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [188352 2017-01-09] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_5\McAPExe.exe [963176 2016-10-07] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-29] (McAfee, Inc.)
R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.2.351.0\\McCSPServiceHost.exe [1934968 2016-10-17] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [1307752 2016-10-20] (McAfee, Inc.)
S2 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [242704 2016-09-08] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [384016 2016-09-08] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [331280 2016-09-08] (McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1473128 2016-10-07] (McAfee, Inc.)
S3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1041512 2016-09-08] (Intel Security, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [71952 2014-03-31] (ASUS Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [88120 2016-09-09] (McAfee, Inc.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77416 2016-12-14] ()
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [216704 2016-08-02] (McAfee, Inc.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-06] ( )
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [176064 2017-01-21] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [102856 2017-01-24] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-01-24] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [250816 2017-01-24] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [91584 2017-01-24] (Malwarebytes)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2013-10-28] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [477752 2016-09-09] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [364088 2016-09-09] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [85656 2016-09-09] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [512056 2016-09-09] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [884792 2016-09-09] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [527496 2016-09-09] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [109336 2016-09-09] (McAfee, Inc.)
R3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [110136 2016-09-09] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [252984 2016-09-09] (McAfee, Inc.)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [444632 2013-10-18] (Realsil Semiconductor Corporation)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
U0 msahci; system32\drivers\msahci.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-01-24 16:12 - 2017-01-24 16:13 - 00001923 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2017-01-24 16:12 - 2017-01-24 16:13 - 00000000 ____D C:\Program Files\HitmanPro
2017-01-24 16:11 - 2017-01-24 16:12 - 00000000 ____D C:\ProgramData\HitmanPro
2017-01-24 16:10 - 2017-01-24 16:10 - 11581544 _____ (SurfRight B.V.) C:\Users\Kiwilina\Downloads\HitmanPro_x64.exe
2017-01-24 16:10 - 2017-01-24 16:10 - 11581544 _____ (SurfRight B.V.) C:\Users\Kiwilina\Downloads\HitmanPro_x64(1).exe
2017-01-24 16:10 - 2017-01-24 16:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2017-01-24 12:05 - 2017-01-24 12:05 - 00003480 _____ C:\Windows\System32\Tasks\ASUS Live Update1
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\Program Files (x86)\ESET
2017-01-23 20:54 - 2017-01-23 20:54 - 02870984 _____ (ESET) C:\Users\Kiwilina\Downloads\esetsmartinstaller_deu.exe
2017-01-23 20:32 - 2017-01-23 20:32 - 00007599 _____ C:\Users\Kiwilina\AppData\Local\Resmon.ResmonCfg
2017-01-23 20:02 - 2017-01-23 20:14 - 00000717 _____ C:\Users\Kiwilina\Desktop\Fixlog.txt
2017-01-23 19:59 - 2017-01-23 20:00 - 00000000 ____D C:\Users\Kiwilina\Desktop\FRST-OlderVersion
2017-01-23 19:54 - 2017-01-23 19:54 - 00000088 _____ C:\Users\Kiwilina\Desktop\Fixlist.txt
2017-01-21 15:03 - 2017-01-21 15:04 - 00027559 _____ C:\Users\Kiwilina\Desktop\Addition.txt
2017-01-21 14:58 - 2017-01-24 16:28 - 00021055 _____ C:\Users\Kiwilina\Desktop\FRST.txt
2017-01-21 14:57 - 2017-01-21 14:57 - 00001269 _____ C:\Users\Kiwilina\Desktop\mbam.txt
2017-01-21 14:35 - 2017-01-21 14:35 - 00176064 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-01-21 14:34 - 2017-01-24 16:07 - 00102856 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-01-21 14:34 - 2017-01-24 16:07 - 00091584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-01-21 14:34 - 2017-01-24 16:06 - 00250816 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-21 14:34 - 2017-01-24 16:06 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-01-21 14:34 - 2017-01-21 14:34 - 00001885 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-01-21 14:34 - 2017-01-21 14:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-01-21 14:34 - 2017-01-21 14:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-21 14:34 - 2017-01-21 14:34 - 00000000 ____D C:\Program Files\Malwarebytes
2017-01-21 14:34 - 2016-12-14 12:55 - 00077416 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-01-21 14:19 - 2017-01-21 14:19 - 00001142 _____ C:\Users\Kiwilina\Desktop\Willkommen zur ASUS Produktregistrierung.lnk
2017-01-21 14:18 - 2017-01-21 14:26 - 00000000 ____D C:\AdwCleaner
2017-01-21 14:17 - 2017-01-21 14:17 - 03988944 _____ C:\Users\Kiwilina\Desktop\AdwCleaner_6.042.exe
2017-01-21 14:10 - 2017-01-21 14:10 - 00000000 ____D C:\Users\Kiwilina\Documents\Neuer Ordner
2017-01-21 14:10 - 2017-01-21 14:10 - 00000000 ____D C:\Users\Kiwilina\Documents\Ceca
2017-01-21 11:42 - 2017-01-24 11:02 - 00003846 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse
2017-01-20 20:06 - 2017-01-24 16:27 - 00000000 ____D C:\FRST
2017-01-19 21:00 - 2017-01-23 19:19 - 00004020 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse
2017-01-18 22:08 - 2017-01-18 22:20 - 00239778 _____ C:\TDSSKiller.3.1.0.12_18.01.2017_22.08.18_log.txt
2017-01-18 22:05 - 2017-01-18 22:06 - 00007096 _____ C:\TDSSKiller.3.1.0.12_18.01.2017_22.05.45_log.txt
2017-01-18 22:01 - 2017-01-18 22:02 - 00007096 _____ C:\Users\Kiwilina\Desktop\TDSSKiller.3.1.0.12_18.01.2017_22.01.24_log.txt
2017-01-18 22:00 - 2017-01-18 22:00 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Kiwilina\Desktop\tdsskiller.exe
2017-01-18 21:56 - 2017-01-18 21:58 - 00027384 _____ C:\Users\Kiwilina\Downloads\Addition.txt
2017-01-18 21:45 - 2017-01-18 21:59 - 00016513 _____ C:\Users\Kiwilina\Downloads\FRST.txt
2017-01-18 21:43 - 2017-01-23 20:00 - 02420736 _____ (Farbar) C:\Users\Kiwilina\Desktop\FRST64.exe
2017-01-18 18:13 - 2017-01-18 18:13 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2017-01-16 16:53 - 2017-01-16 16:55 - 00000000 ____D C:\ProgramData\tmp
2017-01-16 16:53 - 2017-01-16 16:53 - 00000979 _____ C:\Users\Public\Desktop\CEWE FOTOIMPORTER.lnk
2017-01-16 16:53 - 2017-01-16 16:53 - 00000964 _____ C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
2017-01-16 16:53 - 2017-01-16 16:53 - 00000949 _____ C:\Users\Public\Desktop\dm-Fotowelt.lnk
2017-01-16 16:53 - 2017-01-16 16:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dm-Fotowelt
2017-01-16 16:53 - 2017-01-16 16:53 - 00000000 ____D C:\ProgramData\hps
2017-01-16 16:23 - 2017-01-16 16:23 - 00000000 ____D C:\Program Files\dm
2017-01-16 16:22 - 2017-01-16 16:22 - 01628472 _____ C:\Users\Kiwilina\Downloads\setup_dm_Fotowelt.exe
2017-01-14 23:30 - 2017-01-14 23:30 - 00002760 _____ C:\Windows\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance
2017-01-14 20:56 - 2017-01-14 21:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2017-01-10 21:27 - 2017-01-10 21:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-01-10 21:27 - 2017-01-10 21:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-01-10 21:27 - 2017-01-10 21:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-01-10 21:25 - 2017-01-10 21:25 - 13165792 _____ (Microsoft Corporation) C:\Users\Kiwilina\Downloads\Silverlight_x64.exe
2017-01-10 19:36 - 2017-01-10 19:37 - 00000000 ____D C:\Users\Default\AppData\Local\AVG
2017-01-10 19:36 - 2017-01-10 19:37 - 00000000 ____D C:\Users\Default User\AppData\Local\AVG
2017-01-10 18:36 - 2017-01-10 18:36 - 20358232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2017-01-10 17:04 - 2017-01-10 17:05 - 00000000 ____D C:\Users\Kiwilina\Documents\Lena
2017-01-10 17:03 - 2017-01-10 17:03 - 00000000 ____D C:\Users\Kiwilina\Documents\Benutzerdefinierte Office-Vorlagen
2017-01-09 19:27 - 2017-01-09 19:27 - 00035618 _____ C:\Users\Kiwilina\Downloads\Haushaltsbudget.xlsx
2017-01-09 19:25 - 2017-01-09 19:25 - 00001004 _____ C:\Users\Public\Desktop\AVG.lnk
2017-01-09 19:25 - 2017-01-09 19:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2017-01-09 19:23 - 2017-01-23 21:49 - 00003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-01-09 19:23 - 2017-01-09 19:27 - 00000000 ____D C:\Program Files (x86)\AVG
2017-01-09 19:22 - 2017-01-21 14:04 - 00000000 ____D C:\Users\Kiwilina\AppData\Local\AvgSetupLog
2017-01-09 19:22 - 2017-01-09 19:27 - 00000000 ____D C:\Users\Kiwilina\AppData\Local\Avg
2017-01-09 19:22 - 2017-01-09 19:27 - 00000000 ____D C:\ProgramData\Avg
2017-01-08 13:32 - 2015-07-30 15:04 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-01-08 13:32 - 2015-07-30 14:48 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-01-08 00:08 - 2016-12-01 15:13 - 00869576 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2017-01-08 00:08 - 2016-12-01 15:13 - 00678592 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2017-01-08 00:08 - 2016-12-01 15:11 - 00875720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2017-01-08 00:08 - 2016-12-01 15:11 - 00536768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2017-01-08 00:08 - 2016-10-20 14:14 - 00029888 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll
2017-01-08 00:08 - 2016-10-20 14:10 - 00028352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll
2017-01-05 18:01 - 2017-01-05 18:01 - 00001255 _____ C:\Users\Kiwilina\Desktop\Macgo Windows Blu-ray Player.lnk
2017-01-05 18:01 - 2017-01-05 18:01 - 00000000 ____D C:\Users\Kiwilina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macgo Windows Blu-ray Player
2017-01-05 18:01 - 2017-01-05 18:01 - 00000000 ____D C:\Users\Kiwilina\AppData\Local\MacGo
2017-01-05 18:01 - 2017-01-05 18:01 - 00000000 ____D C:\Program Files (x86)\MacGo
2017-01-05 18:00 - 2017-01-05 18:00 - 38318704 _____ (Macgo Inc.) C:\Users\Kiwilina\Downloads\Mac_Bluray_Player_for_Windows.exe
2017-01-05 17:51 - 2017-01-05 17:51 - 00000000 ____D C:\Users\Kiwilina\AppData\Roaming\dvdcss
2017-01-05 17:48 - 2017-01-05 17:49 - 00000000 ____D C:\Users\Kiwilina\AppData\Roaming\vlc
2017-01-05 17:48 - 2017-01-05 17:48 - 00000889 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-01-05 17:48 - 2017-01-05 17:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-01-05 17:47 - 2017-01-05 17:47 - 00000000 ____D C:\Program Files\VideoLAN
2017-01-04 17:28 - 2016-06-18 21:06 - 00590688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2017-01-04 17:28 - 2016-06-10 19:11 - 06521800 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2017-01-04 17:28 - 2016-06-10 19:11 - 01487992 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2017-01-04 17:28 - 2016-05-18 21:28 - 02635264 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2017-01-04 17:28 - 2016-04-09 23:10 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-01-04 17:28 - 2016-04-07 17:06 - 00927744 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2017-01-04 17:28 - 2016-04-06 19:17 - 18825216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2017-01-04 17:28 - 2016-04-06 17:25 - 15158272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-01-04 17:27 - 2016-06-18 21:06 - 00072408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpfve.sys
2017-01-04 17:27 - 2016-06-11 20:52 - 00057184 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2017-01-04 17:27 - 2016-06-11 19:05 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\gpresult.exe
2017-01-04 17:27 - 2016-06-11 18:14 - 00192512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpresult.exe
2017-01-04 17:27 - 2016-06-11 17:50 - 00987136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-01-04 17:27 - 2016-06-11 17:46 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\tpmvsc.dll
2017-01-04 17:27 - 2016-06-11 17:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2017-01-04 17:27 - 2016-06-11 17:37 - 00796672 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2017-01-04 17:27 - 2016-06-11 17:24 - 00800768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-01-04 17:27 - 2016-06-11 17:20 - 00413184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2017-01-04 17:27 - 2016-06-11 17:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2017-01-04 17:27 - 2016-06-10 21:07 - 03820544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-01-04 17:27 - 2016-06-10 19:11 - 00261376 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2017-01-04 17:27 - 2016-06-10 19:11 - 00125024 _____ (Microsoft Corporation) C:\Windows\system32\cryptxml.dll
2017-01-04 17:27 - 2016-06-10 19:10 - 00099136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptxml.dll
2017-01-04 17:27 - 2016-06-10 19:07 - 03273728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-01-04 17:27 - 2016-06-09 20:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2017-01-04 17:27 - 2016-06-09 19:18 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2017-01-04 17:27 - 2016-06-07 19:10 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll
2017-01-04 17:27 - 2016-06-07 18:13 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hbaapi.dll
2017-01-04 17:27 - 2016-05-18 22:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2017-01-04 17:27 - 2016-05-18 22:15 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2017-01-04 17:27 - 2016-05-18 21:56 - 01291776 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2017-01-04 17:27 - 2016-05-18 21:33 - 01060352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2017-01-04 17:27 - 2016-05-18 21:16 - 02317824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2017-01-04 17:27 - 2016-05-14 21:26 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-01-04 17:27 - 2016-05-14 06:19 - 01134768 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-01-04 17:27 - 2016-05-14 00:08 - 00111616 ____C (Microsoft Corporation) C:\Windows\system32\hidclass.sys
2017-01-04 17:27 - 2016-05-14 00:08 - 00111616 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2017-01-04 17:27 - 2016-05-14 00:08 - 00032768 ____C (Microsoft Corporation) C:\Windows\system32\hidusb.sys
2017-01-04 17:27 - 2016-05-14 00:08 - 00032768 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2017-01-04 17:27 - 2016-05-14 00:08 - 00032512 ____C (Microsoft Corporation) C:\Windows\system32\hidparse.sys
2017-01-04 17:27 - 2016-05-14 00:08 - 00032512 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2017-01-04 17:27 - 2016-05-13 23:24 - 00862720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-01-04 17:27 - 2016-05-13 22:42 - 03667968 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-01-04 17:27 - 2016-05-13 22:30 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-01-04 17:27 - 2016-05-13 22:29 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-01-04 17:27 - 2016-05-13 22:27 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2017-01-04 17:27 - 2016-05-13 22:27 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-01-04 17:27 - 2016-05-13 22:26 - 02230784 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-01-04 17:27 - 2016-05-13 22:26 - 00897024 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-01-04 17:27 - 2016-05-13 22:18 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-01-04 17:27 - 2016-05-13 22:18 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-01-04 17:27 - 2016-05-13 22:16 - 00727040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-01-04 17:27 - 2016-05-13 22:16 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-01-04 17:27 - 2016-05-12 19:36 - 00034600 _____ (Microsoft Corporation) C:\Windows\system32\UserAccountBroker.exe
2017-01-04 17:27 - 2016-05-12 18:39 - 00030984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserAccountBroker.exe
2017-01-04 17:27 - 2016-05-06 22:59 - 00331608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2017-01-04 17:27 - 2016-04-09 23:15 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2017-01-04 17:27 - 2016-04-09 23:14 - 00306176 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Geolocation.dll
2017-01-04 17:27 - 2016-04-09 23:09 - 00754176 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2017-01-04 17:27 - 2016-04-09 23:02 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll
2017-01-04 17:27 - 2016-04-09 22:59 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Geolocation.dll
2017-01-04 17:27 - 2016-04-09 22:59 - 00020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2017-01-04 17:27 - 2016-04-09 22:56 - 00543232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2017-01-04 17:27 - 2016-04-09 22:55 - 00881152 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2017-01-04 17:27 - 2016-04-09 22:52 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2017-01-04 17:27 - 2016-04-06 22:21 - 00114528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mup.sys
2017-01-04 17:27 - 2016-04-06 19:20 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2017-01-04 17:27 - 2016-04-05 23:37 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys
2017-01-04 17:27 - 2016-04-02 14:58 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\BdeHdCfgLib.dll
2017-01-04 17:27 - 2016-04-01 18:40 - 00322048 _____ (Microsoft Corporation) C:\Windows\system32\fvecpl.dll
2017-01-04 17:27 - 2016-04-01 17:53 - 00348672 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll
2017-01-04 17:27 - 2016-04-01 17:50 - 00737280 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2017-01-04 17:27 - 2016-02-04 17:57 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\httpprxp.dll
2017-01-04 17:27 - 2016-02-04 17:49 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\httpprxm.dll
2017-01-04 17:27 - 2016-02-04 17:39 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\adhsvc.dll
2017-01-04 17:27 - 2014-10-29 03:45 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2017-01-04 17:27 - 2014-10-29 03:41 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\gpupdate.exe
2017-01-04 17:27 - 2014-10-29 03:23 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerWizardElev.exe
2017-01-04 17:27 - 2014-10-29 03:13 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\BdeUISrv.exe
2017-01-04 17:27 - 2014-10-29 02:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpupdate.exe
2017-01-04 17:27 - 2014-10-29 02:52 - 00809984 _____ (Microsoft Corporation) C:\Windows\system32\fvewiz.dll
2017-01-04 17:27 - 2014-10-29 02:27 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\adhapi.dll
2017-01-04 17:27 - 2014-10-29 02:26 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerDeviceEncryption.exe
2017-01-04 17:27 - 2014-10-29 02:26 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\crypttpmeksvc.dll
2017-01-04 17:27 - 2014-10-29 02:20 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\keepaliveprovider.dll
2017-01-04 17:27 - 2014-10-29 02:16 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2017-01-04 17:27 - 2014-10-29 02:04 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\CertEnrollCtrl.exe
2017-01-04 17:27 - 2014-10-29 02:03 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypttpmeksvc.dll
2017-01-04 17:27 - 2014-10-29 01:54 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2017-01-04 17:27 - 2014-10-29 01:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnrollCtrl.exe
2017-01-04 16:43 - 2016-12-22 23:42 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-01-04 16:43 - 2016-12-22 23:42 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-04 12:48 - 2016-05-12 19:38 - 00135336 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2017-01-04 12:48 - 2016-05-12 18:43 - 00115704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2017-01-04 12:48 - 2016-05-12 17:17 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll
2017-01-04 12:48 - 2016-05-12 17:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll
2017-01-04 12:48 - 2016-05-12 17:07 - 01360896 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2017-01-04 12:48 - 2016-05-12 16:59 - 00398848 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2017-01-04 12:48 - 2016-05-12 16:43 - 00291328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
2017-01-04 12:48 - 2016-05-12 16:37 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
2017-01-04 12:48 - 2016-01-10 18:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\cfgbkend.dll
2017-01-04 12:48 - 2016-01-10 18:16 - 00898048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2017-01-04 12:48 - 2016-01-10 18:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgbkend.dll
2017-01-04 12:48 - 2016-01-10 18:12 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2017-01-04 12:48 - 2016-01-10 17:51 - 00702976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2017-01-04 12:48 - 2016-01-10 17:49 - 00443392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2017-01-04 12:48 - 2015-12-30 22:53 - 02017624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-01-04 12:48 - 2015-04-30 00:22 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\WiFiDisplay.dll
2017-01-04 12:47 - 2016-03-31 07:50 - 01307328 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-01-04 12:47 - 2016-03-31 04:40 - 00747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-01-04 12:47 - 2015-01-27 04:44 - 00933888 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2017-01-04 12:47 - 2015-01-24 02:51 - 00816128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe
2017-01-04 12:43 - 2015-01-23 08:17 - 00723072 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2017-01-04 12:43 - 2015-01-23 06:02 - 00560392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2017-01-04 12:43 - 2014-11-10 03:29 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupStatusProvider.dll
2017-01-04 12:43 - 2014-11-10 02:51 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DeviceSetupStatusProvider.dll
2017-01-04 12:42 - 2014-03-06 10:19 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2017-01-04 12:39 - 2015-05-30 22:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2017-01-04 12:39 - 2015-05-30 20:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2017-01-04 12:39 - 2015-05-30 20:35 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2017-01-04 12:39 - 2015-03-09 03:02 - 00057856 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2017-01-04 12:39 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-01-04 12:39 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2017-01-04 12:39 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2017-01-04 12:39 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2017-01-04 12:39 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2017-01-04 12:39 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2017-01-04 12:39 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2017-01-04 12:35 - 2014-10-29 05:00 - 00544408 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2017-01-04 12:35 - 2014-10-29 05:00 - 00125504 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2017-01-04 12:35 - 2014-10-29 04:59 - 00014144 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\swenum.sys
2017-01-04 12:35 - 2014-10-29 04:58 - 00014528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys
2017-01-04 12:35 - 2014-10-29 04:57 - 01576312 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2017-01-04 12:35 - 2014-10-29 04:57 - 00643064 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2017-01-04 12:35 - 2014-10-29 04:52 - 00962216 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2017-01-04 12:35 - 2014-10-29 04:18 - 00016504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psapi.dll
2017-01-04 12:35 - 2014-10-29 04:12 - 00430176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2017-01-04 12:35 - 2014-10-29 04:12 - 00102728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2017-01-04 12:35 - 2014-10-29 04:10 - 01287112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2017-01-04 12:35 - 2014-10-29 04:10 - 00492232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2017-01-04 12:35 - 2014-10-29 04:07 - 00801584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2017-01-04 12:35 - 2014-10-29 03:45 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2017-01-04 12:35 - 2014-10-29 02:23 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2017-01-04 12:35 - 2014-10-29 02:12 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\defragsvc.dll
2017-01-04 12:35 - 2014-10-29 02:10 - 00302080 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2017-01-04 12:35 - 2014-10-29 02:03 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2017-01-04 12:35 - 2014-10-29 02:03 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2017-01-04 12:35 - 2014-10-29 02:01 - 00843776 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2017-01-04 12:35 - 2014-10-29 01:56 - 01337344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2017-01-04 12:35 - 2014-10-29 01:52 - 01275904 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2017-01-04 12:35 - 2014-10-29 01:46 - 09530368 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2017-01-04 12:35 - 2014-10-29 01:46 - 01015808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-01-04 12:35 - 2014-10-29 01:39 - 01000448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2017-01-04 12:35 - 2014-10-29 01:37 - 06386176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2017-01-04 12:34 - 2014-10-29 05:00 - 02229168 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2017-01-04 12:34 - 2014-10-29 04:59 - 03460472 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2017-01-04 12:34 - 2014-10-29 04:57 - 03118096 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2017-01-04 12:34 - 2014-10-29 03:29 - 04483072 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2017-01-04 12:34 - 2014-10-29 02:45 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\rdpinput.exe
2017-01-04 12:34 - 2014-10-29 01:56 - 01028608 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2017-01-04 12:34 - 2014-10-29 01:45 - 00887296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2017-01-04 12:34 - 2014-10-07 07:45 - 03307112 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2017-01-04 12:34 - 2014-10-07 04:44 - 02890296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2017-01-04 12:33 - 2017-01-14 22:04 - 00000000 ____D C:\Windows\system32\MRT
2017-01-04 12:33 - 2014-10-29 05:10 - 01816008 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2017-01-04 12:33 - 2014-10-29 04:57 - 03138720 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2017-01-04 12:33 - 2014-10-29 04:57 - 01286048 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll
2017-01-04 12:33 - 2014-10-29 04:55 - 01543768 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2017-01-04 12:33 - 2014-10-29 04:52 - 01509688 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2017-01-04 12:33 - 2014-10-29 04:52 - 01165744 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2017-01-04 12:33 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2017-01-04 12:33 - 2014-10-29 04:52 - 00405456 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2017-01-04 12:33 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2017-01-04 12:33 - 2014-10-29 04:12 - 01907384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2017-01-04 12:33 - 2014-10-29 04:11 - 02689392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVCORE.DLL
2017-01-04 12:33 - 2014-10-29 04:11 - 01024200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2017-01-04 12:33 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2017-01-04 12:33 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2017-01-04 12:33 - 2014-10-29 03:25 - 00785920 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2017-01-04 12:33 - 2014-10-29 02:57 - 02924032 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2017-01-04 12:33 - 2014-10-29 02:57 - 01038336 _____ (Microsoft Corporation) C:\Windows\system32\aclui.dll
2017-01-04 12:33 - 2014-10-29 02:54 - 00366080 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2017-01-04 12:33 - 2014-10-29 02:51 - 00941056 _____ (Microsoft Corporation) C:\Windows\system32\XpsFilt.dll
2017-01-04 12:33 - 2014-10-29 02:47 - 02072064 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2017-01-04 12:33 - 2014-10-29 02:43 - 00960000 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2017-01-04 12:33 - 2014-10-29 02:38 - 04690432 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2017-01-04 12:33 - 2014-10-29 02:35 - 03256320 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2017-01-04 12:33 - 2014-10-29 02:31 - 02941952 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2017-01-04 12:33 - 2014-10-29 02:26 - 03561984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2017-01-04 12:33 - 2014-10-29 02:26 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\ReInfo.dll
2017-01-04 12:33 - 2014-10-29 02:24 - 02464768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2017-01-04 12:33 - 2014-10-29 02:24 - 02364928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2017-01-04 12:33 - 2014-10-29 02:24 - 00902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aclui.dll
2017-01-04 12:33 - 2014-10-29 02:11 - 01639424 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2017-01-04 12:33 - 2014-10-29 02:10 - 02469888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2017-01-04 12:33 - 2014-10-29 02:08 - 02174976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2017-01-04 12:33 - 2014-10-29 02:08 - 01822720 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
2017-01-04 12:33 - 2014-10-29 01:52 - 01461248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dui70.dll
2017-01-04 12:33 - 2014-10-29 01:48 - 03056128 _____ (Microsoft Corporation) C:\Windows\system32\xpsservices.dll
2017-01-04 12:33 - 2014-10-29 01:46 - 01919488 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2017-01-04 12:32 - 2014-10-29 04:55 - 00019264 _____ (Microsoft Corporation) C:\Windows\system32\dllhost.exe
2017-01-04 12:32 - 2014-10-29 04:52 - 01518504 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2017-01-04 12:32 - 2014-10-29 04:52 - 01064720 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2017-01-04 12:32 - 2014-10-29 04:52 - 00988544 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2017-01-04 12:32 - 2014-10-29 04:52 - 00821696 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2017-01-04 12:32 - 2014-10-29 04:52 - 00634768 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-01-04 12:32 - 2014-10-29 04:52 - 00580024 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmdev.dll
2017-01-04 12:32 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2017-01-04 12:32 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2017-01-04 12:32 - 2014-10-29 04:52 - 00020160 _____ (Microsoft Corporation) C:\Windows\system32\CompPkgSup.dll
2017-01-04 12:32 - 2014-10-29 04:10 - 01178104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2017-01-04 12:32 - 2014-10-29 04:07 - 01321192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2017-01-04 12:32 - 2014-10-29 04:07 - 00959112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2017-01-04 12:32 - 2014-10-29 04:07 - 00857384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2017-01-04 12:32 - 2014-10-29 04:07 - 00705008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2017-01-04 12:32 - 2014-10-29 04:07 - 00409040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2017-01-04 12:32 - 2014-10-29 04:05 - 00890128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2017-01-04 12:32 - 2014-10-29 03:50 - 01192960 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2017-01-04 12:32 - 2014-10-29 03:43 - 00685056 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll
2017-01-04 12:32 - 2014-10-29 03:31 - 00971264 _____ (Microsoft Corporation) C:\Windows\system32\sqlceqp40.dll
2017-01-04 12:32 - 2014-10-29 03:29 - 01246720 _____ (Microsoft Corporation) C:\Windows\system32\ogldrv.dll
2017-01-04 12:32 - 2014-10-29 03:28 - 01502208 _____ (Microsoft Corporation) C:\Windows\system32\xpssvcs.dll
2017-01-04 12:32 - 2014-10-29 03:26 - 00771584 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2017-01-04 12:32 - 2014-10-29 03:17 - 02003456 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2017-01-04 12:32 - 2014-10-29 03:17 - 00537088 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-01-04 12:32 - 2014-10-29 03:08 - 01540096 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2017-01-04 12:32 - 2014-10-29 03:07 - 06692352 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe
2017-01-04 12:32 - 2014-10-29 02:56 - 01526784 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-01-04 12:32 - 2014-10-29 02:54 - 00833536 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2017-01-04 12:32 - 2014-10-29 02:53 - 00881152 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelinesvc.exe
2017-01-04 12:32 - 2014-10-29 02:52 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-01-04 12:32 - 2014-10-29 02:50 - 01289216 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll
2017-01-04 12:32 - 2014-10-29 02:49 - 00742400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqlceqp40.dll
2017-01-04 12:32 - 2014-10-29 02:48 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2017-01-04 12:32 - 2014-10-29 02:45 - 00618496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2017-01-04 12:32 - 2014-10-29 02:43 - 01092608 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-01-04 12:32 - 2014-10-29 02:43 - 00933376 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2017-01-04 12:32 - 2014-10-29 02:42 - 03724800 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2017-01-04 12:32 - 2014-10-29 02:37 - 01563136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2017-01-04 12:32 - 2014-10-29 02:34 - 01114624 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2017-01-04 12:32 - 2014-10-29 02:34 - 01037824 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2017-01-04 12:32 - 2014-10-29 02:33 - 01056768 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
2017-01-04 12:32 - 2014-10-29 02:32 - 01843712 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
2017-01-04 12:32 - 2014-10-29 02:30 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe
2017-01-04 12:32 - 2014-10-29 02:25 - 01534464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2017-01-04 12:32 - 2014-10-29 02:21 - 00755712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2017-01-04 12:32 - 2014-10-29 02:18 - 01050624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMNetMgr.dll
2017-01-04 12:32 - 2014-10-29 02:17 - 01402368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2017-01-04 12:32 - 2014-10-29 02:17 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2017-01-04 12:32 - 2014-10-29 02:15 - 00809472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2017-01-04 12:32 - 2014-10-29 02:14 - 03553280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2017-01-04 12:32 - 2014-10-29 02:12 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\msTextPrediction.dll
2017-01-04 12:32 - 2014-10-29 02:09 - 00658944 _____ (Microsoft Corporation) C:\Windows\system32\duser.dll
2017-01-04 12:32 - 2014-10-29 02:08 - 01478144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPDMC.exe
2017-01-04 12:32 - 2014-10-29 02:08 - 00881664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
2017-01-04 12:32 - 2014-10-29 02:07 - 01396736 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2017-01-04 12:32 - 2014-10-29 02:07 - 01247232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Http.dll
2017-01-04 12:32 - 2014-10-29 02:03 - 00174592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReInfo.dll
2017-01-04 12:32 - 2014-10-29 02:01 - 01710592 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2017-01-04 12:32 - 2014-10-29 01:59 - 01636864 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll
2017-01-04 12:32 - 2014-10-29 01:56 - 01248256 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2017-01-04 12:32 - 2014-10-29 01:56 - 01001984 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll
2017-01-04 12:32 - 2014-10-29 01:46 - 01265152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RacEngn.dll
2017-01-04 12:32 - 2014-10-29 01:45 - 00918016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NaturalLanguage6.dll
2017-01-04 12:32 - 2014-10-29 01:41 - 02880000 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2017-01-04 12:32 - 2014-10-29 01:40 - 02104832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsservices.dll
2017-01-04 12:32 - 2014-10-29 01:38 - 01262080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2017-01-04 12:32 - 2014-10-29 01:37 - 00724480 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2017-01-04 12:32 - 2014-10-29 01:35 - 00772096 _____ (Microsoft Corporation) C:\Windows\system32\MrmIndexer.dll
2017-01-04 12:32 - 2014-10-29 01:35 - 00688128 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2017-01-04 12:32 - 2014-10-29 01:31 - 00626176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2017-01-04 12:32 - 2014-10-08 23:09 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2017-01-04 12:31 - 2017-01-14 21:48 - 135657872 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-01-04 12:31 - 2014-10-29 05:10 - 00430728 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll
2017-01-04 12:31 - 2014-10-29 05:09 - 01950280 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2017-01-04 12:31 - 2014-10-29 05:09 - 01309744 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-01-04 12:31 - 2014-10-29 05:09 - 01239576 _____ (Microsoft Corporation) C:\Windows\system32\Taskmgr.exe
2017-01-04 12:31 - 2014-10-29 05:00 - 00379568 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2017-01-04 12:31 - 2014-10-29 04:57 - 00662120 _____ (Microsoft Corporation) C:\Windows\system32\DMRServer.exe
2017-01-04 12:31 - 2014-10-29 04:55 - 00730824 _____ (Microsoft Corporation) C:\Windows\system32\clbcatq.dll
2017-01-04 12:31 - 2014-10-29 04:55 - 00426120 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2017-01-04 12:31 - 2014-10-29 04:52 - 00444728 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
2017-01-04 12:31 - 2014-10-29 04:18 - 01782912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2017-01-04 12:31 - 2014-10-29 04:18 - 01103768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Taskmgr.exe
2017-01-04 12:31 - 2014-10-29 04:18 - 00848568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2017-01-04 12:31 - 2014-10-29 04:11 - 00488064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpeffects.dll
2017-01-04 12:31 - 2014-10-29 04:10 - 00569128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clbcatq.dll
2017-01-04 12:31 - 2014-10-29 04:07 - 00551064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2017-01-04 12:31 - 2014-10-29 04:07 - 00482360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmdev.dll
2017-01-04 12:31 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-01-04 12:31 - 2014-10-29 04:07 - 00331048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll
2017-01-04 12:31 - 2014-10-29 03:56 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2017-01-04 12:31 - 2014-10-29 03:48 - 00925696 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2017-01-04 12:31 - 2014-10-29 03:48 - 00636416 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx02000.dll
2017-01-04 12:31 - 2014-10-29 03:45 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.Search.UriHandler.dll
2017-01-04 12:31 - 2014-10-29 03:42 - 01091584 _____ (Microsoft Corporation) C:\Windows\system32\opengl32.dll
2017-01-04 12:31 - 2014-10-29 03:40 - 00610816 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll
2017-01-04 12:31 - 2014-10-29 03:36 - 00546304 _____ (Microsoft Corporation) C:\Windows\system32\sqlcese40.dll
2017-01-04 12:31 - 2014-10-29 03:33 - 07558144 _____ (Microsoft Corporation) C:\Windows\system32\NL7Data0011.dll
2017-01-04 12:31 - 2014-10-29 03:33 - 00799744 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll
2017-01-04 12:31 - 2014-10-29 03:30 - 00734208 _____ (Microsoft Corporation) C:\Windows\system32\MSWB70804.dll
2017-01-04 12:31 - 2014-10-29 03:30 - 00734208 _____ (Microsoft Corporation) C:\Windows\system32\MSWB70404.dll
2017-01-04 12:31 - 2014-10-29 03:30 - 00734208 _____ (Microsoft Corporation) C:\Windows\system32\MSWB7001E.dll
2017-01-04 12:31 - 2014-10-29 03:30 - 00734208 _____ (Microsoft Corporation) C:\Windows\system32\MSWB70011.dll
2017-01-04 12:31 - 2014-10-29 03:29 - 00620544 _____ (Microsoft Corporation) C:\Windows\system32\dsound.dll
2017-01-04 12:31 - 2014-10-29 03:27 - 00899584 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2017-01-04 12:31 - 2014-10-29 03:27 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll
2017-01-04 12:31 - 2014-10-29 03:26 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\SmartCardSimulator.dll
2017-01-04 12:31 - 2014-10-29 03:21 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-01-04 12:31 - 2014-10-29 03:18 - 04616704 _____ (Microsoft Corporation) C:\Windows\system32\NlsData001d.dll
2017-01-04 12:31 - 2014-10-29 03:18 - 00784384 _____ (Microsoft Corporation) C:\Windows\system32\lpksetup.exe
2017-01-04 12:31 - 2014-10-29 03:17 - 04621312 _____ (Microsoft Corporation) C:\Windows\system32\NlsData0414.dll
2017-01-04 12:31 - 2014-10-29 03:17 - 04620288 _____ (Microsoft Corporation) C:\Windows\system32\NlsData0816.dll
2017-01-04 12:31 - 2014-10-29 03:16 - 04621312 _____ (Microsoft Corporation) C:\Windows\system32\NlsData0010.dll
2017-01-04 12:31 - 2014-10-29 03:16 - 04616704 _____ (Microsoft Corporation) C:\Windows\system32\NlsData0416.dll
2017-01-04 12:31 - 2014-10-29 03:11 - 01070080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2017-01-04 12:31 - 2014-10-29 03:11 - 00435712 _____ (Microsoft Corporation) C:\Windows\system32\mswmdm.dll
2017-01-04 12:31 - 2014-10-29 03:09 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2017-01-04 12:31 - 2014-10-29 03:08 - 00858624 _____ (Microsoft Corporation) C:\Windows\system32\comuid.dll
2017-01-04 12:31 - 2014-10-29 03:08 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmnet.dll
2017-01-04 12:31 - 2014-10-29 03:08 - 00390656 _____ (Microsoft Corporation) C:\Windows\system32\difxapi.dll
2017-01-04 12:31 - 2014-10-29 03:07 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2017-01-04 12:31 - 2014-10-29 03:06 - 01313792 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2017-01-04 12:31 - 2014-10-29 03:06 - 00980480 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll
2017-01-04 12:31 - 2014-10-29 03:06 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\MSAC3ENC.DLL
2017-01-04 12:31 - 2014-10-29 03:05 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\wiaaut.dll
2017-01-04 12:31 - 2014-10-29 03:04 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\WavDest.dll
2017-01-04 12:31 - 2014-10-29 03:03 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2017-01-04 12:31 - 2014-10-29 03:03 - 00832000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2017-01-04 12:31 - 2014-10-29 03:00 - 01861632 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2017-01-04 12:31 - 2014-10-29 03:00 - 00642560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2017-01-04 12:31 - 2014-10-29 02:59 - 00670720 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll
2017-01-04 12:31 - 2014-10-29 02:59 - 00564224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\riched20.dll
2017-01-04 12:31 - 2014-10-29 02:57 - 00777728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\opengl32.dll
2017-01-04 12:31 - 2014-10-29 02:56 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxs.dll
2017-01-04 12:31 - 2014-10-29 02:54 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2017-01-04 12:31 - 2014-10-29 02:53 - 01065984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d8.dll
2017-01-04 12:31 - 2014-10-29 02:53 - 00433152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqlcese40.dll
2017-01-04 12:31 - 2014-10-29 02:52 - 02829312 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
2017-01-04 12:31 - 2014-10-29 02:50 - 00711680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqlsrv32.dll
2017-01-04 12:31 - 2014-10-29 02:49 - 02236416 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll
2017-01-04 12:31 - 2014-10-29 02:48 - 00524800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSWB70804.dll
2017-01-04 12:31 - 2014-10-29 02:48 - 00524800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSWB70404.dll
2017-01-04 12:31 - 2014-10-29 02:48 - 00524800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSWB7001E.dll
2017-01-04 12:31 - 2014-10-29 02:48 - 00524800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSWB70011.dll
2017-01-04 12:31 - 2014-10-29 02:47 - 01096192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ogldrv.dll
2017-01-04 12:31 - 2014-10-29 02:47 - 00982016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpssvcs.dll
2017-01-04 12:31 - 2014-10-29 02:47 - 00517120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsound.dll
2017-01-04 12:31 - 2014-10-29 02:46 - 01497600 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2017-01-04 12:31 - 2014-10-29 02:46 - 01001472 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-01-04 12:31 - 2014-10-29 02:45 - 00717312 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2017-01-04 12:31 - 2014-10-29 02:45 - 00672768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll
2017-01-04 12:31 - 2014-10-29 02:42 - 00852480 _____ (Microsoft Corporation) C:\Windows\system32\PurchaseWindowsLicense.dll
2017-01-04 12:31 - 2014-10-29 02:37 - 01436160 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2017-01-04 12:31 - 2014-10-29 02:36 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2017-01-04 12:31 - 2014-10-29 02:36 - 01252864 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2017-01-04 12:31 - 2014-10-29 02:36 - 00609792 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2017-01-04 12:31 - 2014-10-29 02:32 - 00654848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comuid.dll
2017-01-04 12:31 - 2014-10-29 02:32 - 00512512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2017-01-04 12:31 - 2014-10-29 02:32 - 00391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmnet.dll
2017-01-04 12:31 - 2014-10-29 02:31 - 00761344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imapi2fs.dll
2017-01-04 12:31 - 2014-10-29 02:30 - 06465536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspaint.exe
2017-01-04 12:31 - 2014-10-29 02:30 - 00358400 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-01-04 12:31 - 2014-10-29 02:28 - 02213888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncCenter.dll
2017-01-04 12:31 - 2014-10-29 02:19 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll
2017-01-04 12:31 - 2014-10-29 02:18 - 01984000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certmgr.dll
2017-01-04 12:31 - 2014-10-29 02:17 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2017-01-04 12:31 - 2014-10-29 02:16 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2017-01-04 12:31 - 2014-10-29 02:16 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2017-01-04 12:31 - 2014-10-29 02:14 - 00854528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-01-04 12:31 - 2014-10-29 02:14 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2017-01-04 12:31 - 2014-10-29 02:12 - 00516608 _____ (Microsoft Corporation) C:\Windows\system32\es.dll
2017-01-04 12:31 - 2014-10-29 02:11 - 02597376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2017-01-04 12:31 - 2014-10-29 02:11 - 01323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2017-01-04 12:31 - 2014-10-29 02:10 - 00516096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2017-01-04 12:31 - 2014-10-29 02:09 - 00873984 _____ (Microsoft Corporation) C:\Windows\system32\provcore.dll
2017-01-04 12:31 - 2014-10-29 02:09 - 00809984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2017-01-04 12:31 - 2014-10-29 02:09 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
2017-01-04 12:31 - 2014-10-29 02:07 - 00657920 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2017-01-04 12:31 - 2014-10-29 02:07 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\ddraw.dll
2017-01-04 12:31 - 2014-10-29 02:06 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll
2017-01-04 12:31 - 2014-10-29 02:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-01-04 12:31 - 2014-10-29 02:05 - 00606720 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2017-01-04 12:31 - 2014-10-29 02:04 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.dll
2017-01-04 12:31 - 2014-10-29 02:03 - 00781824 _____ (Microsoft Corporation) C:\Windows\system32\wlidcli.dll
2017-01-04 12:31 - 2014-10-29 02:03 - 00740352 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2017-01-04 12:31 - 2014-10-29 02:03 - 00474112 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2017-01-04 12:31 - 2014-10-29 02:01 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2017-01-04 12:31 - 2014-10-29 02:01 - 00573952 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2017-01-04 12:31 - 2014-10-29 02:00 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
2017-01-04 12:31 - 2014-10-29 01:59 - 00649216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
2017-01-04 12:31 - 2014-10-29 01:57 - 01065472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2017-01-04 12:31 - 2014-10-29 01:55 - 00719360 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll
2017-01-04 12:31 - 2014-10-29 01:55 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\es.dll |